Claude Now Marks Everything It Writes. Here's What That Means for You.
Since August 2, 2026, every supported Claude model has embedded an invisible watermark in the text it writes and attached signed provenance metadata to files it generates, applied everywhere Claude runs, well beyond EU borders. The mark also appears when Claude only proofreads or translates words a human wrote. It does not prove a human did not write something, and right now no public tool can even read it. If your business publishes anything Claude touched, under your own name, this quietly changes what that name is promising.
Claude just started signing its own work. You cannot see the signature. One day, someone else might be able to read it.
It is 9 p.m. Marcus is closing out client work for his three-person content studio in Manchester. Twelve small businesses pay him monthly for blog posts, LinkedIn updates, and website copy. He writes the first draft himself, most nights. Then he pastes it into Claude to tighten the grammar and cut the fat.
He has never told a client that part. He never thought he needed to.
As of last week, that draft comes back marked.
What did Anthropic actually change on August 2?
Anthropic signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, and it now marks what its models produce to meet that commitment. Two things happen. Text that a supported Claude model writes carries an invisible, machine-readable watermark. Files it generates or touches, such as PNG, JPG, and SVG images, carry signed provenance metadata built on the C2PA standard, the same open format used across the content-authenticity industry.
Every Claude model launched on or after August 2, 2026 ships with this on by default. Older models are getting it added during a transition period. There is no opt-out documented anywhere in Anthropic's own explanation of the policy.
You do not have to be in Europe, sell to Europe, or think about Europe at all. If you use Claude, this already applies to you.
How does an invisible watermark actually work?
Not with hidden characters. That is everyone's first guess, and it is wrong, which matters, because hidden characters are trivial to strip. Retype a sentence and they vanish. Paste into a plain-text box and they get stripped automatically. Anthropic says its mark survives copy-paste and some editing without changing the meaning, quality, or readability of the text at all. Hidden characters cannot do that.
The mark is in the words themselves. Anthropic has not published its exact method, but the mechanism it describes matches a known technique called statistical watermarking. Picture the model choosing each word from a shortlist of equally good options, the way "fix the grammar," "repair the grammar," and "correct the grammar" are all fine choices in the same sentence. A hidden key quietly splits that shortlist into two halves at every one of those choice points. Call them green and gray. The model gets nudged, gently, toward green.
One word proves nothing. Anyone would land on green about half the time by pure chance. But string together a few hundred words that keep landing green more often than chance allows, and a pattern appears that only someone holding the key can measure. That pattern is the watermark. It travels with the words, because it is woven into which words got chosen, not into anything sitting between them.
Which is also exactly why it breaks. Paraphrase the text and you replace the word choices, so the signal goes with them. Translate it, same result. Heavy editing wears it down. And it needs length: a two-line WhatsApp reply barely has enough real choices in it to separate a watermark from a coincidence. A full page does.

Does a Claude watermark prove content was written by AI?
No. And this is the part getting flattened in a lot of the reaction online. Anthropic's own wording is that a detected mark means text "may have been processed by Claude." That is a much weaker claim than "Claude wrote this," and it fails in both directions.
It fails toward false alarms because proofreading and translation both count as processing. Marcus wrote every word of his client's blog post. Claude only fixed his commas. What comes back still carries the mark, because generation and light editing look the same to the model doing the marking. Anthropic names this exact case in its own documentation.
It also fails toward false negatives. Heavy editing, a short passage, an older unmarked model, or a platform that strips metadata on upload can all hand you clean, unmarked text that Claude wrote start to finish. Absence of a mark proves nothing either.
Put plainly: the mark says Claude probably touched this text. It never says a human did not write it. Anyone who treats a flag as a verdict is reading past the caveats Anthropic put in writing.
What gets marked, and what does not
| Content type | Gets marked? | Survives normal use? | What removes it |
|---|---|---|---|
| Text Claude writes for you | Yes, embedded watermark | Copy-paste and light edits, yes | Paraphrasing, translation, heavy rewriting |
| Your own text, Claude only proofread | Yes, same watermark | Same as above | Same as above (there is no exemption for light-touch edits) |
| Claude-generated PNG, JPG, or SVG files | Yes, signed C2PA provenance metadata | Some transfers and shares | Resaving, re-exporting, or converting the file often strips it |
| Output via the API, Claude Code, Cowork, or Tag | Yes, model-level, regardless of surface | Same rules apply | Same rules apply |
| Open-weight or non-Claude models | Not covered by this policy | N/A | N/A |
Notice what is missing from that table: a detector you can run yourself. As of this week, Anthropic says tooling to check for its own marks is still in progress. The mark exists in your text right now. Nobody outside Anthropic can read it yet.
What this means for your business, step by step
- Assume every Claude draft already carries a mark, starting now. Not eventually. Today, if the model was launched on or after August 2, 2026, or once older models finish their transition.
- Write your disclosure policy before a client, a court, or a platform writes it for you. One sentence is enough: how your business uses AI, and where a person reviews the result before it goes out.
- Retire "100% human-written" as a marketing claim unless you can back it with a workflow. Proofreading counts as processing under Anthropic's own definition. If that promise matters to your brand, it needs a rule, not a slogan.
- Do not lean on file metadata as your only proof of authenticity. C2PA provenance data is real, but it is metadata, and metadata is the easiest thing in computing to strip. One resave and it can be gone.
- If you serve clients who answer to the EU AI Act, keep records anyway. This cuts both ways: it can protect you as easily as it can expose you, depending on who asks the question first.
- Decide out loud, once, rather than explaining it client by client later. The businesses that name their AI policy this month spend less time defending it in six.
This lands harder in places built on freelance content work than most coverage admits. Kenya alone has one of the largest freelance-writing workforces in the world, tens of thousands of people on Upwork and Fiverr producing English-language blog posts, product copy, and marketing content for clients in the US, the UK, and beyond. A watermark on Claude-processed text is not an abstract policy question there. It is a line item in how that work gets sold and defended.
Is there any way to tell if a document has already been marked?
Not from where you are sitting today. Detection tools are, in Anthropic's own words, still being built. That will not last. Watermarking only matters commercially once someone can check it, and every major lab racing toward the same EU transparency requirement has an incentive to ship a checker. Plan as if a working detector arrives within the next year, because it probably will, and by then you want your disclosure habits already in place rather than newly urgent.
What you have after this
A week from now: one written line about how your business uses AI, ready before anyone asks.
A month from now: a client raises it in a call, and you already have the answer instead of an excuse.
Six months from now: the agencies who named their AI policy early are the ones clients trust with the ambiguous cases. The ones who did not are still explaining a watermark they only found out about from a worried client.
Same tools. Same team. Just now, everyone eventually finds out who wrote what, and it pays to be the one who said so first.
Does Claude's watermark apply to every AI tool, or just Claude?
Just Claude, for now. Anthropic's policy covers its own supported models, not ChatGPT, Gemini, or open-weight models. Other providers covered by the same EU AI Act transparency rule are expected to add their own marking, though they may use different techniques, so a Claude-style watermark should not be assumed on other tools.
Can I turn off Claude's watermark?
No opt-out is documented. Anthropic's help article describes the marking as applying automatically to supported models across every Claude surface, with no setting to disable it.
Does editing AI-written text remove the watermark?
Light edits and copy-pasting generally do not remove it, since the mark lives in the word choices themselves. Heavy rewriting, paraphrasing, or translating the text typically does remove it, because those change the underlying word choices the watermark depends on.
Is there a tool to check if text was watermarked by Claude?
Not publicly, as of August 2026. Anthropic says it is working on detection tooling for users and third parties, but nothing is available yet, so neither you nor a client can currently verify a mark either way.
Does this mean using Claude for client work is against the rules?
No. This is a transparency requirement, not a ban on AI-assisted work. The practical effect is that businesses now need a clear, honest position on how they use AI, stated on their own terms, rather than discovered later.
Find your first high-payback workflow.
See the SprintSources
- How Claude marks AI-generated content (Anthropic Help Center)
- @ns123abc on X: "Claude models will now have invisible watermarks embedded in ALL text, and ALL metadata attached to files"
- @SMB_Attorney on X: reaction thread on watermarking's implications for the legal profession and content creators
- "Claude's Invisible Watermark: What It Can't Prove" (SimplyExplain, YouTube)
- Anthropic pledges to embed watermarks to help discern AI slop, in sop to EU (The Register)
Find your first high-payback workflow.
Book a free conversation or start with the fixed-fee Sprint.
Keep reading
Meta's New AI Agent Is Free. Your Hardware Bill Isn't.
On August 10, 2026, Meta released Muse Glimmer, a free, 30-billion-parameter open-weight AI agent model you can download and run entirely on your own…
AI agentsYour AI Forgets Who Introduced You. Fix Its Memory.
Give your AI assistant graph memory instead of a flat chat log: an open-source memory layer like Cognee plus a graph database (FalkorDB or Neo4j), or a…
Back-office AIYou Spend 9.5 Hours a Week on Resumes. Build the Loop That Gets Them Back.
LinkedIn's own hiring engineers found managers lose 9.5 hours a week just reviewing candidates. Their fix was not a bigger team, it was treating hiring as a