Published Invest3 min read
Anthropic Shipped the Watermark Before the Detector
Every new Claude model now weaves a machine-readable mark into its text output worldwide, an obligation that arrived through the EU AI Act transparency code.
Context for builders, not their beat.See today for builders

What happened
- New Claude models launched in the EU on or after August 2, 2026 embed a machine-readable watermark in every piece of generated text, applied at the model level.
- Anthropic says the watermarking will apply worldwide, not only in the EU.
- Anthropic laid out the watermarking plan in a support article after signing the EU AI Act's Code of Practice on transparency.
- Open-source projects to remove the Claude watermark appeared within days of the change.
- The markings apply across every Claude surface: the chatbot, the API, Claude Code, and cloud partners such as AWS, Google Cloud, and Microsoft Foundry.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Anthropic has begun embedding an imperceptible, machine-readable watermark into every piece of text its newest Claude models generate, applied at the model level for models launched in the EU on or after August 2, 2026, and the company says the marking applies worldwide [1][2]. That matters for two reasons: the obligation followed Anthropic signing the EU AI Act's Code of Practice on transparency rather than a product decision [3], and open-source projects to remove the mark appeared within days [4].
The scope is the part operators should read twice. The marking reaches every Claude surface, including the chatbot, the API, Claude Code, and cloud partners such as AWS, Google Cloud, and Microsoft Foundry [5]. In Anthropic's words, the model "weaves an imperceptible watermark directly into the text itself," which "doesn't change the meaning, quality, or readability" and "will travel with the text when it's copied and pasted elsewhere, and may persist through some editing" [6]. Files carry a second layer: signed metadata under the C2PA standard, recording who produced a file and whether it was altered [7].
What Anthropic has not shipped is the ability to check any of this. The company has not said how the watermark is constructed, and the detection documentation and thresholds are not out [8]. Nor has it said when they will be [9]. So the mark is live on every output while no third party can verify a positive or a negative [17]. Researchers infer a statistical signature, nudging word choice toward a faint detectable bias, the same family of approach as Google's SynthID Text, but that remains a guess until the detector is published [10].
The semantics are looser than a provenance label implies. The mark shows Claude had a hand in the text, not that it wrote all of it, so an original paragraph given a small edit is treated like fully generated output [11]. Ask Claude to proofread or translate and the result can still carry the signal [12]. Heavy editing can strip it, and a missing mark does not prove a human wrote something [13]. Both error directions are live, and neither is quantified.
Meanwhile, the counter-tooling is further along than the verification tooling. mikiane/claude-watermark-cleaner, at 106 GitHub stars, scrubs invisible Unicode and then rewrites text with a non-Claude model to disturb the token pattern [14]. guillaumemeyer/watermarks-remover, at 4,600 stars, strips Claude text marks plus C2PA and SynthID-class signals across PNG, JPEG, SVG, PDF, and DOCX [15]. Its authors argue a statistical text mark is "not a reliable way to prove origin" and mostly pushes users into a second model pass to clean their own writing [16]. No removal can be guaranteed until Anthropic ships the detector and thresholds [18].
The trust context is not neutral. Anthropic removed a hidden Claude Code tracker in March after researchers found it tagging some users' location and proxy use through undisclosed Unicode markers, the same quiet-marking technique now at the center of the watermark plan [19]. In the US, the COPIED Act pushes a standardized watermarking approach so platforms can trace origin [20].
Watch for the detector and its false-positive thresholds, since everything downstream, including whether a lightly edited human draft gets flagged, depends on numbers Anthropic has not published [8][9]. Watch whether AWS, Google Cloud, and Microsoft Foundry expose any customer-facing control or disclosure for marked output [5]. And watch whether the removal repos' claims survive contact with published thresholds [18].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
New Claude models launched in the EU on or after August 2, 2026 embed a machine-readable watermark in every piece of generated text, applied at the model level.
- [2]
Anthropic says the watermarking will apply worldwide, not only in the EU.
- [3]
Anthropic laid out the watermarking plan in a support article after signing the EU AI Act's Code of Practice on transparency.
ReportedView cited source - [4]
Open-source projects to remove the Claude watermark appeared within days of the change.
ReportedView cited source - [5]
The markings apply across every Claude surface: the chatbot, the API, Claude Code, and cloud partners such as AWS, Google Cloud, and Microsoft Foundry.
ReportedView cited source - [6]
Anthropic said: "When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself. You won't see it, and it doesn't change the meaning, quality, or readability of Claude's response... Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing."
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- decrypt.coJose Antonio LanzAug 13Anthropic Is Quietly Watermarking Every Claude AI Output. Builders Are Already Trying to Break It
Additional citations
- Anthropic support article, via Decrypt
- Anthropic, via Decrypt
- Anthropic
- researchers, via Decrypt
- guillaumemeyer/watermarks-remover authors



