AIToday
AI Safety & AlignmentAI Regulation & PolicyArs Technica AIPublished: Aug 13, 2026, 22:01 JST5 min read

Claude watermarks all processed text to comply with EU AI Act

Claude watermarks all processed text to comply with EU AI Act

Key takeaway

  • Anthropic is rolling out invisible watermarks on all content Claude processes—including lightly edited human text—to comply with the European Union's AI Act, which requires AI providers to mark generated or manipulated outputs.

  • However, the approach is broader than the law requires and easily defeated by copying text elsewhere or removing metadata, raising questions about whether watermarks will meaningfully clarify content origin or instead blur the line between fully generated and minimally edited material.

3 Key Points

  1. What happened

    Anthropic announced it will add invisible, machine-readable watermarks to all content processed by Claude—not just fully generated text—to comply with the European Union's AI Act, which requires watermarking of AI-generated or manipulated outputs. The company plans to deploy these marks on all new models globally starting immediately, with a detection tool to follow.

  2. Why it matters

    The watermark approach is broader than the EU law requires; Anthropic will mark even minor edits like grammar corrections, which the law explicitly exempts. This means users and readers may struggle to distinguish between fully generated text and slightly edited human writing, potentially muddying the watermark's intended purpose of clarifying what is AI-touched versus human-authored. The watermark is also easily defeated by copying text to another tool or removing metadata.

  3. What to watch

    Anthropic plans to eventually release a detection tool so users can independently verify watermarks, and will update previously released models by December 2026 (the EU's grace period deadline). Violations of the EU AI Act carry fines up to 15 million euros or 3 percent of a company's worldwide annual revenue.

In Depth

Read the full story

Anthropic has announced plans to apply invisible, machine-readable watermarks to all content processed by Claude, including text that Claude has only edited rather than generated from scratch. The company made this disclosure in a support article explaining its response to the European Union's AI Act, which mandates that all AI system providers watermark AI-generated or manipulated audio, image, text, and video outputs. The law applies to any AI model released after August 2 and grants providers until December 2026 to update previously released models; Anthropic confirmed that all new models offered globally will carry these marks "from day one." Text outputs will include embedded watermarks invisible to users, while generated files in other formats will include digitally signed provenance metadata where the technology supports it. Anthropic is taking what the article describes as a "nuke it from orbit" approach by watermarking all processed content where supported, even though the EU AI Act does not require watermarks for cases where an AI system performs "an assistive function for standard editing" (such as grammar correction) or does not "substantially alter" the user's text or its meaning. The company explained that users commonly employ Claude for proofreading, translation, summarization, and file conversion, and all such outputs "can carry a Claude mark even if the underlying ideas, text, or data originated from another source." Technically, watermarks work by biasing the model's word choices in a pattern distributed across an entire document, detectable only in aggregate by the correct tool. However, this approach carries significant limitations. The watermark is trivially easy to defeat: text can be copied and pasted into another system, which may destroy the watermark if that system edits it, and metadata can be removed via standard editing tools. Critically, the watermark is not particularly informative: Anthropic acknowledged that a detected mark "provides a signal that content was processed by Claude, but is not fully conclusive" and that "the content may have been processed by Claude," while also noting that "the lack of a detected mark doesn't mean the content wasn't AI-generated or processed." Anthropic said it plans to eventually share details on how to detect watermarks in order to provide the technical support the EU law requires. The company also stated that watermarks won't work on "some platforms or features" that don't support them. When Ars Technica asked Anthropic about a timeline for detection tool release, potential false negatives or positives, or how its watermarks might conflict with editing exemptions in the AI Act, Anthropic provided a statement that did not directly address these questions. The broader EU regulatory context adds another layer of complexity: while the AI Act requires watermarking at the model level, Section 50(4) addresses how publishers must explicitly label content for public disclosure. Under this regime, wholly AI-generated text—such as an AI-written novel or marketing copy—does not require a label in most cases; labeling is mandatory only if the text is meant to "inform the public on matters of public interest" and has not been editorially reviewed by a known, accountable human. This creates a paradox: a model-level watermark on all content contrasts with a publisher-level rule that does not require labeling for wholly generated text if an editor has reviewed it. Violations of the EU AI Act carry steep penalties, including fines up to 15 million euros or 3 percent of a company's worldwide annual revenue. Anthropic stated that "other labs are taking similar steps" and that the company plans to continue working on watermarks and detection methods that meet the EU's demands.

Context & Analysis

The EU AI Act, which applies to all AI models released after August 2, requires providers to watermark AI-generated or manipulated audio, image, text, and video outputs, with compliance required by December 2026 for previously released models. Anthropic's approach of watermarking all processed content—even minor edits—reflects a deliberate choice to go further than the law mandates. The regulation itself exempts assistive editing functions (such as grammar correction) and content that doesn't substantially alter the user's text, but a watermark applied at the model level cannot distinguish between a full rewrite and a comma fix. This mismatch between technical capability and legal intent creates a problem: users and downstream readers may interpret any watermark as signifying wholly generated content, when in fact it may only indicate that an AI touched the text. The watermark's weakness—that it is trivially easy to defeat through copying, pasting into another tool, or editing metadata—further undermines its reliability as a durably informative signal. Anthropic acknowledges that a detected mark "is not fully conclusive" and that "the content may have been processed by Claude," leaving significant room for misinterpretation, especially among the general public who may not grasp the difference between processing and generation.

FAQ

How will the watermark work?
Text outputs will carry embedded invisible watermarks, while other generated files will include digitally signed provenance metadata where supported. The watermarks work by biasing the model's word choices in a pattern spread across the document, detectable only in aggregate by the right tool.
What content will be watermarked?
All content processed by Claude will be watermarked, including cases where Claude only performs editing tasks like grammar correction, proofreading, translation, summarization, or file conversion. Anthropic noted that this goes beyond what the EU AI Act requires, which exempts assistive editing functions and cases where the AI doesn't substantially alter the text.
Can the watermark be removed?
Yes. The watermark will travel with text when copied and pasted elsewhere but may be destroyed if pasted into another system that edits the text. For images and video, screenshotting, recording, or using metadata editing tools will remove the provenance information.
Ars Technica AIRead Original Article

Get the latest AI Safety & Alignment news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleFoxconn expands beyond AI servers into EVs, robotics, chip fabs

The AI news that matters, in one minute each morning.

Sign up free