On 14 August 2026 Anthropic published how it will watermark future Claude text. The short version: new models will mark outputs; a mark is a likelihood, not a confession; you still have to say when you used the model. The long version is Article 50 of the EU AI Act, a July 2026 Code of Practice, and a detection API that is not shipping yet.
This post is for people who publish with Claude, ship a product on the Claude API, or have to write a disclosure line that will survive legal review. Sources: How Claude’s text watermark works (14 August 2026) and How Claude marks AI-generated content.
Two clocks
The EU rule for providers serving its market is already on. Anthropic’s implementation is staggered.
| When | What actually happens |
|---|---|
| 2 August 2026 | EU marking obligation for AI providers serving the EU market. Anthropic’s cutoff for “new models mark at launch.” |
| July 2026 | Anthropic and other major providers signed the EU Code of Practice on Transparency of AI-Generated Content (~190 signatories). |
| 14 August 2026 | Anthropic explained the method: SynthID-Text-style token-choice watermark; C2PA credentials on supported files. |
| Coming months | Detection API “soon.” Older models (launched before 2 August 2026) get marking during a transition period. |
If your stack is still Sonnet 4 / Opus 4.x, do not assume every paste is already watermarked. Anthropic is explicit that models launched on or after 2 August 2026 support marking at launch, and that pre-cutoff models are “in progress.” Independent testers in mid-August reported nulls on some current Claude names; treat that as “not yet,” not as “never.”
What the watermark is (and is not)
Claude still picks the next token from the same candidate list. On low-stakes choices (“overcast” vs “grey”), the source of the randomness is a key plus recent tokens instead of a plain RNG. Google DeepMind published the family as SynthID-Text in Nature in 2024. Anthropic says internal tests and DeepMind’s own thumbs-up study showed no practical quality hit, no extra tokens, no extra price, no hidden characters.
It does not:
- Identify a user, org, or chat
- Prove a human did not write the piece
- Prove a different model wrote it (other vendors have other keys, other methods)
- Survive a full rewrite
- Work well on short samples, dense facts, or “fix only the grammar” edits
- Sit heavily in code, where the next token is often forced
A translation Claude writes is fully watermarked, because Claude chose every word. A proofread of your draft may not register at all.
Files are a different channel. Supported images (PNG, JPG, SVG, and similar) get a C2PA signed content credential in metadata: Claude was involved. That is not woven into pixels. Strip metadata, screenshot, or re-save and it is gone. Anthropic will offer a drop-a-file checker; any C2PA-aware tool can read the label.
Marks apply worldwide on supported models, including API, Claude, Claude Code, Cowork, Tag, and cloud partners (AWS, Google Cloud, Microsoft Foundry). Provenance metadata may not exist on every platform.
What publishers should disclose
The watermark is the provider’s Article 50 marking duty. Your duty as a deployer or publisher is separate. Anthropic says: if you build on Claude, assess what Article 50 requires of your product. Do not wait for their detection API to write your user-facing sentence.
A workable 2026 policy for a blog, newsletter, or docs site:
- Say when Claude (or any model) drafted or substantially rewrote the piece. A machine-readable mark is not a substitute for a human-readable line. Readers and regulators will not run a detector on every URL.
- Do not claim “this is 100% human” just because a detector is quiet. Pre-cutoff models, short blurbs, heavy edits, and other vendors all produce silence.
- Do not claim “Claude wrote this” just because a detector fires. Anthropic’s own FAQ: a mark means Claude was likely involved — author, heavy editor, or translator. It is not a plagiarism verdict and not a quality score.
- Keep file provenance if you ship Claude-generated images. Prefer formats that retain C2PA. Do not treat a PNG screenshot as equivalent.
- If you are in the EU market or selling into it, write the disclosure into the CMS template, not into a one-off author bio. The Code of Practice is about systems, not hero posts.
For API products: the watermark is at the model, so it is in the text you receive. You still need your own UI disclosure if you present that text as your product’s output. You cannot “turn off” the token-choice mark on a supported model.
What not to do
Do not treat a forthcoming detection API as a cheating oracle for students or employees. Do not fire someone, reject a paper, or nuke a PR because a likelihood score moved. Do not strip C2PA and then claim the image is unmarked in a legal sense — the Act cares about the act of marking, not about whether you later flattened the file. Do not assume US-only traffic exempts you; Anthropic is applying marks globally because it cannot yet scope by region. Do not wait for “older models to catch up” before you write the disclosure sentence.
A simple map
| Signal | What it supports | What it does not support |
|---|---|---|
| Claude text watermark (supported model) | “Claude was likely involved in some of these tokens” | Authorship, cheating, other vendors, short text |
| C2PA on a Claude file | “This file was processed by Claude, and whether it was tampered with after signing” | A screenshot, a re-encoded JPEG, a PDF print |
| Your published disclosure line | What a reader and a regulator can actually use | Nothing, if you skip it and hope the watermark is enough |
| Third-party “AI detectors” (style tells) | A different, noisier guess | Anything you would bet a job on |
The EU rule is a provider marking rule plus deployer transparency. Anthropic is doing the first with SynthID-style text and C2PA files. You still own the sentence on the page. Write it now. Update it when the detection API actually exists.
This post is part of our operator notes on shipping AI. Follow the series at amtocbot.com.
