Claude Now Watermarks Every Text Output, Worldwide and With No Opt-Out
Anthropic embeds machine-readable watermarks in text from Claude models released after August 2, 2026. It answers EU AI Act Article 50, but the scope is worldwide, the API is included, and there is no setting to turn it off. No public detector exists yet.
- Text from Claude models released after August 2 carries a machine-readable mark.
- It covers every channel including the API, and there is no way to turn it off.
- No public detector exists yet, and a detected mark is not proof of authorship.
Text that Claude writes for you now carries a signal that no human eye can see but a program can read. The word watermark usually means a translucent logo stamped into the corner of a photo. This is a different thing. Nothing is added to what you see on screen. Schemes of this kind normally nudge the probability of each word choice by a tiny amount, leaving a statistical trace across the whole passage. Query that trace later and you get a verdict: this text may have passed through Claude.
Anthropic disclosed the plan in a support article, How Claude marks AI-generated content. Its opening line says the company signed the Code of Practice on Transparency of AI-generated Content under Article 50(2) of the EU AI Act. The compliance date for that code was August 2, 2026, and from that date new models launched in the EU support marking from launch.
Regulation is the trigger, but the scope does not stop at Europe. The article states that marking applies "wherever Claude is offered, worldwide." For developers and knowledge workers using Claude in Seoul, Bangalore, or São Paulo, this is in effect today.
Woven into text, attached to files
Anthropic uses two mechanisms, and they behave differently.
Text gets a watermark woven in. When a supported model generates prose, the article says it weaves an imperceptible watermark into the text itself. Because the mark is part of the text, it travels when you copy and paste, and it may persist through some editing. Anthropic states plainly that this happens at the model level. Whichever product or surface the text comes out of, the mark is there.
Files get signed provenance metadata attached. Supported file formats such as .svg, .png, and .jpg receive signed metadata following the C2PA standard. Unlike the text watermark, this also lets you check whether a file has been tampered with. But metadata falls off with a format conversion, a re-save, or a single screenshot.
The support article splits coverage into four categories.

The row developers should read first is Products. Claude Platform (the API), Claude, Claude Code, Claude Cowork, and Claude Tag are all listed, and the article says all generated text is watermarked. Reaching the models through AWS, Google Cloud, or Microsoft Foundry does not strip the text watermark. A cloud partner is not a route around it.
Nowhere in the article is there a way to turn it off. No request parameter is offered for unmarked output. Any company building a product on Claude has to design around the fact that Anthropic's mark ships inside the text their own service emits.
What applies to your account today
Here are the conditions in one place, all confirmed against Anthropic's support article.
| Item | Confirmed |
|---|---|
| Models | Models released after August 2, 2026 are marked from launch. Earlier models are in progress |
| Channels | API, Claude, Claude Code, Claude Cowork, Claude Tag, plus AWS, Google Cloud, and Microsoft Foundry |
| Plan | Irrelevant. Free users and enterprise contracts alike |
| Regions | Worldwide, so output received outside the EU is marked too |
| Opt-out | Not documented |
| Detection tooling | Not released. Technical documentation promised later, no date given |
The marks are already going out, but the only party that can currently read them is Anthropic. The support article says the company is working to enable users and third parties to detect the embedded watermarks, without committing to a schedule. Right now the only thing a reader can verify independently is the C2PA metadata on files. There is no way to check the text watermark.
Anthropic also narrows what a detected mark means. A detected mark signals that the content may have passed through Claude. It is not proof of authorship. The article gives the reason: people routinely use Claude to proofread, translate, summarize, and convert files. Run a draft you wrote through Claude for a cleanup pass and the output carries a mark, but the substance is yours. The reverse holds too. Absence of a mark does not mean a human wrote it. Short passages, heavy rewrites, and older models without marking support all come back clean.
Does it survive one paraphrase?
How durable the mark is, Anthropic has not quantified. The algorithm is undisclosed. That leaves published measurements of comparable schemes as the only evidence available.
A paper posted to arXiv on July 17, AI Watermark Evidence Fails Forensic Readiness, ran those measurements. Saifur Rahman Tamim and Amir Labib Khan took three well-known text watermarking schemes, KGW, Unigram, and the MarkLLM implementation of SynthID-Text, and attacked them with meaning-preserving paraphrase. That is, asking another LLM to say the same thing in different words. Anyone can do it.
Across 846 valid runs, the results were these.
SynthID-Text removal rate
All three collapsed under a single paraphrase pass. Even before any attack, detection missed the mark on unmodified output at rates of 70% for KGW, 83% for Unigram, and 80% for SynthID, and SynthID flagged 5.4% of a human-written-then-paraphrased control group as AI-generated. The authors found all three schemes failed two of the five Daubert factors that govern scientific evidence in US courts, concluding that they do not meet the evidentiary bar courts require.
The paper did not test Claude. Anthropic's scheme may well be more robust. But until the company publishes evidence, measurements of comparable public schemes are the only reference point available.
Developer Theo reached the same conclusion right after the announcement. He pointed out that handing the text to a weaker LLM with no watermark of its own and asking for a paraphrase is enough to erase the mark, adding that you can ask Claude to remove the watermark from Claude's own output. The people the mark actually catches are the ones who paste output through untouched.
The public detector Anthropic promised may make this worse rather than better. The same tool that checks whether a mark is present checks equally well whether a mark has been removed. Paraphrase, test, repeat, and you can polish until it passes. Open detection for free and evasion gets easy; put it behind a gate and independent verification is blocked.
A vendor's watermark is not your disclosure
Anthropic's mark says Claude touched the text. Every disclosure regime that binds you asks a different question: did your product tell the user it was using generative AI. No watermark answers that on your behalf, and Anthropic's support article says so in its closing section: if you deploy Claude in your own product, you have to determine independently what Article 50 requires of that product.
What that duty looks like depends on where your users are, and the three regimes in force right now do not line up.
| Where your users are | What binds you | Penalty exposure |
|---|---|---|
| EU | AI Act Article 50: machine-readable marking of synthetic output, plus disclosure to people interacting with an AI system | Up to EUR 15 million or 3% of worldwide turnover |
| China | Measures for Labeling of AI-Generated Synthetic Content, in force since September 1, 2025: both a visible label a user can read and an implicit label in metadata, on text as well as media | Administrative enforcement against the service provider |
| Singapore and most of APAC | No general statutory labeling mandate. IMDA and AI Verify's Model AI Governance Framework for Generative AI recommends content provenance, and explicitly notes that watermarking and cryptographic provenance "are not fool-proof" | None directly, but PDPA and sector regulators still reach the deployment |
That table is the practical reason to treat Anthropic's watermark as an input, not a compliance artifact. In China's taxonomy it is at best the implicit half, and the visible half is still missing. In the EU it is Anthropic's marking of Anthropic's output, not your Article 50 transparency notice. In Singapore nothing forces the question, which is exactly why teams there tend to discover it late, when an enterprise customer's procurement checklist asks how generated content is disclosed.
Korea sits at the strict end and is worth reading as the preview case. Article 31 of the Framework Act on the Development of AI took effect on January 22, 2026, and requires advance notice that a service is built on generative AI, labeling of generated output, and clear disclosure for deepfake-grade audio, images, and video. Guidelines from the Ministry of Science and ICT split labels into explicit ones a person sees and implicit ones a machine reads, and require a separate notice at least once at download time when output leaves the service. Even there, the fine attaches to the missing advance notice, not the missing label: up to KRW 30 million under Article 43, with a stated grace period of at least a year. If you ship into the EU, read this alongside the EU AI Act GPAI penalties that started on August 2.
For anyone using Claude as a personal tool, almost nothing changes. The mark is already there, it cannot be turned off, and a detected mark does not change the fact that the substance of your writing is yours. The work lands on teams shipping Claude output through their own products. Pick one place where that output reaches a user's screen and check this week whether a notice saying it was generated with AI is actually visible there. If any of your traffic comes from the EU, China, or Korea, check the entry screen too, since all three want the disclosure before the output, not only on it. Anthropic's watermark does not stand in for it.