Claude's AI Watermark Marks Contact, Not Authorship
Anthropic now marks the text Claude writes. How the mark gets in, why it breaks so easily, and why "processed" is the word that settles it for agencies.

Anthropic updated a support page last week, and within a day my feed had it settled. Claude marks everything it writes now. Writing with it is over. Search will punish you. Clients will start asking.
I get why that landed. A hidden mark in your own words sounds like a tripwire.
So I read the page. The mark records that a text passed through Claude, not that Claude wrote it, and Anthropic says so in its own words. That one distinction takes most of the panic apart, and it only lands once you know how the mark gets in. So let's do that first.
What Anthropic actually shipped
Since 2 August 2026, Claude marks its output in two different ways, and only one of them is a watermark in the sense people mean.
Text gets an embedded watermark, woven into the words themselves. In Anthropic's wording: "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing" (Anthropic, How Claude marks AI-generated content). Files are a separate mechanism: for .png, .jpg and .svg, Claude attaches signed provenance metadata using the C2PA standard, which is a record bolted to the file rather than something hidden in the pixels.
The coverage is wider than most of the coverage suggested. It runs across the Claude apps, the API, Claude Code, Claude Cowork and Claude Tag, including Claude accessed through AWS, Google Cloud and Microsoft Foundry, and it applies worldwide rather than only in the EU (TechCrunch, 11 August 2026).
Note the API line, because that is the one agencies skip. If your content pipeline calls Claude through the API, it is in scope. There is no quiet back door where the production system stays unmarked.
Models launched on or after 2 August 2026 carry marking from launch. Older models are being fitted during a transition period, which matters more than it sounds and I will come back to it.
How the mark gets into words
A text watermark is not a hidden message. It is a small, deliberate bias in word choice that only shows up when you count.
Anthropic has not published how its own version works, and I want to be exact about that: everything in this section is the public research the approach sits on, not a description of Claude's scheme. The research is simpler than you would guess.
A model writes one word at a time. Before each word it scores every option it has, then picks one.
The watermark adds a step. Right before each pick, a secret key splits the vocabulary in half: call one half green and the other red. Green words get a small bonus. Red words are still allowed, just a bit less likely. The model writes what it was going to write anyway, with a thumb on the scale. That is the original scheme from Kirchenbauer et al., ICML 2023.
Google DeepMind's SynthID-Text, published in Nature in October 2024, runs a more careful version of the same idea: candidate words go through a small tournament seeded by the key, and the winner is the word you read.
Do that a few hundred times and something countable shows up. The text itself gives nothing away. The count does. About half the words should land green by luck, and in marked text far more of them do.
Why you cannot spot a watermark by reading
Two details are worth holding on to. Detection needs the text, the key and the rule that seeds it, and it does not need the model. And the bias is genuinely too small to feel: in a live test across roughly 20 million Gemini responses, the difference in thumbs-up rate between watermarked and unwatermarked answers was 0.01 percent.
So nobody is going to spot this by reading. Only the key holder can read it, and Anthropic holds the key.
Why the watermark breaks so easily
The mark needs room to hide in. Where the model had no real choice, there is nothing to bias.
Names, dates, figures, quoted passages, code: in all of them the next word is close to forced, so almost no signal goes in. A page of product specifications carries far less mark than a page of argument, and neither of them is a decision the writer made.
How short is too short to detect
Length is the harder limit. The Nature figures give you the shape of it: at 200 tokens, detection ran at roughly 50 percent with a 1 percent false-positive rate, rising to roughly 95 percent at 400 tokens. Those numbers are one model at one setting and not Claude's scheme, so take them as orientation rather than as a spec. As orientation they are blunt enough. Two hundred tokens is around 150 words. A headline, a subject line, an ad hook, a meta description: there is nothing in there to read.
Anthropic lists the rest itself. A mark may not be detectable if the model predates marking, if the text was "heavily edited, paraphrased, translated, or mixed into other writing", if the passage is too short, if file metadata was stripped "through format conversion, re-saving, screenshots, or similar processes", or if the platform or file type does not support that method.
Read that list as an agency and the image half falls apart in your hands. Format conversion, re-saving and screenshots covers roughly everything that happens to a visual between the designer and the client's Instagram. C2PA metadata is the fragile half by a distance, and it is fragile by design: it is a signed record travelling next to the file, not something embedded in the image.
None of that makes the mark useless to Anthropic. At their volume, something that survives often enough is plenty. It makes it useless as a verdict on one specific piece of text, which is the thing you were actually worried about.
"Processed" is the word that decides it
Here is Anthropic's own sentence, and it is the whole argument:
"Detecting a Claude mark tells you that the content may have been processed by Claude."
Processed. That covers a great deal more ground than written.
Ask Claude to proofread a paragraph you wrote, and that paragraph now carries the same mark as one Claude produced from scratch. Translate a client's text, same mark. Tighten a headline somebody agonised over, same mark. Anthropic makes the point plainly on the same page: Claude may not be the original author, because the text may have come from somewhere else and been passed through.
So the mark records contact. That is all it records.
Which makes it useless as a quality signal, and it gets more useless as it spreads, which it will. Eighty-two organisations signed the providers' section of the EU's transparency code, Anthropic, Google, Meta, Microsoft, Mistral, OpenAI, Cohere and Synthesia among them (European Commission, 31 July 2026). A label that ends up on nearly everything tells you nothing about anything.
Does the watermark hurt your SEO?
There is no evidence that it does, and right now there is no public detector for Claude's text mark, so no search engine can read it either.
Anthropic says it will publish technical documentation on how third parties can detect its marks. As of 12 August 2026 that documentation is not out, and without the key the mark is unreadable by anyone outside Anthropic.
Even if that changes, acting on it would be a strange turn for Google, because its published position has never been about how a page was made. From the spam policies: "Scaled content abuse is when many pages are generated for the primary purpose of manipulating search rankings and not helping users. This abusive practice is typically focused on creating large amounts of unoriginal content that provides little to no value to users, no matter how it's created" (Google Search Central).
No matter how it's created. The test is purpose and value, and it has been for years.
The one place Google does raise AI disclosure is in its own self-assessment questions, and it asks the opposite of what everyone fears: "Is the use of automation, including AI-generation, self-evident to visitors through disclosures or in other ways?" (Google Search Central). Saying so sits on the list of things that help you. Hiding it does not appear anywhere on it.
What the EU AI Act actually asks of you
The model providers carry the duty to mark AI output machine-readably. You do not. I am not your lawyer and this is the short version, so get real advice for your own case.
That duty is Article 50(2) of the EU AI Act, which started applying on 2 August 2026, and it is the reason Anthropic shipped any of this. What reaches an agency is Article 50(4), and it is narrower than the panic suggests. You disclose deepfakes, meaning synthetic image, audio or video resembling real people, places or events. And you disclose AI-generated text published to inform the public on matters of public interest, unless a person reviewed it and holds editorial responsibility for it (EU AI Act, Article 50).
A client landing page is not a matter of public interest. Neither is a blog post about pricing. The case I would actually watch is a generated image of a client's CEO at an event that never happened, which counts as a deepfake even when it is flattering and harmless.
If you want a visual label, the European Commission published official icons for exactly this in June 2026, alongside the code of practice. And the fines, up to 15 million euros or 3 percent of global turnover, are not aimed at your agency. They are aimed at the providers. But they are why your enterprise clients will start asking you what you use.
Everyone is already writing with AI
Now the part I actually care about.
Everyone makes content with AI. You know it and your clients know it, and the people scared of being found out are guarding a secret that stopped being one a long time ago.
We still treat it like a confession, and it shows up in odd ways. People run finished text through a second tool to strip the tells. People rough up good sentences so they look less polished. That is a lot of work to hide something nobody is shocked by.
There is a practical cost to it as well, and that is the one that should bother you. When people on your team hide how the work got made, you cannot see the process. And you cannot improve or standardise something you cannot see. Every account ends up with its own private way of working, invisible to everyone else, and the good version never spreads because nobody will admit it exists. So the shame costs you more than a bit of awkwardness.
The assumption underneath the shame
I think it comes from one bad assumption. We decided that writing is supposed to be personal.
For some writing, it is. A real opinion piece needs a position and a week of living with it, and a model cannot do that. It has no stake in anything, and it shows.
But most content is not an opinion piece. A help page is not. A product page is not. A release note is not, and a comparison table has never been personal in its life.
And for that kind of writing, a model is often better than we are. It explains a complicated thing more patiently than most people manage, and it does not get bored on the fourth paragraph.
AI-made does not mean worse. That is the sentence this whole argument keeps people from saying out loud.
Where I'm early, or just wrong
I have been saying that most published text has already been through a model once, so the label was dead on arrival. The direction is right. This month it is not true yet.
Only Claude models from 2 August carry the mark, and older ones are still being fitted. OpenAI does not watermark text at scale: it marks images, using C2PA and SynthID since May 2026, and its text watermarking has never shipped in the public product. Google marks Gemini text with SynthID, and its detector is not open to everyone either.
So today the mark covers Claude and Gemini. The rest of the internet still writes unmarked. My argument is about where this ends up, and it is fair to hold me to the gap. Give it a year.
What I'd worry about instead of the watermark
If you would rather nobody knew a model touched the work, it is worth asking what is actually bothering you. Usually the worry is that the piece would not survive a proper look, by you or by the client.
That is a real problem. No watermark caused it.
So here is the question the mark can never answer, and the one worth your time. Does the text sound like the brand it belongs to, and does it know what it is allowed to claim?
Give a model the current version of a client's positioning, offers and limits, and it writes something you can send. Take those away and it still comes back confident and easy to read, just wrong in the places nobody checks on a first pass. Last quarter's price. An offer that was retired in March. A claim legal struck out and somebody's saved prompt never heard about.
That is the failure that costs you the account, and it has a boring fix. One approved version of that brand context, in one place, that every person and every AI environment working on the account draws from, with somebody whose actual job it is to keep it current. Not a folder. Not a prompt somebody is proud of. One current source, and a name against it.
No watermark will tell you which of the two you are holding. Somebody has to own that.
Frequently asked questions
Does Claude watermark all text it generates?
Not all of it. Claude models launched on or after 2 August 2026 include marking from launch, and older models are being updated during a transition period. Where it applies, it covers the Claude apps, the API, Claude Code, Claude Cowork and Claude Tag, including Claude accessed through AWS, Google Cloud and Microsoft Foundry, and it applies worldwide rather than only in the EU.
Can anyone detect Claude's watermark?
Not publicly, as of 12 August 2026. Detection requires the secret key that biased the word choice in the first place, and Anthropic holds it. Anthropic has said it will publish technical documentation on how third parties can detect its marks, but no public detector exists yet, which means no platform or search engine can currently read the mark either.
Does an AI watermark hurt your SEO?
There is no evidence that it does. No public detector exists, so search engines cannot read the mark. Google's spam policies judge content by purpose and value rather than production method: scaled content abuse is defined as many pages generated primarily to manipulate rankings and provide little value to users, "no matter how it's created". Google's own self-assessment questions actually ask whether AI use is disclosed to visitors.
Does editing remove an AI watermark?
It can. Anthropic lists heavy editing, paraphrasing, translation and mixing into other writing as reasons a mark may no longer be detectable. Short passages carry too little signal to detect at all, and low-choice text such as names, dates, figures and quotations carries almost no signal even at length. For image files, C2PA metadata is removed by format conversion, re-saving or screenshots.
Does a detected watermark mean Claude wrote the text?
No. Anthropic's own wording is that a detected mark tells you the content "may have been processed by Claude". Asking Claude to proofread or translate something you wrote leaves the same mark as text Claude produced from scratch, so the mark records contact with the model, not authorship. That is precisely why it cannot work as a quality signal.
Do marketing agencies have to label AI-generated content in the EU?
Only in narrow cases. Under Article 50(4) of the EU AI Act, which applies from 2 August 2026, deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, and the text obligation falls away where a person reviewed the content and holds editorial responsibility for it. Ordinary marketing material such as landing pages and product blog posts generally sits outside this. The machine-readable marking duty under Article 50(2) sits with the model providers. This is background, not legal advice.
Sources
- Anthropic: How Claude marks AI-generated content (2026)
- TechCrunch: Anthropic says it will watermark text generated by its AI models (11 August 2026)
- Kirchenbauer et al., A Watermark for Large Language Models, ICML (2023)
- Dathathri et al., Scalable watermarking for identifying large language model outputs, Nature 634 (2024)
- EU Artificial Intelligence Act, Article 50: Transparency Obligations
- European Commission: Strong backing for the Code of Practice on Transparency of AI-generated Content (31 July 2026)
- European Commission: EU icons for labelling AI-generated content (2026)
- Google Search Central: Spam policies for Google web search
- Google Search Central: Creating helpful, reliable, people-first content
- C2PA: Coalition for Content Provenance and Authenticity
Christoph Sauerborn is the founder of Brixon AI. He installs the shared AI infrastructure that agency teams work from. RWTH Aachen and Bosch Industry 4.0 background. More about how I work.