Claude now brands every word it writes, and there is no opt-out
Anthropic is embedding invisible watermarks in Claude-generated text and files, rolled out to models released after August 2 and applied worldwide, not just in the EU. The company signed the EU AI Act's Article 50(2) Code of Practice, and the mark survives copy-paste and most edits. Anthropic admits heavily edited, paraphrased, or translated text can lose the fingerprint, so the loopholes are wide enough to matter.
The decision it puts on your desk
If you publish written content at volume, decide by September 1 whether your workflow can survive provenance checks, because detection is shipping into the default experience. Audit how much of your published text is model-generated, and set a written threshold for what publishes as-is versus what gets rewritten. If you build a writing tool, plan for provenance labeling as a standard feature by Q4 2026, because Substack and Quora already ship detection and the gap between labeled and unlabeled platforms is becoming the competitive difference. I have not seen a single public test of the watermark failing on a real false positive. The edge nobody has probed: when a genuinely human draft gets flagged as machine-written, does the system hold?
Anthropic turned on invisible watermarking for every Claude model released after August 2. It applies everywhere, to everyone. You cannot turn it off.
The change came through a support document, not an announcement. Anthropic signed the European Union's AI Act Article 50(2) Code of Practice on Transparency of AI-Generated Content, a voluntary clause that requires model providers to mark synthetic output.
Watermarking covers the whole stack. The Claude Platform API (application programming interface), Claude Code, Claude Cowork, Claude Tag. Text gets an embedded watermark. Files get "digitally signed provenance metadata where supported."
The mark is invisible. It travels with the text when you copy and paste it elsewhere. It survives most edits.
"The watermark will be 'part of the text' and it will 'travel with the text when it's copied and pasted elsewhere,'" the company said, without detailing the mechanism.

Anthropic has not disclosed the mechanism. The closest public blueprint is Google DeepMind's SynthID, published in a 2024 paper: a system that modifies the model's word choices so the output is detectable, swapping "strong" for "solid" along a statistical fingerprint.
For images, Anthropic is using the C2PA (Coalition for Content Provenance and Authenticity) standard. That pairs each generated image with a metadata file recording which model made it, when, and whether copyright restrictions apply. It hashes that metadata so tampering becomes visible.
The loopholes the company admits
Anthropic says the technology will not be foolproof.
"Heavily edited, paraphrased, or translated text could not carry a detectable watermark, and a file's metadata could be stripped through format conversion, screenshots, or other means," the company said.
That is the loophole in writing. The evasion is one extra step for anyone who wants clean output. The honest user cannot remove the mark without effort.
I keep thinking about who carries this cost. The writer who uses Claude transparently cannot opt out and cannot clean the text. The operator who wants clean output regenerates, rewrites, or runs a humanizer in one extra step.
I get the sense the mark will mostly catch people who were not trying to hide anything.
The watermark catches the transparent. It misses the deliberate.
What this actually is
The EU rule created the obligation. The watermark is the cheapest way to satisfy it, and it does something larger than compliance.
It shifts liability. When content is marked, a platform can point at the model instead of absorbing the blame itself. That is the real function.
It also sets the market. Google already watermarks with SynthID. OpenAI signed the same Code of Practice and built a watermark implementation in 2024. Detection tooling is coming from Anthropic.
Free watermarking is the loss leader. The paid product is the guarantee: "fingerprint-free output" as a premium tier. Detectors run the funnel. Antivirus ran the same playbook, and I think the economics will not hold either.
The watermark will probably not stop AI slop. It will make slop honest, which is a different outcome.
What to do this week
Do not build your workflow around dodging the mark. Evasion is a treadmill, and it lowers the writing.
Use the model for structure, feedback, and the first pass. Write the final text yourself. That was the right practice before August 2, and it stays the right practice after.
I have not seen a single public test of the watermark failing on a real false positive. The edge nobody has probed: when a genuinely human draft gets flagged as machine-written, does the system hold?