Skip to main content

Claude's invisible text watermarks are live: what EU AI Act compliance means for your pipeline

Ilustrační obrázek
An invisible, machine-readable fingerprint now travels with every new text Claude generates — in the chat window, through the API, and inside Claude Code. It survives copy-paste and light editing, adds no per-token cost, and it is Anthropic's concrete answer to the EU AI Act's Article 50 transparency rules, which became enforceable on 2 August 2026.

Claude text now ships with a watermark you can't see

Anthropic has rolled out embedded watermarking across every Claude surface: the web app, the API, Claude Code, Claude Cowork, Claude Tag, and the managed offerings on AWS, Google Cloud and Microsoft Foundry. The mark is machine-readable rather than visible, so automated systems can determine that text was produced — or merely processed — by Claude.

That last distinction matters. The watermark indicates that text was processed by Claude, which includes editing, translation and proofreading, not only generation. A human-written article polished by Claude carries the mark just like a fully AI-generated one. For European publishers, agencies and regulators, this is a meaningful nuance: the marker is about machine-readable transparency, not about replacing an author's byline.

Alongside the text watermark, Anthropic attaches C2PA provenance metadata to generated .jpg, .png and .svg files. C2PA is the open cryptographic standard already used by cameras and editing software, so AI-generated images slot into an existing provenance ecosystem rather than a proprietary one.

Why now: Article 50 starts being enforced

The catalyst is the EU AI Act. Article 50 lays down transparency obligations for AI-generated content, and on 2 August 2026 the EU AI Office formally gained investigative and sanctioning powers over general-purpose AI providers. Anthropic signed the Article 50(2) Code of Practice — one of roughly 190 organizations that committed to the voluntary transparency code — and then went further: every Claude model launched on or after 2 August carries built-in watermarking from day one. Older models are being migrated, and Anthropic has committed to releasing detection tools so third parties can verify whether text carries the Claude mark.

The practical detail that matters for real workflows: the watermark survives copy-paste and light editing. That is exactly the most common production path — an API response, into a CMS, a quick human edit, published. Heavy modification, or very short outputs, can strip the mark. That limitation is physical rather than a corner cut: any watermark competes with the information loss of the edit itself.

Where the rest of the industry stands

Anthropic is not alone. Google has been shipping SynthID inside Gemini — a text-watermarking scheme designed not to degrade output quality, alongside watermarks for images, audio and video. OpenAI has long built — and then shelved — text-watermarking prototypes over usability and evasion concerns, though C2PA marking on images is standard. Meta's answer is different again: its flagship Muse Glimmer is an open-weight Apache-licensed model, where mandatory watermarking is not a design constraint in the same way.

ProviderText watermarkImage provenanceStatus
Claude (Anthropic)Yes, from 2 Aug 2026C2PA (.jpg/.png/.svg)Live, global
Gemini (Google)SynthIDSynthID + C2PALive
GPT-5.6 (OpenAI)Prototypes, not defaultC2PAEvolving
Open weights (DeepSeek, GLM, Mistral)NoVariesDifferent AI Act track

That last row matters for EU users who care about the open ecosystem. On our AI Arena rig, most of what we benchmark are local open-weight models via Ollama — DeepSeek-V4-Flash, GLM-5.2, Mistral's Shieldstral. None of them watermark text, and locally hosted generation sits on a different compliance path under the AI Act's open-source provisions. The nuance: deployment context still decides obligations. "Run it yourself" is not an automatic loophole, but it is a structurally different situation from calling a US-hosted mega-API.

The European perspective: price, data, disclosure

For European businesses, the change is invisible in the invoice. Claude Pro stays at $20/month (roughly €18), Team at $30 (about €27), and API prices are unchanged — Claude Opus 5 remains covered by Pro/Team subscriptions and per-token API billing. Watermarking adds no per-token surcharge and no reported latency impact, because the mark is generated as part of the sampling process itself, not bolted on afterwards.

What the watermark gives European companies is a concrete, defensible answer to the question "was this AI-generated?" — for compliance documentation, customer communication and AI Act reporting alike. The enforcement context is new: the EU AI Office now has binding information requests, model evaluations and administrative fines at its disposal, as IndexBox reports. The wider AI Act picture remains layered: the EU Digital Omnibus pushed the heaviest high-risk conformity deadlines to late 2027, so the August wave is specifically the transparency layer — which, notably, is the layer end-users actually see.

What we'd keep and what we'd watch

From our own production experience — AI-assisted article pipelines, transcription and publishing — the copy-paste survival property is the make-or-break feature. A watermark that dies in the clipboard is a checkbox feature; one that survives the CMS round-trip is operational reality.

The under-appreciated consequence is labelling: because the mark covers processed by Claude, any team using Claude for translation or proofreading now generates output that a verifier can trace back to Claude. For European publishers, the practical advice is simple: keep your AI-disclosure label accurate, log when Claude touched a piece of content, and treat the watermark as what it is — transparency infrastructure, not DRM. It is there to be readable, not to punish.

Can users strip the watermark?

Yes, in two ways: heavy rewriting of text, or re-exporting and compressing images, can break the mark, and very short AI outputs may not contain enough signal for reliable detection. But the watermark is transparency, not DRM — its purpose is to give verifiers an informed basis for judgment, not to make removal impossible.

Does watermarking slow Claude down or increase API bills?

No. The watermark is generated during sampling, so there is no added latency and no token overhead, and Anthropic has not changed pricing — Claude Pro remains $20/month (≈€18), Team $30/month (≈€27).

Does the watermark expose my chat data?

No. The text watermark is a statistical pattern in the model's token choices, not a payload containing your conversations. C2PA files carry provenance claims about the asset — what generated it and when — not the underlying conversation content.

Discussion

No comments yet — be the first to share your thoughts.
X

Don't miss out!

Subscribe for the latest news and updates.