What happened?
Anthropic announced that it has begun applying an embedded watermark to text generated by Claude models, and shared technical details on how it works. According to the company, the watermark is created by selecting from among frequently used, high-probability tokens according to a specific pattern. Anthropic argues this method has no practical effect on the text's appearance or quality.
According to the company's statement, the watermark is designed to indicate the likelihood that a piece of text was produced by Claude; it does not offer definitive proof. Because word choice is more constrained in code and factual text, watermark traces are found less frequently there. When text is completely rewritten, the watermark disappears.
Why does it matter?
Anthropic also announced a watermark detection API that will allow third parties to identify text generated by Claude. This step is seen as a response to growing demand for detecting AI-generated text in academic and professional settings.
The announcement drew mixed reactions from users and developers. Some users argued that the watermark would also be applied to tasks like translation, which could create problems for users such as university students. Some tech writers noted that the watermark cannot be removed and will be applied to existing models starting in December. These debates stem from uncertainty over whether watermarking indicates ownership of text or merely its possible source.
What we know
- The watermark is embedded in the token selection process and works invisibly, even if sparsely.
- Watermark traces are found less often in code and factual text.
- The watermark disappears when text is completely rewritten.
- Anthropic announced a detection API for third parties.
- The watermark is planned to be applied to all future Claude models, and to existing models starting in December 2026.
What's next?
Anthropic plans to make the watermark detection API available to third parties, though it has not shared a firm date. This announcement comes at a time when Anthropic is preparing for a public offering and investors are evaluating the company's revenue projections. How watermarking technology will affect debates around AI content detection will become clearer in the coming period.
The method: not probabilities but the source of randomness
How the watermark is built differs slightly from the first version of this story. Anthropic's approach rests on Google DeepMind's SynthID-Text method, and it does not alter token probabilities; what it alters is the source of randomness used when a choice is made. As the model picks a word it meets several plausible options with no difference in meaning between them. Because these low-stakes choices repeat many times across a text, making all of them according to a pattern derived from one secret key leaves a statistical signature behind.
The result is invisible to a reader and measurable to whoever holds the key. Anthropic says the signature does not change the meaning, quality or readability of the text. Because the mark sits inside the text itself, it travels through copy and paste and can survive some editing.
A different method for files
Generated PNG, JPG and SVG files carry no embedded watermark. They instead receive cryptographically signed C2PA provenance metadata stating that the file was created or processed with Claude. The difference matters: the credential lives in the file's metadata rather than its content, so taking a screenshot or passing it through another tool can strip it. The text watermark, embedded in the content itself, is more durable.
Why now
Behind the move is the transparency obligation in the EU AI Act, which applies to new models offered in Europe from August 2. Anthropic turned the system on not only in Europe but everywhere Claude is available. The regulation's geographic scope is narrow; its implementation became global — an example of a rule in one jurisdiction shaping an entire product.