Anthropic has started invisibly watermarking text generated by supported new
Claude models. The move follows the
transparency requirements of the European AI Act and aims to make synthetic content easier to detect automatically. However, the watermark is explicitly not conclusive proof that Claude is the original author of any given text.
The change applies worldwide and isn’t limited to chats on Claude’s website. Anthropic says the marking is applied at the model level, so supported models will produce watermarked output via the API and in products like Claude Code and Cowork. Claude models offered through cloud platforms are also covered.
What exactly changes in Claude’s text?
Claude embeds an invisible, machine-readable signal in generated text. Readers won’t notice it, but specialized detection software should ultimately be able to pick up the pattern.
This is different from a visible label under an AI answer. Because the signal is part of the generated text, Anthropic says it will persist when users simply copy and paste. Some light edits may also not immediately destroy the signal.
Anthropic explains the mechanics and limits in its own
guide to marking Claude content. The company hasn’t disclosed all technical details yet.
For files, Anthropic is also adopting provenance data to make origin and edit history machine-readable. For supported file types, it uses digitally signed metadata under the C2PA standard.
AI writes the way “we” write—because it learns from human text. But it’s still computation. Behind the scenes, signals can be added to make content identifiable, to the human eye in some cases, and certainly to other models.
AI-assisted writing is popular and useful. At the same time, it remains important to be able to express your own thoughts. These new steps put that balance back in the spotlight.
Why is Anthropic rolling out watermarking now?
The immediate driver is the European AI Act. Article 50 requires providers of systems that generate synthetic text, audio, images, or video to make outputs machine-readable and detectable as artificially generated or manipulated.
The rules don’t mandate watermarking as the only solution. Metadata, cryptographic techniques, fingerprints, and other methods are also allowed. The approach must be sufficiently reliable, interoperable, effective, and robust—where technically feasible.
That caveat matters. Text watermarks are far more fragile than a visible label placed on an image.
For Claude models launched in the EU on or after August 2, 2026, support must be in place from day one. For models available before that date, Anthropic is in a transition phase. It’s therefore incorrect to claim that every existing Claude text is now guaranteed to carry a watermark.
A Claude watermark doesn’t prove authorship
The key challenge is interpretation. A detected watermark can show that Claude was involved in processing a text, but it does not prove that Claude wrote the original content end-to-end.
That distinction matters, for example, when someone asks Claude to translate, summarize, or edit a self-written text. The final version may contain a Claude signal even though a human authored the original.
The reverse is also true. If a Claude-generated text is heavily rewritten, translated, shortened, or merged with other content, the watermark can become harder to detect or disappear. Very short texts also carry too little signal for reliable detection.
A negative result therefore doesn’t automatically prove a text was created without AI.
This limitation makes watermark detection fundamentally different from a digital signature that unambiguously records a full provenance chain. A watermark is a technical signal, not a definitive verdict on authorship.
Google’s Gemini text has been watermarked for longer
Anthropic isn’t the first major AI vendor to watermark text. Google DeepMind already uses SynthID for text generated via the Gemini app and web interface.
SynthID subtly adjusts token selection probabilities during generation. Tokens are words, word pieces, or other small units a language model uses to build text. A detector can infer from the resulting pattern whether the SynthID signal is likely present.
Google itself stresses that SynthID isn’t a silver bullet for AI detection. It works best on longer, more varied texts and, according to Google, should be seen primarily as one component in broader systems that aim to identify AI-generated content.
That nuance matters when comparing it to Claude. So the idea that Anthropic is now the only major AI developer adding an invisible watermark to text is simply not correct.
And what about ChatGPT?
For ordinary written answers from ChatGPT, OpenAI, based on its current public documentation, has not announced a comparable, general-purpose text watermark.
OpenAI does use different provenance techniques for other types of generated content. For example, it combines C2PA Content Credentials and Google SynthID for images created with OpenAI systems.
OpenAI has researched text watermarks in the past, but also flagged the risk of false positives when detection is applied to massive volumes of text.
As a result, the three major AI providers take different approaches. Google has already extended SynthID to Gemini text, Anthropic is now rolling out its own machine-readable marking for Claude, and OpenAI’s publicly documented provenance efforts currently focus mainly on other media types.
Why watermarks could spark new debates
Watermarks can boost AI transparency—but only if organizations understand what a detection result really means.
That’s especially relevant for schools and universities. Finding a Claude watermark may be a reason to review AI use, but without additional context it doesn’t prove how much Claude wrote or what a student contributed themselves.
Publishers, employers, and newsrooms face the same issue. A text edited with AI could be flagged as processed by Claude even if most of the intellectual work was human.
Conversely, a fully AI-generated text might no longer be recognized as such after enough human editing.
Research into different text watermarks also shows how hard robust detection remains. A recent study, including an implementation of SynthID, found that meaning-preserving paraphrasing can sharply reduce detectability. The results don’t directly apply to Anthropic—Claude may use a different and not yet fully disclosed method—but they do highlight the broader technical challenge.
The AI Act could make watermarks the norm
Anthropic’s move fits into a broader shift in generative AI. European rules don’t force providers to use the exact same watermark, but they do push them to take machine-readable identification of synthetic content seriously.
That shifts the debate from whether AI output should be marked to how reliable, interoperable, and durable those markers can be.
Google has led the way on text watermarks with SynthID. Anthropic is now following with Claude, while OpenAI is visibly expanding provenance primarily around images and other media.
For users, a new reality is taking shape: an AI watermark can increasingly show that an AI system was involved somewhere in the production process. It just doesn’t automatically reveal who actually wrote the text.