Anthropic plans to embed invisible watermarks into text generated by supported Claude models and attach digital provenance tags to supported files worldwide under the EU AI Act’s new transparency rules.
The San Francisco-based AI company will apply the machine-readable marks to output from supported Claude models worldwide, not just within European borders. "Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch," the company stated in a support article. Anthropic is working to add marking support to older models during a transition period.
The markings will cover output from supported models across the entire Claude ecosystem, including the consumer app, developer API, Claude Code, Claude Cowork, and Claude Tag. Text generated by supported models through cloud partners such as AWS, Google Cloud, and Microsoft Foundry will also carry embedded watermarks, although signed file metadata may not be supported on every platform.
How Claude’s two-layer marking system works
Anthropic plans to use complementary techniques for different content types. For text, supported Claude models will weave an “imperceptible watermark” directly into responses without altering their meaning or readability. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing," the company explained.
For supported files, including SVG, PNG, and JPG images, Claude will attach signed provenance metadata using the C2PA open standard. The metadata signals that a file was processed by Claude and, according to Anthropic, can indicate whether the file has been tampered with.
The unintended consequences
A detected Claude watermark doesn't prove Claude wrote the original content. The company acknowledges that users frequently employ Claude to proofread, translate, or summarize human-written material. That means an editor's final draft could carry a Claude mark even if every idea originated with a human writer.
Conversely, genuine Claude output can slip through undetected. Heavy editing, translation, very short passages, or use of older models without marking support all result in invisible watermarks.
This creates a peculiar situation for publishers and content creators. A writer who runs their draft through Claude for a polish ends up with marked text they may need to disclose — or risk running afoul of transparency expectations. The EU's Code of Practice includes exemptions for standard editing that doesn't substantially alter meaning, but the line between "polish" and "substantial change" remains blurry.
Detection and limits
Anthropic says it will release detection tools and technical documentation soon, enabling users and third parties to check for marks. But the company is careful to manage expectations: a detected mark is a signal, not conclusive proof.
The system has known vulnerabilities. C2PA metadata can be stripped through format conversion, re-saving, screenshots, or social platform uploads. Text watermarks may not survive heavy paraphrasing. Alex Cui, CTO of GPTZero, noted that free tools have bypassed Google DeepMind's SynthID, and intense rewriting can defeat watermarks entirely.
Read more: Learn how the EU’s AI transparency rules affect company disclosures for AI-generated content.


