Claude Is Starting to Mark Its Texts. What Can an Invisible Watermark Really Tell Us?
August 21, 2026

Author
You copy text from Claude into a document, send it by email, or publish it on a website. At first glance, nothing changes. Yet the text may still contain an invisible trace that can later help estimate whether Claude was involved in creating or processing it.
Anthropic has announced machine-readable marking for outputs from supported Claude models. For text, this means an invisible watermark. For supported files, such as images, it means digitally signed metadata.
The term “watermark” can be a little misleading. Claude does not hide a secret code or special characters between the letters. The watermark is created in a different way, and you cannot see it during normal reading.
No secret characters hidden in the text
A language model generates text step by step, choosing from several possible continuations each time. Sometimes there is essentially only one suitable option. In other cases, the model can choose between several words that are equally natural in meaning and style.
In its explanation of Claude’s text watermark, Anthropic describes how these small choices can be used to create a statistical pattern. Over a longer passage, this produces a trace that is invisible to the reader but can later be detected by a system with the appropriate key. The approach is based on Google DeepMind’s SynthID-Text technology.
Simply copying the text into another document or editor therefore does not remove the watermark. It is not part of the formatting or file metadata, but of the sequence of words itself. More substantial rewriting or paraphrasing, however, may weaken or remove the signal.

A watermark does not prove authorship
Imagine that you write an article yourself and ask Claude only to translate it into English. Claude generates the translated version word by word, so the result may contain its watermark. That obviously does not mean Claude came up with the original ideas or wrote the source article.
If Claude only fixes a few typos or minor grammatical issues, its contribution may be too small to create a strong enough signal. The same limitation can apply to short texts, factual passages, or code, where the model has fewer opportunities to choose between several equally suitable alternatives.
Creators’ AI points out an interesting paradox. A person may write most of a text themselves and ask Claude to substantially rewrite part of it, leaving a detectable watermark. Someone else may let AI create the first draft and then rewrite it thoroughly, resulting in a much weaker trace. Creators’ AI discusses this issue in more detail here.
The technical marker can therefore tell us something about the path a text has taken, but it cannot determine who its true author is.
Anthropic also notes that a positive detection is meant to express the likelihood that Claude was involved in creating or processing the text. It cannot simply distinguish between “Claude wrote this” and “Claude significantly edited this.” The watermark is also not designed to contain information about a specific user, organisation, or conversation.
The reaction so far? More questions than excitement
The announcement of invisible watermarking has generated considerable online discussion. According to an analysis by CARMA published by Marketing-Interactive, 69.7% of the monitored reactions were neutral, 25.1% negative, and only 5.1% positive.
Negative reactions were therefore roughly five times more common than positive ones. Much of the attention focused not only on the existence of the watermark itself, but also on questions around removing it, editing text, authorship, and the reliability of future detection.
CARMA specialises in media intelligence, monitoring, and communications analysis. These figures are therefore best seen as an indication of the reactions and questions the announcement generated online, rather than as an assessment of the technology itself.

(source: CARMA / Marketing-Interactive).
The AI Act is starting to shape AI products directly
Anthropic is not introducing this technology purely as an internal experiment. One of the reasons is also the European transparency requirements for AI-generated content.
The company is among the signatories of the European Code of Practice on Transparency of AI-Generated Content and plans to roll out the marking globally. For supported future Claude models, watermarking is expected to be part of the system from launch, while older models fall under a transition period under the European rules.
For text, Claude is expected to use the statistical watermark described above. For supported files such as PNG, JPG, or SVG, a different mechanism applies: Content Credentials based on the C2PA standard. These can use cryptographically signed metadata to record that a file was created or processed using Claude.
This is a very concrete example of regulation moving from legal documents directly into the products that people and companies use every day. We explored the difference between technical marking of AI-generated content and the obligation to visibly inform users in more detail in our article AI Act enters into force: what changes for companies starting August 2.
AI transparency is therefore gradually becoming not just a legal requirement, but a technical property of AI systems themselves.
There is still no public detector
For a watermark to have practical value, there also needs to be a way to verify it.
Anthropic has not yet released a public detector. The company plans to provide its own watermark detection API, but has not yet disclosed details of how it will work. This means that an ordinary user cannot currently paste any paragraph into an official Anthropic tool and receive a simple “Claude yes” or “Claude no” answer.
Watermarking also needs to be distinguished from traditional AI detectors. Those tools typically try to estimate whether a text was probably generated by AI based on its style and other characteristics. A watermark detector instead looks for a specific statistical trace created during generation.
Even a positive result would not be definitive proof of authorship. A more accurate interpretation would be: Claude was probably involved in creating or processing this text.
For companies, a different question matters more
In real-world work, there is often no longer a simple distinction between “human-written text” and “AI-written text.” A person may create the foundation and Claude translates it. AI may produce the first draft and an employee rewrites it completely. A model may prepare the research, a person adds their own experience, and an editor revises the final version before publication.
A watermark can be a useful signal about the provenance of content, but it does not tell us who came up with the idea, who verified the information, or who ultimately took responsibility for the final output.
For companies, the most important task will therefore not be checking every paragraph for traces of AI. It will be more important to understand where AI is used, what it is used for, how its outputs are reviewed, and who is ultimately responsible for them.
An invisible watermark may show that Claude was involved somewhere along the way.
But on its own, it cannot tell us the full story of how the text was created.



