Anthropic will embed invisible watermarks in every text output from Claude, and apply the same treatment to any content Claude edits, translates, or summarizes, the company said in a support article. The move is designed to comply with the EU AI Act, which requires providers to mark AI-generated or manipulated audio, image, text, and video outputs. Violations carry fines up to 15 million euros or 3% of worldwide annual revenue.
The law applies to any AI model released after August 2, with a grace period until December 2026 for updating models already in the field. Anthropic said the watermarks will ship on all new models offered globally, not only in the EU, from day one. Non-text outputs will carry digitally signed provenance metadata using the C2PA standard where supported.
The scope is what makes this notable. The EU AI Act carves out an exception for AI systems performing "an assistive function for standard editing" — the official example is grammar correction — or work that doesn't "substantially alter" a user's text. Anthropic is ignoring that carve-out and marking processed content anyway. The company acknowledged the overreach directly, noting that people often use Claude to proofread, translate, summarize, or convert files, and that the output will carry a Claude mark even when the underlying ideas came from somewhere else.
“will travel with the text when it's copied and pasted elsewhere, and may persist through some editing.”— Anthropic, support article
Key facts
- 01Anthropic will embed invisible watermarks in all Claude text outputs globally, not just in the EU, starting with models released after August 2.
- 02The EU AI Act carries fines up to 15 million euros or 3% of a company's worldwide annual revenue for disclosure violations.
- 03Previously released models get a grace period until December 2026 to add watermarking.
- 04Anthropic will mark content Claude only edited, translated, or summarized — even though the AI Act exempts assistive editing.
- 05Non-text outputs will use C2PA provenance metadata; Anthropic has not yet released a public detection tool.
Text watermarks work by biasing the model's word choices in a statistical pattern spread across a document, detectable only in aggregate with the right tool. Anthropic said the marks will travel with text when copied and pasted, and may persist through some editing. But pasting watermarked text into a different chatbot that rewrites it can destroy the signal, and once Anthropic publishes its detection method — which it has committed to doing to satisfy EU technical-support requirements — building a stripping tool becomes trivial. Screenshots and metadata editors remove the equivalent signal from images and video.
The interpretability problem may be worse than the evasion problem. Anthropic said in its post that a detected mark provides a signal that content was processed by Claude but is not fully conclusive, and that the absence of a mark doesn't mean content wasn't AI-generated. In plain terms: a hit means Claude might have touched the text, and a miss means nothing. A teacher grading a student essay that pings positive has no way to distinguish a full ghostwrite from a spellcheck.
The disclosure regime the watermark is meant to support has its own inconsistencies. Under Article 50(4) of the AI Act, a wholly AI-generated novel or piece of marketing copy needs no public label. Text meant to "inform the public on matters of public interest" does require a label — unless a named human editor reviews it, in which case the labeling requirement drops. The result is a system where the model watermarks aggressively at the technical layer while the public-facing disclosure layer is far more permissive.
The European Commission has framed the requirements as essential to preserving trust in the information ecosystem. One EU support article described the disclosure obligations as the primary compliance challenge for AI firms operating in the bloc. The Commission's guidelines add that techniques should be sufficiently reliable, interoperable, effective and robust as far as this is technically feasible — language that effectively leaves the engineering to the labs.
Anthropic has not published a timeline for releasing its detection tool, nor shared false-positive or false-negative rates from internal testing. The company said it will continue refining both the watermarks and the detection methods to meet EU requirements. Anthropic did not immediately respond to questions about how its broader watermarking scope interacts with the AI Act's editing exemptions.
The compliance calculus for Anthropic is straightforward: 3% of a fast-growing revenue base is a lot more than the cost of over-marking. But the byproduct is a signal that means less the more it's used. If Claude watermarks a spellcheck the same way it watermarks a fully generated essay, downstream readers — teachers, editors, platforms building AI-detection pipelines on top of the mark — will treat the two the same. That collapses the distinction the EU said it wanted to preserve. Expect the next 18 months to produce a wave of research papers on watermark removal, a corresponding wave of detection-tool startups, and eventually a regulatory clarification about what "processed by AI" is actually supposed to mean.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




