Briefly
- New Claude fashions launched within the EU on or after August 2, 2026 embed a machine-readable watermark in each piece of generated textual content, utilized on the mannequin degree.
- The markings apply worldwide throughout Claude, the API, Claude Code, and cloud companions.
- Open-source tasks to take away them appeared inside days.
Anthropic has begun embedding an imperceptible watermark in all textual content its latest Claude fashions generate. The change took impact for fashions launched within the EU on August 2, 2026, and Anthropic says it should apply worldwide.
Anthropic laid out the plan in a help article after signing the EU AI Act’s Code of Apply on transparency. In different phrases, it’s not precisely volunteering to do that. The mark reaches each Claude floor, from the chatbot and API to Claude Code and cloud companions reminiscent of AWS, Google Cloud, and Microsoft Foundry.

“When a supported Claude mannequin generates textual content, it weaves an imperceptible watermark straight into the textual content itself. You will not see it, and it does not change the that means, high quality, or readability of Claude’s response,” Anthropic mentioned. “As a result of the watermark is a part of the textual content, it should journey with the textual content when it is copied and pasted elsewhere, and will persist via some modifying.”
So it is a bit extra advanced than the standard strategies customers have a tendency to consider. When a supported Claude mannequin writes textual content, it weaves an imperceptible watermark straight into the phrases, with no seen tag. As a result of the mark is a part of the textual content, it survives copy-paste and, Anthropic admits, “could persist via some modifying.” Information get a second layer: signed metadata beneath the C2PA open normal (assume a digital transport manifest that information who produced a file and whether or not anybody altered it afterward).
The tactic stays secret
Anthropic hasn’t mentioned how the watermark is made. The help article calls it model-level (the mannequin is skilled with it) and text-native (it’s not an exterior software like metadata generator, for instance), however the detection documentation and the precise approach aren’t out but.
Researchers infer it is a statistical signature: The mannequin nudges its phrase selections towards a faint, detectable bias, the identical household of strategy Google makes use of in SynthID Textual content. That continues to be a guess till Anthropic publishes the detector.
However that isn’t pushing privateness lovers again, and a few consultants are already engaged on strategies to interrupt Anthropic’s secret watermarking. mikiane/claude-watermark-cleaner (106 stars on Github) scrubs invisible Unicode, then rewrites textual content with a non-Claude mannequin to disturb the token sample.
A bigger mission, guillaumemeyer/watermarks-remover (4.6k stars on Githum), strips Claude textual content marks plus C2PA and SynthID-class indicators throughout PNG, JPEG, SVG, PDF, and DOCX. The authors argue a statistical textual content mark is “not a dependable option to show origin” and principally pushes customers to spend a second mannequin move cleansing their very own writing. No removing might be assured till Anthropic ships its detector and thresholds.
Anthropic’s personal historical past makes the privateness response sharper. The corporate eliminated a hidden Claude Code tracker in March after researchers discovered it tagging some customers’ location and proxy use via undisclosed Unicode markers—the identical quiet-marking approach now on the heart of the watermark plan.
The mark proves Claude had a hand in textual content, not that it wrote the entire thing, so it should deal with an unique writing with a small edit the identical as a totally AI-generated textual content. Ask Claude to proofread or translate your paragraph and the output can nonetheless carry the sign. Anthropic is upfront that heavy modifying can strip it, and {that a} lacking mark does not show a human wrote one thing.
A U.S. invoice, the COPIED Act, pushes the identical concept: a standardized option to watermark AI content material so platforms can hint its origin. As Claude’s blackmail drawback confirmed, the corporate’s fashions already draw intense scrutiny over what they do with the textual content they contact.
Anthropic hasn’t mentioned when it should publish the detection instruments that will let anybody confirm the mark.
Each day Debrief E-newsletter
Begin daily with the highest information tales proper now, plus unique options, a podcast, movies and extra.
