Anthropic will build machine-readable markers into new Claude models offered in the EU starting on August 2, 2026. Generated text will carry an invisible watermark, and supported file types such as images will receive signed provenance information. Because the watermark is applied at the model level, it extends beyond text copied from Claude's web interface to outputs delivered through the API and Claude Code as well. However, this is not being rolled out simultaneously across all currently available Claude models. Existing models are still transitioning, and technical documentation on detection methods has not yet been published.
New Models from August 2 Onward, Applied Worldwide
Anthropic's target is Claude models that begin being offered in the EU on or after August 2. Supported models will mark generated text in a machine-readable form from the moment of release. For models released before August 2, Anthropic is working on support but has not indicated a rollout date. As a result, current Claude output cannot uniformly be assumed to be "watermarked."
For supported models, there is no regional distinction. The watermark applies globally to output from the Claude Platform API, Claude, Claude Code, Claude Cowork, and Claude Tag. Text generated using the same models via AWS, Google Cloud, or Microsoft Foundry will also carry the watermark. That said, signed provenance information for files may not be available depending on the features and formats each platform supports.
This global rollout originated from compliance with the EU AI Act. The transparency obligations under Article 50 took effect on August 2, requiring providers of generative AI to mark outputs such as text and images in a machine-readable format so that artificially generated or manipulated content can be detected. While the Code of Practice that businesses participate in is voluntary, the requirements of the law itself are mandatory. Anthropic signed Part I for providers and chose to extend that implementation across all of Claude.
The Exception for Text Under 200 Tokens
The EU's final Code requires that watermarks be applied to free-form text exceeding 200 tokens, even if reliability is lower than for longer text. Text under 200 tokens, meanwhile, is defined as "very short text," and an exception is granted on the grounds that current technology struggles to ensure even basic reliability for such content. A token is the unit in which a model processes text, and does not correspond directly to word count. This threshold reflects a technical limitation baked into the regulation from the outset: the shorter the post or answer, the less material there is available for judgment.
It's also necessary to distinguish between applying a watermark and having it be reliably detectable by anyone. The Code states that, while detection results for free-form text carry low confidence and risk being misleading, access to detection mechanisms may be restricted to verified experts such as regulators, journalists, and researchers. Anthropic has indicated a policy of providing detection means to users and third parties, but has left the method, timing, and the amount of text required for judgment to future technical documentation.
The scope of testing required is broad. The EU Code cites vocabulary substitution and character insertion/deletion as typical forms of manipulation, and calls for robustness to be measured even when paraphrasing and translation are layered together. Deliberate attacks such as copying, removing, or regenerating watermarks are also subject to evaluation. Anthropic's statement that the watermark "may survive some editing" is not sufficient on its own to compare this kind of performance. Whether false positive and false negative rates can be shown broken down by text length and language will determine how practically useful the detector actually is.
What Text Watermarks and C2PA Can and Cannot Prove
Claude uses different methods for free-form text and for files. For text, an invisible watermark is woven directly into the content during generation. According to Anthropic, this does not change the meaning, quality, or readability, and the watermark travels with the text even after copy-and-paste. For supported file types such as .svg, .png, and .jpg, signed provenance metadata is attached in accordance with the C2PA (Coalition for Content Provenance and Authenticity) standard.
C2PA is a mechanism that protects claims about who performed what processing, using digital signatures, so that any later tampering can be verified. This is a different role from a watermark, which leaves a statistical signal within the content itself. Since free-form text cannot carry metadata, the EU Code determined that a single layer of invisible watermarking satisfies the requirement for text. For files, the basic approach is to layer signed metadata together with a watermark.
Neither marker proves that Claude is the original author of the content. If a human-written text is proofread, translated, or summarized by Claude, the output may retain a signal indicating it was processed by Claude. Conversely, the inability to detect a watermark in heavily edited text or a short excerpt does not prove that the content was written by a human alone. C2PA metadata can also be lost when images are re-saved, converted to another format, or captured via screenshot.
How Things Change Once Embedded via the API
Developers who integrate Claude into products via the API will need to track both the model name and whether that model supports marking. Post-processing steps such as re-summarizing, translating, or blending output into other text can change its detectability. Anthropic itself notes that developers must individually assess their own Article 50 obligations for services built on Claude. Even with a watermark applied, the disclosure and recordkeeping responsibilities on the user's side are not automatically taken care of.
There is precedent for model-level text watermarking. Google DeepMind's SynthID-Text leaves a statistical signal by adjusting the probability of the next token chosen. In a real-world evaluation using roughly 20 million Gemini responses, the difference in quality assessment between watermarked and non-watermarked output was not statistically significant. At the same time, the paper acknowledges that editing or paraphrasing by another LLM can weaken the signal. Whether Anthropic adopts the same approach has not been disclosed, but the need to verify quality and detection rate together applies equally.
When will existing models get the watermark? How will third parties be able to use the detector? What are the false positive and false negative rates for short text, different languages, and paraphrased content? If Anthropic can answer these questions with technical documentation and reproducible evaluations, invisible watermarking can move from being merely a mark of regulatory compliance to becoming a practical signal for confirming whether content was processed by Claude.
