Anthropic has confirmed that text produced by Claude now carries an invisible watermark. The company set it out in an updated support page, and the trigger is the European Union’s AI Act, whose transparency code took effect on 2 August and requires AI-generated or AI-edited content to be marked so other systems can identify it.
The company says every model released on or after 2 August embeds the mark automatically. Files use the C2PA open standard. Support for older models is being added.
What Is Actually Marked
| Detail | How it works |
|---|---|
| Text | Watermark woven into the text itself, not metadata |
| Files | Signed provenance data using the C2PA standard |
| Where it applies | Model level, so every Claude surface |
| Products affected | Claude apps, the API, Claude Code, Claude Cowork, Claude Tag |
| Survives copy-paste | Yes |
| Survives editing | Anthropic says it may persist through some editing |
Because the mark lives inside the text rather than alongside it, moving the words moves the watermark. Paste Claude’s output into a CMS, an email or a document and it travels.
Applying it at the model level rather than the product level is the more consequential
decision. There is no Claude surface that produces unmarked text, and no setting to switch it off.
The Question Anthropic Has Not Answered
How much editing removes the watermark. “May persist through some editing” is doing considerable work in that sentence, and it is the single detail that matters most to anyone publishing.
Anthropic has not specified a threshold. Its own documentation acknowledges that heavily edited, paraphrased or translated text may shed the mark entirely, and that a detected watermark is a signal rather than conclusive proof.
Ask Claude And It Cannot Tell You
Here is the part that has gone largely unremarked, and it is worth dwelling on.
A watermark applied at the model level is applied to the model’s output, not by the model as a decision. Claude has no visibility into its own weights, no ability to inspect its output at the byte level as it leaves, and no notification channel telling it what changed between versions.
The practical consequence: ask Claude whether it is watermarking your text and you may get a confident, sincere and wrong answer. Not because the system is lying, but because it has no mechanism for knowing. A user who asked that question on 9 August and again on 11 August could receive the same answer both times, with only one of them true.
Nor can the model do anything about it. There is no instruction a user can give, and no setting Claude can reach, that suppresses a mark applied below the level at which the model operates. Users who want unmarked text have exactly one option, which is to rewrite it themselves.
Anyone relying on an AI assistant’s own account of its capabilities should treat this as a general warning rather than a one-off. Models describe themselves from training data and system instructions, both of which lag behind infrastructure changes.
Why Everyone Is Doing This At Once
The EU code is the immediate cause, but the commercial pressure was already building.
Last week the AI music platform Suno said it would mark tracks made on its service, following a run of legal challenges. In July, Substack partnered with the detection firm Pangram to let readers scan posts, notes, comments and replies longer than 100 words for AI involvement.
Substack’s framing is the sharpest articulation of the underlying problem. Chief executive Chris Best coined the term Claudefishing, riffing on catfishing, for the gap between a reader assuming a human wrote something and the reality that no one did. His argument is explicitly not that AI writing is bad. It is that a mismatch between expectation and reality undermines trust in authorship, including for writers who use AI tools thoughtfully.
Pangram’s own data gives that some weight. It estimates more than 40 percent of longform posts on LinkedIn flag as fully AI-generated, with X close behind. Substack scored lowest among the longform platforms measured, and even there more than a fifth of posts flagged as AI-generated or AI-assisted.
Alongside Anthropic, Black Forest Labs, Google, Meta, Microsoft, OpenAI and Synthesia have all committed to the EU code.
What This Means If You Publish
For most readers, watermarking is a transparency feature they will never notice. For anyone using Claude in a professional workflow, three things change.
Provenance is now technically checkable. Anthropic says it will help third parties detect the marks. Detection tools like Pangram infer AI involvement from statistical patterns and produce false positives; a watermark is a deliberate signal. That is a different class of evidence.
The rule you are working under matters more than the mark. If a contract or an editorial policy prohibits AI-generated content, an unmarked draft was never compliant. The watermark makes it provable rather than making it true.
Editing is doing double duty. Substantially rewriting AI output has always been the difference between publishing a draft and publishing your own work. It now also appears to be what degrades the watermark, though Anthropic has declined to say by how much.






/images/ppid_59c68470-image-178664752557863830.webp)
/images/ppid_59c68470-image-178664752347795736.webp)
/images/ppid_59c68470-image-178664752469853645.webp)



