Claude’s text watermark is a hidden pattern in the words Claude picks, and someone holding Anthropic’s key can test for it to estimate how likely it is that Claude was involved. It exists because EU law now requires AI providers to mark the text they generate. You cannot see it, most people cannot check it yet, and it proves less than the word “watermark” suggests.
- It is a pattern in word choice, not a hidden character. Nothing is added to the text, and the watermark carries nothing about who you are.
- The newest Claude models carry it now. Anthropic says older models are being added under a legal transition period.
- You probably cannot check text yourself. Detection is a private preview for regulators, media, researchers and similar groups.
- Editing weakens it and rewriting removes it. Short passages, facts and code carry little of it.
- A result is a likelihood about Claude only. It cannot say a human wrote something, and a missing mark proves nothing.
What the watermark actually is
A language model writes one word at a time, and when several words would do equally well, a random number picks. The watermark changes where that randomness comes from: “Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick.” Over many such choices, that leaves a pattern.Anthropic, How Claude’s text watermark works, 14 Aug 2026, updated 1 Sep 2026, read at source 22 Sep 2026: “Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick.”
Anthropic says the result reads the same as unmarked text: “That pattern is undetectable to the reader, but is detectable to anyone who has a key that encodes it.” It also says “Nothing is added to the text and there are no hidden characters”, and that the mark “carries no identifying information and can’t be traced to a specific person, organization, or chat”.Anthropic, How Claude’s text watermark works, 14 Aug 2026, read at source 22 Sep 2026: “That pattern is undetectable to the reader, but is detectable to anyone who has a key that encodes it.”; “Nothing is added to the text and there are no hidden characters”; “Watermarking carries no identifying information and can’t be traced to a specific person, organization, or chat”.
The method is borrowed. Anthropic says “Claude’s text watermark is a version of the SynthID-Text approach published by Google DeepMind in a Nature paper in 2024.”Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “Claude’s text watermark is a version of the SynthID-Text approach published by Google DeepMind in a Nature paper in 2024.” The paper: Dathathri et al., Scalable watermarking for identifying large language model outputs, Nature, 23 October 2024, read at source 22 Sep 2026.
There is nothing to find by looking at the text or copying it into a plain-text editor. The mark only shows up statistically, and only to someone with the key.
Which Claude models carry it, and from when
Anthropic’s 14 August post spoke of the future: “Future Claude models will generate text that contains a watermark.” Its help centre now says that “Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch.”Anthropic, How Claude’s text watermark works, 14 Aug 2026, read at source 22 Sep 2026: “Future Claude models will generate text that contains a watermark.” Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch.”
On 23 September 2026 the help centre’s table ticked text watermarks for Claude Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5. Older models in the same table, including Fable 5, Sonnet 5, Haiku 4.5 and the Opus 4 releases, were ticked only for file credentials, not text. Anthropic says it “is adding watermarks to outputs from models released before August 2, 2026, with all covered by December 2, 2026.” This list changes; check the help centre rather than this snapshot.Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026, table “Which Claude models support watermarking” and: “Anthropic is adding watermarks to outputs from models released before August 2, 2026, with all covered by December 2, 2026.” Anthropic, Introducing Claude Opus 5.5, 22 Sep 2026, read at source 23 Sep 2026: “As with Fable 5.1, Opus 5.5 comes with our watermarking measures to comply with the EU AI Act”.
The help centre says marks apply “across Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, and wherever Claude is offered, worldwide.” On the worldwide scope, Anthropic says: “We’re applying watermarking globally at launch because we don’t yet have a durable way to scope it by region.”Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “Marks will apply to output from supported Claude models across Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, and wherever Claude is offered, worldwide.”. Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “We’re applying watermarking globally at launch because we don’t yet have a durable way to scope it by region.”
Text from the newest Claude models is marked wherever you are. Which older models are covered is changing month by month.
Can you check a piece of text yourself?
Almost certainly not, for now. Anthropic says “Watermark detection is currently in private preview, available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups).” It plans to widen access over time.Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “Watermark detection is currently in private preview, available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups).” Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “We are releasing a detection API in private preview.”
Anthropic does run a free public checker, but it is for files, not writing. Its own page says: “The tool does not check text. Claude marks text with a watermark in the writing itself.”Claude, Check if files were made with Claude, read at source 23 Sep 2026: “The tool does not check text. Claude marks text with a watermark in the writing itself.” Any website offering to find Claude’s watermark in pasted text is not using Anthropic’s key unless it says it has detection access.Reasoning, September 2026 — follows from Anthropic’s statement that the pattern is detectable only with the key, and that key-based detection is limited to a private preview.
A teacher, employer or reader cannot run this check today. Treat any tool that claims to read the watermark with suspicion until it names its access.
What survives editing, translation and proofreading
The help centre says it “will travel with the text when it’s copied and pasted elsewhere, and may persist through some editing.” On rewriting, Anthropic is direct: “Light editing probably won’t remove the watermark completely; a complete rewrite where every word is replaced will.”Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “it will travel with the text when it’s copied and pasted elsewhere, and may persist through some editing.” Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “Light editing probably won’t remove the watermark completely; a complete rewrite where every word is replaced will.”
Some text carries little of it to begin with:
- Short passages. “Detecting a watermark also doesn’t work well on small samples, where there are fewer word choices and thus less information to go on.”Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026.
- Facts and code. Anthropic says the watermark “is sparser on factual passages where there are fewer choices that can be made without decreasing the accuracy of the text”, and that code “has generally less watermarking than some other forms of text.”Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “Watermarking is sparser on factual passages where there are fewer choices that can be made without decreasing the accuracy of the text.” and code “has generally less watermarking than some other forms of text.”
- Proofreading. If Claude only corrects your grammar, nearly every word is still yours, and the corrections may be too few to register.Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “The watermark only applies to words Claude chooses.”
- Translation. “A translation produced by Claude carries a watermark, because in this case every word is chosen by Claude.” Claude text later translated or paraphrased elsewhere may lose it.Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026. Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “The text has been heavily edited, paraphrased, translated, or mixed into other writing;”.
The mark is strongest in long, freely written prose and weakest exactly where people often use Claude lightly: short answers, fixes, code and facts.
What a result can and cannot tell you
A positive check answers one narrow question. Anthropic says “A watermark can only determine that Claude was likely involved with the content at some point.” It “doesn’t confirm whether the text was human-written, and it can’t tell whether the text was written by a different AI”. It cannot separate text Claude wrote from text Claude heavily edited, and the help centre adds that marked output can come from ideas or text that “originated from another source”.Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “A watermark can only determine that Claude was likely involved with the content at some point.”; “It doesn’t confirm whether the text was human-written, and it can’t tell whether the text was written by a different AI”. Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “The output can carry a Claude mark even if the underlying ideas, text, or data originated from another source;”.
A negative check proves even less. In the help centre’s words, “Lack of a detected mark doesn’t mean the content wasn’t AI-generated or processed.” Nor does a mark settle ownership: Anthropic says it “doesn’t say anything about ownership or authorship”.Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “Lack of a detected mark doesn’t mean the content wasn’t AI-generated or processed.” Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “It doesn’t say anything about ownership or authorship, and doesn’t change a user’s rights under our terms.”
This differs from AI-detector scores, which guess from style and have been found unreliable and unfair to careful non-native writers; see how to spot AI writing and common AI misconceptions. A watermark check is better grounded, but the same rule holds: a probability about a tool is not a verdict about a person.Reasoning, September 2026 — applies the conclusions of this site’s pages on detectors to Anthropic’s own description of what a watermark result means.
A mark says Claude probably touched the text. No mark says nothing. Neither tells you whether a person did the thinking, or whether the text is right.
How this differs from Content Credentials on images
For supported files such as images, Claude instead attaches a Content Credential: a signed note in the file’s metadata, under the open C2PA standard. Anthropic says: “This metadata label is very different from a watermark. Nothing in the file changes—it is not embedded or hidden.” Unlike the text watermark, anyone can read it: “Any C2PA-aware tool can read it.”Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “This metadata label is very different from a watermark. Nothing in the file changes—it is not embedded or hidden.” Claude, Check if files were made with Claude, read at source 23 Sep 2026: “Any C2PA-aware tool can read it.”
But a credential can fall off; the help centre lists a file’s metadata being “stripped through format conversion, re-saving, screenshots, or other means”. How AI content gets labelled covers credentials and image watermarks in depth, and AI terms people get wrong explains why a credential records who signed, not whether something is true.Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “A file’s metadata was stripped through format conversion, re-saving, screenshots, or other means;”.
Files get a label anyone can read but anyone can strip. Text gets a pattern that is harder to strip but that only approved organisations can test for yet.
Why the EU requires it
Article 50(2) of the EU AI Act covers providers of AI systems “generating synthetic audio, image, video or text content”. Their outputs must be “marked in a machine-readable format and detectable as artificially generated or manipulated”. The same paragraph exempts systems that “perform an assistive function for standard editing”. The Commission says these obligations are “applicable from 2 August 2026”; systems already on the market before then have until 2 December 2026.Regulation (EU) 2024/1689, Article 50(2), read at source 22 Sep 2026 via artificialintelligenceact.eu: “generating synthetic audio, image, video or text content”; “are marked in a machine-readable format and detectable as artificially generated or manipulated”; “perform an assistive function for standard editing”. European Commission, Code of Practice on Transparency of AI-generated Content, read at source 22 Sep 2026: “These transparency obligations, applicable from 2 August 2026”. Article 111 as amended, read at source 22 Sep 2026 via artificialintelligenceact.eu: providers of such systems “that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.”
The Commission published a voluntary Code of Practice on marking and labelling on 10 June 2026. Signing is optional; the law is not: “Even though adherence to the code is voluntary, the transparency requirements under article 50 of the AI Act are legal obligations.” By the end of July about 190 organisations had signed, and the Commission named Anthropic, Google and OpenAI among the providers signing. Anthropic says it signed in July 2026. The wider dates are on the AI rules timeline.European Commission, Commission publishes Code of Practice on marking and labelling AI-generated content, read at source 22 Sep 2026: “Publication 10 June 2026”. Code of Practice on Transparency of AI-generated Content, read at source 22 Sep 2026: “Even though adherence to the code is voluntary, the transparency requirements under article 50 of the AI Act are legal obligations.” Strong backing for the Code of Practice on Transparency of AI-generated Content, 31 Jul 2026, read at source 22 Sep 2026: “By the end of July 2026, about 190 organisations across various sectors - including IT, telecom, education, and retail - have signed the code.” and “Examples for Section 1 include: Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, Open AI, Synthesia.” Anthropic, How Claude’s text watermark works, read at source 22 Sep 2026: “signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026”.
Text is inside the EU marking rule, not outside it. Because Anthropic cannot yet limit the watermark by region, users everywhere get it.
What other AI companies say about text
Google. Its SynthID page says “We’ve expanded SynthID to watermarking and identifying text generated by the Gemini app and web experience.” The page describes checking images, video and audio in Gemini, not text.Google DeepMind, SynthID, read at source 22 Sep 2026: “We’ve expanded SynthID to watermarking and identifying text generated by the Gemini app and web experience.” and “Simply upload the image, video or audio clip to your chat, and ask if it’s been created or altered by Google AI.”
OpenAI. Its help centre lists provenance signals for images and audio; for text, its “goal is to expand provenance signals to all modalities including text”, citing its Code of Practice commitments. It does not say text is marked yet.OpenAI Help Center, Provenance signals (Content Credentials, SynthID) in OpenAI-generated content, read at source 22 Sep 2026: “our goal is to expand provenance signals to all modalities including text”.
Each company has its own key, if it has one at all. A check for one company’s mark says nothing about text from any other tool.
What this page could not verify
- How well the watermark holds up. This page found no detection accuracy or false-positive figures from Anthropic for Claude’s version, and did not test it.
- How the detection API behaves. It is a private preview; this site has no access, and the eligibility process was not tried.
- How Anthropic treats proofreading under the law’s editing exemption. Anthropic describes proofreading as leaving little to mark; it does not say it switches marking off.
- Which older models are covered on any given day. The help centre table was read on 23 Sep 2026 and is changing.
Anthropic, How Claude’s text watermark works (14 Aug 2026, updated 1 Sep 2026) · Claude Help Center, How Claude marks AI-generated content · Claude, Check if files were made with Claude · Anthropic, Introducing Claude Opus 5.5 (2026) · Dathathri et al., Scalable watermarking for identifying large language model outputs, Nature (2024) · Regulation (EU) 2024/1689, Article 50 and Article 111, via artificialintelligenceact.eu · European Commission, Commission publishes Code of Practice on marking and labelling AI-generated content (2026) · Code of Practice on Transparency of AI-generated Content · Strong backing for the Code of Practice on Transparency of AI-generated Content (2026) · Google DeepMind, SynthID · OpenAI Help Center, Provenance signals in OpenAI-generated content. Read at source 22 Sep 2026, except the Claude Help Center, the file checker and the Opus 5.5 announcement, read 23 Sep 2026.