Published Build3 min read
Anthropic marks everything Claude writes. Nobody can mark what it reads.
Models shipped from 2 August 2026 watermark every generated text, across apps, API and three clouds, with no documented off switch. The detection tools are still unpublished.
Written for builders.See today for builders
What happened
- On 11 August 2026 Anthropic confirmed that all the text Claude generates comes out marked with a watermark.
- Models launched from 2 August 2026 ship with marking built in; earlier models will follow with no announced date.
- The mark sits at model level and applies worldwide, not only in the European Union.
- The watermark applies to every surface: the Claude apps, the API, Claude Code, Cowork, Tag, and when the model runs inside AWS Bedrock, Google Cloud or Microsoft Foundry.
- There is no door that lets you get clean content out, and no way to switch the marking off has been documented.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
Anthropic confirmed on 11 August 2026 that every text Claude generates now carries a watermark, and that models launched from 2 August 2026 ship with the marking built in [1][2]. That moves provenance marking from a paper topic to default production behaviour on a frontier model, and it does so in one direction only: what comes out of the model is signed, what went in is not [12].
The scope is the interesting part. According to the account by developer Carlos Ortet, the mark sits at model level and applies worldwide rather than only in the European Union [3], and it covers every surface: the Claude apps, the API, Claude Code, Cowork, Tag, and the model as run inside AWS Bedrock, Google Cloud and Microsoft Foundry [4]. No clean-output path and no off switch have been documented [5]. For operators that is a procurement fact, not a policy footnote. If your pipeline emits Claude text through Bedrock, it emits marked Claude text.
The legal trigger is the EU Code of Practice on Transparency of AI-Generated Content, which develops article 50(2) of the AI Regulation and which Anthropic signed [6]. The Commission found the Code adequate on 8 July 2026, the AI Board on 9 July, and the obligations apply from 2 August [7]. The announcement landed nine days after that date [13], and the global scope means one jurisdiction's transparency rule has been implemented as a worldwide model property.
What the mark proves is narrower than the headline suggests. Anthropic itself says it indicates only that Claude may have processed the text, not that Claude wrote it and not that the publisher used AI [8]. On mechanism, the company has said the mark "is part of the text", that it survives copy and paste, and that it "may persist through some editing" [9]. For generated .svg, .png and .jpg files it attaches signed metadata using the open C2PA standard [10]. Technical documentation and detection tools were announced but, as of 12 August 2026, had not been published, and TechCrunch's question about how much editing removes the mark went unanswered [11]. So the claim is live in production and unverifiable from outside.
Ortet's reading is that the only family that fits "part of the text" and survives copy and paste is generation-time token steering with a secret key, split between the green-list approach of Kirchenbauer et al. at ICML 2023, which nudges logits and raises perplexity, and distortion-free schemes that leave the distribution untouched [14][15]. The durability of either is contested: work presented at EACL 2026 forges another model's mark, and a 2025 paper strips watermarks with a 99 per cent success rate and no access to the model [16].
The asymmetry is the operator problem. The industry has now solved marking what leaves a model; it has not solved proving what went in [12]. If you publish, you still have no equivalent primitive for signing your own corpus before a crawler takes it, and the window to do it closes once a model has read the text [17]. Ortet also corrects his own earlier claim that a mark appearing only once is undetectable, citing an ICML 2025 paper showing it can be detected if you act before publishing [18].
Watch for three things: the promised documentation and detector, whether earlier Claude models get retrofitted (no date has been announced) [2], and whether any cloud reseller documents a way to disable the mark. The first vendor to offer input-side marking with a published verifier will be selling something no one currently has.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On 11 August 2026 Anthropic confirmed that all the text Claude generates comes out marked with a watermark.
- [2]
Models launched from 2 August 2026 ship with marking built in; earlier models will follow with no announced date.
- [3]
The mark sits at model level and applies worldwide, not only in the European Union.
- [4]
The watermark applies to every surface: the Claude apps, the API, Claude Code, Cowork, Tag, and when the model runs inside AWS Bedrock, Google Cloud or Microsoft Foundry.
- [5]
There is no door that lets you get clean content out, and no way to switch the marking off has been documented.
- [6]
Anthropic signed the Code of Practice on Transparency of AI-Generated Content, the instrument that develops article 50(2) of the European AI Regulation.
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- the-decoder.comMatthias BastianAug 14Anthropic announces watermark detection API that will let third parties detect Claude's AI texts
- dev.tocarlosortetAug 15You need to sign your content. Anthropic already marks everything Claude generates and you still don't
Cited in this coverage: Carlos Ortet, dev.to / carlosortet.com
Cited in this coverage: Carlos Ortet, dev.to

