The AI Provenance Compliance Tracker: Which AI Providers Actually Mark AI-Generated Content, Modality by Modality
Two weeks into EU AI Act Article 50 enforcement, machine-readable marks are becoming standard on AI images and video at the major providers, but text - the modality behind AI answers, spam and fraud - is marked at only two of them, and the newest text watermark, Anthropic's, was stripped by an open-source tool within four hours of launch.
The Article 50 tracker: only two of five AI providers mark the text they generate
Of the five AI providers this tracker follows, only Google and Anthropic ship a machine-readable mark on the text their models generate. Anthropic confirmed in August 2026 that Claude models would globally embed invisible watermarks, including in Claude Code output, to comply with the EU AI Act 1; by late September the newer Claude models already carry the mark, and a customer email reported by The Daily AI Digest schedules September 30 as the date three older models, Fable 5, Sonnet 5, and Opus 4.8, receive it, completing a rollout that began in August
2. OpenAI has never deployed a text watermark, Meta and Microsoft signed the EU's transparency code of practice without shipping one, and fines for missing the rules reach 3 percent of annual worldwide turnover, or EUR 15 million, whichever is higher
3. The newest compliant text mark lasted four hours before public code existed to strip it
1.
That four-hour number is the second half of what this tracker measures. Coverage, meaning which marks exist, is easy to count. Whether a mark survives people who want it gone is the live question, and after this September recheck it has two measured answers: a clock number and a survival rate.
The text compliance matrix, five providers
Article 50 of the AI Act, officially titled "Transparency Obligations for Providers and Deployers of Certain AI Systems," is the provision behind the new rules 4. It requires providers of generative systems to label synthetic audio, image, video, or text so the content can be detected by a machine as AI-generated, with fines of up to 3 percent of annual turnover
1. This tracker follows Google, Anthropic, OpenAI, Meta, and Microsoft, counting a modality as marked only when the provider's own public documentation commits to a machine-readable mark by default:
- Google: marks all four content modalities. SynthID watermarks text from the Gemini app and web experience, images and video across Google's generative products, and audio from the Lyria music model and NotebookLM's podcast feature. Coverage Rate: 4 of 4.
5
- Anthropic: marks text and image files. The invisible watermark covers text from supported Claude models, including output from Claude Code, applied globally at launch because Anthropic says it has no durable way to scope marking by region; when Claude produces a supported image file, such as a .png.jpg, or .svg, it attaches a C2PA Content Credential, a cryptographically signed note in the file's metadata. Coverage Rate: 2 of 4 documented modalities. No audio or video marking is documented.
6
- OpenAI: no text mark. Its support page still describes text marking as a goal rather than a feature; the company built a text watermark in 2024, reportedly reaching 99.9 percent detection accuracy on long passages, and shelved it over false positives and the risk of losing users. Coverage Rate: 2 of 4 per September reporting, counting image, marked since May, and audio, marked since July.
2
- Meta: a signatory of the EU transparency code of practice, among 190 signatory organizations, with no text mark shipping as of August 19, 2026 reporting.
1
- Microsoft: same status as Meta: code signatory, no text mark shipping as of the same reporting.
1
The wider record as of September 25: Meta, Microsoft, and Mistral, a sixth major signatory of the code, have shipped nothing for text, and xAI, which never signed, marks Grok's images but not its words 2.
Aggregate Provenance Coverage Rate for text: 2 of 5 providers, or 40 percent. Providers covering all four modalities: 1 of 5, or 20 percent.
Method: a blank cell means no default machine-readable mark existed in the provider's public documentation as of this check in late September 2026, not that no mark exists. OpenAI's provenance announcement pages refused automated access during the August check and again during this recheck, so its image and audio counts rest on dated reporting we can attribute rather than pages we cannot read.
Marked is not the same as detectable
The rules require labels that make content detectable by a machine 1. The September recheck moved this section in one direction only: a text detector now exists, but the public still cannot use it. Google's page documents two checks, and both stop at the same edge; users can upload an image, video, or audio clip to Gemini and ask whether it was created or altered by Google AI, and the SynthID Detector portal, still being tested with journalists and media professionals, accepts image, video, and audio files, with no documented upload check for text
5. Anthropic released a text-detection API in private preview, open to organizations EU law makes eligible, including regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups, plus enterprises verifying compliance for themselves, with access set to expand over time
6. Outside that list, nobody can check a passage; as September 25 reporting put it, a teacher, an editor, or an HR manager cannot
2. Bill Gurley's August objection survives the preview in expanded form: a mark only a fixed list of readers can open makes its issuer, in his words, judge, jury, and prosecutor
2. Visual content at least got a shared industry standard, C2PA's Content Credentials, which the coalition describes as functioning "like a nutrition label for digital content"
7, and the standard now reaches into Claude itself, whose image files carry Content Credentials
6. Text standardization stopped at one company's scheme: both deployed text marks are SynthID, Google's technique
1, and Anthropic's own documentation confirms its watermark is a version of the SynthID-Text approach Google DeepMind published in 2024
6.
Strip resistance: the four-hour benchmark
This tracker's second metric, Strip Resistance, is the time from a mark's launch to a working public circumvention tool. The first measured value: four hours. Within four hours of Anthropic's confirmation, developer Guillaume Meyer had published code that removes the watermark; the tool went viral on GitHub, and freelance content writers and social media creators have contacted Meyer for help using it 1. The removal method, paraphrasing text through other models that do not watermark, attacks the SynthID-text approach itself, the technique family behind both Google's and Anthropic's marks
1. Anthropic itself acknowledged that heavily edited, paraphrased, or translated content might not carry the watermark
1. Software engineer Erik Hughes says he built an alternative stripper in 15 minutes using Claude itself
1.
The paraphrase attack now has numbers. A peer-reviewed robustness evaluation, Watermark under Fire, published at EMNLP 2025, built a platform integrating 10 watermarking schemes and 12 removal attacks and assessed the schemes against them 8. Per September 25 reporting on the evaluation, one pass through a chatbot asked to reword the text drops detection rates below 0.3 for every method tested, and a few rounds take the most resilient schemes below 0.15
2. That is the mechanism behind the stripper trade quantified: not four hours of fame, but detection fractions that keep shrinking with each rewrite.
The law closes only half of that door: providers cannot market circumvention tools, but there is no legal restriction on independent ones 1. Anthropic's position is that the watermark "doesn't change the meaning, quality, or readability of Claude's responses"
1, a claim its own documentation supports with internal testing and a controlled side-by-side study in which human raters saw no quality difference
6. Meyer's counterpoint: the mark can only generate a probability that text was touched by Claude, which he warns could get job candidates rejected over lightly edited writing
1.
The September 1 release of the detection API changed the ground under the four-hour benchmark without settling it: the software now exists, but in private preview, so outside the approved organizations the stripper remains publicly untestable and the four-hour number unconfirmed 6. That is the full picture of Article 50 text compliance as of this recheck: two marks, one detection API locked to a fixed list of organizations, and a stripper the public still cannot test. The next dated entry on the clock is December 2, 2026, the deadline for generative systems already on the market when Article 50 took effect to mark their text
2, with Anthropic's pre-August models due to finish watermarking over the coming months
6.
References
Cite this story
ProvenBrief (2026). "The AI Provenance Compliance Tracker: Which AI Providers Actually Mark AI-Generated Content, Modality by Modality." ProvenBrief. https://provenbrief.com/story/the-ai-provenance-compliance-tracker-which-ai-providers-actually-mark-ai-generat
Free to quote and link with attribution. Republishing in full or AI-training use requires a license.
Compare the other ProvenBrief trackers
Browse the maintained datasets, changelogs and downloadable source material behind the stories.
Explore all datasets →This tracker changes
The figures above move. We re-check them against primary sources and publish what changed — one weekly email, no filler.
This story
WordsProduced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.