Anthropic will watermark all text generated by Claude to comply with the European Union's AI Act, the company confirmed in an updated support page. Every Anthropic model released after August 2 automatically embeds watermarks in both generated text and files, and the marks are designed to persist when users copy and paste output elsewhere. The change is Anthropic's direct response to the EU AI Act's Transparency Code, which took effect on August 2 and requires AI providers to mark generated or edited content in a form other systems can detect.
The watermark is applied at the model level, not the product layer, so it appears in output from every Claude surface: the Claude platform API, the Claude consumer app, Claude Code, Claude Cowork, and Claude Tag. For file outputs, Anthropic is using C2PA, the open provenance standard already adopted across much of the industry. The company said it will extend watermarking support to older models as well, though it did not give a timeline.
The design goal is durability through everyday use. Because the mark is embedded in the text itself rather than attached as metadata, Anthropic says it survives being pasted into other apps and can persist through some editing.
“Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing. Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from”— Anthropic, Support page
Key facts
- 01All Anthropic models released after August 2 will automatically watermark generated text and files.
- 02The EU AI Act's Transparency Code took effect August 2 and requires machine-readable marking of AI-generated content.
- 03Watermarks apply across Claude platform API, Claude, Claude Code, Claude Cowork, and Claude Tag.
- 04Files use the C2PA open standard; text watermarks are embedded at the model level and survive copy-paste.
- 05Black Forest Labs, Google, Meta, Microsoft, OpenAI, and Synthesia have also committed to the EU code.
What Anthropic has not disclosed is how much editing is needed to strip the watermark, or how detection is exposed to downstream platforms that want to check whether a block of text came from Claude. Text watermarking is materially harder than image or audio watermarking — natural-language output has less redundant signal to hide a mark in, and paraphrase attacks are cheap. The company has been asked to clarify the removal threshold and had not responded publicly at time of writing.
Anthropic is one of six frontier AI providers that have committed to the EU code alongside OpenAI, Google, Meta, Microsoft, Black Forest Labs, and Synthesia. The code is technically voluntary but functions as the compliance baseline for the broader AI Act, and signing on shields providers from the regulator's harshest interpretive discretion. Refusing to sign, as some model providers have done, invites case-by-case scrutiny.
The move lands in a week of watermarking announcements from platforms feeling regulatory and reputational pressure at once. AI music service Suno said last week it would begin marking tracks generated on its platform, following a wave of copyright litigation. Newsletter service Substack partnered with Pangram last month to flag AI-generated posts, after CEO Chris Best publicly called out what he termed Claudefishing — writers pushing Claude output into paid newsletters. Pangram itself raised $9M last month to scale its AI-text detector, which the company claims runs at 99% accuracy.
Watermarking at the model level is the most upstream place to enforce provenance, and it is also the hardest to circumvent without breaking the model's output. A platform-level filter — the approach most vendors have taken until now — only marks content that flows through the vendor's own surfaces. A model-level mark travels with the text even when a developer routes API output through their own product with their own branding. For enterprises building on the Claude API, that means every Claude-authored paragraph is now identifiable as Claude-authored, whether the end user knows it or not.
The open question is detection asymmetry. Google's SynthID has been shown to survive roughly 300 edits in benchmark testing, but its usefulness depends on detectors being widely deployed — and today, they are not. A watermark that no one checks for is a compliance artifact, not a provenance system. Anthropic has not said whether it will publish a detector, license one to platforms, or keep detection internal.
The EU's Transparency Code is doing what US voluntary commitments have not: forcing frontier labs to actually ship the provenance features they announced years ago. Anthropic joining Google, OpenAI, Meta, and Microsoft on model-level watermarking means the majority of Western frontier output will soon be marked at the source. Whether that translates into a functioning provenance ecosystem depends less on the labs and more on whether platforms — social networks, publishers, newsletter services, and search engines — build the detection layer to match. Without it, watermarking is a regulatory checkbox rather than an answer to the AI-content flood.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




