- Claude’s text watermark changes the source of randomness used in word selection rather than adding characters or hidden text. [1] - Light editing may leave the signal intact, while a complete rewrite can remove it. Short passages, factual answers, proofreading and much of code produce weaker signals. [1] - Anthropic plans a detection API. Supported files such as PNG, JPG and SVG use cryptographically signed C2PA metadata instead of the text watermark.
[1] Anthropic says Claude’s new text watermark works by steering otherwise interchangeable word choices with a keyed random process, creating a statistical pattern that readers cannot see. The company says the method is based on Google DeepMind’s SynthID-Text approach and does not add characters, require extra tokens or identify the user who generated the content. [1]
The watermark applies globally at the model level for models launched on or after August 2, 2026, including Claude’s products and API surfaces. Anthropic says older models will receive the capability over the coming months as part of its response to the EU AI Act’s transparency requirements. [1][2]
What the mark can and cannot show #
Anthropic says light editing may not remove the watermark completely, but replacing every word will. The company also cautions that detection can only estimate whether Claude was involved at some point; it cannot establish that Claude was the original author, distinguish heavy editing from direct generation, or identify a particular person, organization or conversation. [1]
The signal becomes harder to detect in short passages and factual writing, where the model has fewer acceptable choices. Claude’s proofreading of human-written text may produce too few model-selected words for reliable detection. Code generally carries less watermarking because exact terms are required for programs to work, although comments and other arbitrary language may contain the pattern. [1]
Detection and file provenance #
Anthropic says it is still working out the details of a watermark-detection API. It has not announced a user-facing opt-out or API switch to disable the marking. For supported files, including PNG, JPG and SVG, Claude instead attaches a signed C2PA content credential in metadata. C2PA records provenance through cryptographically verifiable metadata, while Anthropic’s text system changes token selection inside the output itself. [1][3]
Google’s SynthID-Text research describes the same broad strategy of modulating token probabilities, but also reports weaker performance on short, rewritten, translated and highly factual text. That leaves Anthropic’s system useful as a provenance signal, rather than conclusive proof of authorship or AI use. [4]
Companies mentioned #
Further sources #
[[1] Anthropic, “How Claude’s text watermark works,” August 14, 2026. Primary source… ↗](https://www.anthropic.com/news/claude-text-watermark)
[[2] TechCrunch, “Anthropic says it will watermark text generated by its AI models,”… ↗](https://techcrunch.com/2026/08/11/anthropic-says-it-will-watermark-text-generated-by-its-ai-models/)
[3] Coalition for Content Provenance and Authenticity, C2PA Specification 2.2. Refe… ↗
[4] Nature, “Demonstrating the ability of a language model to watermark its text,” … ↗ The stories that matter, in one email. Free — unsubscribe anytime.