TrendingMost audit findings are assertions. These six leave evidence.
SEO

The watermark counts the words Claude chose. It does not say who wrote the page.

Claude’s newest models weave an invisible mark into their text, with no documented opt-out. In Anthropic’s explanation the mark measures one thing, how many words the model chose: faint on a proofread draft, loud on prose it wrote end to end.

MSMikołaj Salecki, portrait
Editor-in-chief
Sep 5, 2026·7 min read
A plaster hand pressing a heavy wax seal onto paper while the face of the seal is completely blank and smooth, with a row of hanging sheets behind it where one carries a faint blue watermark visible at an angle
It stamps every page. It does not say whose page it was.Illustration: Mediovsky · generated with AI
TL;DR
  • Claude models launched on or after August 2, 2026, mark their text output at launch. No opt-out is documented. [1]
  • Marking is global and model-level, across the API, Claude Code, Cowork, and Tag. The text watermark also rides through AWS, Google Cloud, and Microsoft Foundry. [1]
  • The driver is Article 50(2) of the EU AI Act, an obligation on the model provider, with an exemption for assistive editing. [2]
  • The technique is SynthID Text. The watermark only applies to words Claude chooses. [4][8]
  • So a human draft Claude proofread may carry almost nothing, and a fact or a line of code carries almost nothing either. [8]
  • A detected mark is not conclusive. It cannot distinguish text Claude wrote from text Claude heavily edited. [1][8]
  • Text detection is private preview for regulators, media, researchers, and obligated enterprises. Not for you. [1]
  • Google’s stated position is quality over production method, and no published evidence has it ranking on a watermark. [5][6]

There is a specific kind of panic that follows every provenance announcement, and it always takes the same shape. A signal becomes technically detectable, so the industry assumes it will shortly become a punishment.

On August 11, 2026, Anthropic said Claude would start embedding machine-readable marks in what it produces. [3] Within days it had hardened on LinkedIn and X into a coming ranking penalty. [6] That reading is available. It is not supported by the documentation, and the documentation, together with the explanation Anthropic published three days later, is unusually forthcoming about what the mark can and cannot do.

What was actually shipped

Two mechanisms, not one. Anthropic describes an imperceptible watermark woven into generated text, and separately, digitally signed provenance metadata attached to generated files following the C2PA open standard, covering file types such as .svg, .png, and .jpg. [1]

The scope is the part worth reading twice. Marking applies to output from supported models across the Claude Platform API, Claude, Claude Code, Claude Cowork, and Claude Tag, wherever Claude is offered, worldwide. The text watermark carries through when those models are reached via AWS, Google Cloud, or Microsoft Foundry, while file metadata rides along only where the platform offers Claude’s file generation. [1] Models launched on or after August 2, 2026, support it at launch, with Fable 5.1 and Mythos 5.1 named as currently supported and older models being brought in under the transition period the law allows. [1]

No opt-out appears anywhere in that documentation, including for commercial API use.

The mechanism is borrowed rather than invented. Anthropic says it uses the SynthID Text approach Google DeepMind published in 2024, which works by nudging the model’s low-stakes choices, the pick between two words that would serve equally well, into a pattern invisible to a reader and legible to whoever holds the key. [4][7] Nothing is added to the text and there are no hidden characters, so it is not a metadata tag and not something a text editor strips. [8]

The legal driver is Article 50(2) of the EU AI Act, which requires that outputs of a generative AI system are marked in a machine-readable format and detectable as artificially generated or manipulated, with solutions that are effective, interoperable, robust, and reliable as far as this is technically feasible. [2] The same paragraph carries its own limit: the obligation does not apply to the extent that the system performs an assistive function for standard editing, or does not substantially alter the deployer’s input or its meaning. [2] Anthropic has signed the corresponding Code of Practice on Transparency of AI-Generated Content. [1] Note where that obligation sits. It binds the provider of the model. It is a different duty from the one that reaches a marketing team, which is the subject of the labeling rules on creative in the same month, under a different paragraph of the same article.

What the mark measures, in Anthropic’s own words

Most provenance coverage treats detection as binary. Anthropic does not, and the sentence that governs everything is short.

The watermark only applies to words Claude chooses. Anthropic, How Claude’s text watermark works [8]

Follow that sentence to its ends and the mark stops looking like a stamp and starts looking like a meter. When Claude proofreads text written by a person, Anthropic says, nearly all the words are the person’s, so there is very little, if anything, for the watermark to attach to, and the changes might not be enough to make Claude’s involvement detectable. The more Claude writes, the more decisions it makes, and the more space there is for a watermark. [8] Where an exact output is required, where a different word would make a fact wrong or a piece of code break, the watermark is not applied at all, which is why factual passages carry it sparsely. [8] And a complete rewrite in which every word is replaced removes it. [4]

So the signal tracks one thing: how many words the model picked. A page Claude drafted end to end is loud. A page a person wrote and Claude tidied is nearly silent. A page of specifications, prices, and code carries almost nothing, and what it does carry sits in the comments. And a page spun through a third-party rewriter is silent again, for the opposite reason.

What the mark tells you What it cannot tell you
Claude probably chose a meaningful share of these words Who wrote it, or how much of it a person contributed
Whether a file has been altered since Claude produced it, when a C2PA credential is present Whether the ideas or data came from somewhere else entirely
Nothing at all, when it is absent Whether the absence means human authorship, a factual passage, a light edit, or a full rewrite

Anthropic states the other direction with the same directness. A detected mark provides a signal that content was processed by Claude but is not fully conclusive, because Claude may not be the original author: people use it to proofread, translate, summarize, or convert files. [1] A watermark can only determine that Claude was likely involved at some point. It cannot distinguish text Claude wrote from text Claude heavily edited. [8]

One word needs care because it is used in two senses. A translation produced by Claude carries a watermark, because every word in it is chosen by Claude. [8] A Claude-written text that is later pushed through a different translator loses it, because the words are replaced. The mark follows the choosing, not the language.

That is not a flaw someone will patch next quarter. It is what a statistical mark distributed across word choices necessarily does. It is also, read plainly, a description of the content most likely to be strongly marked: prose with many interchangeable words in it, produced end to end by the model. Anyone whose process is a human draft and a machine polish is largely outside its range. Anthropic says so in so many words, [8] and the first careful read of the announcement reached the same conclusion before the panic did. [6]

The ranking question, answered by precedent

The SEO framing deserves a direct answer rather than a hedge, because it is the question most people actually have.

Google’s published position is that its ranking systems aim to reward original, high-quality content, and that its focus is on the quality of content rather than how content is produced. [5] That guidance is from 2023 and has not been withdrawn. Nothing in it treats provenance as a quality signal in either direction.

Then there is the precedent. SynthID is Google’s own system, and Google has expanded it to watermarking and identifying text generated by the Gemini app and web experience. [7] So a search company that wanted to demote watermarked text has had a detector for its own model’s output, and has not published anything suggesting it uses one that way. [6]

There is a practical constraint underneath the policy one. Detection is in private preview, available to eligible organizations such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, EU civil society groups, and enterprises with their own compliance obligations under the Act. [1] A signal a search engine cannot read at crawl scale, that goes quiet on lightly edited human work and on factual prose, would be a poor input to a ranking system even if someone wanted to use it.

What to do on Monday

Very little, which is the honest answer, and the small list matters more than the reassurance.

Stop buying AI-detection services that claim to read this mark. Only the key holder can, access is gated, and any vendor claiming otherwise is selling a guess. Check your files rather than your text, because the free Claude Content Checker verifies C2PA credentials and file provenance is the half of this that is actually interoperable today. [1]

Read your contracts, since this is where the change is real. Clauses promising no AI involvement in delivered work move from unverifiable to partially verifiable, in one direction only, and only for prose the model wrote at length. A mark can now embarrass a supplier who signed one and then let the model draft. Its absence still proves nothing, so the clause remains a bad clause, just a differently bad one. If you sign or issue these, the honest fix is to specify review and accountability rather than tooling, in the same way that quality control has to be measured rather than felt.

And keep the obligation straight. Article 50(2) landed on Anthropic, not on you. Anthropic’s own guidance tells anyone deploying Claude in their own product to independently assess what Article 50 requires of them. [1] That assessment is a real piece of work, and no amount of watermarking upstream performs it on your behalf.

The mark answers a narrow question honestly: did Claude choose a meaningful share of these words. It was never built to answer the question the industry is asking it, which is whether the work is any good. That one still has no machine-readable format.

Sources

  1. Anthropic · How Claude marks AI-generated contentScope, supported models, C2PA file types, detection access, and the stated limitations in both directions.
  2. EU AI Act · Article 50: transparency obligations for providers and deployersParagraph 2 carries the machine-readable marking duty on providers, and its exemption for assistive editing.
  3. TechCrunch · Anthropic says it will watermark text generated by its AI modelsThe August 11, 2026, announcement.
  4. TechCrunch · Anthropic shares more details about how Claude’s new watermarks will workThe SynthID Text attribution and the light-edit versus full-rewrite boundary.
  5. Google Search Central · Google Search’s guidance about AI-generated contentQuality over production method, still the standing guidance.
  6. Seer Interactive · Google is not going to stop ranking your Claude-assisted contentThe LinkedIn and X shorthand, and the absence of any published ranking use.
  7. Google DeepMind · SynthIDThe watermarking family Anthropic adopted for text, and its expansion to Gemini text.
  8. Anthropic · How Claude’s text watermark worksAugust 14, 2026. The proofreading, exact-output, translation, and authorship statements, in the vendor’s own words.

Frequently asked questions

What did Anthropic actually announce?

On August 11, 2026, Anthropic said Claude would embed machine-readable marks in its output. Its documentation states that Claude models launched on or after August 2, 2026, support marking at launch, that generated text carries embedded watermarks, and that generated files carry digitally signed provenance metadata where supported.

Can I turn the watermark off?

No opt-out is documented. Anthropic states that marking applies to output from supported models across the Platform API, Claude, Claude Code, Claude Cowork, and Claude Tag, wherever Claude is offered, worldwide. The text watermark also carries through when supported models are accessed through AWS, Google Cloud, or Microsoft Foundry, while file provenance metadata applies only where a platform offers Claude’s file generation.

Which models are marked?

Models launched on or after August 2, 2026. Anthropic names Fable 5.1 and Mythos 5.1 as currently supported, and says it is working to add marking to models released before that date under the transition period the law allows.

How does the watermark work?

Anthropic says it uses the SynthID Text approach Google DeepMind published in 2024. Where two words would serve equally well, the model’s choice is nudged into a pattern a key holder can detect and a reader cannot see. The watermark only applies to words Claude chooses, so it is sparser wherever there is no real choice.

Does a detected watermark prove the content is AI-written?

No, and Anthropic says so directly. A watermark can only determine that Claude was likely involved with the content at some point. It cannot distinguish text Claude wrote from text Claude heavily edited, and its documentation notes that people use Claude to proofread, translate, summarize, or convert files.

Is a human draft that Claude proofread marked?

Usually barely, if at all. Anthropic states that when Claude proofreads text written by a person, nearly all the words are the person’s, so there is very little for the watermark to attach to, and the changes might not be enough to make Claude’s involvement detectable. The more Claude writes, the more space there is for a watermark.

Does the absence of a watermark prove a human wrote it?

No. Anthropic lists several conditions under which its own mark will not be found: the model predates marking support, the text was heavily edited, paraphrased, or mixed into other writing, the passage is too short, a file’s metadata was stripped, or the platform or file type did not support that marking. It also says the watermark is not applied where an exact output is required, such as a fact or working code.

Are translations watermarked?

A translation produced by Claude is, because every word in it is chosen by Claude. A Claude-written text that is later run through a different translator is a different case: the words are replaced, and the mark goes with them.

Will this hurt my Google rankings?

There is no published evidence that it will. Google’s stated position is that its ranking systems aim to reward original, high-quality content and that its focus is on quality rather than how content is produced. Google also watermarks Gemini’s own text with SynthID, with no published use of that as a ranking signal.

Can I check my own content for the mark?

Not for text, in most cases. Anthropic says watermark detection is in private preview for eligible organizations such as regulators, law enforcement, media, fact-checkers, researchers, educational organizations, EU civil society groups, and enterprises with their own compliance obligations. Files are different: the free Claude Content Checker verifies C2PA content credentials.

What law is driving this?

Article 50(2) of the EU AI Act, which requires that outputs of a generative AI system are marked in a machine-readable format and detectable as artificially generated or manipulated, as far as technically feasible. The same paragraph exempts systems to the extent that they perform an assistive function for standard editing, or do not substantially alter the deployer’s input or its meaning. Anthropic has signed the Article 50(2) Code of Practice.

Does this change what my agency has to disclose?

Not by itself. Article 50(2) is an obligation on the provider of the model, not on you, and Anthropic’s own guidance tells anyone deploying Claude in their product to independently assess what Article 50 requires of them. The obligations that land on a marketing team sit elsewhere in the same article.

Found this useful?
MSMikołaj Salecki, portrait
Editor-in-chief

Mikołaj Salecki

Writes about media, tech, and AI business for people who actually run digital. Former agency lead. Skeptic of frameworks that read better than they perform.

More articles →