New York Tuesday, August 11, 2026

Boldest Voice

Search

Technology

Claude Is Adding Invisible Watermarks to AI Text

Anthropic is introducing machine-readable marks for supported Claude outputs, with text watermarks and signed provenance for files. Existing models are still transitioning.

Image credit: Claude logo, Anthropic / Wikimedia Commons

Anthropic is changing one of the least visible parts of Claude: what remains behind after an answer is copied out of the chatbot. Supported models will embed a machine-readable watermark in generated text, while supported files will carry digitally signed provenance information.

The August 2 date needs a careful reading. That was when the European Union’s Article 50 transparency obligations began to apply. It was not a universal switch that instantly added a watermark to every previously released Claude model. Anthropic says models released on or after August 2, 2026 support marking from launch. Work on existing models is still in progress, and EU rules provide a limited transition period for older systems through December 2 for the marking requirement.

For text, Anthropic describes the watermark as imperceptible. It is woven into output at the model level without changing the meaning, quality or readability of the response. Because it is part of the text rather than a separate file property, the signal can travel when the text is copied and pasted and may survive some editing.

That description does not reveal the underlying technique. Anthropic has not published a detailed technical recipe for the text watermark, so there is no basis for assuming it is simply a string of invisible Unicode characters. The company is also still preparing technical documentation and tools that will allow third parties to detect its marks.

Files use a different mechanism. Where supported, Claude-generated files will include digitally signed provenance metadata. For supported media, Anthropic is using C2PA, a standard for attaching cryptographically verifiable information about the origin and history of a digital asset. That can help a platform or newsroom see where a file came from and what claims were signed into its provenance record.

C2PA is useful, but it is not indestructible. Metadata can be stripped or separated from a file during conversion, re-export or platform processing. And provenance is not a truth certificate: knowing that a file was created or modified by a particular tool does not establish that every claim inside it is accurate.

The text watermark has its own limitations. Heavy rewriting, paraphrasing, translation or mixing with other text may weaken detection. That means a missing watermark cannot prove human authorship. It may indicate that the text was never produced by a supported Claude model, or it may mean the signal was lost through later transformation.

The reverse inference is risky too. A detected Claude mark does not necessarily mean Claude wrote the entire document. A person might have written the original and used the model to translate, polish or rewrite a section. The mark is evidence of model involvement, not a complete account of authorship.

Anthropic says supported marking will be applied globally across Claude surfaces, including the API and supported cloud delivery, rather than being limited to EU users. In practice, a European regulatory requirement is becoming a product-layer change for users elsewhere as well.

The next test will come when detection tools are widely available. If the watermark remains detectable after ordinary editing, it could become a useful provenance signal for publishers, schools, companies and online platforms. If routine transformations erase it, those organizations will still need logs, disclosures and human review to understand how a piece of text was actually made.

Blake Kendall

Author

Science Correspondent

Blake Kendall covers public affairs, politics, business, culture and daily news for Boldest Voice. The role focuses on verification, context, and clear explanations for readers.

Read on