Skip to content

Claude is watermarking everything. The real signal is disclosure, not detection

Anthropic is now marking Claude's text and images with hidden provenance signals. The backlash misses the point: provenance is arriving in regulated work, and the organisations that get ahead of disclosure will be the ones still trusted.

Anthropic has started weaving an invisible mark into everything Claude writes, and a signed credential into every image it makes. The loudest response has been from people worried they will be caught. That is the wrong thing to watch. For any organisation doing regulated work, the signal is that provenance is now built into the tools your teams already use, and the question is no longer whether AI involvement can be seen, but whether you can say what your people generated before someone else tells you.

What you need to know

  • The mark is now in the tool. From 2 August 2026, new Claude models embed a hidden statistical watermark in generated text and a C2PA signed credential in generated images. It travels with copy and paste and survives light editing.
  • It proves processing, not authorship. A positive result means text "may have been processed by Claude", including for proofreading, translation or summarising. It does not prove who wrote what, and short passages fall below detection entirely.
  • It is global and driven by regulation. Anthropic applied the watermark worldwide with no opt-out region, after signing the EU AI Act's transparency code of practice under Article 50.
  • The backlash is loud but narrow. A vocal minority of users objected on Reddit; most did not. Treating detection as the threat is the wrong frame for an enterprise.
  • Get ahead of disclosure, not detection. Know what your teams generate with AI, and be able to say so on demand. That is a governance job you can start this quarter.

2 Aug 2026

Date the EU AI Act's Article 50 transparency duties became enforceable for newly launched AI systems

Source: EU AI Act / Anthropic

Worldwide

Claude applies the watermark everywhere, with no opt-out region, though the driver is European regulation

Source: Anthropic

What Anthropic actually shipped

Anthropic is now embedding two separate provenance signals into Claude's output. For text, it nudges the model's choice between statistically near-equivalent words according to a secret key, leaving a signature that a detector holding the key can read across a longer passage. The approach is the SynthID-Text method published by Google DeepMind, and because the word choices really are near-equivalent, Anthropic says quality does not suffer. The mark travels when text is copied and pasted, and can persist through some editing; a complete rewrite where every word is replaced removes it. For images, it attaches a C2PA content credential, a small cryptographically signed note in the file's metadata, the same standard camera makers and photo editors use.

Two limits matter for anyone planning around this. The text signal is weak and positive-only: it tells you content may have been processed by Claude, not that Claude authored it, and not by whom. And the image credential is trivially stripped by a format conversion or a re-upload. This is a transparency measure, not a forensic one.

Why this is a regulatory event, not a product update

The reason to treat this as more than a feature is where it came from. Anthropic signed the EU's Code of Practice on Transparency of AI-Generated Content, which sits under Article 50 of the EU AI Act. Article 50's transparency obligations became enforceable for newly launched systems on 2 August 2026, and they require providers of generative AI to mark synthetic output in a machine-readable way so downstream users, platforms and regulators can identify it. Anthropic chose to apply the mark globally rather than fence it to the EU.

That pattern is the one to plan for. When a frontier lab builds a regulator's disclosure requirement into its default output for every customer on the planet, the requirement has effectively arrived here too, whatever our own legislation says. Provenance and AI-disclosure are becoming a property of the tools, not a box on a European compliance form. For work that is already regulated in Aotearoa, in health, in insurance, in the public sector, that shift lands whether or not anyone in the building was watching for it.

The backlash is watching the wrong thing

The public reaction has fixated on being caught. On Reddit, some users called the watermark "unethical" and argued it unfairly exposes the casual case, the student who reorganised a paragraph or the journalist who summarised a long transcript, while a determined evader can still rewrite around it. Most users disagreed, and one line cuts through the noise: the main reason to fear a truthful mark is an intention to mislead about it.

For an enterprise, framing detection as the threat is a category error. If your concern is that a regulator, a client or an auditor could learn your team used AI, the problem is not the watermark. It is that you do not yet have an answer ready. The organisations that will be trusted are not the ones whose AI use is invisible. They are the ones that can say, clearly and on demand, what was generated, where, and with what human judgement over it.

What this means for you

Disclosure is a governance capability, and you can build it before it is demanded. Three moves:

  1. Know what your teams generate. You cannot disclose what you cannot see. Map where AI is already producing work that leaves the building: proposals, reports, client communications, code, board papers. Most organisations underestimate this by a wide margin, and an honest map is the whole foundation.
  2. Write your disclosure position down. Decide what you will tell clients, regulators and staff about AI in your work, and record it where the decision can be found and cited, not in one manager's head. This belongs in your AI governance framework and, for the material risks, on your risk register.
  3. Treat provenance as a design requirement. Provenance, who made a thing and with what, is exactly the question te ao Māori has always asked of knowledge through whakapapa. It is a discipline worth building into how you handle data and outputs, not a compliance afterthought bolted on when Brussels asks.

The watermark is a small technical change with a large signal inside it. The era where AI involvement was quietly unprovable is ending, and it is ending in the tools, not the statute book. The organisations that treat that as a reason to hide will spend the next two years anxious. The ones that treat it as a reason to get their provenance in order will simply be trusted.