Skip to content

What Claude's AI Watermark Means: Article 50, Machine-Readable Marks, and Their Limits

How to interpret the result

Result or workflowPractical treatment
A Claude mark is detectedUse it as a signal that Claude may have processed the content
No mark is detectedDo not treat it as proof of human authorship
A C2PA-signed file is publishedVerify that the signature survives the delivery path
AI assists a public-interest articleRecord substantive human review and editorial responsibility

Text may carry a machine-readable Claude mark even when Claude was used only for proofreading, translation, or summarization. Treating that result as proof of AI authorship would misclassify material that began with a human author. A Claude mark is a signal that Claude may have processed content, not proof of who authored it.1

What Claude text watermarks and C2PA provenance metadata can establish

Claude uses different marking methods for text and files

Anthropic describes two complementary methods for supported models.1 An invisible text watermark is woven into generated text, while signed provenance metadata is attached to supported generated files. Text watermarks and C2PA provenance metadata live in different places and fail in different ways.

The text watermark is part of the generated text

Anthropic says the invisible watermark does not change the meaning, quality, or readability of a response. Because it is part of the text, it travels when the text is copied and pasted and may persist through some editing.1 This is not a description of removable hidden characters such as zero-width Unicode marks.

Marking is applied at the model layer. Covered surfaces include Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag. Text watermarks also apply when supported models are accessed through AWS, Google Cloud, or Microsoft Foundry, although a platform or feature may not support every marking type.1

C2PA metadata attaches signed provenance to a file

When Claude generates a supported format such as .svg, .png, or .jpg, it attaches signed provenance metadata based on the C2PA standard.1 A valid signed label signals that Claude processed the file and can be used to detect tampering after the label was applied.

Because this information is attached to the file, format conversion, re-saving, screenshots, or other processing can strip it. C2PA implementation guidance likewise assumes that legacy or non-C2PA systems may remove or corrupt a manifest.5 A publisher using a CMS or image-optimization pipeline should inspect both the source asset and the delivered asset.

The rollout follows the start of Article 50 obligations

Article 50(2) of the EU AI Act requires providers of systems that generate synthetic audio, image, video, or text to mark outputs in a machine-readable format and make them detectable as artificially generated or manipulated.2 Those transparency obligations began to apply on August 2, 2026.

Anthropic says Claude models launched on or after that date support marking at launch and that marks from supported models apply worldwide wherever Claude is offered.1 Systems placed on the market before August 2 have a limited transition period for Article 50(2), ending on December 2, 2026.3

The maximum administrative fine for an Article 50 violation is EUR 15 million or, for an undertaking, 3% of total worldwide annual turnover in the preceding financial year, whichever is higher. For small and medium-sized enterprises, the lower of the amount and percentage caps applies.2

Anthropic signed Section 1 of the voluntary Code of Practice on Transparency of AI-generated Content. The European Commission and AI Board assessed the code as an adequate compliance tool, and about 190 organizations had signed by the end of July 2026.4

A mark proves neither authorship nor the absence of AI

Detection does not establish that Claude was the original author. A human-authored draft may carry a mark after Claude proofreads, translates, summarizes, or converts it. The marked output may also be excerpted, modified, or combined with other material later.1

Non-detection does not establish that content was not AI-generated. Anthropic lists older models, heavy editing or paraphrasing, translation, very short passages, stripped file metadata, and unsupported platforms, features, or formats as reasons a mark may not be detected.1 False-positive and false-negative rates, minimum useful passage lengths, and concrete third-party detection mechanisms have not yet been published; Anthropic says further technical documentation is forthcoming.

An employer, school, editor, or investigator therefore cannot use detection alone as a sound basis for sanctions. It should remain an investigative signal combined with draft history, source records, change history, and documented human review.

SynthID illustrates the mechanism without revealing Claude's design

Anthropic has not published Claude's watermarking method, so another vendor's system cannot predict Claude's detection accuracy. Google DeepMind's public SynthID-Text work is nevertheless a useful example of how a statistical signal can be added during generation.

SynthID-Text derives pseudorandom seeds from recent tokens and a key, then uses tournament sampling to select among candidate tokens. Detection recomputes scores with the same key and tests whether the text carries the expected statistical bias.6 Google DeepMind published the Nature paper and a reference implementation in 2024.7

Longer text provides more statistical evidence. Low-entropy output, where the model has little freedom in the next token, provides less room to carry a watermark. The paper also identifies weakening through edits and LLM paraphrasing, plus stealing, spoofing, and scrubbing attacks, as limitations and open research problems.6

When Google signed the EU transparency code in 2026, it said it was working with Apple, ElevenLabs, Kakao, NVIDIA, and OpenAI on interoperable watermarking tools using SynthID.8 That does not mean Claude uses SynthID. It shows why Article 50 implementation spans providers and distribution systems rather than ending with one detector.

Editorial operations should design review responsibility first

For publication workflows, substantive human review and editorial responsibility matter more than a detector result. European Commission guidance requires disclosure for AI-generated or manipulated text that informs the public on matters of public interest, but explains an exception when knowledgeable natural persons deliberately examine the substance and a person holds editorial responsibility.3 Superficial checks limited to spelling or grammar do not qualify as human review.

An editorial team should record who checked the facts, which sources they read, what they changed, and who approved publication. Separating the fact that Claude assisted with editing or translation from the person or organization responsible for the final claims creates an audit path that does not depend on whether a mark remains detectable.

For files, retain the C2PA-signed original and test whether the published derivative preserves the signature. If the delivery path removes it, visible disclosure in the body or caption is more dependable for readers.

Products built with Claude need their own assessment

A model provider's marking implementation does not automatically satisfy every obligation of a product built with Claude. Anthropic instructs developers to assess independently what Article 50 requires of their own products and services.1

The product assessment should cover the model and its marking status, transformations applied to outputs, available detection mechanisms, notices shown to users, and the owner of human review. Where a path cannot preserve a machine-readable mark, visible labels and audit logs may need to provide another layer.

Start the operating rule with three checks

  1. The editorial owner does not use mark detection as the sole test of authorship or basis for sanctions.
  2. The reviewer records draft history, primary sources, substantive checks, and the person approving publication.
  3. The delivery owner tests whether C2PA survives the published transformation and adds visible disclosure when it does not.

Sources


  1. Anthropic, How Claude marks AI-generated content, updated August 10, 2026. Used for model and product coverage, text watermarks, C2PA provenance, detection limits, and guidance for products built with Claude. 

  2. European Union, Regulation (EU) 2024/1689, July 12, 2024. Used for Articles 50(2), 50(4), 99(4), and 99(6), including obligations, exceptions, and fine caps. 

  3. European Commission, Transparency obligations under Article 50 of the AI Act, accessed August 11, 2026. Used for scope, the December 2 transition date, and the standards for human review and editorial responsibility. 

  4. European Commission, Code of Practice on Transparency of AI-generated Content, updated July 31, 2026. Used for the code's role, adequacy assessment, signatory count, and the scope of Sections 1 and 2. 

  5. C2PA, C2PA Implementation Guidance, accessed August 11, 2026. Used for the assumption that legacy or non-C2PA systems may remove or corrupt manifests. 

  6. Dathathri et al., Scalable watermarking for identifying large language model outputs, Nature 634, 2024. Used for tournament sampling, detection scoring, text length and entropy, and limitations involving edits and attacks. 

  7. Google DeepMind, synthid-text, accessed August 11, 2026. Used for the public reference implementation corresponding to the Nature paper. 

  8. Google, Google is signing the EU AI Act Code of Practice on Transparency of AI-Generated Content, July 24, 2026. Used for Google's signature and its stated SynthID interoperability partners.