4 Min Read

Anthropic Is Now Watermarking Everything Claude Writes

Featured Image

In Brief

Anthropic will now mark content generated by Claude, embedding an invisible statistical watermark in text and signed metadata in files, driven by the EU AI Act's transparency rules. 

The reaction online was loud, but the underlying technology has existed for years, and it still cannot reliably prove who wrote anything.

What Happened

Anthropic detailed how it will start marking content generated by Claude, using two techniques:

  • an invisible watermark embedded directly in generated text

  • digitally signed metadata attached to generated files, a tamper-evident label that shows a file came from Claude and cannot be quietly altered

Anthropic says the text watermark is imperceptible and does not change the meaning, quality, or readability of Claude's responses. But the mark travels with the text when it is copied and pasted, and it may persist through some editing.

For files such as PNG, JPEG, and SVG images, Claude attaches provenance metadata that follows the C2PA open standard, an industry framework for recording how a piece of digital content was created or modified. The markings apply to users worldwide and cover the Claude apps, the API, Claude Code, and Anthropic's cloud platform integrations.

The driver is the European Union's AI Act: Anthropic signed the law's code of practice on transparency for AI-generated content. Claude models launched in the EU on or after August 2, 2026, will support machine-readable marking at launch, with older models updated during a transition period.

The text watermark works because AI models write by predicting the next word based on probabilities. As Chris Penn of Trust Insights explained in a LinkedIn post, watermarking introduces a secret key that subtly "loads the dice," boosting the probability of certain word choices until the text carries a measurable statistical pattern. Humans cannot see it, and finding it requires access to both the model that wrote the text and the secret key. Without those, Penn wrote, AI detectors are "actually likely to perform worse because now the statistical patterns they're trained to detect are slightly less predictable. They're still dangerous and inappropriate to use in any punitive context."

The announcement set off a wave of criticism online, well beyond the usual AI circles. SmarterX founder and CEO Paul Roetzer broke down why the backlash surprised him on Episode 232 of The Artificial Intelligence Show.

The Key Numbers

2 - Marking techniques Claude uses: an invisible text watermark and C2PA signed metadata

4- Years text watermarking has been a known technology

2022 - Year OpenAI built a text watermarking tool it chose not to release

8/2/2026 - Effective date of the EU AI Act's transparency obligations

0 - Proof of Claude authorship from a detected mark, per Anthropic's own caution

Why the Backlash Is Four Years Late

The reaction caught Roetzer off guard. People who rarely comment on AI news were suddenly upset about it. "I was kind of taken aback, honestly, by the visceral reaction from some people to this topic, and I actually thought I was missing something," Roetzer says.

But none of this is new. OpenAI built a text watermarking method in 2022, before ChatGPT even launched, and chose not to release it. In reporting Roetzer revisited on the show, one insider called releasing it "just a matter of pressing a button." Google's SynthID has watermarked AI-generated content for years. OpenAI adopted C2PA metadata and SynthID watermarks for images earlier this year, then extended the approach to audio on July 31. Substack recently launching AI detection through Pangram. "Nothing seems new here to me other than Anthropic released the thing that we knew existed for four years that still doesn't work," Roetzer says.

False positives are still a real problem. These tools will land in the hands of teachers, professors, and anyone eager to police AI use, and a detected mark will get treated as absolute fact. Anthropic cautions that a detected mark does not prove Claude authored the content, and that the absence of a mark does not prove a human wrote it.

The real issue is slop, not assistance. AI is increasingly part of how people write, whether it helps them draft work, edit it, or spark ideas. Roetzer uses it that way himself. The problem is output with no human thinking behind it, such as the suddenly prolific posters on LinkedIn whose words come straight from a chatbot. That distinction led him to a working definition worth keeping.

"When you present an AI system's ideas and words as your own with no critical thought, that is AI plagiarism to me."

— Paul Roetzer, founder and CEO of SmarterX, Episode 232 of The Artificial Intelligence Show

SmarterX Take

Detection will never settle who wrote what. Roetzer's answer is to normalize transparency instead: saying you collaborated with Claude on the words but the ideas are your own, or noting that an article was co-authored with ChatGPT. "I don't think we should make people feel bad for using AI in their writing," he says. "I think we just need to get to a point where we accept it's part of writing, but we just need to be transparent about it and use it in a responsible way."

For business leaders, the practical move is to stop treating detection tools as truth machines and start setting disclosure norms.

  • Decide what your organization considers acceptable AI use in writing

  • What deserves disclosure?

  •  What crosses into plagiarism?

Teams that settle those questions will handle the coming wave of watermarks calmly, instead of re-examing every flagged document.

What to Watch

The watermark will get cracked fast. Roetzer expects someone to reverse-engineer Anthropic's technique almost immediately. "I give it a week before someone cracks how they're doing it," he says. The bigger question is whether OpenAI, which has sat on its own text watermarking tool since 2022, will follow Anthropic's lead as the EU rules take effect.

Schools are the first test of responsible use. Blanket detection policing helps no one, Roetzer argues. "They should be encouraged to use it in the proper ways, unless there's specific instances where you want them to use pen and paper and just prove that they have critical thinking and writing skills," he says. 

How Many Companies Have Rules for AI-Generated Content?

Only 48% of organizations have generative AI policies guiding the use of AI-generated text, images, video, audio, and code, according to the 2026 State of AI for Business Report. That is up from roughly 38% a year ago, but it still means more than four in ten companies have no formal rules for the content their people create with AI, the exact gap the watermarking and disclosure debate now exposes.

The full report, built on more than 2,100 responses across roles, functions, and industries, maps where organizations actually stand on adoption, governance, training, and tooling. Read the full report →

Related Posts

What Do 81,000 AI Users Actually Worry About?

Mike Kaput | March 24, 2026

Anthropic interviewed 81,000 Claude users across 159 countries. Their top concern was not job loss. It was hallucinations and unreliability.

Our AGI Episode Struck a Nerve. Here's What It Revealed About Where We Are in AI

Mike Kaput | January 13, 2026

Listeners to The Artificial Intelligence podcast responded with awe to the news of Anthropic's new Opus 4.5 and Claude coding. They see what's possible.

Anthropic Just Launched Claude Cowork. It's Already Raising Red Flags

Mike Kaput | January 20, 2026

Anthropic released a new coding tool called Claude Cowork but cautioned users against pitfalls: It can access internal files and accidentally delete them.