Published Product3 min read
Claude's watermark is an EU compliance artifact, and it lands on undisclosed output
Anthropic says it is watermarking Claude text to satisfy the EU AI Act Transparency Code and plans a detection API. The exposure sits with teams shipping generated work as their own.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Anthropic published a blog post on Friday seeking to answer basic questions about how it will watermark text generated by Claude, including how the watermarking will work, whether it can be hidden with editing, and how it affects code.
- Anthropic revealed earlier that week that it would watermark Claude's text output to comply with the EU AI Act's Transparency Code, which requires AI companies to use systems that make it possible to identify AI-generated content.
- Anthropic said Claude will not be the only AI chatbot to generate watermarked text, because other major model developers have signed the same Code of Practice and will be implementing their own watermarks.
- Anthropic explained that when making low-stakes choices, such as choosing between the words "overcast" and "grey" to describe the weather, Claude can create a pattern in its responses that is undetectable to the reader but detectable to anyone who has a key that encodes it.
- Anthropic said "Watermarking does not impact the quality of Claude's output" and that to a reader a watermarked response is indistinguishable from an unwatermarked one.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Anthropic published a blog post on Friday setting out how it will watermark text generated by Claude, covering how the mechanism works, whether editing defeats it, and what happens with code [1]. The company had said days earlier that it is doing this to comply with the EU AI Act's Transparency Code, which requires AI companies to use systems that make it possible to identify AI-generated content, which makes this a compliance artifact rather than a product decision that user complaints will reverse [2].
The mechanism, as Anthropic describes it: on low-stakes choices, such as whether to write "overcast" or "grey", Claude arranges its selections into a pattern that is undetectable to a reader but detectable to anyone holding the key that encodes it [4]. The company says it is using the SynthID-Text approach published by the Google DeepMind team in 2024 [6], and that watermarking does not affect output quality, with a watermarked response indistinguishable to a reader from an unwatermarked one [5]. The load-bearing piece for operators is not the watermark but the detection API that Anthropic says it plans to release [7]. TechCrunch's account of the post does not describe who will get access to that API or on what terms [18], and that one question decides whether the watermark is an audit instrument for regulators or a check any client, editor, or procurement reviewer can run on a delivered document.
On robustness, Anthropic says light editing probably will not remove the watermark completely, while a complete rewrite in which every word is replaced will [9]. In that second case, the company notes, it is arguable whether the text can still be described as AI-generated [10]. Where Claude only proofreads or edits human writing, detectability depends on the length of the text and how heavily Claude edited it; under light editing, nearly all the words are the human author's and there is very little for the watermark to attach to [11]. The practical rule that follows is that detectability tracks the share of words Claude actually chose [17], which puts the highest exposure on the workflows that generate long passages and ship them intact.
Code is the softer case. Anthropic says code should carry less of a watermark because the model has to produce something that works and so lacks the freedom to pick among many equally valid options [12], while the watermark can attach where a choice is arbitrary, such as comments inside code, with what the company calls a negligible effect on the code produced [13]. For an engineering deliverable, then, the detectable surface is the prose wrapped around the code rather than the executable lines [16].
Anthropic also separates this from AI detectors such as Pangram, which look for stylistic tells like the "This isn't [X], it's [Y]" construction; checking for a watermark, it says, is fundamentally different from picking up on those patterns [8]. In a dispute, that distinction is the difference between a keyed check and a stylistic guess. The user reaction so far has been loud and narrow: one Reddit poster characterised the move as a conspiracy against innocent Claude users, another wrote that "The only reason you wouldn't want this is to lie to people" [14], and Business Insider reports dozens of users on X claiming to have cancelled subscriptions [15].
Three things to watch. The access terms for the detection API, since they set who can audit whom [7][18]. Whether the other major model developers that signed the same Code of Practice ship comparable watermarks on a similar timeline, which removes vendor-switching as an escape route [3]. And whether contracts that promise human-authored deliverables begin naming watermark checks as an acceptance test.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Anthropic published a blog post on Friday seeking to answer basic questions about how it will watermark text generated by Claude, including how the watermarking will work, whether it can be hidden with editing, and how it affects code.
- [2]
Anthropic revealed earlier that week that it would watermark Claude's text output to comply with the EU AI Act's Transparency Code, which requires AI companies to use systems that make it possible to identify AI-generated content.
- [3]
Anthropic said Claude will not be the only AI chatbot to generate watermarked text, because other major model developers have signed the same Code of Practice and will be implementing their own watermarks.
- [4]
Anthropic explained that when making low-stakes choices, such as choosing between the words "overcast" and "grey" to describe the weather, Claude can create a pattern in its responses that is undetectable to the reader but detectable to anyone who has a key that encodes it.
- [5]
Anthropic said "Watermarking does not impact the quality of Claude's output" and that to a reader a watermarked response is indistinguishable from an unwatermarked one.
- [6]
Anthropic said it will be using the SynthID-Text approach that the Google DeepMind team outlined in 2024.
Sources & coverage · 4 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- techcrunch.comAnthony HaAug 15Anthropic shares more details about how Claude’s new watermarks will work
- theverge.comJess Weatherbed6d agoAnthropic explains how Claude’s invisible text watermarks will work
- 9to5mac.comBen Lovejoy



