64 Sources
[1]
Can Anthropic's invsibile watermarks curb 'AI slop'? Researchers remain sceptical
Anthropic, the firm behind the artificial-intelligence model Claude, has announced that text generated by any models launched on or after 2 August will be invisibly embedded with a watermark that indicates the output was written by AI. Meanwhile, images generated by Claude will in most cases come with metadata that contains a digital signature to show that the model processed the file. Text-based watermarks use an algorithm to tweak how an AI model selects its wording. When applied to a stretch of text, this process leaves a statistically observable trace in the output. Anthropic, based in San Francisco, California, says that its watermark won't change the "meaning, quality, or readability of Claude's response" and that the mark "may persist through some editing". The move comes in response to the EU AI Act, which was formally adopted in 2024. As of 2 August this year, providers of frontier AI models have to ensure that AI-generated outputs are detectable as such or be hit with fines of up to €15 million (about US$17 million) or 3% of their global annual turnover. Models released after 2 August will have to meet the requirements immediately, whereas versions already on the market have until 2 December to do so. Anthropic says that watermarks will be applied on Claude's outputs worldwide. The presence of the watermark reveals little about how the model was used. Detecting one "provides a signal" that content was made with Claude, says Anthropic, but is not conclusive: the model might have been used just to summarize or translate an original human idea, for example. Equally, a lack of a watermark doesn't mean that the text was not generated by AI. Because the watermarks are based on patterns of subtle changes in a model's word choice, passages that are very short, or that have been paraphrased or rewritten, might no longer carry a signal. The impact that such watermarks will have on academic integrity remains unclear. Given that watermarks can be stripped from text easily -- for example, by using another model -- they are unlikely to stop motivated people from using AI to produce fake or low-quality papers, known as AI slop, says Reese Richardson, a metascientist at Northwestern University in Evanston, Illinois. But if AI firms create tools that allow others to check for the watermark -- as Anthropic has said it will do -- and if these tools have an acceptably low rate of false positives, some illegitimate uses of AI could be detected, says computer scientist Nihar Shah, who studies the evaluation of science at Carnegie Mellon University in Pittsburgh, Pennsylvania. Watermarks could, for example, help journal editors or conference organizers to enforce strict 'no AI' policies in peer reviews, as the International Conference on Machine Learning (ICML) 2026 did in one of its two possible review streams. Organizers of the July event added a watermark to papers distributed for peer review that generated telltale text when AI was used in review reports. They caught 506 reviewers who violated the no-AI policy. "This experience suggests that while some illegitimate AI uses may be done carefully to evade detection, many others may simply copy-paste AI outputs," says Shah, who was behind the ICML's watermarking process. Invisible ink Outside of these strict confines, some academics warn against using a watermark to judge academic integrity in universities. "My concern would be if it starts being treated as a binary measure of authorship: watermarked equals AI written and not watermarked equals human written," says Amina Yonis. Trained as a molecular biologist, Yonis now runs The Page Doctor, a company that helps students with writing and editing, and also promotes the ethical use of AI. Students who are deliberately trying to conceal AI use might be the ones who are most likely to evade detection, she adds. "It could be useful for transparency, but it isn't a reliable way of determining whether a student has cheated," she says. Watermarking has little impact in a world in which legitimate papers are written with AI, says Paul Ginsparg, a physicist at Cornell University in Ithaca, New York, and a founder of the preprint repository arXiv. In mathematics, where AI has had a string of successes, many people assume that certain kinds of claims will be AI-assisted, he says. "Few will even bother to try to obfuscate a watermark." Anthropic is not the first company to introduce watermarks, and all frontier models will have to include them eventually if they are to comply with the EU AI Act. Google has been using its SynthID mark since 2023 on text made by browser and app versions of its model, Gemini. OpenAI has also adopted SynthID for its image and audio content. Although AI firms can use the watermark to identify written content generated by their own models, none has yet introduced a text-specific tool for the general public, although OpenAI and Google have these for AI-generated images and audio. A spokesperson for Anthropic told Nature that the firm is working on a public "text detection" tool. If the company ends up being the only chatbot with a detector tool, says Yonis, some users might "simply migrate to the model that leaves less of a trace".
[2]
Claude's new Scarlet Letter watermark is invisible -- for now
Anthropic has revealed that it will soon watermark content that is processed (not just generated!) by any of its models. In a support article, Anthropic explained that it was rolling out machine-readable watermarks to comply with the European Union's AI Act, which requires all AI system providers to watermark AI-generated or manipulated audio, image, text, and video outputs. The law applies to any AI model released after August 2 and provides a grace period until December 2026 for providers to update previously released models. Anthropic confirmed that moving forward, all new models offered globally -- not just in the EU -- will mark AI-generated content "from day one." Text outputs will "carry embedded watermarks," invisible to the user, and other "generated files will include digitally signed provenance metadata where supported," Anthropic said. Notably, Anthropic is deploying a "nuke it from orbit" approach, applying the watermarks to all processed content where supported, even though the EU does not require it for cases where an AI system performs "an assistive function for standard editing" (the guidance's own example is grammar correction), or where it doesn't "substantially alter" the user's text or its meaning. A watermark applied at the model level can't tell wholesale generation from a comma fix, so Claude may end up stamping exactly the content the law was written to leave alone. How thoroughly it truly watermarks will not be known until Anthropic releases a detection tool that can be tested. The company said that it plans to eventually share details on how to detect marks in order to offer technical support that the EU's law requires. Anthropic also noted that the watermarks won't work on "some platforms or features" that don't support them. For non-text content, Anthropic will use the C2PA metadata approach to record provenance. Easy to get around, easy to misunderstand The approach described by the EU and implemented by Anthropic is unfortunately trivially easy for bad actors to bypass, while potentially punishing users who trust the system to accurately label their outputs. Text watermarks work by biasing the model's word choices in a pattern spread across the entire document, only detectable in aggregate by the right tool. The catch is that "invisible" can also mean the model occasionally trades the best word for a slightly worse one, just to keep the signal intact. Anthropic noted that those marks "will travel with the text when it's copied and pasted elsewhere, and may persist through some editing." But if watermarked text is pasted into another chatbot system that edits the text, the watermark could be destroyed. With image and video content, screenshotting/recording or using any decent metadata editing tool will suffice to remove this information, too. And once Anthropic tells the world how to identify these watermarks, building a system to remove them would be trivial. Further, the potential for misinterpretation seems high; the watermark is not particularly informative. Anthropic explained that a "detected mark provides a signal that content was processed by Claude, but is not fully conclusive." The only real message the mark sends is that "the content may have been processed by Claude," Anthropic said, and the mark may even appear on content that was not generated by Claude. On top of this, you have the general public, who may not grasp the difference between processed text and wholly generated text. If the system watermarks human-authored text simply because it was edited in a workflow that touches Claude, suddenly it carries the same denotation as wholly generated text does. And all of this, in a system where the "Lack of a detected mark doesn't mean the content wasn't AI-generated or processed," Anthropic said. Claude may label more AI content than required To its credit, Anthropic acknowledges that it may be marking some content that the AI Act does not require to be labeled: "people often use Claude to proofread, translate, summarize, or convert files. The output can carry a Claude mark even if the underlying ideas, text, or data originated from another source." So, despite being explicitly exempted by the law, Claude will mark any editing work done on original writing. If the watermarks become a catch-all for any Claude use, from spellchecks to complete rewrites, Anthropic's solution will likely frustrate users by going further than necessary to label content in ways that could inadvertently muddle provenance. A teacher or professor, for instance, should not interpret this watermark signal as anything beyond "AI touched this," but it is easy to imagine they will. After all, what is the point of a watermark that cannot differentiate between light editing and wholly generated text? The matter becomes even murkier when we turn to another section of the EU AI Act, 50(4), which addresses how those publishing such text must explicitly label content. Under their labeling regime, wholly generated AI text does not require a label in most instances. AI-written novel? No label. Marketing copy generated by AI? Nope. But if the text is meant to "inform the public on matters of public interest," you have to label it unless a human reviews it editorially (meaning, the editor is known and accountable). So, we have a strange situation where, on the model level, it's "watermark all the things," but on the public disclosure front, it's "you don't need to label this AI text if Joe looked at it." Ars reached out to Anthropic to see if there's a timeline for details on detection to be released or results from any testing the company can share assessing the likelihood for false negatives or positives. We also asked if Anthropic could address how its watermarks may conflict with standard editing and other exemptions from the AI Act, but Anthropic did not immediately respond. The fun is just starting In the EU, transparency requirements are meant to ensure AI tools like Claude don't upset "the integrity and trust in the information ecosystem, raising new risks of misinformation and manipulation at scale, fraud, impersonation, and consumer deception." One EU support article forecasted that the obligations would be the "primary compliance challenge" for many AI firms. "People should know when they are interacting with AI or exposed to AI-generated content," the European Commission's guidelines said. "This will help them make informed decisions, calibrate their trust and reliance on AI, and avoid misinformation or deception." Still, it's hard to square this with the fact that a wholly generated article on a matter of public interest gets a watermark, but not a reader-facing label, if an editor properly reviews it. AI firms like Anthropic are best positioned to develop watermarking solutions, the EU expects, since AI moves fast and there will be an ongoing "need for new methods and techniques to trace origin of information." But that largely leaves the societal value of such marks up to tech firms to decide, with the EU only stipulating that "techniques and methods should be sufficiently reliable, interoperable, effective and robust as far as this is technically feasible." In its post, Anthropic said it plans to continue working on its watermarks and detection methods that meet the EU's demands. If Claude's labels fail, the AI Act carries steep penalties for violations, including fines up to 15 million euros or 3 percent of a company's worldwide annual revenue. Ars Editor-in-Chief Ken Fisher contributed to this report.
[3]
Anthropic shares more details about how Claude's new watermarks will work
Anthropic published a blog post Friday seeking to answer some basic questions about how it will watermark the text generated by its chatbot Claude. Such as: How will the watermarking actually work? Can it be hidden with editing? And how does this affect code? Claude users have been debating the move since the company revealed earlier this week that it would be doing this watermarking to comply with the EU AI Act's Transparency Code, which requires AI companies to use systems that make it possible to identify AI-generated content. On Reddit, for example, one poster characterized this as a conspiracy against innocent Claude users, while another claimed, "The only reason you wouldn't want this is to lie to people." And Business Insider reports that "dozens" of users on X have claimed to cancel their Claude subscriptions as a result. Anthropic's new post starts with a general overview of the watermarking concept, explaining that when making "low-stakes choices" -- like choosing between the words "overcast" and "grey" to describe the weather -- Claude can create a pattern in its responses that is "undetectable to the reader, but is detectable to anyone who has a key that encodes it." "Watermarking does not impact the quality of Claude's output," the company said. "To a reader, a watermarked response is indistinguishable from an unwatermarked one." More specifically, Anthropic said it will be using the SynthID-Text approach that the Google DeepMind team outlined in 2024, and that it plans to release a watermark detection API. It also noted that watermarking is distinct from the AI detection approaches offered by companies like Pangram that look for "tells" in the writing (like the construction "his isn't [X], it's [Y]") to reveal AI usage: "Picking up on these patterns is fundamentally different from checking for a watermark." Could someone just rewrite the text to hide the watermark? Anthropic said it's possible, but "light editing probably won't remove the watermark completely," while "a complete rewrite where every word is replaced will." "In the latter case, of course, it's arguable whether the text can any longer be described as AI-generated," the company said. As for whether the watermark will be detectable in text that was only proofread or edited by Claude, Anthropic said that will depend on "the length of the text and how heavily Claude has edited it." If it's only been lightly edited, "nearly all the words" will have been written by the human author and "there's very little (if anything) for the watermark to attach to." Code, meanwhile, should have less of a watermark than other text, because the model will need to create working code and won't have the freedom to choose between a variety of equally valid options. "Having said that, in areas where there is an arbitrary choice between particular words or terms within the code, the watermark can be used, such as comments within code," Anthropic said. "But by definition, it will have a negligible effect on the actual code produced." Anthropic also said that Claude won't be the only AI chatbot to generate watermarked text, as "other major model developers have signed the same Code of Practice and will be implementing their own watermarks."
[4]
Some Claude users are mad that Anthropic's new watermarks will catch them cheating at their jobs, classes
Anthropic recently made the decision to watermark Claude's outputs -- inserting invisible code into the chatbot's editorial text that marks it as AI-generated. Anthropic rolled out this new policy to satisfy the EU AI Act's Transparency Code, which now requires tech companies to label content that has been AI-generated or edited in a manner identifiable to computer systems. Yet while European regulators may be happy, some AI users are decidedly not. One need look no further than Reddit to find evidence of brewing discontent, though other posters on the site are not in agreement. One of the more histrionic posts I came across was from a user named visionode, whose account is notably only three weeks old. According to visionode, the new watermarking system is a draconian conspiracy designed to victimize innocent chatbot users worldwide. Visionode's basic argument appears to be that, while savvy Claude users may be able hide evidence of their AI usage by paraphrasing or otherwise cleaning their outputs through other AI services, the average user of Claude will be caught. "Who will get caught? You. The student who used Claude to reorganize a paragraph. The journalist who asked the AI to summarize a two-hundred-page transcript. The writer who had creative block and asked for synonyms. Those guys come out of the process with a digital tattoo on their forehead." Far be it from me to undermine visionode's outrage, but those are not the best examples. A journalist asking AI to summarize a two-hundred-page transcript is not going to be bothered by a watermark attached to that summary, unless they are copying and pasting the summary verbatim into their article -- which is plainly unethical and shouldn't be happening. It is equally unethical for a student who copies and pastes Claude's output into an essay after asking it to "reorganize a paragraph." Other Redditors were also not particularly supportive of the poster's outrage. "Get a load of this guy," one poster merely commented. Another asked the OP to take "a deep breath." Visionode wasn't the only one complaining. Another unhappy camper called the watermarks "unethical" and "disgusting" and argued that by using Claude, they had done the lion's share of the work. In their view, the chatbot was merely a "tool" that had facilitated their arduous labor. "I gave the instructions, context, decisions, and countless refinements, claude was the tool. If Claude starts watermarking the code or anything else it generates, what exactly is it claiming credit for?" the poster asked. Again, other users dogpiled onto the critic. "It's not claiming credit though," one user shot back. "It's about being able to detect AI generated outputs because of the risks AI generated outputs can cause in various situations." "Bro couldn't even complain about Claude without using Claude to write it," another quipped. Some critics have steered clear of the victimhood narrative and made slightly more nuanced arguments against Anthropic's new policy. For instance, one poster complained of a general hypocrisy in watermarking an editorial product that was, itself, generated by hoovering up other people's work. "I think it's a very sinister direction to take," said the user. "I don't use Claude to write anything but having an AI that watermarks your work is terrifyingly ironic given how many of the frontier models came by their training data." In general, however, users have tended to support the watermarking system as a sensible way to track material that was generated by algorithm. "There is literally no good argument for why this isn't a good idea," a user on another thread said. "The only reason you wouldn't want this is to lie to people."
[5]
Anthropic's Claude Will Add Watermarks to AI-Generated Text and Files - CNET
Ever since being admittedly fascinated by the Cambridge coffee webcam from the 1990s, I've written about VPNs, the NFL, smartphones, living wages, over/unders and everything in between. Read full bio You might soon be able to know for sure if something came from a human being or from Claude. Anthropic said this week that text and files generated by its family of AI models will be watermarked to let consumers know. The change will allow the company to comply with EU regulations governing the transparency of AI use. The EU's Code of Practice on Transparency of AI-generated Content requires companies that provide and deploy AI systems to inform customers when they are interacting with AI and to include watermarks on AI content. Consumers also must know when they're exposed to deepfakes and emotion-recognition and biometric-categorization tools. Watermarking -- an authentication process that originated in Italy in the 13th century -- is entirely different for AI content. The AI system can automatically embed markers in text indicating that the content originated from AI and not a human. Examples could be different spacing between words and numbers, word sequencing and other invisible signals that remain with the text even if the person copies and pastes it across different platforms. Readers can't see these markers, but computer systems can. In its announcement this week, Anthropic said Claude models launched on or after Aug. 2 would include watermarking. That includes content created by Claude through the API, Claude, Claude Code, Claude Cowork and Claude Tag. Watermarking will apply to all Claude-generated content wherever the AI system is offered, not just the EU. Anthropic said it would share details on detecting the watermarks in the future. A representative for Anthropic didn't immediately respond to a request for comment and clarification. What will be watermarked Claude will include watermarks in text and files -- including .svg, .png, or .jpg -- that it generates. With text, the watermarks will be signals embedded into letters and words that will be invisible to readers but visible to machine systems. Even if the text is copied and pasted from text editors such as Windows Notepad or MacOS's TextEdit, the watermarks will remain. The marks also might not be eliminated through human editing, either. "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from," the company said. Image files created by Claude will have signed provenance metadata, including information about where the image came from, who created it and if it has been modified. If someone tries to tamper with it -- for example, trying to hide that it was generated by AI -- the cryptographic signature will break and thus will show the reader that it was tampered with. AI transparency is a growing trend. Substack partnered with Pangram to let readers know how much, if any, a post was generated by AI. Suno recently announced changes to help listeners know if a song was created by AI. If LinkedIn customers suspect AI slop, they can let LinkedIn know. Spotify's new feature, AI Persona, allows listeners and creators to know which music was created with AI. It's not foolproof Anthropic included a caveat in its announcement. The presence of watermarking doesn't necessarily mean the content or image was created by Claude, nor does the absence of watermarking mean Claude wasn't involved, either. For example, let's say someone wants to repurpose an essay from another writer. They punch the essay into Claude and ask the AI to reword it. The output will have watermarking, but the content's facts and details came from a writer, not AI. People often use Claude for proofreading, translating and summarizing, the company said. Someone might also take content from Claude and edit it and combine it with other text. Even if only a small portion of the final draft is from Claude, there could be a watermark, perhaps undermining the legitimacy of the document for the reader. Anthropic said content generated or processed by Claude might not have a watermark, for various reasons. It could be that the amount of AI-generated content is too small, or perhaps the content has been "heavily edited, paraphrased, translated or mixed into other writing." It's also possible that a Claude-generated image doesn't have a watermark either. For example, if someone takes a screenshot of the image and re-saves it as a different file, it won't have the metadata. Although Anthropic is trying to comply with EU rules, AI detection has been significantly less than reliable, according to some reports. For example, content from non-native English speakers is often falsely flagged as AI-generated.
[6]
Anthropic explains how Claude's invisible text watermarks will work
Anthropic has clarified how it's planning to apply invisible watermarks to Claude-generated text in order to comply with Europe's AI transparency rules. On Friday, Anthropic announced that Claude's text marking system is "a version of the SynthID-Text approach" -- an open-source watermarking technology developed by Google DeepMind that creates detectable patterns using wording probabilities. This watermarking feature, alongside C2PA support for Claude-processed images, is being introduced to meet Anthropic's obligations under the European Union's AI Act, which requires synthetic audio, image, video, and text to include machine-readable marks that enable the content to be detected as artificially generated or manipulated. Anthropic says the text watermarks won't make Claude more expensive for users, or "have any practical impact on the quality or content of Claude's outputs." Here's Anthropic's explanation for how it works: Take the sentence "The weather today was cold and...". The next word is very unlikely to be "sugary." But it is quite likely to be "overcast" or "grey." Under most circumstances, it doesn't matter much to the reader which of these latter two words the model ultimately chooses -- the meaning of the sentence is largely the same either way. In cases like this, the choice is settled by a random number. Watermarking uses low-stakes choices like these -- which occur many times over a piece of generated text -- to leave a pattern in Claude's responses. That pattern is undetectable to the reader, but is detectable to anyone who has a key that encodes it. When watermarking is used, choices are still made at random, but the source of the randomness is different. Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick. As Anthropic notes, the EU's AI transparency requirements also impact other major AI developers, so Claude won't be the only model introducing text watermarks. Google's Gemini chatbot has supported the SynthID Text solution since 2024, and while OpenAI hasn't detailed any text watermarking plans for ChatGPT in its AI Act compliance roadmap, it will also be subject to the law's requirements.
[7]
Anthropic says it will watermark text generated by its AI models
Anthropic will watermark text generated by its models, including Claude, to comply with European regulations, the company now says. The AI model maker confirmed the watermarking in an updated support page. EU AI Act's Transparency Code, which took effect on August 2, requires AI companies to mark AI-generated or edited content in a way other systems can identify them. Anthropic said that all models released after August 2 will automatically have tech to watermark both computer-generated text and files. For files, the company is using the C2PA open standard. The company said it will extend support for older models as well, adding that the watermark will travel when users copy and paste the text. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing. Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from," the support page reads. It's not clear how much editing users need to do to remove the watermark. We have asked Anthropic to clarify and will update the story if we hear back. The company noted that watermarking will apply to different products like Claude platform API, Claude, Claude Code, Claude Cowork, and Claude Tag. Platforms are now rushing to watermark AI-generated content after backlash from users and to avoid regulatory scrutiny. Last week, AI music platform Suno said it will mark tracks created on its platform after a spate of legal challenges. Last month, newsletter service Substack teamed up with Pangram to flag AI-generated content. The company's CEO, Chris Best, called out Claudefishing, a term used for people using AI to generate content. Apart from Anthropic, other companies like Black Forest Labs, Google, Meta, Microsoft, OpenAI, and Synthesia have committed to adhering to the EU's code.
[8]
Facing Backlash, Anthropic Explains Why Users Shouldn't Fear AI Watermarking
(Credit: Timon Schneider/SOPA Images/LightRocket via Getty Images) User anger over Anthropic's decision to "watermark" text outputs from the Claude AI chatbot is prompting the company to downplay the potential impact. On Friday, Anthropic published a blog post that tries to clear the air by explaining exactly how the watermarking will work and why the system faces various limitations, making it far from a flawless method for flagging Claude-generated text. "Watermarks can't be traced to a specific person, organization, or chat," the company tweeted. Anthropic is implementing the "invisible" watermark to comply with the EU AI Act, which requires tech companies to label AI-generated text. But unlike a traditional watermark, Anthropic's system intends to stamp Claude's text outputs by creating an invisible pattern in the words chosen in the AI-created text. As a result, the company has faced pushback from users who fear that watermarking will degrade Claude's outputs and even place a "scarlet letter" on works users create with the chatbot. Friday's blog post confirms that Anthropic is using a watermarking system based on Google's SynthID Text to "leave a pattern in Claude's responses" in the words picked for each line of text. "That pattern is undetectable to the reader, but is detectable to anyone who has a key that encodes it. When watermarking is used, choices are still made at random, but the source of the randomness is different," the company says. "In internal testing, we've seen no impact of watermarking on the content, level of creativity, or readability of Claude's text," the blog post adds. As an analogy, Anthropic says the watermarking is like playing the board game Monopoly, but rather than using a die, the first player moves using a randomly chosen digit from the number pi, and then the next player does the same, following the next digit. "For all intents and purposes, the moves are still random: it makes no difference to the players -- or to the outcome of the game -- whether the randomness comes from pi or from dice rolls each time. But if we could see the sequence of all the moves after the game (and we knew the value of pi), we could work out whether this was a game that likely used pi to determine its moves. The game that used pi is, in a sense, 'watermarked,'" the blog post says. That invisible pattern-marking faces limitations, though. Anthropic's system to detect the watermark can only "assign a probability that the text was generated by Claude. It doesn't confirm whether the text was human-written, and it can't tell whether the text was written by a different AI (even if that other AI uses watermarking, it would have a different key; it might also use a different watermarking method altogether)," the company noted. In addition, the watermarking can't place an invisible pattern in small text samples, factual passages, or specific computer code fragments, since there are fewer word choices for the AI to choose from. "In areas where there is an arbitrary choice between particular words or terms within the code, the watermark can be used, such as comments within code. But by definition, it will have a negligible effect on the actual code produced," Anthropic says. On the privacy front, the company also notes "there's nothing in the watermark, or its key, that would allow anyone to recover any information about the user, their organization, or their chats with Claude." On why Anthropic is implementing the watermark widely, rather than only in the EU, the company says: "We're applying watermarking globally at launch because we don't yet have a durable way to scope it by region. However, we will continue to evaluate different approaches, and will share updates when we have them."
[9]
Claude will begin digitally watermarking marking AI-generated text and images -- Anthropic details how it'll comply with the EU's Artificial Intelligence Act
Text will carry a hidden "statistical pattern," but image pixel watermarking is notably absent. The identifiability of AI-generated content is critical as more and more people use text and images from these services, and the European Union's Artificial Intelligence Act (AIA) set a deadline of August 2, 2026 for AI service providers to start implementing identifiability measures. To that end, Anthropic has published a guidance article detailing how new versions of Claude will comply with article 50 of the law specifically. The legislation is accompanied by a Code of Practice with suggestions for implementation, and in keeping with that code, all new Claude models will watermark text and add provenance data to generated files, namely images (of SVG, PNG, and JPG file types). Anthropic's guidance is a bit late to the party, as OpenAI and Google already published their own versions a while back. When it comes to text, unlike steganography in images that hides data in the picture content, the lab says that watermarking is performed by biasing the selection of tokens (parts of words) during generation. When the generated text is analyzed, it'll fit a determined statistical pattern, revealing the watermark. Anthropic says it'll provide detection tools that look for these patterns in "forthcoming technical documentation." Text that is copied-and-pasted and only lightly edited should retain the identifiable pattern. Anthropic says that the quality and meaning of the generated text won't suffer as a result of the marking process. Slices of text under 200 tokens are exempt under the Code of Practice, as they don't carry sufficient data to reliably watermark. As for images, the aforementioned file types support additional metadata attached to the picture itself, and Claude will start adding a provenance certificate using the C2PA standard. In simplified terms, the files will carry an associated digital certificate that will be invalidated if the file is altered in any way. Attentive readers might note there's no mention of actual image watermarking, and indeed Anthropic made no mention of that feature, although it's a requirement of the Code of Practice for images, alongside the provenance information. It's expected the firm will implement image watermarks at some point, otherwise, just copy-pasting the picture content would make it untraceable. Anthropic also says that it's working to add these capabilities to existing Claude models -- as required by the AIA, with a deadline of December 2, 2026. The company's guidance starts by describing "models launched in the EU," but subsequent paragraphs clarify that "marking will apply to output from supported models wherever Claude is offered, worldwide." The text further notes that direct quote content may be erroneously watermarked as part of a response, and that the lack of a text watermark is no indication that the content wasn't AI-generated or processed. The AIA also requires service providers to offer tools to detect watermarks, and Anthropic says it'll "share details in forthcoming documentation." Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.
[10]
Anthropic says text watermarking scheme relies on inconsequential words
In an effort to "watermark" text that Claude has generated and comply with the EU AI Act, Anthropic unveiled a plan on Friday to modify its bots' choice of words in a way that would be detectable as AI. Traditional watermarks are patterns or images overlaid on currency, postage, or official documents as an assertion of authenticity. In the digital realm, the term is more flexible and can refer to a variety of techniques for applying an identifier to electronic data. Anthropic's approach involves influencing inconsequential word choices made by its models, a technique introduced in Google DeepMind's SynthID-Text paper. To oversimply things, large language models work by predicting the next word in a sequence of words. The AI biz explains that while composing sentence output like "The weather today was cold and...", a model like Claude might respond with words like "cold" or "gray" and would be unlikely to respond with a word like "sugary." That's the theory, but when actually asked to complete that sentence, Claude Opus 4.8 went a bit overboard: "...crisp, the kind of cold that nips at your fingertips and turns your breath to little clouds. The sky was a pale, washed-out blue, and everything felt sharp and clear. "Want me to take it somewhere specific -- cozy, gloomy, cheerful? Or keep going with the same tone?" But remove whatever training has been applied to promote engagement and simulate literary style, and that's basically what Claude is doing here - predicting the next word in a sequence. Anthropic asserts that in most cases, the example sentence could be completed by either "cold" or "gray" and "the meaning of the sentence is largely the same either way." The watermark gets generated by deviating from the predicted word to something else. A different source of randomness is used and that can be detected with a digital key. As Google DeepMind researchers explain in their paper, "Generative watermarking works by carefully modifying the next-token sampling procedure to inject subtle, context-specific modifications into the generated text distribution. Such modifications introduce a statistical signature into the generated text; during the watermark detection phase, the signature can be measured to determine whether the text was indeed generated by the watermarked LLM." Anthropic insists this will be done with low-stakes passages in a way that won't alter the meaning. "In internal testing, we've seen no impact of watermarking on the content, level of creativity, or readability of Claude's text," the company said, adding that in a controlled study, human raters saw no difference in quality between watermarked and unwatermarked answers. That assumption hinges on not applying the watermark to any consequential text. As Anthropic puts it, "Watermarking is sparser on factual passages where there are fewer choices that can be made without decreasing the accuracy of the text." The biz goes on to say that the situation is similar with code - the watermarking algorithm can't simply start swapping method names. In the context of literature, the notion that some words are interchangeable is likely to raise a few hackles. While it may be a satisfying thought experiment to imagine Claude emitting, "It was the best of times, it was the least of times..." or "Telephone me Ishmael", anyone trying to pass off generated text as serious writing probably should face whatever social backlash watermarking may entail. On the plus side, Anthropic's flavor of watermarking isn't excessively intrusive. It doesn't involve any personally identifying information and only serves to indicate that Claude was probably involved at some stage of the creation of the marked text. What's more, the technique is expected to be only semi-effective. In its FAQs, Anthropic points out that some amount of editing should erase the watermark. "Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will," the company said. "In the latter case, of course, it's arguable whether the text can any longer be described as AI-generated." In all likelihood, Anthropic doesn't care if its watermarking scheme can be defeated. The company's post makes clear that it is doing so as a matter of legal compliance and has chosen a solution that doesn't raise costs. "Watermarking has a negligible impact on the speed of models, and because it produces no extra tokens, the model is the same price to serve and use," the biz said. Hey Claude, what's another word for performative compliance? ®
[11]
How Anthropic plans to watermark Claude's AI-generated text
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. As you may be aware, the EU now requires AI companies serving its market to mark their AI-generated content so it's easier to identify. Anthropic and several other major AI providers have agreed to comply with the EU's Code of Practice, with Anthropic becoming one of the first companies to share details about how it will implement watermarking across Claude. Anthropic has also confirmed that a regular user won't be able to see the watermark. According to the company, it has no practical impact on the quality or content of Claude's output, including creativity and readability. For those unaware, invisible watermarking and provenance systems are already being used for some AI-generated images, and text-based output will now follow a similar concept, although the underlying implementation is different. While the change is being introduced to comply with the EU AI Act, Anthropic says the watermark will initially be applied to Claude-generated text worldwide. "We're applying watermarking globally at launch because we don't yet have a durable way to scope it by region," Anthropic explained in a blog post. Anthropic says future Claude models will generate watermarked text. Models launched before August 2, 2026, are covered by the EU's transition period, and Anthropic says it is working to add watermarking to those models over the coming months. Claude's watermark doesn't add hidden characters Anthropic says its implementation is based on Google DeepMind's SynthID-Text approach and explained that it works during generation, with certain exceptions. As you may be aware, AI models generate text by repeatedly choosing which token could reasonably come next. Instead of adding characters or modifying the finished response afterward, Claude's watermark changes the source of randomness used when making some of those choices. "Watermarking uses low-stakes choices like these -- which occur many times over a piece of generated text -- to leave a pattern in Claude's responses. That pattern is undetectable to the reader, but is detectable to anyone who has a key that encodes it," Anthropic explained. "When watermarking is used, choices are still made at random, but the source of the randomness is different. Instead of using an arbitrary random number generator to pick the next word, watermaking uses the key and a few words that come before to settle what word the model should pick." "That is, the words that Claude picks are still random, but now, one can check the sequence of words and see if it's consistent with the choices Claude would make if it was using the key. If it is, one can assign a probability that the text was generated by Claude." I also read the research paper on the topic, and here's an excerpt that explains how generative watermarking works: Generative watermarking works by carefully modifying the next-token sampling procedure to inject subtle, context-specific modifications into the generated text distribution. Such modifications introduce a statistical signature into the generated text; during the watermark detection phase, the signature can be measured to determine whether the text was indeed generated by the watermarked LLM. A key benefit of the approach is that the detection process does not require performing computationally expensive operations or even access to the underlying LLM (which is often proprietary). The paper goes in depth and has more examples, but the important part is that Anthropic is not adding a visible marker or hidden characters to Claude's response. Instead, when Claude has multiple reasonable choices for what to generate next, the watermarking system uses a secret key and some of the preceding words as part of the randomness used to make that choice. Those individual choices should look completely normal to a reader, but across a sufficiently long piece of text, they leave behind a statistical pattern. A detector that has Anthropic's key can examine the sequence of words and determine how consistent it is with the choices Claude would have made while using the watermark, allowing it to estimate the likelihood that Claude was involved in writing the text. According to Anthropic, internal testing found no impact on creativity, readability, or the content of Claude's responses. The company also says watermarking requires no additional tokens and has a negligible impact on generation speed. "Nothing is added to the text and there are no hidden characters," Anthropic noted. "Watermarking doesn't require extra tokens, and will not be more expensive." Code and factual answers may carry less watermarking As I mentioned, there are certain exceptions to watermarking, and they're for good reasons. For factual statements where only one answer is correct, Anthropic says the watermark does not interfere with the choice. Likewise, the same principle applies to code, where replacing one term with another could break the output. "Where an exact output is required -- where there isn't a choice, and something would be factually wrong or a piece of code would break if a different term was chosen -- the watermark isn't applied." "For example, once the model has written "2 + 2 =", there is a very clear best choice for the next token (if the model is completing the sum, there isn't an answer that's equally as good as "4"; if it's talking about George Orwell's Nineteen Eighty-Four, there isn't an answer that's equally as good as "5")," the company noted. "The "nudge" of the watermark wouldn't be applied here. For the same reason, code -- which in very many cases has to be exact -- has generally less watermarking than some other forms of text." Anthropic notes that watermarking can still be used in parts of code where arbitrary choices exist, such as comments, but says it should have a negligible effect on the actual code produced. This aligns with Google's SynthID-Text paper, which notes: There are two primary factors that affect the detection performance of the scoring function. The first is the length of the text x: longer texts contain more watermarking evidence, and so we have more statistical certainty when making a decision. The second is the amount of entropy in the LLM distribution when it generates the watermarked text x. For example, if the LLM distribution is very low entropy, meaning it almost always returns the exact same response to the given prompt, then Tournament sampling cannot choose tokens that score more highly under the g functions. In short, like other generative watermarks, Tournament sampling performs better when there is more entropy in the LLM distribution, and is less effective when there is less entropy. It is also worth noting that light proofreading of human-written text may leave too little Claude-generated material for reliable detection. Anthropic says the watermark only applies to words Claude actually chooses, so a few grammar or punctuation changes might not provide enough evidence. Anthropic says a translation produced by Claude carries a watermark because Claude chooses every word in the translated output. Anthropic is building an API to detect Claude watermarks It turns out that there'll be an easier way to detect the watermarks, as Anthropic plans to offer a watermark detection API. The API will be able to estimate the likelihood that Claude was involved in writing a piece of text, but Anthropic stresses that this is not the same as proving who wrote it. A Claude watermark also cannot identify whether the text was written by another AI model, since other providers may use different watermarking methods and different keys. "A watermark can only determine that Claude was likely involved with the content at some point. It cannot distinguish "Claude wrote this" from "Claude heavily edited this." "Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will." Detection also becomes less reliable with small samples because there are fewer word choices for the detector to analyze. For generated PNG, JPG, and SVG files, Anthropic is taking a different approach. Claude will attach cryptographically signed C2PA provenance metadata indicating that the file was created or processed with Claude, rather than modifying the file itself with an embedded watermark.
[12]
Claude will apply invisible watermarks to AI text and images
Anthropic has pledged to start marking Claude-generated text and images with machine-readable data, in an effort to comply with European rules for AI transparency. "Generated text will carry embedded watermarks, and generated files will include digitally signed provenance metadata where supported," Anthropic says on a new Claude support page. The changes are invisible to human eyes, but will make it easier for people and online platforms to detect if content was generated by Claude models. These updates are a future commitment rather than something that will go into effect immediately. New AI labeling and transparency obligations under the EU's AI Act, which came into effect on August 2nd, include a four month compliance grace period for existing AI products that launched prior to that date. As such, Anthropic says new Claude models will mark AI-generated content from day one upon release, but support for its existing models is a work in progress. The machine-readable marks will be applied globally to supported Claude models, including Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag. Two different marking techniques are being used: for images processed by Claude, C2PA -- a provenance metadata standard already embraced by Adobe, OpenAI, and Google -- will be applied to supported files, but the process for marking Claude-generated text is much lighter on details. According to Anthropic, an "imperceptible watermark" is woven directly into the text generated by Claude models without changing the meaning, quality, or readability of the chatbot's response. Anthropic doesn't name this watermarking system, but says those text watermarks will also be applied when Claude models are accessed through AWS, Google Cloud, or Microsoft Foundry. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing," Anthropic says on the Claude support page. "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from." Anthropic is also working to enable users and other third parties to detect watermarks and provenance metadata embedded into Claude-generated content, and says it'll share details on this detection system in upcoming technical documentation. There are several tools already available that are designed to detect C2PA metadata, including Google's Gemini chatbot, but it isn't clear if those will work with Claude-generated files. I've asked Anthropic for clarification. This is another step towards AI-generated text and images being clearly tagged across online platforms, and a potential win for folks who want to avoid consuming such content. Fanfiction readers have already been building more rudimentary detection systems to flag when Claude tools have been used in AO3 fanworks, but these marking systems can be applied far more broadly -- if they work, that is. C2PA data is known to be easily stripped out, sometimes even accidently when the media carrying it is uploaded to online platforms, and it's unclear how robust Anthropic's text watermarking solution is. Even the company itself is hedging that these marking systems are far from infallible, and that any content that lacks detectable marks could still originate from generative AI models.
[13]
Anthropic's Claude Will Now Add Invisible Watermarks to Text, Image Outputs
Anthropic will begin watermarking image and text outputs generated by Claude models to comply with the transparency requirements of the European Union's AI Act. The watermarking requirement will apply to Claude models released on or after Aug. 2, the day the AI Act went into effect, and Anthropic will be using two different machine-readable markings for text and image outputs. For text, Anthropic will embed an "imperceptible watermark" directly into the output. You won't be able to see the watermark, but it will travel with the text and persist through copy-pastes and even some minor edits. "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from," the AI startup says. For image outputs, including .svg, .png, or .jpg files, Anthropic will attach signed provenance metadata that follows the C2PA open standard already adopted by OpenAI and Meta. Google also accepts the standard, but uses its proprietary SynthID watermark to label images. Its Gemini chatbot and a dedicated SynthID detector portal can identify images generated by the company's own AI tools. Anthropic said it is "working to enable users and other third parties to detect Claude's embedded watermarks and provenance metadata," but added that the watermarks aren't definitive evidence for outputs generated by Claude. And while this is intended to comply with EU regulations, Anthropic says its watermarks will apply to outputs generated by Claude models -- including Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag -- anywhere in the world. The announcement has made some Claude users, who use the AI tool for writing or photo-editing, upset, but a large section believes they can overcome the detection by paraphrasing the text or using other AI tools to remove the watermark.
[14]
Anthropic is watermarking text generated by Claude to comply with EU law - Engadget
Anthropic has revealed how it's watermarking text generated by Claude AI to comply with the European Union's new AI transparency rules. The company said its text watermarking will not have easy-to-see visuals, will not be distinguishable to the people who read it and will not be adding hidden characters to the text. Instead, Anthropic's method involves leaving a pattern in the text that can only be decoded by someone who has the key for it. The company explained that large language models pick one word at a time when generating text by choosing from a list of potential appropriate words to use. They pick words randomly, as long as they make sense for the context of what they're generating. With watermarking on, Claude will use a key to decide on what word to choose instead of using an arbitrary random number generator to pick the next word. In its example, Anthropic used the digits of pi as a key. Say, the key starts with the digit 2 from the pi sequence 3.1415926535. The next word generated is the sixth in the list of choices, then the fifth, the third and then the fifth again. This method is an adaptation of Google DeepMind's SynthID-Text approach to watermarking, which the team described in a paper published in Nature. Watermarking doesn't affect the quality of Claude's output or slow it down, the company said, and it will not require extra tokens or make generations more expensive. Of course, AI-generated prose typically has tells. Models are fond of using certain sentence constructions like "this isn't [X], it's [Y]," for instance. But those tells are only enough to let you know that an AI was involved in writing that text, not the model used. Anthropic will release an API that has "keys" to decode Claude's watermarking and will be able to say whether the its AI generated the block of text being checked. Anthropic admits that its text watermarking method does have limitations. It can't tell whether Claude actually wrote the text or just edited it, which means if you ask the AI to edit something for you, it will be watermarked too. As the company explains, it can only tell that Claude was likely involved with the text at some point. Even translations will be watermarked. If Claude has only proofread and lightly edited the text, or if the text is too short, the watermark may not be enough to be detectable. Take note that lightly editing Claude-generated text probably won't remove its watermark. If you want to be sure, you will need to rewrite it completely. There have been some concerns on how watermarking would affect code, since it may not be copyrightable without significant human input. If one could prove that an entire codebase was AI-generated, they could copy and then iterate on it. Anthropic said, though, that code has "generally less watermarking than some other forms of text" because it typically requires exact output. If there are no choices to be made in the text generation, then watermarking can't be applied. Anthropic will also watermark images by adding a cryptographically signed note in its metadata that says it was generated by Claude. In its announcement, the company said it was applying watermarks to all of Claude's output at launch because it doesn't have sure ways to implement the changes by region. The changes will affect output across all Claude products that use models released after August 2. Anthropic will also add watermarking capability to older Claude models over the coming months.
[15]
Anthropic pledges to embed watermarks to help discern AI slop in sop to EU
Anthropic will embed watermarks in the text and files generated by future models it launches in the EU, as part of its effort to comply with content and transparency rules in the bloc's AI Act. "Generated text will carry embedded watermarks, and generated files will include digitally signed provenance metadata where supported," the company said in a help document published on Monday. The AI biz is also working on models it has already released, to add output marking during the transition period allowed under EU law. "Marking will apply to output from supported models wherever Claude is offered, worldwide," the company said. The move may further amplify the appeal of open weight models and alienate Claude customers, who don't necessarily want consumers of their AI-generated content to know its provenance. In the past, Claude users have expressed frustration with pricing changes, reliability issues, and model safeguards that have hindered legitimate work in the name of safety. Claude users appear to be skeptical that a text-based watermarking scheme will work. Researchers have already demonstrated that image-based watermarking can be undone. Anthropic intends to apply marks to output from covered Claude models on the Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag. This also includes third-party providers of Anthropic models like AWS, Google Cloud, and Microsoft Foundry. The Ai biz expects to provide details about how people can detect Claude's marks, as required under EU law, in forthcoming documentation. "When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself," the biz said. "You won't see it, and it doesn't change the meaning, quality, or readability of Claude's response. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing. Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from." Absent examples or technical documentation, it's unclear how Anthropic will make the watermarks hard to remove. But it should not be difficult to create an optical character recognition system that strips or omits obscure marks from Claude-generated text. Anthropic's insistence that its text marking scheme "doesn't change the meaning" of Claude's output appears to preclude using word choice and placement as a text provenance identifier - a technique Apple has reportedly used to catch those who would violate its employee secrecy agreements. As for marks attached to Claude-created files, Anthropic says it will rely on signed provenance metadata that conforms to the C2PA standard, for which there are already open source removal tools. Anthropic itself is already hedging about the utility of its marking method, noting that detected marks are not conclusive evidence that Claude produced the content and that the absence of marks cannot guarantee that AI wasn't involved in the creation of a particular piece of content. But perhaps the scheme is good enough to count as legal compliance. ®
[16]
Here's how Claude secretly watermarks AI-written text
Anthropic claims that the system doesn't affect the content or quality of generated text, doesn't leave hidden characters, and doesn't need extra tokens. Google and OpenAI have adopted SynthID watermarks for images generated by their AI models. This allows people to find out whether that shared image is the real deal. Generated text is a different story, though. However, Anthropic announced last week that Claude can add watermarks to generated text, and it's now revealed more details about the system. Anthropic explained in a blog post that Claude's text watermark system is based on the SynthID-Text solution published by Google DeepMind. It adds that the watermark system isn't visible to readers, doesn't have a "practical" impact on content or quality of generated text, doesn't have hidden characters, doesn't require extra tokens, and can't be traced to a specific person/organization/chat. The company says AI models typically generate a word at a time and decide on the next word based on the preceding text. It uses the example of "The weather today was cold and..." It notes that the next word is unlikely to be "sugary" but likely to be "overcast" or "grey." The company says the same holds true when you ask Claude to proof-read your own text, as the watermarks will only reside in the corrections (e.g., punctuation, grammar, etc). Furthermore, generated code has less scope for watermarking due to its "exact" requirements in many cases. Anthropic says it will "soon" offer a watermark detection API so you can check whether text was generated by Claude. Either way, I really hope Gemini, ChatGPT, and other prominent AI models/platforms embrace text watermarking sooner rather than later. SynthID has already proven to be an indispensable tool for detecting AI images, so we hope text watermarking like this becomes similarly useful.
[17]
Anthropic Explains Its Watermark System as Some Claude Users Loudly Revolt
In a blog post on Friday, Anthropic elaborated on its controversial watermarking system, announced earlier this week as an effort to comply with the European Union's Artificial Intelligence Act. Watermarking will make it harder for users to get away with pretending they wrote AI-generated text. It may be too late to preserve Anthropic's relationships with some outraged users, who have, it appears, already canceled their subscriptions. Posts on X show many supposed paying Claude users claiming to have cut off ties. Math and AI influencer John Ennis is one. He posted a screenshot of his cancellation Saturday, and cited Anthropic's "ridiculous watermark idea" as a cause. There are countless other X users claiming to have canceled because of watermarking. "This is bullsh*t" wrote one. Another called Anthropic the r-slur in response to one of its X posts about watermarking. "Why should I, being a non EU citizen watermark my work generated by a paid subscription of Claude?" asks another. Anthropic's explanation does make fascinating reading if you're not a cryptographer, and you imagined that the only way to watermark text is by, for instance, crudely replacing certain instances of "S" with "$" and the like. It's not that at all. "The difference between watermarked and un-watermarked text will not be distinguishable to readers," Anthropic claims. As Anthropic notes, the system stems from the famous (to some) 2024 SynthID paper, meaning it's the same basic technology Google uses for its SynthID watermarking system. The text implementation for Google's SynthID is summed up quickly -- maybe a little too quickly -- in this video from Google: In a bit more detail, the watermarking in Claude's text outputs takes the form of token choices likely to be favored according to a secret key, a string of characters Anthropic compares to pi in terms of its complexity and randomness. The watermarking system generally applies when the stakes are low, like in the example sentence, "The weather today was cold and..." where the next token could result in the word "grey" or, just as likely, "overcast." On the other hand, in the case of "Paris is the capital of..." the watermarking system is unlikely to kick in, because there's only one "correct" token for that situation: "France." The key steers these low-stakes token choices toward statistical "preferences" that can't be detected by a human reader in part because they're context-dependent. "Overcast" in the above example might be the key's preference in one situation, but depending on the context, it might prefer "grey," and there's no way for a human to know which it will be at what time. In a long text, enough statistically preferred tokens constitute the watermark, and a detector will be sure that passage was generated by Claude. In shorter texts, or in certain kinds of coding with few ambiguities, the watermark might not be as visible to the detection system, which will be available as an API. Anthropic says generating the watermark has a "negligible" impact on speed and token cost. One remarkable section of Anthropic's blog post is the passage on editing, which makes it clear that even if Claude is ostensibly only used to edit human-written text, the watermark may appear. "Depending on the length of the text and how heavily Claude has edited it, those changes might not be enough to make Claude's involvement detectable," the blog post says. So caveat emptor to all the AI-using "editors" out there. As Insider's story on Claude cancelations notes, some Claude users admit that they don't want their AI-generated work to be detected by clients and school faculty who expect work to be done by a human. But for what it's worth, these cancelations might be a blip -- or even less -- and not some major change in consumer attitudes toward Anthropic. People regularly complain about Anthropic and other AI companies on X, and even claim to be canceling. Currently, some apparent Claude users claiming to have canceled their subscriptions also cite a recent Wall Street Journal article about CEO Dario Amodei's wife's past business practices as a cause for their cancelations. Anthropic claimed to Business Insider that in terms of the number of cancelations it's seeing, there hasn't been an increase since watermarking was announced.
[18]
Etzioni on AI: Claude is marking its text -- Caveat Promptor!
Claude models launched on or after Aug. 2 embed an invisible mark in everything they write. It's woven into the text itself, so it travels when you copy and paste. You didn't opt in, you can't see it, and you can't turn it off. Anthropic confirmed on Tuesday that it's watermarking Claude's output and published a support page with the details. The trigger is Article 50 of the EU AI Act, which took effect August 2, along with the Code of Practice on Transparency of AI-Generated Content. About 190 organizations signed the code, though only 82 signed the section that covers marking. Anthropic, Google, OpenAI, Meta, Microsoft and Mistral are on that list. The rule was written in Brussels, but the effect lands on anyone using Claude anywhere. Here's how text watermarking works. When Claude writes a sentence, it's constantly choosing among words that would all work fine. The watermark tilts those choices toward a pattern Anthropic's software can recognize. Nothing is hidden between the letters or in the spaces. The pattern is the word choices, which is why it survives copy and paste. Until now, a claim that you used AI rested on a hunch or on a style detector that guesses from tone and rhythm. This is different: a statistical test with a computable error rate. Two things follow. First, a single sentence is too short to mark. Second, and this one the internet got wrong: when I ask Claude to fix the punctuation in a paragraph I wrote, Claude has to reproduce my words, so there's nowhere to put a watermark. Radio host Erick Erickson announced that he'd "ditched Grammarly for Claude for proofreading," and now his own writing "will be watermarked that Claude did the work." Depending on the extent of Claude's input, he could be safe, because minor proofreading edits (i.e., punctuation) don't make room for a watermark. Watermarking text raises several issues, though. A mark means Claude modified the text, not that Claude wrote it. Have it summarize or condense a memo you wrote yourself and it comes back marked, though every idea in it is yours. Beatrice Nolan noted in Fortune that a flat AI label treats someone generating a thousand fake news videos the same as a writer cleaning up a paragraph. Worse, the absence of a mark proves nothing. The results of older models, and other non-marking models, all come back "clean." Removal is harder than the workaround crowd assumes. Paraphrasing degrades the signal but rarely erases it, because a rewrite keeps enough of the original wording to rebuild the statistic. Researchers who tested this on similar schemes found watermarks still detectable after a strong human paraphrase, once there was enough text to work with. Anthropic hasn't shipped a detector. Yet. It hasn't published a false positive rate, and hasn't said how many words it takes. The mark is going into text that no one outside the company can read, but the marks are still consequential because they don't expire. The essay a college freshman turns in this fall is still marked when she's a junior and someone finally has a tool to read it. Technical problems aside, it's important to highlight the core problem that watermarks aim to solve. Chris Best, Substack's CEO, put it eloquently in the July post that coined Claudefishing: "The core problem is not people using AI, or the quality of its output. Not everything made with AI is slop, and not all slop is made with AI. The problem is when there is a mismatch between a reader's expectation and reality, especially when they unwittingly invest their attention in something with no human thought on the other end. That's Claudefishing." That's a harm worth addressing, and it's the one a watermark can't reach. A mark can't tell slop from careful work. It tells you a model was involved. What that means depends on how it was used. Personally, I use Claude and have mixed feelings about watermarks. On the one hand, AI use should be disclosed appropriately. On the other hand, anyone determined to hide their AI use can still do so by using xAI (no watermark on Grok), or open-weight models that carry no watermarks. So what impact will the mark have in practical terms? My conclusion is to judge the outcome, not the tool. I used Claude extensively in writing and researching this column, as I described in AI coach or AI ghostwriter, and I'm pleased with the result. Where do you stand?
[19]
Claude watermark marks more than the EU AI Act asks
The Claude watermark now marks anything the model touched, including a grammar fix the EU explicitly exempted. Meanwhile the same law lets a wholly AI-written article publish with no label at all, provided a named human signs it off. The rule and the compliance are pulling in opposite directions. Start with what the mark actually is, because it is not a stamp on the page. When a model writes, it picks each word from a set of reasonable options. A watermark quietly splits those options into two groups using a secret key, then nudges the model towards one group. One word proves nothing. Across 500 or 1,000 words, a detector holding the key can see the pattern. Anthropic began marking Claude output on 2 August, worldwide rather than only in Europe. It has not published the algorithm or released a detector. It marks what Claude touched, not what Claude wrote This is the part most coverage skipped, and Anthropic states it plainly in its own support article. A detected mark means the content "may have been processed by Claude". It does not mean Claude wrote it. Ask the model to proofread, translate or summarise your own writing, and the output carries the mark anyway. The reverse also holds. No mark does not mean no AI. Short passages, heavy paraphrasing, older models and stripped file metadata all produce clean text that a machine still helped make. So the signal has two failure directions at once, and the company says so upfront. The law exempted the grammar fix Here is where it gets strange. The EU AI Act does not require marking when a system performs an assistive function for standard editing, and the Commission's own example of that is grammar correction. Anthropic marks it regardless. Ars Technica called the approach "nuke it from orbit". The reason is structural rather than ideological. A watermark applied at the model level cannot distinguish a full draft from a comma. It marks the output, and the output is all it sees. The result is a mark landing on exactly the content the law was written to leave alone. And the label almost nobody has to show Now look at the other half of Article 50, the part that governs what publishers must tell readers. It is far narrower than most people assume. An AI-written novel needs no label. AI-generated marketing copy needs no label. Text that informs the public on matters of public interest does need one, unless a named and accountable human editor has reviewed it. Put the two halves together and you get the contradiction. Every keystroke gets watermarked at the model level, while a fully synthetic article can reach readers unlabelled because an editor looked at it. The EU has been building this machinery for a while. It has already made compulsory labels for synthetic content, and it has given itself powers to inspect and fine models directly. The penalty here runs to €15m or 3% of worldwide annual turnover. The objections arrived within a day Investor Bill Gurley argued that if only Anthropic can read the mark, it becomes "judge, jury, and prosecutor". Anthropic told Business Insider it will ship a free detection API so anyone can check. Former Microsoft executive Steven Sinofsky raised a different worry. The issue, he wrote, is "data retention and your right to private thoughts free of a digital trail". Simon Smith, who runs generative AI at the health agency Klick, asked whether a grammar check would now be flagged as AI-authored. Anthropic's answer is the one above: the mark shows processing, not authorship. The software trainer John Crickett asked a sharper question about code. If AI-generated code carries a mark, does that complicate a copyright claim in which the author must show human input? The case for doing it anyway The objections are not the whole story. Developer Donn Felker pointed out that marking helps models avoid training on their own output, the problem he called a "snake eating itself". Aadit Sheth of The Narrative Company made the reader's case. Audiences should be able to tell whether the words they are reading reflect a person's thinking. The Commission's own reasoning is broader still. It wants people to calibrate their trust, and it names fraud, impersonation and consumer deception as the risks. Anthropic frames this as compliance rather than a stance. It is adding marking "to comply with the EU AI Act, and other labs are taking similar steps", the company said. It also says the watermark does not change the meaning, quality or readability of Claude's responses. Some questions remain open. Ars Technica asked the company for a timeline on detection, for any testing on false positives and false negatives, and for how the marks square with the standard-editing exemption. Anthropic sent a statement that did not address those points. The false-positive rate is the number that matters most here, because it decides how much weight a teacher or an editor should give the mark. It will not stop anyone who is trying The uncomfortable part is that the mark catches the honest and misses the deliberate. Paste watermarked text into a second model and ask for a rewrite, and the signal is likely gone. File-based provenance is weaker still. A screenshot removes it, and so does any competent metadata editor. The desk has seen this failure before. Meta's own AI detector missed cropped images, which is roughly the amount of effort involved. There is also a quiet cost. To keep the statistical signal intact, the model sometimes takes a slightly worse word than the one it would otherwise have chosen. Anthropic is the only one doing text This is the commercial risk, and it is real. OpenAI declined to comment specifically to TechRadar and pointed to a support page instead. That page confirms OpenAI marks images and audio using SynthID and C2PA metadata. On text, it says expanding provenance to all modalities is a goal, as standards and tooling "continue to mature". Google uses SynthID too. Neither company has shipped text marking, and both face the same requirement to sell generative systems in the EU. Existing models have until 2 December to comply. Until then, one lab is carrying the friction alone. What the law does not touch at all Article 50 requires disclosure that you are speaking to a machine. It says nothing about what happens to the conversation afterwards. Stanford researchers reviewed the privacy policies of six major American AI developers. Every one used customer chat data to train by default, and some retained it indefinitely. So the law now marks the output and ignores the input. What would settle it Two things, and both are checkable. The first is the detection API, and specifically its false-positive rate, because a mark on a student's proofread essay carries the same weight as one on a fabricated news story. The second is whether OpenAI or Google ship text marking before 2 December, or discover that the standards are still maturing. Labels already misfire without any of this. X put a "Made with AI" tag on the resignation post of the departing White House press secretary on Wednesday, and then the tag quietly disappeared.
[20]
AI 'watermark removers' flood the web. Almost none can prove they work.
A market for removing AI watermarks has sprung up days after Anthropic disclosed switching on invisible marks in everything Claude writes, spanning a GitHub project with over 4,500 stars, a cluster of newly registered web tools, and at least one established AI detection evasion service. None of the claims about defeating the text watermark can currently be checked, though, because Anthropic has not yet published how it works or released the detector that would show whether a cleaned document still carries the mark. Who is offering what Among the largest is watermarks-remover, an MIT-licensed tool from software developer Guillaume Meyer, founder of Memo. It began as a Claude-only agent skill and now advertises coverage of Claude, Gemini and SynthID-Text, OpenAI provenance surfaces, and open-weight models using Kirchenbauer-style marks. Meyer's post on social media quickly gained momentum surpassing 2 million views: Alongside it sit repositories including claude-watermark-cleaner, remove-ai-watermarks, and noai-watermark, plus a cluster of web tools that have appeared since: claudewatermark.com, claudewatermark.rip, gptcleanup.com and claudewatermarkremover.app. StealthGPT, which sells AI detection evasion, added a Claude watermark remover to its use-case pages. Another, Human Writes, advertises bypassing Turnitin and GPTZero on essays and assignments, claims to strip Claude's watermark, and carries a footer telling users it must only be used in compliance with academic integrity policies. StealthGPT's own comparison table caveats that "no tool guarantees 100% bypass, detector models update regularly," on the same page where it announces it now removes Claude watermarks. What 'watermark removers' actually do The tools do three different things, and only some of it is verifiable. Stripping hidden characters from text works and can be counted: zero-width characters, bidirectional controls, Unicode tag characters and lookalike spaces. Stripping C2PA, EXIF and XMP metadata from files works too, across PNG, JPEG, SVG, PDF, DOCX, ODT, HTML and Markdown. That is the part that touches Anthropic's signed provenance data directly, and it is also not much of an achievement. File metadata does not survive a re-save, a format conversion or a screenshot anyway. The hard part is the watermark itself. It does not live in hidden characters. The watermark lives in which words the model picked, which means the only known way to remove it is to rewrite the text heavily, using a second model. Meyer is unusually candid about this, posting on Wednesday that his tool removes metadata only for now, and that stripping the actual marks may come later but is not available today. His README goes further, arguing that a rewrite swaps the original model's word choices for the cheaper model's, and asking why anyone paying for a premium model would then run its output through a worse one. The commercial sites are less careful. Several promise clean, undetectable output, and the scores some of them return are measured against ordinary AI detectors rather than against Anthropic's watermark, for which no public detector exists. Independent testing has already found gaps. Pasquale Pillitteri cloned the main projects and read the code rather than the READMEs, finding that one popular text cleaner let the most common hidden-payload technique through untouched. The hidden payload decoded back intact after the tool had supposedly cleaned the text. Why Claude is marking text at all Anthropic published a support page this week setting out its approach. Text from models launched on or after August 2, 2026 carries an imperceptible watermark woven into the wording. Supported file types get signed C2PA metadata. Marking is applied at the model level, so it appears across the API, claude.ai, Claude Code, Claude Cowork and Claude Tag, and through AWS, Google Cloud and Microsoft Foundry. The trigger is Article 50 of the EU AI Act, enforceable since August 2, with penalties reaching 15 million euros or 3% of global turnover. A detected mark also means less than it appears to. Anthropic acknowledges that it indicates content was processed by Claude, not necessarily written by it. Run your own prose through the model for a grammar pass, a translation or a summary and the output comes back marked. Anthropic's page also lists the ways a mark disappears, including heavy editing, paraphrasing and translation. The company says it will support third-party detection as the EU transparency rules require and will publish technical documentation later. The reaction online has been less charitable. Responding to Meyer's post, one user, Emad Ghorbaninia, called watermarking a "compliance checkbox, not a real defense." Meyer agreed on the first half, replying that it is "pure compliance to stay in the EU market." Ghorbaninia's stronger claim, that a single tool strips provenance marks from three vendors in one pass, does not survive contact with the repository, which says the opposite. The part that should worry defenders watermarks-remover ships as an agent skill, installed by symlinking a directory into a local skills folder and invoked with a slash command. Its optional scoring setup clones a third-party research repository and pulls a roughly 220MB artifact. Note: BleepingComputer has not audited or tested any of the tools named in this article. Readers should treat them with the same caution as any other unvetted code from the internet. That is the pattern worth watching. Whatever the merits of the underlying argument about provenance and privacy, a fast-moving category of tools that people wire directly into agent pipelines, and then feed their documents through, is a supply chain surface. The projects currently in the space are at least open and readable, even where they ship no licence at all. The next wave, arriving into a market with over four thousand stars of proven demand and no way for buyers to verify any claim, may not be.
[21]
Claude now watermarks your generated text for instant detection
You might want to think carefully the next time you copy-paste text from an AI chatbot. Anthropic has confirmed that its Claude AI models now watermark generated text and files, making it easier to gauge the authenticity of material -- with major ramifications for slop and privacy issues. An updated support page reveals that all Claude models launched from August 2, 2026 onward add watermarks. Text has an "imperceptible" mark in the text itself, while files like JPEG and PNG images use the open C2PA standard to make clear Anthropic's model was involved. Anthropic notes that the watermarking isn't "fully conclusive." It can tell you AI was involved, but won't tell you who was responsible or whether the content was changed afterward. Heavy editing, "very short" text, and processing can also dilute the watermark, so you can't assume a human was wholly responsible if a mark isn't detected. The watermarks will be present worldwide and travel with the content. Models released before August 2 will introduce watermarking in the future, Anthropic says. Why does Claude watermark AI text and files? EU law gives Anthropic no choice Anthropic is applying a watermark in response to the European Union AI Act's Code of Practice on Transparency of AI-Generated Content, whose first provisions entered into effect on August 1, 2024. The EU has gradually enforced more provisions around "general-purpose" AI models, and on August 2, 2026 began enforcing "core obligations" around transparency and "high-risk" AI systems in fields like education, justice, and medicine. Companies that violate the AI Act face penalties of up to €35 million (about $40.4 million) or 7 percent of their worldwide yearly turnover, whichever is higher. Anthropic doesn't have much choice, in other words. Even if you generate AI content outside the EU, it has to be marked in case it passes through. Google, Meta, OpenAI, and other companies have also said they would comply with the AI Act's Code of Practice, so switching models won't help you avoid watermarks. The marking could have mixed consequences. It might discourage AI slop, plagiarism, and misinformation by helping to spot machine-made content. However, there are privacy implications. Even though the watermarks won't directly identify you, they will show that someone used Claude and aid efforts to trace the origins of your work. Especially in text, where metadata is still rare, you might share more than you'd like.
[22]
AI-generated text should be detectable, but Apple needs to avoid this huge error
As someone who writes for a living, you would correctly guess that I'm wholeheartedly in favour of allowing AI-generated text to be detectable and marked as such. There's just a ridiculous amount of AI slop out there, and an "AI content" label means I don't need to waste my time reading any of it. However, Anthropic has just announced that it's complying with an EU initiative to have Claude watermark AI-generated text, but doing so in a particularly perverse manner ... Watermarking AI-generated images & text Apple is already preparing its own response to the problem of AI-generated imagery through a feature known as Apple Reference Image. It's likely the company will have to do something similar with Siri AI tools since they can be used for anything from proofreading to writing something for you. There's no perfect solution to this, as I mentioned last week when referring to the approach of using invisible characters to serve as watermarks. The most eye-opening requirement in the EU initiative is that AI companies must digitally watermark text output as well as images. This can be done using invisible characters, such as the one I just used to replace the space between the words 'invisible' and 'characters.' This would survive copying and pasting, although would be very easy to defeat using optical character recognition. Anthropic's perverse approach I mentioned then suggestions that Anthropic might instead take a different approach. Some are suggesting that Anthropic may go as far as using particular language patterns in Claude output in order to allow detection even for OCRed text. I could have very much to say about this, but that's beyond the scope of this piece. Well, it now appears that the company is indeed doing this, so it's time for me to have my say about it! The issue isn't that Claude will embed these language patterns in text entirely generated by the AI; I have no issue at all with that. The problem is that some people write their own text and then use AI chatbots for proofreading. It would appear that Claude will embed these hidden watermarks in the language even when it was only asked to identify and correct any grammatical errors in human-written work. This is, of course, one of the features offered by Siri AI. You can highlight text that you've written, tap the Siri button and select the Proofread option. Admittedly, my own limited tests of this suggest that it is rather too aggressive. It doesn't just detect and correct grammatical errors, but proposes its own phrasing. I would certainly like to see this toned down so that it is definitely the author's work, with no more correction than would be performed by a human sub-editor with a light touch. As an aside, this is why I tested but ultimately discarded Grammarly: the changes it suggested went beyond highlighting grammatical errors and typos and instead offered wording I would simply not choose to use. But assuming a light touch is Apple's intention, it would be wrong for an AI to deliberately mangle the language in order to allow it to be marked as AI content. It would also be wrong to mark it as AI content at all if the changes made amounted to nothing more than sub-editing. At most, a 'Proofread by AI' label would be appropriate. As I say, I don't pretend to have all of the answers to this. The growing use of AI chatbots to assist with writing and editing raises tricky questions. At what point does a piece written by a human and edited by AI become something that should be correctly identified as the hybrid work of the author and the AI system? What I do know is that deliberately changing the wording chosen by a human author who has asked an AI system for nothing more than proofreading is not the correct approach. While Apple will certainly need to respond in time to this issue, I very much hope it will choose a smarter path than that employed by Anthropic. What are your thoughts on this? Please share in the comments.
[23]
Claude text watermarks will "nudge" its word choices. Should we care?
Anthropic gave a nuanced answer to that question in a recently published blog post, arguing that the watermarking method it's chosen "does not impact the quality of Claude's output," although it will nevertheless "nudge" some of the model's word choices. "To a reader, a watermarked response is indistinguishable from an unwatermarked one," Anthropic said. "In internal testing, we've seen no impact of watermarking on the content, level of creativity, or readability of Claude's text." Claude's text watermarks, which are coming in response to the recently adopted EU AI Act, will employ a "version" of Google DeepMind's SynthID-Text process, which "changes the source of the randomness used to pick among words." As Anthropic explains, Claude's method of writing is similar to other LLMs: It generates each word one at a time, calculating the probability of each subsequent word and then picking from among the most likely choices. In some cases, such as responses with factual information, there may only be one good choice for a given word. For example, if you ask Claude who was the first human on the moon, there will be an obvious best choice for the next word after "Neil." Similarly, ask Claude what 2 + 2 is, and "4" will be the "very clear best choice" for the next word, Anthropic says. But (in an example served up by Anthropic), when generating a sentence about a cloudy weather forecast, Claude might have a range of likely next words in the sentence "It's going to be a..." The word "grey" could be a top choice with a 30-percent probability (I'm making that percentage up for argument's sake), as well as "overcast" with a 28-percent probability. Even without watermarking, Claude won't necessarily pick the word "gray" just because it has a higher probability ranking than "overcast." In a close contest like this one, the word Claude eventually chooses comes down to a roll of the dice.
[24]
Claude is watermarking every response -- here's what that means if you use AI for writing
Every word or code Claude writes now contains an invisble watermark Anthropic recently announced that all new Claude models will embed an invisible signal into their text output. The goal is to help identify AI-generated content and meet new transparency requirements under the European Union's AI Act. But if you're picturing an invisible digital stamp that permanently proves the words were written by AI, that's not exactly how it works. Instead, Claude subtly changes the statistical patterns in its writing. The text still reads naturally to humans, but software designed to look for those patterns can potentially recognize that it came from Claude. The announcement has reignited debate over whether AI watermarking is finally the answer to identifying AI-generated writing or if it even works. What is an AI watermark? Unlike a copyright watermark on an image or hidden metadata inside a file, a statistical watermark is built directly into the words themselves. The AI slightly favors certain word choices and sentence patterns while generating text. Individually, those choices are meaningless to us as humans, but across hundreds of words, they create a statistical signature that specialized detection software can identify. It's kind of like a fingerprint that is only recognized by software trained to understand the pattern. The watermark itself is invisible to readers and doesn't appear anywhere in the document. Copying text into Word, Google Docs or an email won't reveal anything unusual because the signal is designed to be detected only by software that understands the statistical patterns Claude leaves behind. Does watermarking affect the quality of Claude's writing? Slightly, but let's be real, AI writing isn't great to begin with. Alexander Cui, head of research at GPTZero, tells Tom's Guide that the statistical watermarking does introduce a small tradeoff because the model has to make slightly different word choices than it otherwise would. "The output quality does subtly decrease," Cui said. "Directionally, it does reduce the output quality." He added that modern watermarking techniques have become sophisticated enough that most users are unlikely to notice the difference in everyday use. And, while the watermark can be removed, it makes things much more complicated. Editing a few words won't remove a statistical watermark, in fact, many watermarking systems are designed to survive minor edits or paraphrasing. But the signal becomes much more fragile if Claude's response is rewritten by another AI model. That is, if you asked Claude to write your science paper and then asked ChatGPT to revise the draft. In that case, the watermarking becomes important because Claude's output often isn't the final product. A response might become the input for another chatbot, an AI coding agent or a document editing assistant before anyone reads it. Cui says the watermark generally doesn't survive that kind of workflow. "The watermark applies very subtle changes," he explained. "They usually would not affect downstream output. What you need is the actual text written by the model itself." Does this mean AI detectors finally have proof? Anthropic's watermark is one additional signal, but it's not definitive proof that a document was written by AI. Alon Yamin, CEO of AI detection company Copyleaks, says statistical watermarks can help identify AI-generated content, but shouldn't be treated as a silver bullet. "While this seems like a big step forward for AI detection on the surface, it's far from a silver bullet," Yamin said. He argues that watermarking should be considered alongside other evidence rather than replacing broader AI detection methods. These days, modern documents often mix human writing with AI assistance. From tools like Grammarly to help edit or Apple Intelligence Writing Tools, these common AI features have become integrated into daily use by many. For example, someone might draft an article themselves and ask Claude to improve grammar, reorganize paragraphs or rewrite a headline. Does ChatGPT do the same thing? OpenAI has spent years researching watermarking and other provenance technologies, but it has not broadly deployed statistical text watermarking across ChatGPT responses. Google has also explored watermarking techniques for AI-generated content, while several companies have experimented with metadata-based approaches instead of statistical signals embedded in text. As a result, Claude is currently taking one of the most visible steps toward model-level watermarking for everyday AI writing. You'll likely never notice a watermark while using Claude, and it won't suddenly make AI-generated writing easy to identify. But where it could matter is in education, publishing, enterprise software and workplaces that need to disclose when AI was used to create content. Bottom line The big picture here is that watermarking is a tool companies are experimenting with as governments push for greater transparency around AI-generated content. It can be useful under the right conditions, disappear after enough editing or rewriting and works best when combined with other evidence rather than on its own. But as of August 2, 2026, every word Claude writes now contains a hidden statistical watermark that most people will never see. Follow Tom's Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds. Subscribe to Tom's Guide on YouTube and follow us on TikTok. Finally, you can visit our dedicated Tom's Guide Savings Squad hub for expert help on getting the best products for less.
[25]
Claude will hide a watermark in your AI-written text, and it'll follow you around
Anthropic says existing Claude models will also gain marking support during the EU AI Act's transition period. Anthropic is adding invisible watermarks to text generated by the latest Claude models, giving AI-written content a hidden signal that can follow it even after it's copied out of the chatbot. The change comes as Anthropic signs the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content. In an update published on its privacy and legal support page, Anthropic says that new Claude models launched from August 2, 2026, will support machine-readable marking from day one. Despite the EU regulation prompting the move, the markings will apply worldwide wherever Claude is offered. The watermark is embedded directly into generated text and is designed to be imperceptible. Anthropic says it won't change the response's meaning, quality, or readability. Because the marking is applied at the model level, it will work across Claude, the Claude API, Claude Code, Claude Cowork, and Claude Tag, as well as supported cloud platforms. Importantly, the mark isn't tied to where you use Claude. Supported models accessed through AWS, Google Cloud, or Microsoft Foundry will also embed the watermark, where supported. The watermark will travel with the text when it's copied and pasted elsewhere and may survive some editing. However, Anthropic isn't positioning the technology as a definitive test of AI authorship. A detected mark indicates that content may have been processed by Claude, rather than proving that Claude originally wrote it. For example, someone could use AI to proofread, translate, summarize, or reformat their own work. The reverse also applies. A missing mark doesn't prove that the text wasn't generated or processed by AI. Heavy editing, paraphrasing, translation, short passages, or combining Claude's output with other writing can make the watermark undetectable. Anthropic hasn't yet detailed how users or third parties will detect the marks, saying it will publish technical guidance and detection mechanisms later. The company is also adding signed provenance metadata to supported file types, including PNG, JPG, and SVG. The metadata uses the Coalition for Content Provenance and Authenticity (C2PA) standard and can indicate that a file was processed by Claude. Anthropic isn't the first major AI company to sign the code. Google announced in July that it would sign the EU's transparency code, while Meta also confirmed its participation. The code provides a framework for complying with Article 50's requirements regarding the marking and detection of AI-generated content, which took effect on August 2. Existing Claude models launched before August 2 won't immediately support the new marking system. But the company is working to add the feature to those models during the transition period provided by the EU AI Act.
[26]
Anthropic's Claude Will Start Adding Invisible Watermarks to AI-Generated Text
Students and even some professionals trying to pass off AI-generated work as their own may soon have a harder time getting away with it. Anthropic announced this week that it will start adding machine-readable watermarks to content generated by its chatbot Claude, including invisible marks embedded directly into AI-generated text. With this announcement, Anthropic joins OpenAI and Google in outlining how it plans comply with transparency requirements under the European Union's Artificial Intelligence Act. According to an Anthropic support page, new Claude models launched in the EU on or after August 2 will support the marking system from launch. Generated text will contain embedded watermarks, while supported files will carry digitally signed provenance metadata. But the system won't be limited to Europe. Anthropic says the marks will apply to supported models across "Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, and wherever Claude is offered, worldwide." The company says it is also working to add marking to existing models and plans to provide tools that will allow users and third parties to detect Claude's marks. When it comes to text, Claude will hide a machine-detectable pattern directly in the words it generates. "When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself. You won't see it, and it doesn't change the meaning, quality, or readability of Claude's response," the company wrote. Because the watermark is embedded in the text itself, it travels with the writing when it is copied and pasted elsewhere and may even survive some editing. Still, there are some major caveats. Anthropic warns that finding a watermark only indicates that the content may have been processed by Claude. Because people also use Claude to proofread, translate, summarize, or otherwise edit their own writing, text that originated somewhere else could still carry a Claude watermark. Marked text could also have been modified or combined with other material after Claude processed it. The reverse is also true. The lack of a detectable watermark doesn't necessarily mean something wasn't generated by AI. Claude-generated text may lose the signal if it is heavily edited, paraphrased, translated, or mixed with other writing. Short passages may also not contain enough text for a reliable signal. Anthropic isn't the first major AI company to experiment with this kind of text watermarking. Google already uses its SynthID technology to embed invisible watermarks in AI-generated text. Meanwhile, OpenAI currently uses transparency tools including SynthID for images and audio, but hasn't pubilcally announced a detection system for text. Beyond text, Anthropic will also start attaching signed provenance metadata to supported files such as .svg, .png, and .jpg. The metadata follows the Coalition for Content Provenance and Authenticity (C2PA) open standard and can signal that a file was processed by Claude and whether it has been tampered with.
[27]
Anthropic starts marking all of Claude's output worldwide as EU transparency rules take effect
The company has signed the EU AI Act's Article 50(2) code of practice, committing to machine-readable marks on AI-generated text and images. The rules also reach the businesses that use the tools. Anthropic has begun attaching machine-readable marks to the text and images that its Claude models generate, and will apply them to users worldwide rather than only in Europe, after signing a European Union code of practice tied to new transparency rules that took effect on 2 August 2026. The company confirmed in a support document that it had signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-generated Content, as a provider of both generative AI models and generative AI systems. The step makes Anthropic one of the first large AI developers to set out, in operational terms, how it intends to comply with a law that will eventually require most AI-generated material circulating in the EU to be identifiable as such. The obligations reach further than one company because they divide responsibility between two groups. Providers, the firms that build and supply AI models, must ensure their systems' output can be recognised as artificial. Deployers, the far larger set of organisations that use those systems to create and publish content, carry separate duties to disclose it. The distinction determines who is responsible, and for what. How Anthropic is marking Claude's output According to Anthropic's documentation, Claude uses two techniques. For text, it embeds an imperceptible watermark that the company says does not change the meaning, quality, or readability of a response, and that remains in place when the text is copied and pasted or lightly edited. For files, it attaches signed provenance metadata to supported image formats, including .png, .jpg, and .svg, following the open C2PA standard maintained by the Coalition for Content Provenance and Authenticity. That metadata records where a file came from and can reveal whether it has been tampered with. The same scheme has been adopted by Adobe, the BBC, and a number of camera manufacturers to label the origin of images. Claude models launched in the EU on or after 2 August 2026 will carry the marking at launch, Anthropic said, while models released before that date are being updated to support it. The marking spans the company's products, including its developer API, the Claude apps, Claude Code, and its enterprise deployments, and is being applied globally rather than restricted to European users. Anthropic attached an important qualification. A detected mark shows only that content "may have been processed by Claude," the company said, and the absence of a mark does not rule out that content was AI-generated, because output from older models or heavily edited text may carry no mark at all. The company said it would publish further technical documentation on how third parties can detect its marks. A machine-readable mark is not the same as a visible label. The watermark and metadata are signals a detection tool can read, not a notice a reader sees on the page. Turning one into the other, an on-screen disclosure that a human can understand, is a separate step, and under the AI Act it is largely a duty for the organisations that publish the content rather than for the model provider. How it compares with rival AI companies? Anthropic is not the first major developer to move on content marking. In May 2026, OpenAI joined the C2PA coalition and partnered with Google to embed the latter's SynthID watermark into its image outputs, and previewed a tool that lets users check whether an image was generated by its models. SynthID, developed by Google DeepMind, embeds invisible marks into images that are designed to persist through screenshots, resizing, and compression. C2PA had attracted more than 6,000 members and affiliates by early 2026, though adoption across the wider industry remains uneven. What sets Anthropic's commitment apart is its emphasis on watermarking text, the format Claude is most used to produce and the hardest to mark reliably, and its framing of the work as compliance with a specific legal obligation rather than as a voluntary provenance effort. What Article 50 requires? The obligations stem from Article 50 of the AI Act, the bloc's risk-based law governing artificial intelligence, which entered into force in 2024 and is being phased in over several years. The transparency provisions in Article 50 became applicable on 2 August 2026. Paragraph 2 of the article addresses providers. It requires that the outputs of generative AI systems be "marked in a machine-readable format and detectable as artificially generated or manipulated," using technical solutions that are "effective, interoperable, robust and reliable as far as this is technically feasible." The requirement carries narrow exceptions, including cases where an AI system performs only an assistive or minor editing function and does not substantially alter the input. Paragraph 4 addresses deployers, and it is here that the obligations extend to organisations that simply use AI tools. Anyone deploying a system that produces a deep fake, meaning a synthetic or manipulated image, audio, or video resembling real people, objects, or events, must disclose that the content has been artificially generated. Deployers that publish AI-generated text to inform the public on matters of public interest must also disclose it, unless the content has undergone human review and a person or organisation holds editorial responsibility for it. Material that is evidently artistic, creative, satirical, or fictional is treated more lightly, needing only an indication that synthetic content is present in a way that does not spoil the work. In practice, the duty to label often falls on the user rather than the model. A marketing team producing a synthetic product image, a newsroom drafting copy with an AI assistant, or an agency generating an AI voiceover would each count as a deployer under the Act. A provider's machine-readable mark can make that disclosure easier to automate further down the chain, but it does not shift the legal responsibility from the deployer onto the company that built the model. The Code of Practice that Anthropic signed is a voluntary instrument intended to help companies meet the Article 50 obligations. It was published by the European Commission on 31 July 2026, two days before the rules applied, and sets out what the Commission describes as a "streamlined, predictable and legally certain pathway" to compliance. Signing the code and following it gives a company a presumption that it is meeting the relevant obligations. Around 190 organisations have signed, according to the Commission, spanning sectors from IT and telecoms to education and retail, with about half of them small or recently founded companies. The code is split into two sections: 82 organisations have signed the section covering providers and their marking duties, and 152 have signed the section covering deployers and disclosure. Provider signatories include Google, Meta, Microsoft, OpenAI, and the AI video company Synthesia, while the deployer list includes Getty Images, Lenovo, and Lufthansa. The Commission said two task forces would begin work in September 2026 to share best practice and develop the technical detail the law leaves open, an indication that key elements of implementation are still being settled. Enforcement and open questions Enforcement of the transparency provisions is only beginning, and questions remain over how robust the marking can be in practice. T ext watermarks are particularly hard to make tamper-proof: paraphrasing a passage, passing it through a different model, or simply retyping it can strip out the signal. That difficulty is part of the reason the Act qualifies its requirement with the phrase "as far as this is technically feasible," and it is consistent with Anthropic's own decision to present its marks as indicative rather than conclusive. The financial stakes for non-compliance are set to be significant once oversight matures. Under the AI Act's tiered penalty structure, breaches of the transparency obligations can draw fines of up to €15 million or 3% of a company's total worldwide annual turnover, whichever is higher. As we reported, regulators have been granted powers to inspect models and restrict market access, though the bodies responsible for enforcing the AI Act are still building up capacity. The EU has positioned the AI Act as an attempt to set a global benchmark for AI governance, and Anthropic's decision to apply Claude's marking worldwide, rather than maintain a separate compliant product for Europe, is a further example of European rules shaping products well beyond the bloc's borders. It is a pattern that has drawn both praise and criticism, with some industry figures arguing that Europe risks over-regulating a field where it lags the United States and China on investment. For the businesses that build on Claude and rival models, the more immediate task is a practical one: identifying which of their own AI-assisted outputs now require a label under Article 50, and how to attach one, before enforcement of Europe's new transparency regime gathers pace.
[28]
What Claude's AI text watermark actually does
Credit: Thomas Fuller/SOPA Images/LightRocket via Getty Images Anthropic has begun building a watermark into text generated by future Claude models, a change the company says is meant to help identify whether a given piece of writing was likely produced by its AI. This new feature, implemented to comply with EU rules, is meant to be indistinguishable to the human eye, without changing Claude's normal writing output. The company laid out the mechanics and rationale behind the feature in a post published to its website. How does the watermark work? According to Anthropic, the watermark exploits the countless small, low-stakes decisions a language model makes as it generates text. Rather than using a truly arbitrary random number to make that pick, the watermarked version of Claude bases the decision on a cryptographic key combined with the preceding text. The result, Anthropic says, is a subtle statistical pattern spread across a response that's invisible to a human reader but detectable to anyone with the matching key, which allows them to estimate the probability that Claude generated the text. Does it cost more or slow Claude down? Anthropic was clear in that the change carries no cost to output quality. The company said internal testing turned up no measurable difference in the creativity, accuracy, or readability of watermarked versus unwatermarked responses, and pointed to findings from Google DeepMind's original research on the underlying technique -- the method Claude's watermark is based on. The company also said that its researched showed no statistically significant shift in user satisfaction when a similar watermark was tested on live traffic. Anthropic also said the feature adds no extra tokens, meaning it doesn't slow Claude down or make it more expensive to use. Where does the watermark break down? Like with all tools, the watermark has limits. Anthropic explained that it only works when a model is choosing among several equally valid options, so text with little room for variation, such as hard factual statements, precise code, or math answers, carries a much weaker or nonexistent signal. Detection also grows less reliable on very short passages, since there's simply less pattern to analyze. So you'll get a much clearer read on Claude's likely involvement in longer-form text. And because the watermark tracks only the words Claude itself selects, lightly edited or proofread human writing may carry little to no detectable trace, since most of the original wording remains unchanged. A sufficiently heavy rewrite, the company noted, can remove the watermark entirely. At that point, per Anthropic, it becomes debatable whether the resulting text is still meaningfully AI-generated. Can the watermark identify my organization or me? Anthropic stressed that the watermark can't be traced back to a specific user, account, or conversation, and that it doesn't establish authorship or ownership over content. All it can tell you is the likelihood that Claude was involved in producing or editing it at some point. The company also distinguished the approach from third-party AI-detection tools, which typically rely on spotting stylistic patterns in AI writing rather than checking for an embedded signal tied to a private key. Why is Anthropic doing this? The rollout is tied to regulation rather than a purely voluntary move: Anthropic said it signed the European Union's Code of Practice on Transparency of AI-Generated Content in July 2026 alongside roughly 190 other signatories, following an EU AI Act requirement, effective Aug. 2, that AI providers mark generated text. Because the company doesn't yet have a reliable way to apply the watermark only within the EU, Anthropic said it's rolling out the feature globally and plans to extend it to older Claude models over the coming months. The company also said it will soon offer a separate API allowing anyone to check whether a piece of text carries Claude's watermark. Want to learn more about getting the best out of your tech? Sign up for Mashable's Top Stories and Deals newsletters or get Mashable push alerts today.
[29]
Claude to start watermarking AI-generated text - but will it make quality worse?
Anthropic says it will change way chatbot makes small, random choices, to comply with EU regulation The world is familiar by now with the usual tropes of machine-generated text: overuse of the word "delve", an excess of em dashes, and the chirpy, relentless construction of "it's not X but Y". But is it about to get even worse? Over the weekend, Anthropic released an update saying it would change how its Claude AI model generated prose. This is to comply with an EU regulation that requires all AI-generated text to be watermarked starting in December. Anthropic said the changes would be made at the granular, random level at which its models generated text and would be undetectable to the average reader. But at least one commentator thinks otherwise. "This entire endeavour is a perverse adulteration of what it means to write," wrote John Gruber, a veteran tech blogger. He argued the watermark would constrain Claude, forcing it to make worse, less precise word choices overall. While it may not make the model's writing less accurate, he suggested these limits would make it worse. There is a stochastic element in the small choices that an AI model makes in framing a sentence: whether it chooses to call a day "grey" or "overcast", for example, or refers to a running water as a "stream" or a "brook". Anthropic's new watermark will alter these random choices, it said, leaving a pattern that will be detectable to Anthropic itself, and to those who have a key to decode it. Steven Murdoch, a professor of computer science at University College London, said the change "probably wouldn't have any noticeable impact". Gruber's complaint appears to centre on the fact that watermarking will make a large language model less free to decide which word comes next in a sentence, and may therefore not pick the best choice. However, LLMs already do not make the best choices. "There's already randomness involved in any of these large language models," said Murdoch. "It's pretty essential to how they work. If it wasn't for this randomness, then they'd get stuck in loops and start repeating the same thing over and over again." In other words, a chatbot does not necessarily decide to call running water a "stream" as opposed to a "brook" because the latter might have a more old-fashioned register. The model does not contemplate these choices: it makes them by chance. This was evidenced recently when a paper in a leading chemistry journal had to be retracted because the authors appeared to have used an AI tool to draft part of the publication. The tool used the phrase "mass killing of an ethnic group" as an alternative for "final solution", though the paragraph in question appeared to be about a zinc nanogel. On the update, Murdoch said: "There's going to be no noticeable difference. There's the same random number generators there - it just used to be completely random, and now it's statistically predictable, but still random." The regulation, which applies to all AI companies operating in the EU, means they will have to put in place these watermarks within months. This could make it harder for students, lawyers and university professors to pass off chatbot-written content as their own. There is another reason to watermark AI content, though, Murdoch said: there's so much of it already out there that it might damage the models themselves. Training AI on AI-written content creates "model collapse", leading models to confuse concepts. In other words, watermarking is not just a quietly powerful way to combat disinformation-it's a deeply transformative system to ensure the chatbots don't go insane. If you delve into it.
[30]
'New models will mark AI-generated content from day one': Claude will now hide an invisible watermark inside ordinary words -- here's how that's even possible, and how EU rules could push OpenAI and Google to follow suit
To comply with the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, Anthropic has announced that "New models will mark AI-generated content from day one". This is a remarkable step for Claude, because it not only applies to any images it generates, which are relatively easy to watermark, but also to any text it generates. Anthropic says that Claude models will have an "imperceptible watermark" embedded directly into generated text at the model level. It says the mark should survive copying/pasting and minor edits. Anthropic has not yet publicly explained the exact algorithm or released a detector, so we can only speculate for now about how it might be doing this and its effectiveness. Hemorrhaging customers Personally, I think that Claude is about to start hemorrhaging customers, unless the marking is relatively easy to circumvent, or all the other major AI players immediately follow suit. If every piece of text it produces will now be easily identified as AI, then Claude becomes useless as a tool to a lot of people who are currently using it to generate text and are not being entirely honest about where that text came from. And then there's the issue of using Claude to proofread your human-written text -- will your text now be flagged as AI if you accept Claude's editing advice? Your initial reaction to that might be "Good! You should be forced to reveal when AI has written something, and it's about time people started writing on their own again!", and you'd be entirely justified in that opinion. But while it remains the only one of the big three AIs that's doing this, I think we'll see a lot of people switch to either ChatGPT or Gemini, because they don't want to be revealed as using AI in their work. How is watermarking plain text even possible? We don't know exactly how Anthropic is doing its marking with text yet, but my best guess is statistical watermarking during token generation rather than hidden Unicode characters or metadata. Imagine that at every point Claude is choosing among several perfectly reasonable next words: e.g. The movie was excellent / superb / terrific / impressive. Normally it chooses according to the model's probability distribution. A watermarking system can secretly divide possible tokens into preferred and non-preferred groups using a key. Claude then gives a tiny statistical nudge toward the preferred group. One word tells you nothing. But across 500 or 1,000 words, a detector with the key can ask if the text is choosing the preferred tokens significantly more often than chance would allow. If yes, then there's statistical evidence it came from the watermarked model. So, the watermark is more like a faint statistical fingerprint distributed across hundreds of choices, which would also explain how it can survive a copy-and-paste. You're essentially copying the fingerprint along with the words. But can you crack the code? Since Anthropic hasn't released an AI text detector yet, it's impossible to know how easy this code will be to break just by changing a few words. For instance, if you put your 1,000-word Claude article into another LLM and wrote "Rewrite this completely in different words while preserving the meaning", would it then be impossible to detect as AI? I'd also be interested to know how long a piece of text has to be before it can be marked in this way, and as soon as a detector is made available, I'll be testing it. Perhaps the bigger issue is that Claude has done this to comply with Article 50(2) of the EU AI Act. From August 2, 2026, providers of generative AI systems that produce text, images, audio, or video are required to make those outputs machine-readable and detectable as artificially generated or manipulated, insofar as that is technically feasible. Existing systems get a limited transition period until December 2, 2026 for this particular requirement. A note on Anthropic's statement confirms that the watermarking additions will be applied retroactively to all existing Claude models, not just any new models it produces. Anthropic's new system is explicitly a response to those rules, and it says the watermark will apply globally, not just when Claude is being used in Europe. Broadly speaking, OpenAI and Google face the same requirement if they want to offer qualifying generative-AI systems in the EU. They don't necessarily have to copy Anthropic's method of using statistical text watermarking, but they will need to produce output that is machine-readable and detectable, and the technical solution should be effective, interoperable, robust and reliable as far as technically feasible. I've contacted OpenAI and Google for comment, and will update this article if I receive it. For now, I think if Anthropic embarks on this path as the only one of the major three AI chatbots to do so, it could have a disastrous effect on its customer base. Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
[31]
Anthropic's text watermarks signal new front in AI detection
Why it matters: Comms teams using Claude to simply clean up, translate, or format human-drafted press releases could stamp those documents with an AI signature. How it works: For models launched in the EU after Aug. 2, Anthropic is marking content in two ways, "wherever Claude is offered, worldwide." * Text watermarks: Claude embeds patterns into the generated text that Anthropic claims are "imperceptible." * File metadata: Generated media files carry digital signatures confirming the asset was processed by Claude. Yes, but: Anthropic highlighted two major limitations to its detection tech. * AI-assisted can look AI-generated: Content may trigger a detected mark even if Claude was used solely to proofread, format or translate human-written copy. * Detection drop-off: If text is heavily rewritten, mixed with other copy or too short, then the watermarks might not be detectable. Zoom out: Anthropic explained its changes are designed to meet Article 50 of the EU AI Act, which mandates AI disclosures for generated or manipulated content. * OpenAI similarly outlined its compliance approach, though its current watermarking efforts primarily focus on images and audio rather than text. * The moves mark a regulatory-driven turn in the ongoing effort to help audiences identify AI-generated text, audio and visual content. * Digital platforms have recently accelerated their own AI identification measures: LinkedIn is testing a "seems like AI slop" button, Substack embedded Pangram's AI detection suite, and Snap stopped promoting AI-generated video in its main feed. What's next: AI providers have until Dec. 2 to bring legacy models into compliance with EU rules, meaning we'll get a clearer picture in the coming months of how the industry's biggest players plan to mark AI-generated content.
[32]
People Horrified That They'll Be Busted Now That Anthropic Is Watermarking AI Content
Can't-miss innovations from the bleeding edge of science and tech Using AI to crank out everything imaginable, from your homework to emails to code, is great and all -- until you have to own up to it. Fearless embracers of AI are suddenly clutching at their pearls, after Anthropic announced that its Claude chatbot will watermark the text it generates, potentially exposing anyone who wants to get away with using the tech without detection. The announcement has caused a meltdown in AI circles. "This watermark is the dumbest f*cking thing I've ever heard in my life. Are they going to ask you to provide an ID so you can write non-watermarked text?" seethed one user on r/ClaudeAI. "That mark will be the kiss of death on any piece of text that people can sell," another said. "People won't want to pay for it. It will be a scarlet letter." There were occasional injections of levity. "I thought it was already watermarking text by including an em dash every 4 words," one joked. But TechCrunch spotted an especially dramatic breakdown on the r/artificial subreddit, where a user who goes by visionode posted an extended rant comparing the watermarking scheme to nefarious police tactics and to systemic oppression. No, really. "Who will get caught? You. The student who used Claude to reorganize a paragraph. The journalist who asked the AI to summarize a two-hundred-page transcript. The writer who had creative block and asked for synonyms," visionode wrote. "Those guys come out of the process with a digital tattoo on their forehead." "You know what this reminds me of?" visionode asks. "Those police operations that arrest the drug user and leave the dealer alone. Watermarking is the same thing." "And the stigma," the user continued. "We're creating a caste of 'dirty' creators. People who dared to use a tool." Unfortunately for visionode, not many could get behind their heavily-downvoted post. "Did you generate this histrionic screed with a chatbot too?" one replier asked. Anthropic said it was implementing the watermark system in response to the European Union's landmark AI Act passed in 2024, which requires that AI companies mark content that's been generated or edited by their systems. It works by making subtle changes in the AI's word choices across the text it generates, which are supposed to be imperceptible to a human but, in aggregate, form a pattern that is detectable with the tool. It's definitely not a bulletproof approach. Anthropic says that the watermarks will "persist through some editing," but if it's pasted and rewritten with another chatbot, that signal could be destroyed, Ars Technica noted in its breakdown. And there's a worry that the word choices the AI goes with to create a watermark might deteriorate the quality of its prose. Terrifyingly, AI users may have to start polishing their writing without a chatbot. Worst of all, Ars warns, once Anthropic releases how its detection tool works, it'll be easy for bad actors to create a tool that goes in and erases the watermarks. We're already starting to see that happen with SynthID, Google DeepMind's own system for embedding hidden telltales of AI provenance in images -- though no one has figured out how to fully remove its watermarks yet.
[33]
Claude is getting ambitious with watermarking, and I can smell the problems from a mile away
Claude's text watermark could flag AI involvement even when it only helped with translation or editing Anthropic wants to make AI-generated text easier to identify, and on paper, I have very little reason to complain. The company is experimenting with an invisible watermark that can be baked directly into text generated by Claude. It sounds like a sensible idea. AI-generated text is everywhere, and knowing where something came from could certainly help. Moreover, Anthropic isn't simply hiding a marker somewhere inside a document. Its approach changes how Claude selects words to create a statistical pattern that can later be detected. Recommended Videos But there is one detail that bothers me. Anthropic is testing just how persistent that watermark can be, even after the text has been modified. That is where I can already smell trouble. Claude touched my writing. Did it actually write it? Think about translation for a moment. Let's say someone writes an entire essay themselves in Spanish and asks Claude to translate it into English. The ideas are theirs. The research is theirs. The arguments are theirs. Claude's only job is translation. Yet the resulting text could still carry Claude's watermark. The same question applies to proofreading. What if someone writes something themselves and asks Claude to fix the grammar? What about shortening a paragraph, changing its tone, cleaning up dictated text, or simply making an awkward sentence easier to read? These aren't fringe uses for AI anymore. People increasingly turn to assistants like ChatGPT, Gemini, and Claude for everyday tasks that have little to do with generating original work. A watermark can tell you that Claude was involved with a piece of text. It cannot tell you whether Claude actually wrote it. Anthropic makes the same point, saying the watermark shows Claude's involvement, not who created the original work. Now imagine explaining that distinction to a professor after their detection software has just flagged your essay. We already know how messy AI detection can get I wouldn't worry nearly as much if our track record with AI detection were particularly good. It isn't. MIT Sloan's guidance is quite straightforward about existing AI detectors. It says they have high error rates and can lead instructors to falsely accuse students of misconduct. We've already seen what that looks like in practice. Students have found themselves defending work they say they wrote themselves after automated systems identified it as AI-generated. In one case documented by The Guardian, a student's essay was flagged as entirely AI-generated despite the student saying they had only used approved spelling and grammar assistance. The appeal was eventually accepted. To be clear, Claude's watermark is fundamentally different. Conventional AI detectors look at writing and essentially estimate whether an AI might have produced it. Anthropic is deliberately planting a detectable signal in Claude's output. In theory, that should make its system considerably more reliable. But reliability isn't the only problem here. Interpretation is. We're using AI to prove we didn't use AI Things have already reached a slightly ridiculous point. Students worried about AI detection are turning to so-called AI humanizers, which rewrite text specifically to make it less likely to trigger detectors. Some students are even using these tools on work they wrote themselves because they're worried about false positives. Detector companies, naturally, are developing ways to identify humanizers. Read that again. A human can write something, worry that an AI will think an AI wrote it, feed it through another AI to make it look more human, and then have yet another system determine whether the AI made it look human. It's a technological ouroboros. Making Claude's watermark resilient enough to survive editing and translation is technically impressive. Previous research has shown that translation can defeat some text-watermarking techniques, so solving that weakness would represent meaningful progress. I just don't think making the signal harder to remove solves the more important problem. A watermark needs context There are good reasons to watermark AI-generated content. It could help identify mass-produced misinformation, undisclosed synthetic text, or AI-written material that later ends up in training datasets. The problem is that AI assistants now do far more than generate content from scratch. People use them to translate text, proofread documents, summarize research, help with code, improve accessibility, or simply clean up an email before sending it. In that context, detecting AI involvement does not automatically tell you who actually created the work. All of those interactions involve AI to wildly different degrees. If Claude writes an essay from scratch, knowing that is useful. If Claude translates an essay someone spent three weeks researching and writing themselves, knowing Claude was involved tells you considerably less. The watermark may be perfectly capable of answering "Did Claude touch this?" My concern is what happens when people start treating the answer as proof of "Did Claude write this?" Anthropic can build the smartest watermark in the world. Unless the people using it understand that difference, I suspect we're going to have some problems.
[34]
Anthropic adding watermarks to Claude AI-generated text and images
The AI company signed the E.U. AI Act's transparency code and says new Claude models will mark content from day one of release Anthropic is adding machine-readable marks to text and images generated by its Claude models, a step toward complying with E.U. rules requiring AI companies to label AI-produced content. The markings are imperceptible to the human eye but enable people and platforms to identify when content has been produced by Claude. The company uses two methods. Text generated by supported Claude models carries an embedded watermark that Anthropic says travels with the content if users copy and paste it and may hold up through some degree of editing. For files such as .png, .jpg, and .svg images, Anthropic is applying signed provenance metadata using the C2PA open standard, which is also used by Adobe $ADBE, OpenAI, and Google $GOOGL, according to The Verge. Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag are all covered by the marking system, and the company said the watermarks extend to supported models running through AWS, Google Cloud, or Microsoft $MSFT Foundry as well. Anthropic said it is also working to let users and third parties detect these marks, with technical documentation to follow. The E.U. AI Act's Article 50(2) transparency requirements took effect on August 2. Anthropic said Claude models launched on or after that date support marking from release, while the company is still working to add marking support to models released before that date. The Verge noted that existing AI products carry a four-month compliance grace period under the rules. Anthropic is hedging on the reliability of the system. The company said a detected mark signals that content may have been processed by Claude but is not fully conclusive -- Claude may not be the original author if it was used to proofread or translate someone else's work, and the content may have been modified after processing. The absence of a mark also does not confirm content is human-generated, since heavy editing, short passages, format conversions, or use of older models can all result in undetectable marks. Anthropic is not alone in making these commitments. According to TechCrunch, Black Forest Labs, Google, Meta $META, Microsoft, OpenAI, and Synthesia are among the other companies that have pledged to follow the E.U. code. C2PA metadata can be lost through routine actions -- including uploading files to social platforms -- and Anthropic has declined to name or describe the technical underpinnings of its text watermarking method.
[35]
Your Claude-generated text will soon include AI watermarks
The new policy, which is mandated by the European Union's AI Act, will apply to any text or files that were created or otherwise touched by Claude, including computer code, company reports, or cover letters to potential employers. In a recently published support page, Anthropic says that new Claude models launched in the EU on or after August 2, 2026 will support adding watermarks to the content they create or edit, and that it's working to add watermarking abilities to previously launched Claude models. The watermarking mandate stems from the EU AI Act, which includes a provision boosting the transparency of content that was created or "processed" by AI. Anthropic says it will deploy Claude's watermarking abilities worldwide and across all Claude products, including Claude Cowork, Claude Code, and the Claude API, to comply with the law. When it comes to marking text, Anthropic says a "supported" Claude model "weaves an imperceptible watermark into the text itself," and that the mark will remain present after the text is copied and pasted, or even after "some" editing. Meanwhile, Claude will attach "provenance" metadata to certain files it creates, including SVG, PNG, and JPG files. Anthropic says it plans on releasing tools that allow anyone to detect the watermarks, with details on those tools slated to arrive in "forthcoming" announcements.
[36]
Anthropic Is Quietly Watermarking Every Claude AI Output. Builders Are Already Trying to Break It
The markings apply worldwide across Claude, the API, Claude Code, and cloud partners. Anthropic has begun embedding an imperceptible watermark in all text its newest Claude models generate. The change took effect for models launched in the EU on August 2, 2026, and Anthropic says it will apply worldwide. Anthropic laid out the plan in a support article after signing the EU AI Act's Code of Practice on transparency. In other words, it's not exactly volunteering to do this. The mark reaches every Claude surface, from the chatbot and API to Claude Code and cloud partners such as AWS, Google Cloud, and Microsoft Foundry. "When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself. You won't see it, and it doesn't change the meaning, quality, or readability of Claude's response," Anthropic said. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing." So it's a bit more complex than the usual methods users tend to think about. When a supported Claude model writes text, it weaves an imperceptible watermark directly into the words, with no visible tag. Because the mark is part of the text, it survives copy-paste and, Anthropic admits, "may persist through some editing." Files get a second layer: signed metadata under the C2PA open standard (think a digital shipping manifest that records who produced a file and whether anyone altered it afterward). The method stays secret Anthropic hasn't said how the watermark is made. The support article calls it model-level (the model is trained with it) and text-native (it's not an external tool like metadata generator, for example), but the detection documentation and the exact technique aren't out yet. Researchers infer it's a statistical signature: The model nudges its word choices toward a faint, detectable bias, the same family of approach Google uses in SynthID Text. That remains a guess until Anthropic publishes the detector. But that isn't pushing privacy enthusiasts back, and some experts are already working on methods to break Anthropic's secret watermarking. mikiane/claude-watermark-cleaner (106 stars on Github) scrubs invisible Unicode, then rewrites text with a non-Claude model to disturb the token pattern. A larger project, guillaumemeyer/watermarks-remover (4.6k stars on Githum), strips Claude text marks plus C2PA and SynthID-class signals across PNG, JPEG, SVG, PDF, and DOCX. The authors argue a statistical text mark is "not a reliable way to prove origin" and mostly pushes users to spend a second model pass cleaning their own writing. No removal can be guaranteed until Anthropic ships its detector and thresholds. Anthropic's own history makes the privacy reaction sharper. The company removed a hidden Claude Code tracker in March after researchers found it tagging some users' location and proxy use through undisclosed Unicode markers -- the same quiet-marking technique now at the center of the watermark plan. The mark proves Claude had a hand in text, not that it wrote the whole thing, so it will treat an original writing with a small edit the same as a fully AI-generated text. Ask Claude to proofread or translate your paragraph and the output can still carry the signal. Anthropic is upfront that heavy editing can strip it, and that a missing mark doesn't prove a human wrote something. A U.S. bill, the COPIED Act, pushes the same idea: a standardized way to watermark AI content so platforms can trace its origin. As Claude's blackmail problem showed, the company's models already draw intense scrutiny over what they do with the text they touch. Anthropic hasn't said when it will publish the detection tools that would let anyone verify the mark.
[37]
EU rules force Anthropic to expose AI writing worldwide
Anthropic will invisibly watermark all of Claude's text and file output from 2 August to meet EU AI Act transparency rules, with the marking applied globally, whether or not the user is anywhere near Brussels. Anthropic will begin embedding invisible watermarks into text generated by its Claude large language model and chatbot in a move designed to satisfy new European Union rules on AI transparency. "Claude models launched on or after August 2, 2026 support marking at launch. We're also working to add marking support to Claude models released before that date," the San Francisco based AI giant said in a statement. The new marking policy includes all of the services provided by Claude, including its consumer app, the developer-facing Claude Platform (API), Claude Code, Claude Cowork and Claude Tag, as well as versions of Claude accessed through AWS, Google Cloud and Microsoft Foundry. The watermark will either be weaved in as "an imperceptible watermark directly into the text itself" or as metadata, so that when "Claude generates a supported file type, such as a .svg, .png, or .jpg, it will attach signed provenance metadata... [that] signals that a file was processed by Claude and lets you detect whether the file has been tampered with." Anthropic said the watermark would apply to every region where Claude is offered, not just the EU. The marking will not be limited to Europe. Anthropic said the watermark would apply everywhere Claude is offered worldwide, another example of how the EU's standard of compliance has ripple effects on the global standards being set for AI. How the watermark works Anthropic uses two separate techniques. The first includes inserting an imperceptible pattern directly into generated text, invisible to readers but detectable by machines and able to travel with the text even after it has been copied and pasted elsewhere. According to the company, it doesn't change the meaning, quality or readability of Claude's response. The second technique applies to files. It functions more like a digital paper trail, similar to EXIF data on a photograph, and is designed to be checkable rather than concealed. Seeing it in practice would likely require a C2PA-aware tool or Anthropic's planned detection system, rather than a standard "properties" menu, and it would not necessarily identify Claude by name so much as flag that the file passed through an AI system. The company has also been explicit that the metadata can be lost. Anthropic said a file's marking can be stripped through format conversion, re-saving, screenshots, or other similar processes, meaning a document or image that once carried a Claude mark may no longer show any trace of it after being edited or converted. Why now The timing traces directly to the EU's AI Act. The act requires that AI systems creating synthetic content, such as deepfakes, mark their outputs as artificially generated under Article 50. Regulators expect providers to rely on a multi-layered marking strategy, combining digitally signed metadata, imperceptible watermarking and, in some cases, fingerprinting or logging as a fallback, since the Code of Practice makes clear that no single marking technique is sufficient on its own. The transparency obligations under Article 50 took effect on 2 August 2026. Non-compliance can trigger fines of up to €15 million or 3% of total global annual turnover, whichever is higher. Can people still cover their tracks? Anthropic has been explicit that a detected watermark is a signal, not proof. A mark showing up in a piece of text confirms only that it may have passed through Claude at some point, not the full history of how that text came to be. People often use the assistant to proofread, translate or summarise material that originated elsewhere, so a watermark can appear on text Claude did not originally write. The reverse is also true: heavy editing, translation, very short passages, or use of an older model without marking support can all mean genuine Claude output goes undetected. Anthropic is not alone in this. Google DeepMind has already developed SynthID for marking AI-generated text, images and audio, while OpenAI has discussed watermarking approaches but has moved more slowly to deploy them broadly.
[38]
Claude to start watermarking AI-generated content
Anthropic's Claude is the latest AI to start watermarking AI-generated text and files. Credit: Anthropic Anthropic's Claude will start watermarking AI-generated content in compliance with EU rules, the company announced on Tuesday. In a Claude support document, Anthropic wrote that it has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, and explains how it plans to put those rules into practice. Models launched in the EU on or after Aug. 2, 2026, wrote Anthropic, will support watermarking at launch. This includes output from all models including Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag. Generated text will have embedded watermarks, while generated files will include "digitally signed provenance metadata where supported." Notably, it won't apply only to Europe; instead, the watermarks will appear wherever Claude is offered, worldwide, though Anthropic warns that some platforms or features may not support certain watermarking types. The watermarks won't be visible if you don't know what you're looking for. For text files, the watermark will be "part of the text" and it will "travel with the text when it's copied and pasted elsewhere," but Anthropic doesn't really go into the technicalities of how this will work. For files such as images, Anthropic will use the Coalition for Content Provenance and Authenticity (C2PA) open standard. Details on how to recognize these watermarks will be shared in "forthcoming documentation," wrote Anthropic. As for existing models that were launched before Aug. 2, 2026 (that's pretty much all of them at writing time), Anthropic says it's working to add watermarking support to those as well. Watermarking won't be foolproof, warns Anthropic. For example, heavily edited, paraphrased, or translated text could not carry a detectable watermark, and a file's metadata could be stripped through format conversion, screenshots, or other means. Anthropic's move follows similar commitments by AI companies including OpenAI, Google, and Meta. Want more tech and digital culture news delivered to your inbox daily or sent straight to your device? Sign up for Mashable's Top Stories newsletter or get Mashable push alerts today.
[39]
Anthropic to start watermarking Claude-generated text, images
Anthropic PBC has announced plans to embed an invisible watermark in text and images generated by Claude. The Register reported the change today, citing a help desk article published on Monday. It applies to the Claude artificial intelligence model series and the Anthropic services that it powers. The watermarking mechanism is designed to bring Claude into compliance with the European Union's AI Act. The law, which went into effect in 2024, includes a voluntary clause known as the Code of Practice that Anthropic has signed. The provision requires model providers to mark AI-generated content. Anthropic says that text watermarking will be performed by Claude models released after August 2. It plans to bring the capability to earlier models further down the line. According to the company, the watermark is invisible and persists if the text that contains it is copied to other applications. It may even remain in place if users make edits. Anthropic didn't specify how the text watermark works. However, a research paper released by Google DeepMind in 2024 may provide clues. The paper describes a technology that modifies a language model's word choices to make the text it generates detectable. Anthropic's watermarking mechanism may use a similar method. DeepMind's watermarking mechanism supports not only text but also AI-generated images, videos and audio. The technology, which is known as SynthID, is integrated into several of Google LLC's consumer AI services. Anthropic likewise plans to mark media files generated by Claude. The company's Monday help desk article lists JPG, PNG and SVG among the image formats covered by the initiative. Anthropic will mark images using a technology called C2PA. It works by pairing AI-generated images with a metadata file that specifies what model created them, when and whether any copyright restrictions apply. Developers can also add in other details. C2PA includes multiple mechanisms designed to prevent hackers from tampering with images' metadata. It creates a hash, or unique identifier, of each metadata file that makes it easy to spot edits. The technology can also detect when hackers attempt to replace the entire metadata file rather than edit it. Anthropic plans to release tooling that will make it easier for users to detect Claude-generated content. However, the company cautioned that the technology won't be perfect. In particular, it may not always detect watermarks embedded in short or heavily edited text snippets. OpenAI Group PBC has also signed the AI Act's voluntary Code of Practice. The provision went into effect last week, which means that the ChatGPT developer may soon launch its own text watermarking mechanism. OpenAI created an implementation of such a feature in 2024 and sits on the steering committee of the consortium that develops C2PA.
[40]
Anthropic models will soon inject watermarks identifying AI-generated text
The imperceptible marks will be invisible and will travel with the text, the company says. Anthropic said in a support document Tuesday that its future AI models will put an invisible watermark in all text, identifying it as AI-generated. The change comes in response to new AI transparency laws in the EU, but Anthropic says it will apply in all countries where Claude models are used. No U.S. law currently requires AI-generated content to carry transparency disclosures or watermarks, although a growing number of states, California among them, have enacted AI transparency laws with labeling requirements. In the support document, Anthropic says it has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, which includes watermarking provisions, and explains how it plans to put those rules into practice. Claude models released after August 2, 2026, will generate watermarks within text at launch, Anthropic explained. Under EU law, AI providers will have until December 2, 2026 (about four months), to upgrade earlier or existing models to support the machine-readable marking requirement. Anthropic isn't giving away too much information about how it will add the watermarks to the text, but it says the watermark will "travel with the text when it's copied and pasted elsewhere." More details will be included in "forthcoming technical documentation," the company says. The models will also inject standard provenance data into generated images, video, and audio. That part of the plan will satisfy the requirements of California's AI transparency law. Anthropic will use the Coalition for Content Provenance and Authenticity (C2PA) standard. According to the European Commission's signatory list, about 190 companies and organizations had signed the Code of Practice on Transparency by the end of July 2026. Other than Anthropic, signatories include OpenAI, Google, Microsoft, Amazon, Mistral, Cohere, and others. Conspicuously absent are Elon Musk's xAI and Mark Zuckerberg's Meta.
[41]
Anthropic pledges to watermark AI content in EU
Models launched on or after 2 August will support machine-readable content marking. Anthropic said its new models will begin watermarking content in the EU, as strict obligations from the bloc's landmark legislation on AI start taking effect. New transparency rules under the EU AI Act began taking effect earlier this month, which require certain AI systems to tell users when they are interacting with AI and how the content they are consuming is generated or altered by it. The Claude-marker is one of more than 200 signatories of the Act's Code of Practice on Transparency of AI-Generated Content - a voluntary tool aimed at helping businesses comply with the sweeping law. Several major AI providers, including OpenAI, France's Mistral, Meta and Microsoft are also signatories. Anthropic said that models launched on or after 2 August will support machine-readable content marking, meaning files generated by its AI will include digitally signed provenance metadata such as embedded watermarks on text and Coalition for Content Provenance and Authenticity (C2PA). The watermarks will only appear when supported Claude models are accessed through its cloud partners Amazon Web Services, Google Cloud or Microsoft Foundry, it said. The company said it is also working on adding watermarking capabilities to its older models. "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from," Anthropic explained. "If a signed metadata label is present, it signals that a file was processed by Claude and lets you detect whether the file has been tampered with." AI labelling has emerged as a way to for users to detect artificially altered content as the technology advances to produce near-realistic outputs. OpenAI's now defunct image generating model Sora, for example, was outfitted with C2PA mechanisms, alongside other major platforms such as TikTok and YouTube. China, meanwhile, rolled out a new law last year that forced social media companies in the country to label all AI-generated content, including text, images, video and audio. Despite this, content created or altered using AI is going increasingly undetected. Anthropic said that it is "working" to enable users and other third parties to detect Claude's embedded watermarks and provenance metadata. The company, however, did not share how, yet. Meanwhile, the company recognises several pitfalls to content marking. It explained that Claude-generated content may not carry a watermark if the text has been heavily edited, paraphrased, or translated; if the generated passage is too small or if a file's metadata was forcible stripped through conversion or screenshots. At times, the model's watermark may appear on human-generated content if it was processed through Claude for reading or summarising. Don't miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic's digest of need-to-know sci-tech news.
[42]
Anthropic is adding imperceptible, model-level watermarks to Claude's AI-generated text
AI-generated text, images, and video have all reached that level where it's becoming increasingly difficult to tell the difference between what's human-generated versus stuff spat out by hardware sitting in a data center somewhere. This is why the European Union's Artificial Intelligence Act (AIA) requires AI companies to implement identification measures to ensure there's a simple check, while offering a Code of Practice. And on that note, Anthropic has posted a new article on its Claude support portal titled: How Claude marks AI-generated content. Here it details how Claude will begin to embed watermarks in AI-generated text, which the company describes as imperceptible and injected directly into the text itself. It will reportedly persist even with some editing, meaning that for those who do some light editing and reword Claude-generated text, the result will still include the watermark identifying it as AI-generated content. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing," Anthropic confirms. "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from." Anthropic notes that it's also working to enable Claude users and third parties to detect the embedded watermarks, with details on how this will work still to come. Anthropic notes that a positive detection means that it will mark text as being "processed by Claude," but it won't be "fully conclusive." One reason is that someone using Claude to proofread or make changes to a document doesn't necessarily mean Claude is the original author. Interestingly, when it comes to AI-generated images, Anthropic's Artificial Intelligence Act (AIA) compliance doesn't actually embed a watermark in the .svg, .png, or .jpg images you see, but rather via attached signed provenance metadata. Basically, the metadata in the file will include the confirmation that it was processed by Claude. When it comes to copying an AI-generated image via a screenshot and then saving it manually, this digital certificate of sorts is lost, so it's not as foolproof as embedding the watermark in generated text at the model level.
[43]
Anthropic's New AI Watermark Sparks Backlash From Claude Subscribers
Some Claude users say they are canceling paid subscriptions after Anthropic announced Friday that future versions of its AI models will automatically add invisible watermarks to AI-generated text, a move the company says is necessary to comply with the European Union's AI transparency rules that went into effect August 2. Dozens of Claude subscribers on X criticized the decision, expressing concerns that content generated or revised with Claude could still be identified as AI-assisted even after the text is reworked, reformatted, or incorporated into another piece of writing. Some critics described the policy as "a conspiracy against innocent Claude users." Others characterized the watermark as a modern-day "scarlet letter," a mark that could remain identifiable long after any piece of AI-assisted text leaves the platform. "Who will get caught? You," a user named visionode wrote in a lengthy post on Reddit. "The student who used Claude to reorganize a paragraph. The journalist who asked the AI to summarize a two-hundred-page transcript. The writer who had creative block and asked for synonyms. Those guys come out of the process with a digital tattoo on their forehead." Anthropic disputes that characterization. The company said the watermark "carries no identifying information and can't be traced to a specific person, organization, or chat." The new watermark, based on Google DeepMind's SynthID-Text technology, allows AI-generated text to be identified without a visible label. Instead, it embeds a statistical pattern into ordinary word choices made by the model. The pattern is invisible to readers, Anthropic said, but can be picked up by someone using a verification key to determine "the likelihood that Claude was involved in writing the text." The company said editing can affect whether the watermark can be detected, but acknowledged that minor revisions are unlikely to delete it. "Light editing probably won't remove the watermark completely," Anthropic said. "A complete rewrite where every word is replaced will."
[44]
Hey, Your AI Is Showing
It's obvious to anyone with an internet connection that AI-generated content is all over the place. Still, case-by-case determinations are often difficult to make. For every piece of unapologetic copy-and-paste chatbot content, there's a student essay with a style that's suspicious but not quite dispositive, an avatar that's polished but not implausible, or a LinkedIn post that's useless and annoying in a way that seems GPT-ish but also might just be how your co-worker writes now. A few years into the era of easy-to-generate AI images, videos, and text, the status quo is a mess, if not quite the crisis predicted by many AI firms and their critics. Generated images and videos have, as many worried, become a force in politics, but the assault on democracy has been mostly aesthetic rather than strategically deceptive, contributing to a general sense of uncertainty and unreality; likewise, across platforms where people congregate online, automated content has often behaved like rapidly advancing spam, glutting cultural spaces and marketplaces and exacerbating their worst tendencies. (When generative AI was new, the prevailing political fears were of high-stakes deepfakes and targeted disinformation. So far, what we've gotten is slopaganda.) This sucks, to be frank, and people are quite vocal about hating it. Which is why some platforms are taking steps to detect and label AI-generated content. Last week, Spotify announced it would be taking steps to label AI-generated music. "Listeners have been clear in telling us that they don't like seeing an artist profile that seems human, only to find out that the persona is AI-generated," the company said. Last month, Substack partnered with AI-detection tool Pangram to give users the ability "to scan text to see how much of it was likely written by hand or with AI assistance." TikTok, YouTube, and even Meta have taken steps to label some AI-generated content, while LinkedIn, where many users haven't encountered a human word in months, introduced a "Seems Like AI Slop" button. These steps are mostly downstream of the problem's cause, which limits how well they work. But there have been attempts at a solution closer to the source in the form of image watermarks. Google, for example, embeds one on pictures generated with Gemini, while OpenAI and Meta have systems for imprinting images generated with their tools with detectable marks. Some of this was preemptive of regulation -- Google has been using image watermarks for a while. But new European Union regulations, some of which are coming into force this month, kicked such efforts into high gear. The EU summarizes the rules as follows: Providers of chatbots, virtual assistants and other systems intended to interact with people must design them so that users are informed they are interacting with AI. Providers of generative AI systems -- producing text, images, audio, video -- must mark outputs in a machine-readable format and ensure they are detectable as artificially generated or manipulated. Image watermarking is familiar and works reasonably well, although it's far from a panacea (motivated actors can remove or avoid them, and there are plenty of unrestricted models that aren't as exposed to EU regulations as a trillion-dollar company). Multiple studies have confirmed the obvious about tagging images -- that such disclosures tend to reduce engagement, suggesting that at least some people want to know even if they can't tell. But Anthropic is first out with what it says is durable text watermarking: When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself. You won't see it, and it doesn't change the meaning, quality, or readability of Claude's response. Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing. For people with heavy exposure to current models, this is kind of funny: While AI text often carries obvious tells -- excessive "it's not x, it's y" formulations being the most notorious -- Anthropic's Claude writes in an incredibly distinctive voice. (Of the grating, meta-argument-obsessed "Claudish" -- also described as "Claudespeak" and "Claudeslop" -- programmer Werner Robitza writes that Claude talks as if it's "proving its reasoning rather than informing a reader," which may be a side effect of the model's focus on producing software rather than prose. In any case, it's unmistakable.) But it's also a pretty big deal, especially if other companies follow suit. There are people who readily disclose that they're speaking through a chatbot or using AI to put text in places where the status of its creation doesn't really matter in the same way it might in, say, a personal email (in a code base, for instance, or the pre-ruined, desolate social context of a LinkedIn feed). And there are certainly workplaces where AI use is encouraged across the board and such watermarks won't imply anything untoward. But there are plenty of situations where they will, and it's undeniable that dishonesty and misrepresentation are part of a lot of early AI use cases. Pretending that something wasn't generated by AI at school, or at work, or in public output on social media, accounts for a lot of AI text that people generate, encounter, and object to and for much of the value that some people are getting from LLMs. Watermarking AI text won't immediately solve the school-cheating crisis, for example, but it might make things interesting! At Stratechery, Ben Thompson argues that "to insist on [AI] watermarking is no different than insisting that a ballpoint pen advertise itself as the author," suggesting that the EU, with the help of AI firms, is drawing an arbitrary line. And in the long term, there really are challenges for this sort of thing: At some point, every piece of software on your computer or phone will have immediate adjacency to a generative-AI model. Already, Anthropic says, its watermark will be inserted into text where Claude was used to "proofread, translate, [or] summarize," content, which could mean marking such a wide range of outputs that the mark becomes less meaningful, or it could result in something like false positives (Substack's Pangram tool has inspired some backlash along these lines). But even if the cluster of technologies that the EU is currently regulating as AI does eventually disappear into anonymous, no-credit-needed tool-dom, and AI watermarking is reduced to the status of "Created With Microsoft Word" metadata or a digital camera's EXIF photo information, it's hard to argue today that Claude is much like "a ballpoint pen" at all -- an instrument that (1) gives away its own use to start with and (2) transmits the movement of its users' hands precisely with no elaboration and without pretending to have a human personality. For the next few years, at least, slop peddlers will be faced with three choices. They could acknowledge what they're doing and bet that their audiences don't care. They could double down and find tools that don't automatically give them away. Or maybe, just maybe, some of them will give up.
[45]
Anthropic Reveals How Claude Will Watermark AI-Generated Text
* Anthropic is developing a tool to detect Claude watermarks * Short passages may be harder to identify with the watermark * Light editing may not completely remove the watermark Anthropic has provided more details about the text watermarking system it is introducing for Claude, explaining how the invisible marker will work and what it can reveal. The company says the system will rely on word-selection patterns rather than adding characters or other visible elements to generated text. The watermark will not affect the quality, meaning or readability of Claude's responses and will not require additional tokens. Anthropic is implementing the technology as part of its compliance with the EU AI Act. Anthropic Details Claude's Text Watermarking System and Its Limits The watermark will change the source of randomness Claude uses when choosing between words that are similarly suitable, according to an Anthropic press release. These choices can create a pattern across a passage that a detection system can identify using a key. The method does not force Claude to use unusual words or favour specific terms. Anthropic is using a version of Google's SynthID-Text method, which Google DeepMind published in 2024. The company says its internal testing found no effect on the content, creativity or readability of Claude's responses. Google DeepMind also found no statistically significant difference in user ratings between watermarked and unwatermarked Gemini responses. The watermark is designed to show how likely it is that Claude contributed to a passage, rather than establish its complete origin. It does not reveal the user's identity, organisation or conversation, and cannot determine whether another AI generated the text. Detection is also less reliable with short passages because they provide fewer word choices for the system to analyse. The technology has similar limitations with certain types of content. Factual writing leaves fewer opportunities for alternative word choices without affecting accuracy. Proofreading can also produce a weak watermark because most of the text remains unchanged from the original. Code is likely to contain less watermarking because it often requires exact outputs, although the system can still apply to flexible elements such as comments. Anthropic says the watermark will have a negligible effect on Claude's performance and will not increase usage costs because it does not generate additional tokens. The company is also developing a detection API that will allow users and third parties to check text for the watermark. Light editing may not remove the watermark, while a complete rewrite can eliminate it. Translations generated by Claude will also carry the watermark because Claude selects all the words. Anthropic says this approach differs from conventional AI detection tools, which look for stylistic patterns rather than a model-specific watermark. Anthropic will also use C2PA content credentials for supported files created or processed by Claude, including PNG, JPG and SVG files. The cryptographically signed metadata will show that Claude was involved without revealing user information. C2PA is an open standard already used by camera manufacturers and image-editing software. The company is applying the watermark globally because it does not currently have a reliable way to limit the feature by region. Anthropic is doing so to meet EU AI Act requirements after signing the EU Code of Practice on Transparency of AI-Generated Content in July 2026 alongside several other major AI providers and around 190 signatories. Anthropic is also working to add the watermark to models launched before August 2, 2026. Those models are covered by a transition period under the EU rules, with the company planning to introduce the feature over the coming months.
[46]
AI Companies Are Suddenly Racing to Watermark Their Content -- Here's What That Means
Opinions expressed by Entrepreneur contributors are their own. AI companies are suddenly scrambling to watermark their work. Anthropic said this week it will start marking text created by its AI, including Claude, so it can be identified as AI-generated. The move complies with a new European Union law that kicked in August 2, according to TechCrunch. Every new model going forward will have this built in automatically, and the mark is supposed to stick around even after you copy and paste the text somewhere else. It's still unclear exactly how much you'd need to edit that text before the mark disappears. TechCrunch asked Anthropic point-blank and didn't get a straight answer. Anthropic says it'll eventually add this to older models too, but hasn't said when. Anthropic isn't the only one doing this. AI music app Suno said last week it'll start tagging songs made on its platform after getting hit with lawsuits. Newsletter platform Substack teamed up with a detection company last month to flag AI-written content, after its CEO complained about people passing off AI writing as their own, something he calls "Claudefishing." Big names like Google, Meta, Microsoft and OpenAI have all agreed to do the same.
[47]
Claude watermark explained -- What Indian users need to know
If you wrote it with Claude, it may now carry an invisible, machine-readable watermark inside the text.Anthropic has introduced a text watermarking system for Claude-generated content that travels with the words when they are copied and pasted. The marking applies across Claude's app, API, Claude Code, Claude Cowork and supported cloud platforms. Files can also carry C2PA provenance metadata.The move is linked to EU AI Act transparency requirements, but the marking applies globally, meaning Indian users are already affected.There is an important India-specific distinction, however. India's IT Amendment Rules require labelling and provenance metadata for synthetically generated information, while MeitY's clarification has focused on multimodal content such as images, audio and video rather than ordinary text.And the detection tool itself has not shipped yet. Heavy editing, paraphrasing or translation can weaken or destroy the signal. Even if a text is flagged, that does not prove Claude originally wrote it. Using Claude to proofread or summarise your own draft can leave the same trace.For students, freelancers and newsrooms, the takeaway is simple: *treat an AI-detection flag as a signal, not proof of authorship.*
[48]
Claude's New Watermarks Will Follow Text Even After It's Copied. The Era of Secret AI Use May Be Ending
Using AI can be empowering, but it can also spark controversy when people try to pass off AI-generated content as actually being human-made. The European Union is wary of the implications of deepfakes and other AI-fashioned material, so a new law mandates that AI-generated content is clearly labeled as such. Reacting to this legal change, Anthropic just announced that it's adding markers to text written by Claude, starting with the latest generation model and extending, soon, to earlier versions of the chatbot; the change applies, for now, to users inside the EU. It sounds like a subtle shift, but it may have large, long-term implications and affect businesses across the globe. In a blog post announcing the news, Anthropic noted that from now on, in the EU, "new models will mark AI-generated content" with "machine-readable marking." This means any text you generate with Claude, for personal or business use, will "carry embedded watermarks" and any generated files will "include digitally signed provenance metadata where supported." The company explains that it's conscious that as "AI-generated content becomes commonplace, greater transparency and signals about where content comes from can give people useful context about the information they consume." So while its move to watermark content is following E.U. law, it's really a transparency push that'll help consumers and perhaps the public in general. As well as marking any generated files with relevant metadata, Anthropic notes that "when a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself." It's invisible, so "you won't see it," and the company stresses it "doesn't change the meaning, quality, or readability of Claude's response." To ensure that people don't try to circumvent these protections, Anthropic explains that since these invisible marks are part of the text, they'll "travel with the text when it's copied and pasted elsewhere, and may persist through some editing." Of course, embedding these kinds of watermarks in Claude's output is pointless unless they can be detected, so Anthropic notes it's "working to enable users and other third parties to detect Claude's embedded watermarks and provenance metadata." It works by checking "whether a piece of text or a file carries a supported Claude mark. If a supported mark is found, it indicates that the content may have been processed by Claude." There are a couple of important words here: "users" and "may." The word users implies that this kind of AI provenance checking isn't going to be limited to institutions or companies, which may signal an end (of sorts) to the ongoing "is this piece of text written by AI or not?" debate. But the word may is significant too: Anthropic is not guaranteeing that the absence of a watermark indicates that some text is not AI-generated. What are the practical implications of this digital watermarking? Some people using AI may be tempted to disguise the fact, for a host of different reasons -- from as simple as "I was late to the project, so I used AI to write a bit" to more complex legal and ethical positions. Public debate has swirled around unfair use of AI too, including students relying on chatbots like Claude to cheat at school. Watermarking that's hard to remove could solve this issue: your boss, suspicious that you delivered so quickly, may run your project text through a detector to see if Claude was used or not.
[49]
Claude AI Now Embeds Invisible Watermarks Into Generated Text
Invisible watermarks in AI-generated text are no longer just a concept; they are now a reality, thanks to Anthropic's Claude AI. These watermarks, while imperceptible to human readers, embed a machine-readable signature into the text by subtly favoring specific linguistic patterns during generation. Squintist explores how this system aligns with the EU AI Act, which mandates identifiable markers for AI outputs and examines its broader implications. However, the approach is not without challenges, particularly in scenarios where paraphrasing or translation could strip away these markers, raising questions about its robustness in real-world applications. In this analysis, you'll gain insight into how the watermarking mechanism operates and the specific constraints it faces in highly structured or factual text. Discover the potential vulnerabilities introduced by open source AI models and the limitations of watermarking in combating misuse. Finally, understand how these developments intersect with evolving regulations and the broader debate over transparency in AI-generated content. This breakdown offers a detailed look at the balance between innovation and practicality in the quest for accountable AI communication. How Does the Watermarking System Work? The watermarking system operates through a hidden scoring mechanism integrated into the text during its creation. By subtly favoring specific word choices or phrasing patterns, the system embeds a unique signature tied to a secret key. For example, the AI might consistently prefer certain synonyms or sentence structures that are undetectable to human readers but can be identified by algorithms equipped with the corresponding key. This ensures the watermark remains invisible to the naked eye while allowing machine verification of AI involvement. This approach offers a practical solution for distinguishing AI-generated content, but its reliance on linguistic patterns also introduces vulnerabilities, particularly in scenarios where text is paraphrased or translated. Meeting EU AI Act Requirements The EU AI Act, set to take full effect in 2026, requires generative AI outputs to include machine-readable markers to combat misinformation, fraud and impersonation. Anthropic's watermarking system is a direct response to this regulation, making sure compliance with the law. Notably, the Act exempts basic editing tasks, such as grammar corrections, from this requirement. However, Anthropic has chosen to watermark all text generated by Claude AI, regardless of its complexity or purpose. This proactive approach underscores the company's commitment to transparency and accountability, but it also raises concerns about potential overreach. For instance, simpler use cases like minor text edits or casual writing may not necessitate such stringent measures, prompting debates about the balance between transparency and practicality. Here are more guides from our previous articles and guides related to Claude AI that you may find helpful. Challenges and Limitations of Watermarking Despite its innovative design, the watermarking system faces several challenges that limit its effectiveness in certain contexts. * Limited Effectiveness in Constrained Scenarios: The system struggles in contexts with restricted linguistic variability, such as generating factual answers, code, or highly structured text. These scenarios offer fewer opportunities for embedding unique patterns. * Vulnerability to Paraphrasing and Translation: Tools like paraphrasers or translation software can alter the text enough to strip away the watermark, rendering it undetectable. * Bypassing Through Open source Models: Open source AI models allow users to generate unmarked content, bypassing watermarking systems entirely and complicating efforts to ensure transparency. These limitations highlight the inherent difficulty of creating a foolproof system for identifying AI-generated text, particularly in an environment where content can be easily manipulated or produced using alternative tools. AI Detectors vs Watermarking: A Growing Arms Race AI detectors, which analyze writing style to identify AI-generated content, offer an alternative but imperfect solution to watermarking. These tools often produce false positives, especially when evaluating work by non-native English speakers or highly polished human authors. Conversely, advanced AI models are increasingly capable of mimicking human writing styles, further complicating detection efforts. This dynamic has created a technological arms race between watermarking systems and detection tools. As both technologies evolve to outmaneuver one another, the challenges of reliably distinguishing AI-generated content from human writing become more pronounced. While this competition has spurred innovation, it also underscores the complexities of maintaining transparency and accountability in digital communication. Impact on Academia and Professional Writing The rise of watermarking and detection tools has far-reaching implications for academia and professional writing. AI detectors have already flagged and rejected human-written content, including academic papers and creative works, due to stylistic similarities with AI-generated text. This trend raises critical concerns about originality, authorship and the reliability of detection systems in high-stakes environments such as education and publishing. For students, researchers and professionals, the increasing sophistication of AI tools blurs the line between human and machine authorship. This not only complicates efforts to verify originality but also challenges traditional notions of intellectual property and creative ownership. As these tools become more prevalent, institutions may need to adopt new frameworks for evaluating and authenticating written work. Broader Implications for Digital Content While invisible watermarks provide a method for tracing AI involvement in content creation, they do not address the accuracy or truthfulness of the content itself. The interplay between AI tools, detection systems and human creativity highlights the complexities of building trust in digital communication. As AI-generated text becomes increasingly indistinguishable from human writing, questions about transparency, accountability and ethical AI use will grow more urgent. Watermarking systems represent a step toward addressing these concerns, but they are not a comprehensive solution. Broader efforts will be needed to ensure that AI technologies are used responsibly and that their outputs can be trusted in critical contexts. Looking Ahead: The Future of AI Transparency Anthropic's introduction of invisible watermarks in Claude AI's text generation marks a significant step toward compliance with regulations like the EU AI Act. However, the system's limitations, such as its vulnerability to paraphrasing tools and the challenges posed by open source models, underscore the difficulty of making sure transparency in AI-generated content. As the boundaries between human and AI authorship continue to blur, the need for robust, reliable verification methods will become increasingly critical. These tools will play a vital role in maintaining trust, accountability and ethical standards in the evolving landscape of digital communication. The ongoing development of watermarking systems, detection tools and regulatory frameworks will shape the future of AI transparency, influencing how society navigates the challenges and opportunities presented by generative AI. Media Credit: Squintist Disclosure: Some of our articles include affiliate links. If you buy something through one of these links, Geeky Gadgets may earn an affiliate commission. Learn about our Disclosure Policy.
[50]
Claude Launches Invisible Markers to Detect AI-Generated Text
Artificial intelligence giant Anthropic launches an all-new machine-marking model to detect AI-generated text. Here is all we know. * Make Telecom Talk My Trusted Source Anthropic's Claude Adds Invisible Markers to AI-Generated Text Anthropic has introduced machine-marking for content generated by its Claude AI models, adding an invisible layer to help identify AI-generated text. The move comes as governments and technology companies seek to improve transparency around AI. The marking is embedded directly in the generated text rather than appearing as a visible label. Users reading or copying Claude-generated content may not notice it, but systems designed to detect the marker can identify its origin. Also Read: Microsoft Boosts India AI Push With New Hyderabad Data Center Anthropic says new Claude models launched in the European Union on August 2, 2026, will support machine-readable marking from launch. The system is part of its commitments under the EU AI Act's Code of Practice on Transparency of AI-Generated Content. The marking is also being extended worldwide to support models. The company is also applying provenance technology to generated files where supported. These measures aim to make it easier to establish the origin of AI-generated material as AI tools become common in writing, education, software development, and other professional settings. The development is significant because identifying AI-generated content has become increasingly difficult as language models produce text that closely resembles human writing.
[51]
AI-generated text will no longer be undetectable thanks to an "invisible" watermark
Differentiating human-written text from AI-generated text gets more and more complicated by the day, but in the European Union there are measures in place to prevent this, especially when transparency and legal obligations enter the game. Now Claude creator Anthropic says new models will actually mark AI-generated content from launch. Specifically, Claude models launched in the EU on or after 2 August 2026 will support machine-readable marking, with generated text carrying embedded watermarks and supported files carrying digitally signed provenance metadata. Anthropic claims it is also working to add marking to older Claude models. Basically, this means that Claude-generated text will include an invisible watermark. Anthropic explains the watermark is woven into the text itself, does not affect meaning, quality or readability, and can travel with the text when it is copied and pasted elsewhere. However, concerns about the quality of the generated text or about potential tools and techniques to cheat the system have been risen already, for instance by GPTZero's CTO Alex Cui. In fact, the system is designed for transparency, but it is not foolproof. Anthropic insists detection will indicate that content may have been processed by Claude, not prove full authorship. Marks may also disappear or become undetectable if text is heavily edited, paraphrased, translated, mixed with other writing, or if a passage is too short. Do you generate text with AI or polish your own writing already? With what model?
[52]
Anthropic's Claude Just Got a Hidden Watermark That Follows Your AI-Written Text Everywhere You Paste It
Anthropic is embedding "imperceptible" machine-readable watermarks directly into text generated by new Claude models, making copied AI output easier to trace as schools, publishers and other organizations grapple with undisclosed machine-written content. Claude Watermarks Follow Text Across Platforms IPO-bound Anthropic on Monday said Claude models launched on or after Aug. 2 will support marking from launch. The watermark "doesn't change the meaning, quality, or readability" of Claude's response, travels when users copy and paste text and "may persist through some editing." The marking applies worldwide across supported models used through Claude, Claude Code, Claude Cowork, Claude Tag and Anthropic's API, as well as through AWS, Google Cloud and Microsoft Foundry. Anthropic is also working to retrofit older models and plans detection tools for third parties. The move follows Anthropic's commitment to the European Union AI Act's transparency framework. EU rules require generative-AI providers to make synthetic output identifiable in a machine-readable format, aiming to give users clearer signals about content provenance. Schools And Publishers Gain New Detection Tool The technology could matter particularly in education. Anthropic recently launched Claude for Teachers, expanding the chatbot deeper into classrooms as educators debate responsible AI use. Watermarking could give schools another signal when investigating whether students submitted generated work as their own. Publishing faces similar pressures over AI authorship and training data. Anthropic recently secured final approval for a $1.5 billion copyright settlement with authors, highlighting how generative AI continues to collide with questions of authorship, ownership and disclosure. Detection Limits Leave Room for Workarounds That said, the watermark is not foolproof. Anthropic says heavy editing, paraphrasing, translation or mixing Claude output with other writing can destroy the detectable signal. Very short passages may also provide too little material for reliable detection. A detected mark also does not prove Claude originally wrote the material. Using Claude merely to proofread, translate or summarize human-authored text can leave a mark, Anthropic said. Image via Shutterstock Market News and Data brought to you by Benzinga APIs To add Benzinga News as your preferred source on Google, click here.
[53]
Claude Can Secretly Watermark AI Text Even After You Copy, Paste It
The move aligns with the EU AI Act Code of Practice for transparency Anthropic on Tuesday announced that it is adding invisible watermarks to text generated by its artificial intelligence (AI) models. According to the company, the content will have a hidden signal that remains even when it is copied and pasted elsewhere. The move builds upon Anthropic's decision to sign the European Union's AI Act Article 50(2) Code of Practice on Transparency of AI-Generated Content. Anthropic says Claude models launched from August 2, 2026, will support the marking system from day one, and the feature is rolling out globally. Invisible Watermarks in Claude Anthropic updated its support page to reveal a list of commitments it is putting into practice, in line with the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, which it has signed as a provider of both generative AI models and generative AI systems. As per the company, the watermark will be embedded within text generated by supporting Claude models. It has been designed to travel with the text when copied and pasted elsewhere, and can also survive some level of editing. While how the detection system will work is still being finalised, Anthropic eventually aims to provide users and third parties with tools to detect the embedded watermarks. Anthropic, however, emphasised that it will be imperceptible to users. Further, the addition of a watermark will not affect the meaning, quality or readability of the response. The process is claimed to be carried out at the model level and is not tied to a particular Claude product or interface. The company also claims that the watermark will not be a definitive AI detector, and should not be treated as such. "Detecting a Claude mark tells you that the content may have been processed by Claude. It does not, on its own, confirm the full provenance of the content," the support page reads. Citing an example, Anthropic said a user could write an article themselves and then use Claude to either proofread, translate, summarise, or change its formatting. Even then, there is a chance that the result could carry a Claude watermark, despite the initial idea and writing originating from the user. Meanwhile, the opposite is also likely; a missing watermark may not prove that content was not generated or processed by AI. Heavy editing, paraphrasing, translation, combining Claude output with other writing, or using a very short passage could make the mark undetectable, the company said. The new watermarking system is said to cover supported Claude models across Claude, Claude Platform (API), Claude Code, Claude Cowork and Claude Tag. Such watermarks will also be applied when supported models are accessed through cloud platforms including AWS, Google Cloud and Microsoft Foundry, where supported. Anthropic will use digitally signed provenance metadata for supported file types like SVG, PNG, and JPG, based on the Coalition for Content Provenance and Authenticity (C2PA) standard. This metadata will indicate if a file has been processed by Claude, and whether the provenance information has been tampered with. The watermarking system is being introduced in markets where supported Claude models are available.
[54]
AI watermarking: <b>Explained: Anthropic's plan to watermark all Claude-generated content, and how it works</b>
Invisible watermarks will be woven directly into text generated by Claude models. It will not alter the meaning, quality, or readability of a response and can travel with the text when copied elsewhere, potentially persisting through some editing. In a bid to make AI-generated material easier to identify, Anthropic has said it is working to add machine-readable marks to Claude-generated content. The move comes after the European Union's AI Act took effect. Anthropic has signed the Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, a voluntary framework aimed at making AI-generated material easier to identify. How it will work According to a post on Anthropic's website, Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch, with generated text carrying embedded watermarks and generated files having digitally signed provenance metadata where supported. Invisible watermarks will be woven directly into text generated by Claude models. It will not alter the meaning, quality, or readability of a response and can travel with the text when copied elsewhere, potentially persisting through some editing. For files generated via Claude, supported file types such as .svg, .png, or .jpg, will include signed provenance metadata. If a signed metadata label is present, it signals that a file was processed by Claude and lets you detect whether the file has been tampered with. Applicable to full Claude suite Anthropic said Claude markings will cover output from supported models, including Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag. Embedded watermarks will apply to all generated text. Provenance metadata will apply where Claude supports processing files. Conditions apply The AI giant cautioned that a detected mark does not mean it is a proof of AI authorship. "Claude may not be the original author. People often use Claude to proofread, translate, summarize, or convert files. The output can carry a Claude mark even if the underlying ideas, text, or data originated from another source," it said. Similarly, the absence of a mark also does not confirm that the content wasn't AI-generated, since older models, heavy editing, very short passages, or metadata stripped through format conversion could all prevent detection. EU's AI transparency rule in focus The European Union's new artificial intelligence transparency rules require companies to clearly label AI-generated content, including deepfakes, to help users distinguish between authentic and synthetic material. Under the new rules, companies operating AI systems, such as chatbots, must inform users that they are interacting with artificial intelligence. Text, images and other content generated using AI must also carry clear labels, which may include watermarks or other markers to facilitate identification. Existing AI systems have until December 2 to adapt to the new rules, and there are exemptions for "artistic, creative, satirical, fictional" work.
[55]
Tech's Big Push to Make AI Content Traceable | PYMNTS.com
Anthropic began embedding invisible, machine-readable watermarks into text from new Claude models launched on or after Aug. 2, 2026, the artificial intelligence company confirmed in an updated help center article. Canon and Google Embed a Signature the Instant a Photo Is Taken For photos, the fix starts in the hardware, not in software that runs after the fact. Canon launched its Authenticity Imaging System on May 11. It is the first manufacturer-operated service carrying C2PA Content Credentials, a cryptographically signed record of a file's origin and edit history, from capture through publication. The rollout starts in Europe, the Middle East and Africa, with Reuters as its pilot partner, C2PA Viewer reported. Google took a similar approach at the consumer level. Every photo taken with a Pixel 10's native camera app is signed by default with C2PA credentials, using hardware-backed keys in the phone's Titan M2 chip. That makes the Pixel 10 the first mainstream smartphone to sign every photo, not just the ones edited with AI, C2PA Viewer reported separately. Apple is taking a different route than the C2PA standard Canon and Google use. Code in iOS 27 beta 5 points to a feature called Apple Reference Image, authenticating a photo using data tied to the specific iPhone camera hardware that captured it, 9to5Mac reported. The feature would require a separate capture mode, so ordinary photos would carry no provenance data. Verification happens through Apple's Private Cloud Compute, where Apple says it never sees the raw photo, only sensor data and metadata. It has not shipped. The distinction between camera-level systems and Anthropic's text watermark is structural. A camera signs an image the instant light hits the sensor, before software touches the file. A text watermark cannot prove a person wrote something, since people already use Claude to edit or polish writing that started as their own. Anthropic warns that a watermark hit only signals that content may have passed through Claude. It is not proof of authorship, according to TechCrunch. Guessing After the Fact Has Limits That distinction changes what platforms can detect after content is already uploaded. More than 40% of LinkedIn posts longer than 250 words are fully AI-generated, according to detection company Pangram's analysis of over 1 million posts, PYMNTS reported. LinkedIn responded in July with a "Seems like AI slop" button, and Substack launched a Pangram-powered detector the same month. LinkedIn's classifiers correctly flagged generic AI content roughly 94% of the time in early testing, LinkedIn said, with no published data on false positives. Neither approach solves the problem alone. Metadata and embedded credentials routinely disappear during screenshots or re-uploads, and Nikon suspended its own C2PA signing service in 2025 after a security flaw forced it to revoke every certificate issued, according to C2PA Viewer. After-the-fact detection is becoming one layer of defense, not the whole system, as each company works to establish a chain of custody that starts at creation.
[56]
Anthropic Adds Invisible Watermarks to Claude AI for EU AI Act
Anthropic's Claude AI now embeds invisible watermarks into all text and code it generates, a feature aimed at complying with the EU AI Act. This legislation requires AI-generated content to include machine-readable markers for identification. According to Kyle Balmer | AI with Kyle, these watermarks are integrated directly into the structure of outputs, allowing traceability even after modifications like edits or reformatting. While this approach enhances transparency and accountability, it also introduces technical and practical considerations for users in fields such as software development and content creation. Understand how these watermarks function, including their reliance on embedded markers and provenance metadata. Explore potential challenges, such as the risk of false positives during detection or unintended effects on edited outputs. Gain insight into how this feature fits within broader regulatory trends and what it means for professionals navigating compliance and usability concerns. Why the EU AI Act Matters The EU AI Act is a pivotal regulation aimed at making sure transparency and ethical practices in AI-generated content. It requires the inclusion of machine-readable markers in all AI outputs, regardless of where they are created, if they are used within the EU. This means that even if you operate outside the EU, your AI-generated content may still need to comply with these rules. By embedding watermarks, Anthropic ensures that Claude AI adheres to these legal requirements. This proactive approach not only sets a compliance standard for other AI developers but also reflects the growing global emphasis on responsible AI practices. For users, this regulation underscores the importance of understanding how AI-generated content is identified and managed, particularly in cross-border contexts. How Claude AI's Watermarking Works Claude AI employs two primary methods to embed watermarks in its outputs: * Embedded Watermarks: These are imperceptible markers integrated directly into the structure of text or code. They remain intact even if the content is copied, edited, or reformatted, making sure consistent traceability. * Provenance Metadata: Digital signatures are attached to files, such as documents or images, to indicate their origin as AI-generated. This metadata provides an additional layer of verification. These mechanisms enable detection tools to identify AI-generated content, even after modifications. However, Anthropic has not disclosed the technical specifics of its watermarking system, leaving questions about its reliability and resistance to tampering. For users, this lack of transparency may create uncertainty about the robustness of the system and its ability to withstand deliberate attempts to obscure or remove watermarks. Browse through more resources below from our in-depth content covering more areas on Claude AI. Challenges You Should Be Aware Of While watermarking aims to enhance transparency and accountability, it introduces several challenges that could directly impact you: * False Positives: Human-edited or AI-assisted content might still be flagged as AI-generated, leading to potential misunderstandings or disputes in professional or academic settings. * False Negatives: Older AI models or short outputs may lack watermarks, making them harder to identify as machine-generated, which could undermine the system's reliability. * Impact on Code: Developers may encounter issues where slight structural changes introduced by watermarks affect the quality, readability, or functionality of generated code. * Misinterpretation Risks: Detection tools used by employers, educators, or other stakeholders could misidentify content, potentially leading to unfair accusations of plagiarism or misconduct. These challenges highlight the need for robust detection tools and clear guidelines to ensure fairness and prevent misuse. As a user, being aware of these potential pitfalls can help you better navigate the complexities of AI-generated content in your work or personal projects. Industry-Wide Adoption of Watermarking Anthropic is not alone in adopting watermarking practices. Major AI providers, including OpenAI, Google AI, Meta AI and Microsoft AI, have implemented similar measures to comply with transparency regulations. For example, Google's SynthID system, introduced in 2024, embeds watermarks in AI-generated images and text, offering a comparable solution to Anthropic's approach. This industry-wide shift reflects the growing importance of distinguishing AI-generated content from human-created material. For users, this trend signifies a broader movement toward standardized practices in AI transparency, which could lead to more consistent and reliable tools for identifying machine-generated outputs. Benefits of Watermarking Despite its challenges, watermarking offers several significant advantages: * Preventing Synthetic Data Contamination: Watermarks help ensure that AI-generated content is clearly identified, reducing the risk of synthetic data being inadvertently used to train future AI models. This prevents the compounding of errors and maintains the integrity of training datasets. * Fostering Transparency: By making the origin of content clear, watermarks promote trust in AI systems and their outputs. This transparency is particularly important in contexts where the distinction between human and machine-generated content has ethical or legal implications. These benefits align with the EU AI Act's broader goals of making sure responsible and ethical use of AI technologies. For users, the ability to clearly identify AI-generated content can enhance confidence in the tools they use and the outputs they produce. Unanswered Questions While Anthropic's watermarking initiative represents a significant step forward, several questions remain unresolved: * How effective will detection tools be in identifying watermarked content, especially in cases of significant editing or reformatting? * Can watermarks withstand deliberate attempts to remove or obscure them and what measures will be in place to address such scenarios? * How will users be informed about the presence of watermarks in their outputs and what level of control will they have over this feature? Anthropic has promised to release detection tools and documentation soon, but until these resources are available, the full impact of this feature remains uncertain. For users, these unanswered questions highlight the importance of staying informed and engaged with ongoing developments in AI transparency. Notable Exceptions in the Industry Interestingly, not all AI developers have embraced watermarking. For instance, XAI, Elon Musk's AI initiative, has notably refrained from signing the EU transparency commitments. This divergence underscores the ongoing debate within the industry about the best approach to making sure AI transparency and accountability. For users, this lack of consensus among developers may result in inconsistencies in how AI-generated content is identified and managed across different platforms. Understanding these differences is crucial for making informed decisions about which AI tools to use and how to comply with relevant regulations. What This Means for You The introduction of invisible watermarks in Claude AI's outputs marks a significant shift in the AI landscape. While it aligns with regulatory requirements like the EU AI Act and promotes transparency, it also raises important questions about usability, fairness and technical implementation. As a user, staying informed about these changes is essential. Understanding how watermarking works and its potential impact on your work can help you navigate this evolving landscape. Whether you are a content creator, developer, or educator, being aware of the benefits and challenges of watermarking can empower you to make informed decisions and adapt to the changing dynamics of artificial intelligence. Ultimately, this development highlights the delicate balance between innovation, regulation, and public trust in AI technologies. By engaging with these changes, you can better position yourself to thrive in a world increasingly shaped by artificial intelligence. Media Credit: Kyle Balmer | AI with Kyle Disclosure: Some of our articles include affiliate links. If you buy something through one of these links, Geeky Gadgets may earn an affiliate commission. Learn about our Disclosure Policy.
[57]
Anthropic, Google Explain How Their Respective AI Watermarks Will Work
For now, the solutions appears to be specifically targeted to fulfil EU regulations and may not exactly produce the outcomes users need The transparency code enacted as part of European Union's AI Act has seen two of the three major chatbot-makers respond, both clarifying that their solutions are merely to mark a content or code as made with AI help and not necessarily meant to "detect" its usage, a service offered by companies such as Pangram in recent times. Anthropic's latest blog post clarifies that "Watermarking does not impact the quality of Claude's output," the company said. "To a reader, a watermarked response is indistinguishable from an unwatermarked one." So, when making low-stake choices like between "overcast" and "grey" to describe the weather, Claude creates a pattern in its responses. And this is largely "undetectable to the reader, but is detectable to anyone who has a key that encodes it," the company says, while noting that it would be using the SynthID Text approach that the Google DeepMind team had outlined back in 2024. They had given access to from AI platform Hugging Face and Google's own Responsible GenAI Toolkit. Google's own approach, which it revealed last week, is that it would allow users to remove visible watermarks from AI generations on images, videos and songs, but these won't affect the invisible watermark delivered by SynthID and the C2PA standards-related metadata. In effect, both companies are using the same toolkit to deliver similar results. Google's VP for Gemini Josh Woodward took to X stating that this feature would be available for Nano Banana, Omni, and Lyria modles where users can turn visible watermarks off in Gemini and Google's video editor. Both companies seem to believe that while visible watermarks make users look askance at content, chatbot-makers must identify AI-generated slop, given the surfeit of it on the internet. Coming back to Anthropic, the blog post notes that it would soon release a watermark detection API. It also clarified that a light editing of content or code will not remove the watermark completely but a "complete rewrite where every word is replaced will." "In the latter case, of course, it's arguable whether the text can any longer be described as AI-generated," the post noted. When it comes to code, there would be less of watermarks than other textual content because the model would need to create working code and may not have the freedom to choose between a variety of valid options. "Having said that, in areas where there is an arbitrary choice between particular words or terms within the code, the watermark can be used, such as comments within code," the blog said. However, "by definition, it will have a negligible effect on the actual code produced," the post said while noting that Claude will not be the only AI chatbot to generate watermarked text, as "other major model developers have signed the same Code of Practice and will be implementing their own watermarks." Last year, Google had noted that the SynthID Text had been integrated into Gemini models does not compromise the quality, accuracy, or speed of text generation. It also works on text that has been cropped, paraphrased, or modified. "We're striking a balance here between creative control and safety: while the visible watermarks are now optional, invisible SynthID watermarks and C2PA metadata are still being used for transparency. So you can still use Gemini or Search to see if an image was AI-generated," Woodward said on X.
[58]
Anthropic Adds Watermarks to Denote AI-Generated Content | PYMNTS.com
The artificial intelligence (AI) startup noted the change on the support page for its Claude model Tuesday (Aug. 11), saying it came in response to the European Union's AI Act's Code of Practice on Transparency of AI-Generated Content. "As AI-generated content becomes commonplace, greater transparency and signals about where content comes from can give people useful context about the information they consume," Anthropic wrote. "To support transparency and comply with our legal obligations, Anthropic is working to include machine-readable marks in content that Claude generates." According to the announcement, Claude models launched in the EU on or after Aug. 2 -- the day the new regulations went into effect -- will support machine-readable marking at launch, with watermarks embedded into AI-generated text. Generated files will include "digitally signed provenance metadata where supported," the company added. The marking works everywhere people encounter Claude, Anthropic said, applying to output from supported Claude models across the company's stable of models. The embedded watermarks also apply when users access Claude via Anthropic's cloud partners at Amazon, Google and Microsoft. PYMNTS wrote about the new EU rules last week, noting that they arrive as California is preparing to institute its AI Transparency Act next year. While the California legislation is somewhat more narrowly focused, the report said both laws arrive at a similar conclusion: organizations need to go beyond just informing users when AI has been used and develop systems to allow them to detect AI-created content. "For businesses, particularly regulated financial institutions, the shift signals the emergence of a new enterprise AI governance challenge," that report said. "Rather than treating AI transparency as a consumer disclosure obligation, companies are increasingly being required to embed technical controls, governance processes and audit capabilities into the way AI-generated content is created, distributed and managed." The implications are especially important for financial institutions, which are increasing their use of generative AI in areas such as customer service, fraud detection, document preparation and internal operations. "Banks already operate under extensive supervisory expectations governing model risk management, cybersecurity, operational resilience and third-party risk management," the report continued. "AI transparency obligations increasingly intersect with each of those existing governance frameworks." For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.
[59]
Claude's Text Watermarking Will Be Misinterpreted
Note: This article was originally published on Reasoned and is being cross-posted on MediaNama. Read the original version here:[link]. Is it a bird? Is it a plane? One of the things that I've been saying for a while is that it's not possible to do AI detection of text, and it seems that I've now been proven wrong. Watermarks, in terms of labeling, are possible when it comes to images and videos, but then those can be removed. I had said that this isn't possible with text because text can be copypasted everywhere. Here's how Anthropic is doing this: AI models are next word prediction models, and when Claude has to finish the sentence, "The weather was ___", it can choose from cold, grey, gloomy, purple or cloudy. Purple is a low probability output, but the rest of them aren't. Anthropic has a mechanism as per which, when given choices of words, Claude has a temporary "preferred" group of words that it favours to choose from, based on a particular key it provides. Across passages, the choices create a statistical pattern, in terms of a bias, which Anthropic's, which Anthropic can detect when asked whether the text contains a pattern that Claude would probably have produced. Important limitations: So the "watermark" is closer to a statistical fingerprint than a label stamped onto the text. Why Anthropic is doing this A few months ago, there was a controversy about Jamir Nazir's short story The Serpent in the Grove, which won the Commonwealth short story prize, that Ethan Mollick called 100% AI-generated, and Pangram said was 100% AI-generated. Something like this detection will help those judging awards, assignments, publishing and hiring figure out whether the output is AI-generated, because it has a material impact for them. One can argue that we've seen AI-generated text in courts, and therefore courts have come down hard because there has been hallucination in some of those outputs. But I would attribute that more to stupidity than malice. And so do we really need to solve for stupidity when we should be solving for malice? For a minute, let's also discount AI slop flooding social media. Beyond these instances, unlike images and videos, which can be deep-faked, how does AI generation of text really harm anyone? What's the "job to be done" for AI watermarking of text? Maybe, if you invert this, perhaps it can be used to prove that something isn't AI-generated when they're accused of it. Anthropic is "implementing this change to comply with the EU AI Act. Anthropic, along with several other major AI model providers and around 190 total signatories, signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026. This requires AI system providers to use methods of "marking" AI-generated text." So this looks more like regulatory compliance than a market need, and Anthropic is rolling this out globally. AI writing has its utility As I've written earlier, saying, what does AI slop actually tell us? "The words may have come from AI while the emotion and thinking behind them maybe did not." Writing is compliance, thinking is not. What you're trying to challenge really is unoriginal thought, not whether something was written with AI. Someone who perhaps can't express themselves well, but can think smartly and sharply, especially those who are not native English speakers, they can still use AI to express their thoughts better than they could on their own because of a language barrier. Should they be penalised? AI helps reduce cognitive overload of figuring out which sentence comes after the next, when you have a rambling voice note, like I did for this post. It can suggest a better way of expressing the same idea, like it improved the headline for this post, which was initially "Claude's text watermarking will lead to misleading interpretations". Students will use AI for school and college assignments, because assignments typically measure compliance, not learning. If anything, AI usage needs to be normalised in education, and we need switch to measuring learning. I know of instances where students are allowed to use AI for research, but they need to write the paper themselves. Is there not editorial selection taking place there, and thought given to it? Isn't that selection itself an indication of originality? How will automated translation be impacted? If I had written this article in Hindi and used AI to translate it to English, would it be penalised as AI writing? Just as translation isn't transliteration, AI writing isn't AI thinking. And we've seen tools come out like Pangram that also do AI text detection fairly aggressively, but these remain imperfect tools. I also think that we're reading so much AI that the way we write is changing, influenced by the sentence construction, choice of words, and the way paragraphs are constructed to express a thought by AI. This last sentence would be detected as written by AI, btw, because it has three parts, and that's a common AI trope. These are imperfect tools, and AI writing detection is full of false positives. We need to be very careful about this. How this can probably be bypassed "A watermark can only determine that Claude was likely involved with the content at some point." What happens when I use two different platforms to generate an output? How does detection solve for that? Because each has its own patterns, and if I mix two or three AI generation tools to generate an output, the variance in the output by itself will mean that none of them will be able to detect it. Isn't it easy to mess up the hash if you paraphrase the text? The answer is mostly yes, however, you can use a statistical model to get your hash instead of a deterministic function (SIR, Adaptive Watermark). Since the entire watermark is probabilistic, this is fine. And so this is a loss for those who are trying to comply, but when market forces are taking things in another manner because really, AI text generation helps, just like image and video generation does in most cases. We're letting the exceptions define the rule. P.s.: I ran Pangram on this article, and it found this article to be 100% human. It is.
[60]
Anthropic adding watermarks to AI-generated content to comply with EU law
Dario Amodei's Anthropic is adding watermarks to AI-generated content in order to comply with a strict new transparency law in Europe -- drawing gripes from some users. The AI giant, known for its Claude chatbot, linked the move to the European Union AI Act's transparency code -- aimed at helping people distinguish human-made content from the AI-generated variety -- which took effect on Aug. 2. The watermarks appear automatically in AI-generated text, images and files, according to a support page on Anthropic's website. "When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself," the company's website said. "You won't see it, and it doesn't change the meaning, quality, or readability of Claude's response." Anthropic added that the watermarks will "travel with the text when it's copied and pasted elsewhere, and may persist through some editing." The watermarks will be implemented "wherever Claude is offered, worldwide," including within the Claude Platform API, Claude Code, Claude Cowork and Claude Tag. Anthropic acknowledged that its detection program has "limitations" and may not always identify AI-generated content, especially in cases where text has been "heavily edited, paraphrased, translated, or mixed into other writing" or the "passage is very short." The European Commission, the EU's digital watchdog, has said it had "strong backing" from the tech industry in its push to clearly label AI-generated content so that users aren't misled. As of July 31, the EU had secured commitments from nearly 200 companies to comply with its transparency rules. Aside from Anthropic, AI giants like Sam Altman's OpenAI, Mark Zuckerberg's Meta, Google and Microsoft all signed on to the pledge. "By signing the code, providers and deployers of generative AI systems signal their intention to promote public trust in AI and to mitigate deception and misinformation," the EU said in a press release. The efforts by Anthropic and other companies come amid heightened concerns about the rise of so-called "AI slop" and AI-generated content being passed off as authentic. Last month, a debut novelist's $2 million book deal was canceled after a publisher became concerned that he had used AI to write the manuscript. Still, Anthropic's new policy irked some commenters, with one calling it "total bulls-t." Others pointed out that tech-savvy consumers may be able to find workarounds. It's "hard to see what Claude's watermarking approach really solves," one person wrote on X. "There are already plenty of free and open-source models without watermarks, so anyone who really wants to avoid them can simply use something else."
[61]
Anthropic to Watermark Text Generated By Its AI Models
The regulations are are result of increasing AI slop generated and shared by content creators on to the internet over the past few years Anthropic updated its support page to announce that henceforth it would watermark all text generated by its models as part of its efforts to comply with European regulations. The Claude-maker confirmed that in future text generated by its models would be watermarked. The European Commission, which announced its AI Transparency Code some time back, took effect from August 2, leading AI companies to ensuring such watermarking. The EU guidelines on transparency says, "the rapid development of generative and interactive AI systems is making it increasingly difficult to distinguish AI interactions and AI-generated content from human-created and authentic content. "Individuals are also increasingly being exposed to emotion recognition and biometric categorisation without their knowledge. This is raising new risks of misinformation and manipulation at scale, fraud, impersonation, and consumer deception," it said. It specifies that AI providers must design AI systems to ensure individuals are explicitly informed whenever they interact with an AI system directly. Also, they must add machine-readable marks to enable the detection of AI-generated or manipulated content. Deployers of AI systems also must inform users of their exposure to emotion recognition and biometric categorisation tools, deepfakes, and text on matters of public interest without human review or editorial control. In response, Anthropic has noted that all models released after August 2 will automatically watermark computer-generated text and files. For the latter, the company would use the C2PA open standards while also extending support to older models. The water market will also travel when users copy and paste the text. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing. Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from," the support page says. Going forwards, Anthropic also clarified that watermarking will apply to all its products such as Claude platform API, Claude, Claude Cowork, Claude Code and Claude tag. Other companies that are committed to the EU code include OpenAI, Google, Meta and Microsoft. The EU guidelines also clarifies that providers and deployers of AI system would be set clear expectations around what the transparency obligations that each of the stakeholders needs to adhere to along the value chain. In addition, "they provide definitions of certain concepts and outline exemptions and diverse, practical examples of what is in and out of scope. These include definitions of directly interactive AI systems, synthetic content, deepfakes, AI-generated text on matters of public interest and examples of exceptions, such as standard editing," the EU document says.
[62]
Anthropic adds watermarks, C2PA metadata to Claude AI content
Access the blog post here. The text and media generated by Claude will now have: * A watermark for text responses: "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing. Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from." * Provenance metadata for media, such as .svg, .png, or .jpg, following C2PA open standard: "This metadata follows the Coalition for Content Provenance and Authenticity (C2PA) open standard, which is used across the industry to record information about content provenance. If a signed metadata label is present, it signals that a file was processed by Claude and lets you detect whether the file has been tampered with." Watermarking and provenance are implemented worldwide: "Marking will apply to output from supported models wherever Claude is offered, worldwide," clarified Anthropic. It also said that "Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch." Detection tools and technical documentation to be published soon: Anthropic has yet to enable users or other third parties to detect Claude's embedded watermarks and provenance metadata. It also said that it will release detailed technical documentation soon. Anthropic implemented these measures to comply with the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content. The EU finalised the Code of Practice containing these labelling guidelines in June 2026. Article 50 of the EU AI Act has two sections aimed at two different stakeholders: * Providers: Those who build AI systems; and * Deployers: Those who use these systems to create and publish content. In its "Code of Practice on Transparency of AI-Generated Content," the EU laid out the symbols that AI platforms can use to label AI-generated content. They are: * "AI GENERATED" -- for fully AI-generated deepfakes or published text. * "AI MODIFIED" -- for partially AI-manipulated content. * Basic "AI" icon -- a minimal version that can be supplemented with a custom interactive layer. Read MediaNama's lowdown on the EU's Code of Practice for AI-generated content here. MediaNama's Take: * If platforms comply with EU rules but not India's, does this suggest weaker enforcement by Indian authorities? Or does it simply reflect the global adoption of EU standards? The Ministry of Electronics and Information Technology released India's synthetically generated information (SGI) rules in February 2026, while the European Union finalized its code of practice for generative AI content in June 2026. Most platforms and intermediaries operating in India have not fully complied with India's SGI rules, except for users' self-disclosures. During a recent Parliament session, Member of Parliament Karthi Chidambaram asked for figures on complaints, takedowns, or requests under the new three-hour takedown notice for SGI content, but the government did not disclose them. * Platforms need stronger anti-circumvention measures for watermarking and C2PA metadata: Platforms need to strengthen C2PA metadata and watermarking to prevent bypassing. For example, developers created tools to circumvent Google's SynthID after its launch. How can AI companies and intermediaries design C2PA standards that resist circumvention, especially when metadata is stripped via screenshots or shared on encrypted platforms like WhatsApp or Signal? How much metadata survives when AI-generated content is modified or doctored? "As of now, there is not a single AI model that can detect a really good deepfake-generated video and tell you this is fake," said Tarun Wig, co-founder of Innefu Labs, at the India AI Impact Summit (2026). * Can platforms technically trace the originator of AI-generated media, especially when law enforcement agencies request or legally compel them to do so? What are the law enforcement compliance requirements for C2PA, and how would platforms provide user information for the original prompt-giver if requested? "Every AI developer requires a sign-in, and the data the user inputs is embedded in the metadata. Through that metadata, you can trace back the person who created the content." -- a speaker at MediaNama's discussion on 'Regulating Deepfakes in India.' * Watermarking has limited impact on deepfake content: Major AI platforms already use watermarking or C2PA standards, yet deepfakes persist. Recently, the Press Information Bureau's fact-checking account debunked a deepfake video of Prime Minister Narendra Modi, Finance Minister Nirmala Sitharaman, businessman Mukesh Ambani and Rajya Sabha MP Sudha Murthy, where Sitharaman's deepfake promoted a fraudulent scheme promising users 1 lakh rupees. Despite the video being AI-generated, the fact-checking post on X did not include an "AI-generated" label. "The biggest problem with deepfakes is that [something new is] generated every time, and the content can change quite a bit, as opposed to the classical photographs that we have. These techniques are based on the idea that there's a database of hashes that we can cross-check with really quickly. And so it's really hard for a company to maintain a database of hashes of every possible content that can be generated," -- Gautham Koorma, machine learning researcher at MediaNama's Deepfakes and Democracy.
[63]
Claude will introduce a secret watermark in all its texts: goodbye to using AI without other people knowing
Anthropic's hidden signal may survive copy-paste and later edits Anthropic is preparing a change for Claude that, while not seeming all that major, will change AI forever. Because of its commitments to the Code of Practice under the EU AI Act, the company will soon require its supported models to include an imperceptible signal in the text they generate. The watermark will stay with anything we copy and paste, and it may even survive edits. This transparency measure comes as the European Union is tightening obligations around AI. An invisible mark that will stay with our text According to Anthropic, the system will operate at the model level and, therefore, will be present in Claude, Claude Code, Claude Cowork, the API, and Claude Tag. The company will roll out watermarking worldwide, even though the measure originates in Europe. Anthropic says the mark will be imperceptible and won't interfere with the meaning, quality, or readability of the text it generates. It also explains that detection mechanisms, including third-party ones, will be released later in the technical documentation needed to detect the hidden patterns. While OpenAI works on systems to detect AI-generated images and more and more services label posts and content as "created by AI," the trend is clear. We don't want to read content that doesn't have someone behind it we can trust. There is still a long, long way to go before we can confidently say that a piece of content was generated by AI without false positives, if that's even possible.
[64]
You may no longer get away with AI generated text, here is how Anthropic wants to detect it
Anthropic is working on tools to detect AI-generated content. Anthropic has recently clarified that the company will now be making text generated by supported Claude AI models. The AI startup recently updated its support page, where they clarified the adding of machine-readable marks to content generated by Claude. The marks will remain hidden from readers and are designed not to change the text's meaning, appearance, or readability. Reports also indicate that the watermark could survive copying and pasting, as well as some forms of editing, allowing the origin of AI-generated content to be traced more easily. Anthropic clarified that the new rules are in compliance with the transparency rules under the European Union's AI Act. The company is also reportedly developing tools that users, publishers, schools and other parties can use to check for these marks. Anthropic Claude watermarking: How it works According to the Claude support page, the models will place a machine-readable watermark directly into the generated text. The watermark is designed to be invisible to people but detectable by software. Moreover, it's also clarified that it will travel with the text when it is copied into another document. Anthropic says that the watermark will also remain after some editing. However, the support page also clarifies that the watermark is not permanent in every situation, as heavy editing, paraphrasing, translation, or mixing Claude's writing with other text can make the mark difficult or impossible to detect. Claude can also process files such as PNG, JPG and SVG. For these files, Anthropic uses signed information about the file's origin, following the C2PA standard. This information can indicate that Claude processed a file and can help show whether the file was changed later. Also read: Amazon Great Freedom Sale 2026: Samsung Galaxy A56 vs OnePlus Nord CE6 vs Redmi Turbo 5, which one should you buy The marking applies worldwide to supported Claude models, which include Claude, Claude Code, Claude Cowork and Claude Tag, as well as Claude accessed through cloud services such as AWS, Google Cloud and Microsoft Foundry. New Claude models will support marking from launch. Anthropic is also reportedly working to add marking to the text generated using the older models of the AI tool which were released before August 2, 2026. Anthropic isn't the first company to do so, as OpenAI and Google also previously did the same when they allowed the users to identify images generated using their models. Anthropic Claude watermarking: How to detect it Anthropic says it is working on detection tools that can be used by organisations to check whether a text or a file contains a supported Claude mark. However, the details regarding the tool still remain under wraps. The Claude support page also clarified that if a Claude mark is identified, then it should not be treated as proof that Claude wrote the entire piece, as many people use the tool for proofreading, translating, summarising or converting content. Hence, the content may also have been changed or combined with human writing afterward. Also read: Google Pixel 11 series to launch this week: Date, India timing and what to expect Moreover, the AI company also noted that the opposite is also possible. If you find a mark, then that does not prove that AI was not used to generate content, as older Claude models may not have marking support yet, and heavy rewriting or other changes can also remove or hide the watermark.
Share
Copy Link
Anthropic has begun watermarking all Claude AI outputs globally to meet EU AI Act requirements. Text carries invisible watermarks while images include cryptographic metadata. But researchers question effectiveness as watermarks can be stripped easily, and users worry about false positives flagging legitimate editing as AI-generated content.
Anthropic announced that all Claude models launched on or after August 2 will embed invisible watermarks in text outputs and digital signatures in generated images
1
. The San Francisco-based company is implementing this globally, not just in the EU, to comply with the EU AI Act's Transparency Code2
. The regulation mandates that AI system providers make AI-generated content detectable or face fines up to €15 million or 3% of global annual turnover1
.
Source: Benzinga
The AI watermarking system uses the SynthID-Text approach developed by Google DeepMind in 2024
3
. The algorithm tweaks word selection during generation, creating statistically observable patterns across the document without changing "meaning, quality, or readability," according to Anthropic1
. For images, Claude will use C2PA metadata with cryptographic signatures that break if tampered with, revealing manipulation attempts5
.The watermarks remain detectable even after copying or editing, persisting through light modifications
1
. However, Anthropic acknowledges significant limitations. Short passages, heavily paraphrased text, or complete rewrites will likely lose the watermark signal3
. Code outputs will carry minimal watermarking since the model must prioritize functional code over arbitrary word choices, though comments within code may contain marks3
.
Source: Geeky Gadgets
Researchers express skepticism about effectiveness against determined bad actors. Reese Richardson, a metascientist at Northwestern University, notes that watermarks "can be stripped from text easily -- for example, by using another model"
1
. Simply pasting watermarked text into another chatbot for editing could destroy the signal2
. With images, screenshotting or using metadata editing tools removes the digital signature entirely2
.Despite limitations, enforcing 'no AI' policies in specific contexts shows promise. The International Conference on Machine Learning (ICML) 2026 added watermarks to peer review papers and caught 506 reviewers violating their no-AI policy
1
. Nihar Shah from Carnegie Mellon University, who led the ICML watermarking process, notes this "suggests that while some illegitimate AI uses may be done carefully to evade detection, many others may simply copy-paste AI outputs"1
.However, experts warn against treating watermarks as binary indicators of authorship. Amina Yonis from The Page Doctor cautions that "watermarked equals AI written and not watermarked equals human written" creates false certainty
1
. Students deliberately concealing AI use will likely evade detection, while legitimate users face potential false positives. Cornell physicist Paul Ginsparg suggests watermarking has "little impact in a world in which legitimate papers are written with AI"1
.Related Stories
Anthropic's approach watermarks all processed content, going beyond EU requirements that exempt "assistive function for standard editing" like grammar correction
2
. The company admits people "often use Claude to proofread, translate, summarize, or convert files" and outputs "can carry a Claude mark even if the underlying ideas, text, or data originated from another source"2
.This has sparked user controversy, with some Claude subscribers reportedly canceling over the policy
3
. Reddit discussions reveal polarized reactions. Critics argue the system unfairly labels human work that received minor AI assistance, while supporters counter that transparency serves public interest4
. One user complained about "having an AI that watermarks your work" being "terrifyingly ironic given how many of the frontier models came by their training data"4
.
Source: Gadgets 360
Anthropic joins other major providers implementing similar systems. Google has used SynthID marks since 2023 on Gemini outputs, while OpenAI adopted SynthID for image and audio content
1
. All frontier models must eventually comply with the EU AI Act, though no company has yet released a public text-specific detection tool1
.Anthropic plans to release a watermark detection API and share technical details for verification
2
. The company emphasizes that detected marks "provide a signal" but are "not fully conclusive" -- content might have been merely summarized or translated rather than generated wholesale1
. Conversely, absence of watermarks doesn't confirm human authorship, as AI-generated content detection has proven significantly unreliable, particularly for non-native English speakers who face higher false positive rates5
.The effectiveness of AI watermarking in curbing AI slop and ensuring accountability remains uncertain. While regulatory compliance drives adoption, the technology's limitations and potential for misinterpretation raise questions about balancing transparency with user convenience and accuracy.
Summarized by
Navi
[2]
[4]
19 Aug 2026•Policy and Regulation

Today•Technology

24 Oct 2024•Technology

1
Policy and Regulation

2
Technology

3
Technology
