Anthropic Will Watermark Claude's Text Worldwide as EU Transparency Rules Bite

The marking sits inside the words themselves and survives copy and paste. Anthropic also admits a detected mark does not prove Claude wrote anything.

Anthropic has committed to embedding invisible watermarks in text produced by Claude and attaching digitally signed provenance metadata to the files Claude generates, according to a company support document updated on Monday. The move places the AI firm inside a compliance regime that took legal effect across the European Union on August 2, and it applies to Claude output everywhere the assistant is sold, not only in Europe.

The company has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content. It did so wearing two hats at once, registering as a provider of generative AI models and as a provider of generative AI systems. That distinction matters because the two categories carry different obligations under the Act.

What Anthropic has actually promised

Any Claude model launched on or after August 2, 2026 will support machine-readable marking from day one. Text output carries an embedded watermark. Generated files carry signed metadata built on the Coalition for Content Provenance and Authenticity standard, better known as C2PA.

Coverage spans the full product line. Anthropic names Claude Platform (its API), the Claude consumer apps, Claude Code, Claude Cowork and Claude Tag. Because the watermark is applied at the model level rather than bolted onto individual surfaces, output picks up the mark regardless of which product a person is using.

Third-party clouds are included too. Amazon Web Services is covered, as are Google Cloud and Microsoft Foundry, though Anthropic warns that signed provenance metadata may not work on every platform depending on what features each one supports.

Two techniques, two failure modes

The text system is the genuinely new piece here.

"When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself," Anthropic wrote. The company says the mark does not change the meaning, quality or readability of a response, and that because the signal lives in the text rather than in an attached file header, it travels when someone copies and pastes the output elsewhere. It may also survive a degree of subsequent editing.

How much editing? Anthropic has not said. TechCrunch reported that it asked the company to clarify the threshold and had not received an answer at the time of publication.

The file system is more familiar territory. When Claude produces a supported file type, currently .svg files plus .png and .jpg images, it attaches C2PA metadata that signals the file passed through Claude and allows a checker to see whether the file has been tampered with since. C2PA is already deployed at scale elsewhere in the industry, and open source tools to strip that metadata are freely available, as The Register noted in its coverage.

The mark says "processed by Claude," not "written by Claude"

This is the part most likely to be misread once detection tools reach schools and hiring platforms.

Anthropic states plainly that a detected mark "provides a signal that content was processed by Claude, but is not fully conclusive." A person can write an essay entirely themselves, hand it to Claude for proofreading or translation, and get back a version carrying the watermark. The underlying ideas and the original wording came from a human. The mark still appears.

The reverse gap is just as wide. Absence of a mark proves nothing about whether AI was involved. Anthropic lists several ways marked content loses its signal: generation by a model released before marking existed, text that has been heavily edited, paraphrased, translated or blended into other writing, passages too short to carry a reliable signal, and file metadata stripped through format conversion, re-saving or a screenshot.

Read together, the two limitations describe an asymmetric tool. A positive result is weak evidence of involvement at some stage. A negative result is evidence of nothing at all.

There is an awkward overlap with the regulation itself. The Commission's guidance on Article 50 carves out cases where an AI system performs only an assistive function for standard editing, such as grammar correction, or where it does not substantially alter the input data or its semantics. Anthropic's model-level watermark does not appear to distinguish between rewriting an article from scratch and fixing its commas.

Current Claude models are not covered yet

Marking applies at launch only to models released on or after August 2. Everything Anthropic already has in market, including Opus 5, Sonnet 5 and Fable 5, predates that cutoff and sits inside a transition period the law allows.

The company describes retrofitting work on those models as in progress. It has published no date.

That timeline is set by Brussels rather than by Anthropic. Under the grandfathering agreed in the Digital Omnibus, generative AI systems already on the market before August 2 have until December 2, 2026 to bring their Article 50(2) marking and detection into conformity. Content generated and published before August 2 does not have to be marked retroactively, although the Commission encourages it where possible. A further deadline lands on February 2, 2027, by which point providers must have a watermark detection interoperability solution in place.

Detection is promised, not documented

Anthropic says it will support users and third parties in detecting its marks, as the Code requires, with details to follow in technical documentation.

None of that documentation exists yet. There is no published algorithm, no stated false-positive rate, no minimum passage length at which detection becomes reliable, and no guidance on how a token-level marking scheme interacts with sampling parameters that API developers control directly.

Roughly 190 organisations have signed the Code

Anthropic is far from alone. By the end of July, about 190 organisations had signed the Code of Practice ahead of the marking obligations taking effect, according to the European Commission. Signatories span IT, telecom, education and retail, and roughly half are small or recently founded companies.

The Code splits into two sections. Section 1 addresses marking and detection by providers of generative AI systems, and has 82 signatories. Section 2 covers labelling duties for deployers and has 152.

Anthropic appears in Section 1 alongside Aleph Alpha, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI and Synthesia. Section 2 signatories include Bulgari, Fastweb, Getty Images, Iberdrola, Lenovo and Lufthansa.

Signing carries a concrete regulatory benefit. The Commission and the AI Board assessed the Code as adequate on July 8 and July 9 respectively, which means signatories can rely on it as the only EU-wide compliance instrument currently judged sufficient for these obligations. The Commission has indicated that enforcement for signatories will focus on monitoring adherence to the Code. Non-signatories must demonstrate compliance by other means and can expect more requests for information from authorities. National market surveillance authorities handle enforcement and hold the power to impose fines.

The AI Office plans to launch two task forces in September to share implementation practice among signatories.

Watermarking pledges are arriving in clusters

Anthropic's announcement follows a run of similar commitments across content-generating platforms.

On August 6, AI music company Suno said it would introduce audio watermarking and fingerprinting so that tracks made on its platform can be identified when they surface elsewhere. Co-founder and chief executive Mikey Shulman wrote that the tools are designed to be durable and resistant to tampering without affecting the listening experience, and added that they are not intended to pass judgment on whether a song is good, meaningful or sufficiently human. Suno paired the announcement with a download policy aimed at curbing mass distribution of generated tracks onto streaming services, plus screening partnerships with Audible Magic and Musixmatch.

Suno's timing was not incidental. The Munich Regional Court ruled that the company trained its systems on protected music without the rights to do so, a decision Suno disputes, and it faces separate suits from Universal Music Group and Sony Music Entertainment.

In July, newsletter platform Substack partnered with detection firm Pangram to flag AI-generated writing. Substack chief executive Chris Best used the term "Claudefishing" for the practice of passing off machine-written work as one's own.

If you build on Claude, the obligation is still yours

Anthropic closes its support document with a line aimed squarely at its business customers. Companies deploying Claude inside their own products must independently assess what Article 50 requires of those products and services. The model-level watermark helps, but it does not discharge a deployer's own duties under the Act.

For any organisation touched by Article 50, the operative detail is geographic scope. Anthropic chose to apply marking globally rather than fencing it to European users, which means output generated in New York or Bengaluru carries the same signal as output generated in Berlin.

Comments

Join the discussion and share your perspective.