Guide

Claude’s invisible text watermark: what it proves, and what it doesn’t

From August 2026, text generated by new Claude models carries an invisible, machine-readable watermark — worldwide, under an EU AI Act code Anthropic signed. Here is what a watermark actually establishes, what its absence does not, and how detection changes when provenance enters the picture.

By Stipple Research9 min readUpdated 11 August 2026
Useful next steps

If you are learning this topic for the first time, these Stipple pages help you move from reading to checking, verifying, or building.

Key takeaways
  • From August 2, 2026, new Claude models embed an invisible, machine-readable watermark in generated text — applied worldwide, not only in the EU.
  • The mark is part of the text itself, not metadata: Anthropic says it travels with copy-paste and may persist through some editing.
  • A present watermark is strong provenance — the text came from a supported Claude model.
  • An absent watermark proves nothing. Most models don’t watermark, older Claude models don’t yet, and heavy rewriting may strip a mark.
  • Anthropic says it will publish detection details, so third parties can verify marks. Until then, nobody outside Anthropic can check for one.
  • The EU is not alone: China’s labelling rules (September 2025) and South Korea’s AI Basic Act (January 2026) already require AI content to be identifiable — three major blocs, one direction.
  • Watermarks don’t make AI detectors obsolete — they split detection into two tiers: provenance verification where marks exist, style analysis everywhere else.
Evidence path
  1. 01

    What Anthropic announced

    Start with the material.

  2. 02

    How text watermarks work

    Add one more signal.

  3. 03

    What presence proves

    Add one more signal.

  4. 04

    What absence doesn’t

    Add one more signal.

  5. 05

    The regulation behind it

    Add one more signal.

  6. 06

    What changes for detection

    Make a careful call.

01

What Anthropic announced

Short answer

Text generated by new Claude models carries an invisible, machine-readable watermark from August 2, 2026 — worldwide, across the API, the Claude apps, and cloud platforms.

Anthropic committed to embedding machine-readable marks in content generated by its models, under the European Union’s Code of Practice for Article 50(2) of the AI Act. The obligation date is August 2, 2026, and the rollout applies to models launched on or after that date; Anthropic says it is working on adding marks to current models as well.

Two kinds of marking were announced: invisible watermarks inside generated text, and signed provenance information for generated files. The text watermark is not metadata sitting alongside the output — in Anthropic’s description, “it will travel with the text when it’s copied and pasted elsewhere, and may persist through some editing.”

The marks apply worldwide, not only to European users, and ride the supported models wherever they are offered — the API, the consumer apps, and the major cloud platforms. Anthropic also said it will publish technical details for detecting its watermarks, which is the part that matters most for anyone who checks content: third-party verification becomes possible once that specification exists.

02

How an invisible text watermark works

Short answer

The mark lives in the pattern of the words themselves — imperceptible to a reader, detectable by an algorithm that knows what to look for.

An invisible text watermark is not a hidden character or a tag you can find by inspecting the file. The established approach — used in published schemes from other labs — subtly biases the model’s word choices as it generates, in a pattern that reads perfectly naturally but is statistically distinctive to a detector built for it. The text is the watermark.

That design is why the mark survives copy-paste: there is nothing to strip, because there is no separate layer. It is also why detection requires the publisher’s cooperation — you can only test for the pattern if you know what pattern to test for, which is what Anthropic’s promised technical details would provide.

Anthropic has not yet published its specific scheme, its detection method, or robustness numbers. Until it does, statements about exactly how strong the mark is — how much editing it survives, how short a text can be and still carry it — are guesses, including ours. This guide sticks to what was announced.

03

What a present watermark proves

Short answer

Provenance: the text came from a supported Claude model. That is a much stronger statement than any style-based score.

Style-based AI detection — every detector on the market today, ours included — produces a probability: this text reads like model output. A verified watermark is a different kind of statement: this text came from this provider’s model. It is closer to a signature than a signal.

For the people who deal with AI-writing questions daily — teachers, editors, reviewers — that difference matters. A verified mark ends the guessing for that specific text. It also changes the conversation: “the detector thinks this is AI” invites argument; “this carries the provider’s mark” mostly doesn’t.

The limits still deserve stating. A watermark identifies the origin of generated text, not the intent — AI-assisted writing is legitimate in many settings, and a mark is not an accusation. And a mark says nothing about the parts of a document that were written by a person around pasted model output.

04

What an absent watermark does not prove

Short answer

Nothing. Unmarked text is not evidence of human authorship — and treating it that way would be a worse error than having no watermarks at all.

The watermark only exists in text from supported Claude models generated after the rollout. Text from other providers’ models, from older Claude models, from local open-weight models, or from before August 2026 carries no mark and never will. For years, the overwhelming majority of AI-generated text in circulation will be unwatermarked.

Anthropic’s own phrasing — the mark “may persist through some editing” — is an honest hedge, and it cuts both ways: some editing may preserve it, and heavier rewriting may not. Paraphrasing tools exist precisely to launder AI text. A determined evader is the least likely person to hand you a marked document.

So the asymmetry is the whole story: presence is strong evidence, absence is no evidence. Any workflow that treats “no watermark found” as “human-written” has built a hole exactly where the dishonest cases walk through.

05

The regulation behind it — three blocs, one direction

Short answer

The EU’s Article 50(2) drove this announcement — but China and South Korea got there first. The world’s three largest regulatory blocs now require AI-generated content to be identifiable.

Article 50(2) of the EU AI Act requires providers of AI systems that generate synthetic text, images, audio or video to ensure the outputs are marked in a machine-readable format and detectable as artificially generated. The obligation applies from August 2, 2026. A Code of Practice operationalises it, and Anthropic is a signatory — which is why the announcement lands on that exact date.

China moved a year earlier. Its Measures for Labeling AI-Generated Synthetic Content, with a mandatory national standard (GB 45438-2025), took effect on September 1, 2025 — and go further than the EU in two ways. They require both explicit labels (visible notices a person can see) and implicit labels (machine-readable marks in the content or its metadata), and they put duties on distribution platforms too: platforms must check for labels and flag suspected AI content even when it arrives unlabelled. Maliciously removing, altering, forging, or concealing a required label is itself prohibited — as is providing tools to do it.

South Korea’s AI Basic Act took effect on January 22, 2026 — the first comprehensive national AI framework law after the EU’s. Its transparency provisions require businesses providing generative-AI products or services to indicate that outputs were AI-generated; content that could be mistaken for reality must be clearly labelled, by human-visible or machine-readable means. Enforcement of the transparency provisions carries a grace period of at least a year, with fines deferred except in cases of serious harm — the duty exists now; the penalties wait.

The strategic consequence: Anthropic is unlikely to remain alone. With three major blocs requiring identifiable AI content — one of them already making label-checking a platform duty — the share of provenance-carrying AI text grows, and content checking gradually shifts from pure statistical guessing toward verification. That shift will take years, but its direction is now set by regulation on three continents, not by any one company’s choice.

RegimeIn forceCore dutyDistinctive feature
China — Labelling Measures + GB 45438-2025Sep 1, 2025Explicit (visible) + implicit (machine-readable) labelsPlatforms must verify labels; label-stripping prohibited
South Korea — AI Basic ActJan 22, 2026Indicate outputs are AI-generated; label realistic synthetic contentEnforcement grace period of at least a year
EU — AI Act Article 50(2)Aug 2, 2026Machine-readable marking, detectable as artificialThe Code of Practice Anthropic signed
06

What changes for AI detection

Short answer

Detection splits into two tiers: verify provenance where marks exist, and read style everywhere else. Both tiers are needed — they answer different questions.

When Anthropic publishes its detection details, checking for the mark becomes a deterministic test: the mark is verifiably present, or it is not found. That is the first tier — provenance verification. It is proof-grade for the text that carries a mark, and silent about everything else.

The second tier is what exists today: style-based analysis, which estimates the probability that prose reads as model-generated, and which remains the only tool for the unwatermarked majority. Its honest framing does not change — a probability with evidence, a signal rather than proof, abstention when there is too little prose to judge.

Where Stipple stands: we do not detect Claude’s watermark today — nobody outside Anthropic can, until the technical details are published. When they are, watermark verification is a natural deterministic check in front of our style analysis, the same way our fact-check tool already reads the provenance markers some AI-exported documents carry. Until then, the only honest claims are the ones on this page.

07

What to do differently now

Short answer

Nothing changes overnight — but provenance-first habits are worth building early.

If you review submitted writing: keep asking for process evidence — drafts and version history remain stronger evidence of authorship than any detector score, and they will remain stronger than watermark absence too.

If you publish with AI assistance: expect provenance marking to spread, and disclose AI use where your context calls for it — transparency ages better than discovery.

If you rely on detection tools: prefer ones that show their evidence and state their limits. A tool that claims certainty from style alone was overclaiming before watermarks; it is overclaiming after them too.

Questions

Frequently asked questions

Can Stipple detect Claude’s watermark?

Not yet — and today nobody outside Anthropic can, because the detection specification has not been published. Anthropic has said it will publish technical details for detecting its marks; when that happens, we plan to add watermark verification as a deterministic check alongside our style analysis. Until then, our detector does what it says: style-based probability with the evidence shown.

Does the watermark survive copy-paste?

Yes, by design — the mark lives in the text itself, not in metadata, so pasting the text carries the mark with it. That is Anthropic’s stated design goal: “it will travel with the text when it’s copied and pasted elsewhere.”

Can the watermark be removed by editing?

Anthropic’s own wording is that the mark “may persist through some editing” — an honest maybe. Light edits may leave it intact; heavy rewriting or paraphrasing may not. No robustness numbers have been published, so any confident claim in either direction is currently unfounded.

If a text has no watermark, was it written by a human?

No. Only new Claude models mark their output — text from other providers, from older models, or from before August 2026 carries no mark. Absence of a watermark is not evidence of human authorship, and treating it that way creates a blind spot exactly where evasion lives.

Will other AI companies watermark their text too?

The pressure points that way. EU AI Act Article 50(2) requires machine-readable marking of AI-generated content from August 2, 2026, and the Code of Practice that operationalises it has multiple signatories. Adoption speed will vary by provider, but the regulatory direction is set.

Do watermarks make AI detectors obsolete?

No — they change the job. Watermark verification answers “did this come from a marked model?” for the minority of text that carries a mark. Style analysis answers “does this read as model-written?” for everything else, which will be the majority for years. The two are complementary tiers, not competitors.

Sources

Sources and further reading

  1. 01The Register — Anthropic pledges to embed watermarks (2026-08-11)
  2. 02Business Standard — How the Claude watermark works
  3. 03EU AI Act, Article 50 — transparency obligations
  4. 04China Law Translate — Measures for Labeling of AI-Generated Synthetic Content
  5. 05Future of Privacy Forum — South Korea’s AI Framework Act

Educational guidance, not a forensic certification. Detection technologies and standards change; review material decisions against current evidence.

Check text the honest way

Until watermark verification is possible, style analysis with the evidence shown is the honest tool: a probability, a confidence band, the specific tells — and abstention when there’s too little prose to judge.

Open the AI detector