News·8 min read

Claude Now Hides a Watermark in Every Word It Writes. There Is No Off Switch, and No Tool Can Strip It

Quick answer ✦Every Claude model launched on or after August 2, 2026 weaves an invisible watermark into the text it generates, everywhere Claude is offered, worldwide: the app, the API, Claude Code, and cloud platforms. Anthropic says the mark survives copy-paste and may survive light editing. A detected mark means Claude processed the text, not that Claude wrote it. There is no opt-out in the documentation, and no public detector exists yet.

The quiet part is the scope. Anthropic’s own help document, the primary source for this story, says new models “will support machine-readable marking at launch” and that marking applies across the Claude app, the API, Claude Code, Claude Cowork, and Claude Tag, plus AWS, Google Cloud, and Microsoft Foundry. Older models are being retrofitted. Nothing in the document mentions a way to turn it off.

The trigger is European law. Article 50 of the EU AI Act requires generative AI providers to mark outputs “in a machine-readable format” so they are detectable as artificial, and those obligations apply from 2 August 2026. Anthropic signed the EU’s voluntary Code of Practice on transparency, then went further than the law demands: rather than run a marked Claude for Europe and a clean one for everyone else, it flipped the switch globally. TechCrunch broke the story on August 11.

Aug 2, 2026

EU AI Act Article 50 took effect

Transparency rules for AI-generated content, per the official EU text.

10 billion+

pieces of content Google had already watermarked by May 2025

Via SynthID across Gemini and NotebookLM, per TechCrunch. Claude is not the first, it is the loudest.

99.9%

reliability of the text watermark OpenAI built, then never shipped

The Wall Street Journal reported OpenAI sat on it for two years, partly because a third of users said they would use ChatGPT less.

1 to 2%

of provably human essays falsely flagged by AI detectors

Bloomberg Businessweek tested 500 pre-ChatGPT essays, some flags claiming near-100% certainty.

How do you hide a watermark inside words?

There is no secret character and no metadata. Anthropic says Claude “weaves an imperceptible watermark directly into the text itself.” The published way to do that: at every step, a language model chooses between many near-equivalent next words, and a secret key nudges those choices in a pattern a detector can later count. Google has run this in production since 2024, open-sourcing its SynthID text scheme after a live test on roughly 20 million Gemini responses found users “did not notice a difference in quality.” Anthropic has not published its method: “We’ll share details on detection mechanisms in forthcoming technical documentation.” Until that ships, only Anthropic can check for the mark.

  • Survives copy-paste. In Anthropic’s words, “it will travel with the text when it’s copied and pasted elsewhere.”
  • May survive light edits. The mark “may persist through some editing.” No one has said how much editing is enough.
  • Weakens under heavy rewriting. Anthropic’s own failure list: text “heavily edited, paraphrased, translated, or mixed into other writing.”
  • Short text carries no signal. A sentence or two leaves “too little text for a reliable signal.”
  • Absence proves nothing. “Lack of a detected mark doesn’t mean the content wasn’t AI-generated.”

A mark proves Claude touched it, not that Claude wrote it

This is the distinction that will be misread everywhere, so here it is plainly. Anthropic’s document says output can carry the mark when Claude was used to “proofread, translate, summarize, or convert files,” and warns that “Claude may not be the original author.” Paste your hand-written novel in for a grammar pass and the pages that come back may carry the mark. The mark is a receipt that says Claude was in the room. It is not a verdict on who did the writing.

That nuance matters because the world already convicts on weaker evidence. Bloomberg Businessweek tested two popular AI detectors against 500 college essays written before ChatGPT existed, and 1 to 2 percent were flagged as AI anyway, with detectors “in some cases claiming to have near 100% certainty.” Roughly two-thirds of teachers surveyed report using AI checkers regularly. A cryptographic mark with a real detector would be an upgrade over that guesswork, but only if the people reading the result respect the line between processed and authored.

The internet’s verdict, in four posts

The announcement threads are enormous: 2.9k upvotes on r/ClaudeAI, 1.1k on r/singularity, 343 points on Hacker News. The spectrum runs from students afraid of false accusations to developers arguing the mark cannot coexist with code quality, to an entire comment chain written in Claude’s own cliches to prove you never needed a watermark to spot it.

The image half is weaker, and Anthropic says so itself

Text and images get completely different treatment. Files like .svg, .png, and .jpg do not get an invisible watermark. They get signed provenance metadata under the C2PA open standard, a cryptographic label that “signals that a file was processed by Claude.” Metadata is the weaker mechanism, and Anthropic’s own failure list says so: the label disappears when “file metadata was stripped through format conversion, re-saving, screenshots.” Taking a screenshot of an image defeats it. So does saving it in a different format.

For transparency: C2PA is the same class of metadata our metadata remover reads and strips, alongside EXIF and GPS, and any re-encode through an image converter drops it too. That is not a loophole we built, it is how metadata works, and Anthropic documents it openly. The text watermark is the opposite case, and we will be just as plain about that: no tool can strip it, ours included. It lives in the words themselves. The only thing that degrades it is rewriting the words, which Anthropic already tells you.

What this changes for you

If you...What actually changes
Publish Claude text as-isAssume it carries a durable mark that survives copy-paste. Post it where AI assistance is fine, or rewrite it in your own voice.
Only proofread with ClaudeThe returned text can still carry the mark. Keep your drafts and timestamps; the mark proves processing, not authorship.
Grade, hire, or moderateNo public detector exists yet. Any product claiming to detect Claude’s watermark today is guessing.
Generate images with ClaudeThe C2PA label rides in metadata and vanishes on re-save, conversion, or screenshot, per Anthropic’s own docs.
Use the API or Claude CodeMarking applies there too, worldwide. The EU’s Article 50 even exempts “assistive” editing, so Anthropic is marking more than the law requires.
Can I turn off the Claude watermark?

No. Anthropic’s documentation describes no opt-out. Marking applies to new models across the Claude app, API, Claude Code, and cloud platforms, everywhere Claude is offered, and older models are being retrofitted.

Can a tool remove the Claude watermark from text?

No. The watermark lives in the word choices themselves, not in metadata, so nothing can strip it from finished text. Per Anthropic, the signal weakens only when text is heavily edited, paraphrased, translated, or mixed with other writing, and very short passages carry no reliable signal at all.

Does a detected mark prove the text was written by AI?

No. Anthropic states that text Claude merely proofread, translated, summarized, or converted can carry the mark, and that Claude may not be the original author. A mark proves Claude processed the text at some point, nothing more.

Does the watermark apply outside the EU?

Yes. The legal driver is EU AI Act Article 50, in force since August 2, 2026, but Anthropic applies marking globally, everywhere Claude is offered, rather than running separate versions per region.

Can teachers or platforms detect the watermark today?

Not yet. There is no public detector. Anthropic says detection details will come in forthcoming technical documentation. Until then, only Anthropic can verify a mark, and any third-party product claiming to detect it is guessing.

Try the tools ✦

Free browser tools that never upload your files.

Open Tools