Anthropic Watermarks Claude Text, but the EU Compliance Test Still Lacks a Detector
TL;DR
Anthropic is adding text watermarks and C2PA file provenance to new Claude models in the EU, while older-model coverage and third-party detection remain unfinished.
One outcome will make Anthropic’s new marking system testable over the next three to six months: whether users and independent platforms receive a detector they can actually operate. The company currently says only that it is working on detection for users and third parties. Until that tool arrives, an outside service cannot independently establish whether a passage carries a Claude mark, so the compliance mechanism has no public end-to-end verification yet.
Anthropic updated its support documentation on August 10, 2026 to explain how Claude will mark AI-generated material. The regulatory dividing line is August 2, 2026. Claude models launched in the European Union on or after that date support machine-readable marking from launch, while models released earlier fall under a transition period and are still being updated. TechCrunch reported the change the following day and connected it to the European Union’s AI transparency requirements.
Text carries its mark; files use C2PA
Anthropic describes two complementary mechanisms. Supported Claude models embed an imperceptible watermark directly in generated text. A reader should not see it, and the company says it does not alter the response’s meaning, quality, or readability. Because the mark is part of the text, it travels when a user copies and pastes the passage and may survive some editing.
That last qualification matters. Anthropic has not disclosed how much rewriting is needed to remove the mark, and TechCrunch identified the same issue as unresolved. The documentation therefore supports a narrower claim than “tamper-proof”: a mark may persist after some edits, but its durability under paraphrasing, translation, formatting changes, or model-assisted rewriting has not been published.
For files that Claude generates or processes, the company plans to attach signed provenance metadata where the file workflow supports it. The metadata follows the open C2PA standard and can indicate that Claude processed a file, as well as help identify tampering after signing. Anthropic also cautions that a detected mark shows only that material may have been processed by Claude. It does not, by itself, prove who authored the content, why it was created, or whether its claims are accurate.
The marking is implemented at the model level rather than in a single user interface. Anthropic says it covers supported output from Claude Platform API, Claude, Claude Code, Claude Cowork, and Claude Tag. Text marks are also intended to remain present when a supported model is accessed through AWS, Google Cloud, or Microsoft Foundry. That architecture closes an obvious enterprise loophole in which the browser product is marked but API or cloud output is not. File provenance still depends on whether Claude supports the relevant file-processing path.
Older models and external verification remain unfinished
The announcement gives no completion date for adding marks to older models. It also provides no detector interface, false-positive rate, false-negative rate, or retention measurements after different degrees of editing. A company that wants to use the marks for content review would need all four: an accessible detector, representative test samples, documented error rates, and a process for disputed results.
The most useful follow-up measures are therefore concrete. Observers can track the share of older Claude models covered, the release date of a third-party detector, and detection rates after copying, light editing, translation, and substantial rewriting. If Anthropic has not released a detector or reproducible test results within six months, the model-side marking requirement may be implemented while outside verification remains unavailable. That would leave platforms able to cite the presence of a mechanism but unable to measure its performance across real content flows.
Sources:
Related Articles
EU AI Act Article 50 Takes Effect: AI Disclosure Failures Can Cost 3% of Global Turnover
The EU began enforcing AI-system transparency rules on 2 August 2026, requiring AI disclosure for chatbots and visible, machine-readable marking of certain synthetic content.
Claude Reached Three Companies During Cyber Tests After Isolation Controls Failed
Anthropic reviewed 141,006 cybersecurity evaluations and found that three Claude models reached real systems at three organizations through an internet-enabled test environment.