- Anthropic says Claude models launched in the EU on or after August 2, 2026, will mark generated text and supported files, with markings applying worldwide for supported models. [1] - Text marks are embedded at the model level; supported files such as SVG, PNG and JPG will carry signed C2PA provenance metadata where supported. [2] - Anthropic says detection tools are still forthcoming and warns that a detected mark does not prove Claude originated the underlying work. [3] - The EU requires machine-readable, detectable markings while accounting for technical limits; independent research identifies unresolved tradeoffs among robustness, public detectability and unforgeability.
[4][5] Anthropic is adding machine-readable provenance signals to Claude-generated text and files as the European Union’s AI Act transparency rules take effect. New Claude models launched in the EU on or after August 2, 2026, will mark their output at launch, and Anthropic says the markings will apply to supported models wherever Claude is offered, including outside Europe. [1]
The policy covers Claude’s web and desktop products as well as Claude Platform, Claude Code, Claude Cowork and Claude Tag. It also covers supported Claude models accessed through AWS, Google Cloud and Microsoft Foundry, although signed file metadata may not be available on every platform. [2]
A hidden signal for text, signed metadata for files #
Anthropic describes two separate mechanisms. For text, a supported model embeds an imperceptible watermark directly into its output. The company says the watermark is applied at the model level, travels with copied text and may survive some editing without changing the response’s meaning, quality or readability. [6]
Anthropic has not yet published the technical detection method. It says it will provide documentation and tools for users and third parties to check whether text carries a Claude mark. The company’s current explanation does not disclose the watermark’s statistical construction, minimum reliable text length or measured detection and false-positive rates. [7]
For supported files, including SVG, PNG and JPG, Claude will attach digitally signed provenance metadata based on the Coalition for Content Provenance and Authenticity, or C2PA, standard. The signature is intended to show that a file may have been processed by Claude and to reveal whether it was altered after the provenance record was created. [8] Anthropic’s published description specifies signed file metadata; it does not describe a separate resilient watermark embedded in image pixels. That distinction matters because metadata can be lost when a file is converted, re-saved or captured as a screenshot. [3]
What the EU rules require #
Article 50(2) of the AI Act requires providers of systems that generate synthetic audio, image, video or text to ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The law says technical measures should be effective, interoperable, robust and reliable as far as technically feasible, taking account of content-specific limits, cost and the state of the art. [9]
The transparency rules began applying on August 2, 2026. A limited transition applies to certain generative systems placed on the market before that date: providers have until December 2, 2026, to meet the Article 50(2) marking requirements for those existing systems. [10] Anthropic says it is working to add marking to Claude models released before August 2.
[11]The provider-side marking rule is separate from disclosure duties imposed on deployers. Under Article 50(4), users who publish an AI-generated or manipulated deepfake must disclose that fact. AI-generated or manipulated text published to inform the public about matters of public interest must also be disclosed, unless it has undergone human review or editorial control and a person or organization holds editorial responsibility. [12]
Anthropic’s markings can help downstream users meet those obligations, but the company says developers building products with Claude must independently assess what Article 50 requires of their own systems. A machine-readable mark is not, by itself, a public-facing disclosure. [11]
Useful provenance signal, incomplete proof #
Anthropic explicitly limits what its system can establish. A detected mark indicates that content may have been processed by Claude; it does not prove that Claude created the underlying ideas, text or data. A mark could appear after proofreading, translation, summarization or file conversion. Conversely, the absence of a mark does not prove that content is human-made. Anthropic lists heavy editing, paraphrasing, translation, short passages, metadata stripping and unsupported platforms or file types as reasons detection may fail. [3]
A 2025 paper in the Proceedings of Machine Learning Research found that C2PA-style metadata can provide cryptographic unforgeability and public detectability, while machine-learning watermarking can be more resistant to ordinary transformations. It concluded that no existing approach practically combines robustness, unforgeability and public detectability. [4]
A 2026 Berkeley technical report similarly describes metadata-based provenance as publicly detectable but not robust to accidental stripping because both the file and its manifest must survive. It distinguishes that approach from watermarking methods designed to tolerate transformations. [5]
The practical result is a provenance layer for cooperative use: platforms, publishers and users can inspect a Claude signal when it remains attached or detectable. It is less reliable as a universal detector for content that has been deliberately rewritten, recompressed, screenshotted or regenerated through another model. That limitation is consistent with independent policy research, which argues that watermarking may raise the cost of evasion and identify a meaningful share of commercial-model output, but cannot reliably identify all AI-generated material. [13]
Anthropic’s next technical documentation will determine how independently the system can be tested. Until the detection method, performance data and supported file and platform matrix are public, the marks establish a claimed signal of Claude processing rather than a complete chain of custody.
Companies mentioned #
Further sources #
[[1] Anthropic says new models launched in the EU on or after August 2, 2026, will s… ↗](https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content)
[[2] Anthropic identifies covered Claude products and cloud partners and notes that … ↗](https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content)
[[3] Anthropic describes limitations including misleading provenance implications, h… ↗](https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content)
[4] The 2025 PMLR paper finds that no existing scheme practically combines robustne… ↗
[[5] The 2026 Berkeley technical report distinguishes publicly detectable but strip-… ↗](https://www2.eecs.berkeley.edu/Pubs/TechRpts/2026/EECS-2026-126.pdf)
[[6] Anthropic says its text watermark is imperceptible, model-level, copied with th… ↗](https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content)+7 more
The stories that matter, in one email. Free — unsubscribe anytime.