Friday, September 25, 2026Verified technology journalism

Claude now watermarks all generated text invisibly, making Anthropic the first major lab to mark AI output model-wide

All Claude models launched on or after August 2 embed invisible, machine-readable watermarks in generated text and attach C2PA provenance metadata to files, applying worldwide across the API, Claude Code, and cloud partners. The move complies with EU AI Act transparency rules, though the file metadata layer carries a known vulnerability: open-source tools can already strip C2PA signatures. Anthropic becomes the first major AI lab to implement model-level content marking, establishing a transparency benchmark that OpenAI and Google may face regulatory pressure to match.

Claude now watermarks all generated text invisibly, making Anthropic the first major lab to mark AI output model-wide

Anthropic is now embedding invisible, machine-readable watermarks in all text generated by Claude models launched on or after August 2, 2026. The marks apply worldwide across the Claude API, Claude Code, Claude Cowork, Claude Tag, and cloud partners including AWS, Google Cloud, and Microsoft Foundry 1.

The rollout is timed to the EU AI Act. Article 50, which became enforceable on August 2, 2026, requires generative AI providers to ensure their output is marked in a machine-readable format and detectable as artificially generated 2. Anthropic signed the Code of Practice, which roughly 190 companies and organizations had joined by the end of July 2026 2. The company says marking will apply globally, not only to European users 3.

Two layers, built to different standards

Anthropic's system ships two layers of transparency, and they are not built to the same standard.

For generated text, Anthropic weaves an imperceptible signal into the text itself at the model level, meaning the mark is present no matter which Claude product produced the output. The company says the watermark persists through copying, pasting, and some editing 4.

For generated files, Anthropic attaches signed provenance metadata using the C2PA standard from the Coalition for Content Provenance and Authenticity 3. C2PA embeds a cryptographically signed manifest in a file. The removal economics for this layer are fundamentally different:

  • Taking a screenshot of a C2PA-marked image strips the metadata with zero quality loss.
  • Re-saving, re-encoding, or converting file formats removes the manifest.

The C2PA standard's own FAQ is explicit about this. Asked whether C2PA can be removed, it answers: "Yes, C2PA can be removed by stripping metadata, taking screenshots, or re-encoding. This is by design" 5.

That admission sits in tension with the regulation that compelled the rollout. The EU Code of Practice requires watermarking to be embedded in content "in a manner that is difficult for it to be separated from the content" 6. C2PA was built to be separable. Anthropic's file layer meets the EU requirement by attaching provenance metadata, but that metadata was engineered for easy removal. The text watermark, embedded in the model's token sampling, is the only layer that approaches the standard the EU actually demands, though Goedecke argues that even this can be "trivially removed" by paraphrasing the text through another model 6.

Anthropic itself is hedging about the system's reliability. The company notes that detected marks are not conclusive evidence that Claude produced a given piece of content, and that the absence of marks does not guarantee human authorship 1. Heavy editing can weaken a text watermark, and short passages may not carry enough signal for reliable detection 3.

Older Claude models that launched before August 2 do not yet carry the watermark. Anthropic says it is working to add marking during the EU's transition period, which grants generative AI systems already on the market until December 2, 2026 to comply with the machine-readable marking requirement 7.

Which layer to build on

Text watermarks require deliberate paraphrasing to defeat and survive basic copying 4. C2PA provenance metadata can be removed by a screenshot 5. Google's SynthID takes a similar token-level approach, scoring tokens during generation to leave a detectable fingerprint that also breaks under paraphrasing 6. Anthropic's two layers are now flowing through Claude's output, but they are not equal tools for detecting machine-written text.

References

1.The Register, Aug 11 2026theregister.com ↗
3.Interesting Engineering, Aug 10 2026interestingengineering.com ↗
4.Claude Help Centersupport.claude.com ↗
5.C2PA FAQc2pa.wiki ↗
7.EU AI Act transparency rulesartificialintelligenceact.eu ↗

Cite this story

ProvenBrief (2026). "Claude now watermarks all generated text invisibly, making Anthropic the first major lab to mark AI output model-wide." ProvenBrief. https://provenbrief.com/story/claude-now-watermarks-all-generated-text-invisibly-making-anthropic-the-first-ma

Free to quote and link with attribution. Republishing in full or AI-training use requires a license.

Verified36 factual claims in this story were independently checked against primary sources before publication. Read our editorial standards.

Get the next brief in your inbox

One weekly email. Every claim verified against primary sources before we hit send.

Produced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.