For AI agents: the public content index is available at https://we0.ai/llms.txt, and the English article bundle is available at https://we0.ai/llms-full.txt.
For AI agents: the complete content index is available at https://we0.ai/llms.txt, the full English article bundle is available at https://we0.ai/llms-full.txt, and this page is available as Markdown at https://we0.ai/articles/claude-now-marks-ai-generated-text.md.
Anthropic has begun rolling out machine-readable marking for supported Claude-generated content. The change has two layers: 1. An embedded w...

Anthropic has begun rolling out machine-readable marking for supported Claude-generated content.
The change has two layers:
The policy is tied to Anthropic’s commitments under the European Union’s AI Act Article 50(2) Code of Practice on Transparency of AI-Generated Content.
But the implementation is broader than the EU.
Anthropic says that when a Claude model supports marking, the marks apply wherever that model is offered worldwide. The same model-level text marking is intended to appear whether the output comes from Claude’s consumer interface, the API, Claude Code, Claude Cowork, Claude Tag, or supported cloud-provider integrations.
That does not mean every piece of Claude text ever generated can now be detected.
There are several important limits:
Those distinctions are the difference between a useful provenance signal and a universal AI-authorship detector.
The immediate regulatory backdrop is the EU AI Act.
Article 50 introduces transparency obligations for certain AI systems and AI-generated content. The European Commission’s transparency Code of Practice is designed to help providers and deployers satisfy those obligations.
The Commission describes the relevant requirements as covering:
The transparency obligations became applicable on August 2, 2026.
Anthropic signed the Article 50(2) transparency code as a provider of generative AI models and systems.
Its Claude marking system is the company’s implementation path for those commitments.
The key point is that the legal requirement is about transparency and provenance signals, not about making every AI-generated sentence visibly display a warning to the reader.
Machine-readable marking can operate invisibly in the content while still allowing compatible tools to inspect it.
Anthropic’s design separates text from file provenance.
| Layer | Applies to | What it does | Main limitation |
|---|---|---|---|
| Embedded watermark | Generated text | Places an imperceptible machine-readable signal in the text itself | Can weaken after heavy editing, translation, paraphrasing, or shortening |
| Signed provenance metadata | Supported generated files | Adds signed origin/history information following C2PA | Metadata can be stripped by conversion, screenshots, re-saving, or unsupported workflows |
Using both layers matters because text and files fail differently.
A metadata-only system is easy to lose when a file is converted.
A text-only signal cannot describe the richer history of a generated image or other file.
Anthropic is therefore using a layered approach rather than treating one technique as sufficient for every output type.
For supported models, Claude-generated text contains an imperceptible watermark embedded directly in the text.
Anthropic says the watermark:
That last point is especially important.
The watermark is not just an HTML tag added by the Claude website.
Anthropic says it is integrated at the model-output level, which is why supported text can remain marked even when the same model is accessed through different Claude products or platforms.
If a user copies a marked Claude paragraph from one interface into:
the watermark may travel with the text.
That is different from visible labels or ordinary file metadata, which can disappear as soon as content is copied out of the original application.
However, “travels with the text” should not be interpreted as “cannot be removed.”
Anthropic explicitly says that sufficiently heavy transformation can make the signal undetectable.
Anthropic lists several cases where Claude-generated text may no longer carry a detectable mark:
This is a fundamental limitation of text watermarking.
Text is easy to transform while preserving meaning.
For example:
Original Claude draft
→ human rewrites 30% of it
→ translator changes the language
→ editor combines it with human-written paragraphs
→ final document contains only short excerpts
At some point, there may not be enough of the original statistical or embedded structure for the detector to identify a supported Claude mark reliably.
This means the watermark should be treated as a positive provenance signal when present, not a proof of human authorship when absent.
This is one of Anthropic’s most important caveats.
A detected mark can mean the content was processed by Claude.
That is not the same as proving Claude originated all of its ideas or wording.
Consider a user who writes a report manually and asks Claude to:
The resulting output may carry a Claude mark even though the underlying content began with the user.
The correct interpretation is:
Claude mark detected
→ Claude likely processed this content
not:
Claude mark detected
→ Claude independently authored everything in this content
That distinction matters for schools, publishers, employers, compliance teams, and anyone attempting to infer authorship from an automated signal.
When Claude generates a supported file type, Anthropic says it can attach digitally signed provenance metadata.
Examples include:
.svg
.png
.jpg
The metadata follows the Coalition for Content Provenance and Authenticity (C2PA) standard.
C2PA is an open technical standard for recording the provenance of digital content.
Its Content Credentials can contain signed information about a file’s history, such as:
Anthropic says a valid signed label can signal that a file was processed by Claude and help detect whether the provenance information has been tampered with.
C2PA is sometimes described too loosely as “an AI watermark.”
That is not quite right.
C2PA is a provenance standard.
It can be used for AI-generated media, but it can also be used for:
Its purpose is to create a verifiable history of the content.
A useful analogy is a signed provenance record attached to a digital asset.
The record can tell a compatible verifier something about where the asset came from and how it was processed.
It does not make the pixels themselves impossible to copy.
Anthropic explicitly warns that provenance metadata is not indestructible.
It may disappear through:
For example:
Claude creates a PNG with signed provenance metadata
→ user takes a screenshot of the PNG
→ screenshot becomes a new file
→ original metadata may no longer be present
This is why file provenance and embedded watermarks are complementary.
The provenance layer can carry richer information.
The embedded layer can sometimes survive transformations that remove metadata.
No single layer is perfect.
Anthropic says supported Claude models apply marking across the company’s major product surfaces.
The official coverage list includes:
The company also says marking is intended to apply worldwide wherever supported Claude models are offered.
This is broader than a rule that activates only when the user is physically located in the European Union.
The implementation is tied to the model’s marking support.
Once a model supports the system, the output is marked across supported Claude surfaces.
Developers using Claude through the API are not outside the marking system.
Anthropic explicitly includes Claude Platform (API) in the list of covered products.
For supported models:
Application
→ Claude API
→ generated text
→ embedded Claude watermark
The developer does not need to be using the consumer Claude website for the watermark to be present.
This creates an important compliance question for businesses that use Claude behind their own interface.
The downstream product may:
Anthropic recommends that developers independently evaluate their own Article 50 obligations rather than assuming Claude’s upstream marking automatically solves every downstream compliance requirement.
Anthropic lists Claude Code as a covered surface.
That means text generated by a supported model through Claude Code can carry the same model-level embedded watermark.
This is relevant because coding-agent output can take several forms:
The official help page describes the watermark as applying to generated text generally.
However, Anthropic has not yet published enough technical detail to support reliable claims about how the detector will behave on every programming language, short code fragment, minified file, or heavily edited codebase.
Developers should therefore avoid treating the watermark as a software-compliance scanner.
The same policy extends to Claude Cowork and Claude Tag when they use supported models.
This matters because these products can generate work artifacts beyond a simple chat response.
A user may ask Claude to:
Text marking and file provenance can therefore appear in different parts of the same workflow.
A document may contain watermarked text while an exported supported image carries signed provenance metadata.
Anthropic also addresses third-party cloud platforms.
For supported Claude models accessed through:
the embedded text watermark is intended to apply.
The file-provenance layer is more conditional.
Anthropic says signed provenance metadata may not be supported on every cloud platform because the available file-processing features differ.
The practical distinction is:
| Access path | Embedded text watermark | Signed file provenance |
|---|---|---|
| Claude / Anthropic surfaces | Supported for marked models | Supported where file type and feature allow |
| Claude Platform/API | Supported for marked models | Supported where Claude file processing allows |
| AWS | Supported for marked models | Platform/feature dependent |
| Google Cloud | Supported for marked models | Platform/feature dependent |
| Microsoft Foundry | Supported for marked models | Platform/feature dependent |
This is another reason not to describe the entire system as one universal watermark.
The text and file layers have different deployment requirements.
Anthropic’s current rule is based on model launch date.
The official documentation says:
Claude models launched in the EU on or after August 2, 2026 support machine-readable marking at launch.
Models released before that date are not automatically covered by the same statement.
Anthropic says it is working to add marking support to earlier models.
The company has not published one simple permanent table stating that every historical Claude model now carries both marking layers.
Therefore, a reliable implementation should check current model documentation rather than infer support only from the word “Claude.”
A product using an older model should not assume:
Claude model
= definitely marked
The correct question is:
Does this specific Claude model currently support marking?
Watermarking applies when supported models generate or process content.
It does not retroactively alter text that Claude produced months earlier.
A document created before the rollout does not suddenly receive a hidden signal because the model is later updated.
Likewise, if an old model did not support marking at the time it generated a passage, the absence of a mark says very little about whether Claude was involved.
That is one reason the detector cannot function as a complete historical AI-authorship database.
A watermark has limited practical value if nobody can inspect it.
Anthropic says it plans to support detection by:
The company says future technical documentation will explain the detection mechanisms in more detail.
As of the publication date of this article, that technical guidance is still forthcoming.
This means there is an important difference between:
Anthropic has deployed marking support
and:
Anyone can already run a fully documented public detector for every Claude mark
The first statement is supported.
The second is too strong.
Anthropic describes detection as checking whether a piece of text or a file carries a supported Claude mark.
If a supported mark is detected, the safe interpretation is:
This content may have been processed by Claude.
That wording matters.
A detector should not automatically claim:
Provenance is evidence about processing history.
It is not a moral or quality judgment.
Anthropic is equally clear about the reverse case.
Failure to detect a mark does not prove that content is human-written.
A Claude-generated passage may lack a detectable signal because:
This makes the detector asymmetric.
A positive result can provide useful evidence.
A negative result cannot reliably exclude AI involvement.
AI-detection systems are often used in high-stakes contexts.
Examples include:
The Claude watermark can improve provenance, but it should not be turned into an automatic guilt detector.
A responsible process should distinguish:
Machine-readable Claude signal
from:
Evidence that a person violated a rule
If a university allows AI-assisted proofreading but prohibits fully AI-written assignments, a detected mark alone cannot determine which activity occurred.
Describe your idea once, and We0 AI can generate a showcase site, pages, and CMS, then help you attract customers and traffic after launch.
One complete project generation for free registration
Best for trying one complete generation flow and seeing a first project draft quickly.
The text may have originated with the student and only passed through Claude for editing.
Human policy and contextual evidence are still required.
Publishers may find machine-readable provenance useful for internal workflow tracking.
For example, a newsroom could distinguish:
But provenance systems work best when the workflow preserves the data.
If the content is repeatedly copied between tools that strip metadata or heavily rewritten, the chain becomes incomplete.
For sensitive publishing workflows, organizations may need to preserve:
Watermarks are most useful as one signal in a broader provenance system.
The source article’s headline suggests that AI-generated content may become impossible to hide.
That overstates what Anthropic says.
Anthropic explicitly documents several ways marks can become undetectable.
Heavy rewriting can weaken the text signal.
Screenshots and format conversions can remove file metadata.
Unsupported surfaces may not preserve every marking type.
The more accurate conclusion is:
Claude-generated content is becoming easier to identify when its provenance signals survive, but the system does not make AI involvement permanently or universally detectable.
This is consistent with the broader technical reality of provenance systems.
Robustness is a spectrum, not an absolute guarantee.
Anthropic’s approach combines two ideas that are already visible elsewhere in the AI industry.
C2PA provides cryptographically signed provenance information for digital assets.
The standard is supported across a growing ecosystem of:
The public Content Credentials Verify tool can inspect supported files for compatible credentials.
Google DeepMind’s SynthID embeds imperceptible watermarks directly into AI-generated content.
Google says SynthID can be used across:
The concept is closer to Anthropic’s embedded watermark layer than to C2PA metadata.
OpenAI currently documents provenance signals for supported generated media, including C2PA metadata and SynthID in supported image and audio workflows.
OpenAI’s public verification tool is designed for supported media files, not as a universal detector for arbitrary AI-generated text.
The broader industry direction is therefore toward layered provenance:
Embedded signal
+
signed metadata
+
verification tool
+
platform labels
Anthropic’s addition of a text watermark brings Claude more directly into that pattern.
Text creates a particularly difficult provenance problem.
An image can retain the same visual object while carrying hidden information in pixels or metadata.
Text is routinely transformed at the semantic level.
A user can:
The result may preserve the same meaning while replacing most of the original token sequence.
A robust text watermark therefore has to balance competing goals:
Anthropic has not yet published enough implementation detail to evaluate all of those tradeoffs independently.
Watermark systems face an adversarial problem.
If an attacker knows exactly how a watermark is constructed, they may attempt to:
At the same time, a system that is completely opaque is difficult for researchers and regulators to evaluate.
Anthropic’s current position is an intermediate one.
It publicly documents:
Detailed detection guidance is still pending.
That gives the company room to publish a more complete technical framework later.
Anthropic’s marking system should be understood as one provider’s implementation of a wider European transparency regime.
The European Commission says Article 50 addresses transparency for providers and deployers of generative AI systems.
The Code of Practice is voluntary as a compliance mechanism, but the underlying Article 50 legal obligations are not merely voluntary.
The code includes separate sections for:
The practical obligations can therefore differ depending on whether an organization:
builds the generative AI system
or:
uses the generative AI system to publish content
Developers should not assume that using a compliant upstream model automatically satisfies every obligation imposed on the downstream deployer.
There are multiple EU AI codes of practice, which can create confusion.
The Code of Practice on Transparency of AI-Generated Content relates to Article 50 marking and labelling obligations.
The earlier General-Purpose AI Code of Practice addresses obligations for general-purpose AI model providers, including areas such as:
Anthropic is a signatory to the GPAI Code as well.
The Claude marking article specifically references the Article 50(2) transparency code.
Those two compliance frameworks should not be treated as the same document.
Anthropic’s advice is straightforward: assess your own obligations independently.
A practical implementation checklist looks like this.
Record the exact model used by your application.
Do not rely on a generic “Claude” label.
Check whether the model currently supports machine-readable marking.
Older model behavior may differ.
Document what happens after Claude returns content.
For example:
Claude API
→ application post-processing
→ database
→ another model
→ template engine
→ PDF export
→ customer
Every transformation can affect provenance.
Do not assume that C2PA metadata and text watermarking survive the same operations.
Test them separately.
For regulated or high-trust workflows, retain:
A positive mark can show Claude processing.
It may not prove original authorship.
Your use case may involve:
These are exactly the cases where detection may be less reliable.
If your product is offered in or affects the EU market, assess the law and current Commission guidance for your specific role.
Anthropic says more technical guidance is coming.
Do not build a permanent compliance architecture around assumptions about an unpublished detector.
For a company that uses Claude to create public content, a defensible workflow could look like this:
Human or source data
↓
Claude supported model
↓
Original marked output saved
↓
Human editing
↓
Final publication file
↓
Provenance metadata preserved where supported
↓
Disclosure / label added where legally or editorially required
↓
Audit record retained
This approach does not depend on the watermark surviving every transformation.
It preserves an internal evidence chain even when the public artifact changes.
If you use a supported Claude model to draft:
the generated text can contain a machine-readable watermark.
Copying the text into another application does not necessarily remove it.
That does not mean your visible document will display “Written by Claude.”
The mark is intended to be imperceptible.
It also does not mean every future reader can immediately scan it today.
Anthropic’s third-party detection guidance is still being developed.
There is no single percentage of editing after which the watermark disappears.
Anthropic does not publish a universal threshold such as:
20% rewrite = detectable
50% rewrite = undetectable
The company only says the mark may survive some edits and can become undetectable after heavy editing, paraphrasing, translation, or mixing.
The outcome can depend on:
Any tool claiming a precise universal edit threshold should therefore be treated cautiously unless Anthropic publishes evidence supporting it.
For supported generated file types such as PNG and JPG, Claude can attach signed provenance metadata following C2PA.
If the metadata remains intact, compatible verification tools can inspect it.
If the image is:
the provenance information may disappear.
A missing credential is not proof that an image was human-created.
Anthropic specifically includes SVG among its examples of supported file types for signed provenance metadata.
SVG is useful because Claude can generate vector graphics and diagrams as structured files.
Like other file formats, provenance survives only when the processing chain preserves the metadata.
A user who copies only the SVG markup into a new file may not preserve the original credential.
Anthropic’s current public documentation does not provide enough information to make a reliable claim about the difficulty of forging its embedded text mark.
This is an important open security question.
Any provenance system has to consider both:
removal attacks
and:
forgery attacks
A malicious actor could benefit from making human content appear AI-generated just as they could benefit from hiding AI origin.
That is one reason high-stakes decisions should not rely on one automated signal.
No.
Machine-readable marking can improve transparency, but it cannot solve misinformation on its own.
Bad actors can use:
Provenance helps answer:
What can we learn about how this content was created or processed?
It does not answer:
Is this content true?
Fact-checking and provenance are complementary tasks.
The phrase “AI detector” suggests a binary test:
AI
or
human
Real content creation is becoming more mixed.
A document may involve:
In that world, the more useful question is not:
“Was AI used?”
It is:
“What happened to this content, which tools were involved, and which parts of the chain can be verified?”
That is the problem provenance standards are designed to address.
Supported Claude models can embed machine-readable watermarks in generated text. Anthropic says models launched in the EU on or after August 2, 2026 support marking at launch, while marking support for earlier models is still being added.
No. Anthropic describes the watermark as imperceptible and says it does not change the intended meaning, quality, or readability of the response. It is designed for machine-readable detection rather than visible labelling.
Not necessarily. Anthropic says the embedded signal travels with copied and pasted text and may survive some editing. Heavy rewriting, paraphrasing, translation, mixing, or shortening can make the mark undetectable.
No. A detected mark can indicate that the content was processed by Claude, but Claude may have only proofread, translated, summarized, or reformatted human-written material. Anthropic explicitly warns that the mark is not full proof of original authorship.
Anthropic says supported generated file types such as SVG, PNG, and JPG can receive digitally signed provenance metadata following the C2PA standard. Support can depend on the product, platform, feature, and file type.
Anthropic says embedded text watermarks apply when supported Claude models are accessed through AWS, Google Cloud, or Microsoft Foundry. Signed provenance metadata may not be supported on every cloud platform because file-processing capabilities differ.
Anthropic says it is building detection support for users and third parties and will publish more technical guidance. As of August 11, 2026, the company’s official documentation does not yet provide a complete public detection specification for the embedded text watermark.
No. A mark may be absent or undetectable because the model predates marking support, the passage is too short, the text was heavily edited or translated, or the relevant file metadata was stripped. Absence of a signal is not reliable proof of human authorship.
Anthropic is introducing machine-readable provenance for supported Claude outputs through two complementary mechanisms: an imperceptible watermark embedded in generated text and signed C2PA-based provenance metadata attached to supported files.
The rollout is tied to the EU AI Act’s Article 50 transparency framework, but Anthropic says supported models apply marking worldwide across Claude, the API, Claude Code, Claude Cowork, Claude Tag, and supported cloud-provider access paths. New models launched in the EU on or after August 2, 2026 support marking at launch, while earlier models are still being updated.
The system is useful, but it is not a perfect AI-authorship detector. Text marks can become undetectable after heavy editing or translation, file metadata can be stripped, and a detected signal only shows that Claude may have processed the content—not that Claude originated every part of it.
The practical shift is from guessing whether something “looks AI-written” toward preserving verifiable evidence about how digital content was created and processed.
Start from one sentence and have a complete website in minutes.