← All posts

Claude is watermarking its text. Here's what it can prove

2026-08-13 · 4 min read

On August 11 a post from @M1Astra laid it out: new Claude models now embed invisible watermarks in all generated text, everywhere Claude is offered. The line that got people's attention came from Anthropic's own documentation. The mark lives in the text itself rather than in metadata, so it "will travel with the text when it's copied and pasted elsewhere."

The AI side of X spent the next two days arguing about whether that is a big deal. It is worth understanding, because if your business writes anything with Claude, this is already on.

What Anthropic turned on

Anthropic's support page says Claude models launched on or after August 2, 2026 support marking at launch, and that older models are getting it too. Two things are happening. Text gets an imperceptible statistical watermark woven into the word choices. Files like PNG, JPG and SVG get signed provenance metadata using the C2PA standard.

The coverage is wide. It applies to the Claude API, Claude itself, Claude Code, Claude Cowork, Claude Tag, and Claude models accessed through AWS, Google Cloud and Microsoft Foundry.

The trigger is European. The EU AI Act's Article 50(2) transparency code took effect on August 2, and Anthropic signed it. TechCrunch reported that Black Forest Labs, Google, Meta, Microsoft, OpenAI and Synthesia signed the same code. Anthropic chose to apply the mark worldwide rather than only in Europe, which means a business in Illinois gets a Brussels rule by default.

The pushback

Plenty of people shrugged. @steveruizok, who builds the tldraw canvas, called the whole thing pointless because "Everyone I know can identify a Claude generation from like four tokens." Fair enough for his circle. A hiring manager going through 300 cover letters on a Tuesday is not his circle.

The more useful response came from @alexcdot, CTO of the AI detection company GPTZero, who posted an explainer arguing that Claude's watermark "probably doesn't work how you think." His walkthrough: the model hashes the tokens it has already written together with a secret key, splits its vocabulary into a green set and a red set, and leans toward the green words. A detector counts how often green words turned up. Across several hundred words that skew is hard to explain away. Across a paragraph it is noise. Cui also notes that paraphrasing or substituting words by hand defeats it.

Anthropic says roughly the same thing in quieter language. Its documentation admits that heavy editing, paraphrasing or format conversion can strip the mark, that a detected mark only means the content "may have been processed by Claude," and that finding no mark proves nothing.

My read

The watermark answers one narrow question: did a Claude model touch this text. It does not answer who wrote it, how much a human changed, or whether the thinking is yours. Someone who drafts in Claude and then rewrites every sentence will likely come out clean. Someone who pastes 900 words untouched will not. I think that asymmetry is the right design, and I also think it is far weaker than the headlines suggest.

The part that bothers me is the detector. Anthropic says it is "working to enable users and other third parties" to check for these marks, without saying when or in what form. Until that ships, the watermark is a signal only Anthropic can read. Everyone else gets the disclosure without the tool.

If your business writes with AI

Nothing here says stop using AI to write. It does change a few habits worth adopting now:

  • Treat anything you publish straight out of Claude as machine-attributable, especially proposals, job applications, RFP responses and anything a client might scrutinize later.
  • If you resell content, check whether your client agreements say anything about AI disclosure. This is the year that question stops being hypothetical.
  • Marketing images generated through Claude now carry signed C2PA metadata, so they can be traced even when the caption cannot.

The bigger lesson is one I keep running into with clients. Rules like the EU transparency code do not arrive with a warning, and they land on whatever process you already have. If your AI usage is one person pasting things into a chat window, you have no way to answer basic questions about what got generated, edited or shipped. If it runs through a defined workflow with a human review step, you do.

That is the sort of thing our free process audit is for. We look at where AI already sits in your operation, what it touches, and where the gaps are before somebody else finds them.

08 / Start here

Find your worst bottleneck. Free.

A 20 minute call. We map where your week goes and pick out the first process worth automating. You keep the map either way, and there is no deck to sit through at the end.

Email

pgorski@newfacedesign.com

Phone

+1 (773) 627-2176

Based in

Chicago area

Working with clients everywhere