Claude is starting to leave machine-readable traces in text and image files. The missing detector matters as much as the mark.
Anthropic has documented a new Claude watermark and provenance system tied to the EU AI Act’s transparency code. New Claude models launched in the European Union on or after August 2, 2026 support marking from launch. The same supported models carry the marks worldwide, not only when a user is in Europe.
That is narrower than the claim circulating on social media that every current Claude answer is already watermarked. Anthropic says older models are still being moved through a transition. It also has not yet released the third-party detector or the documentation an auditor would need to test the signal independently.
Claude uses two different marking systems
Text and image files do not receive the same treatment. Supported text output gets an imperceptible model-level watermark. Anthropic says the signal survives ordinary copy and paste and may persist through some editing. Supported SVG, PNG, and JPEG files can receive signed C2PA provenance metadata.
| Output | Marking method | What may survive | Current limit |
|---|---|---|---|
| Text | Imperceptible model-level watermark | Copy and paste; some editing | Public third-party detection is not yet available |
| SVG, PNG, JPEG | Signed C2PA provenance metadata | File transfer when metadata remains intact | Metadata can be stripped by some workflows and platforms |
The distinction is operational. A publishing pipeline can preserve C2PA metadata by retaining the original file, but an image optimizer, screenshot, or social platform may remove it. Text has no file container to protect, so the signal must live in the output itself. Teams should not treat one successful test as proof that the other path works.
The rollout starts with new models, not every Claude answer
Anthropic connects the change to its signature on the EU AI Act Article 50(2) Code of Practice on Transparency. New models introduced in the EU after the August 2 date are expected to support machine-readable marking at launch. Existing models are being handled during a transition.
The company lists Claude, Claude Code, Cowork, Tag, the Anthropic API, and supported cloud-partner deployments in its coverage explanation. For text watermarks, that partner list includes Amazon Web Services, Google Cloud, and Microsoft Foundry where the supported model and integration preserve the mark.
The safe product claim is “supported new models carry machine-readable marks,” not “all Claude content is detectable.”
A positive result would not prove authorship
Anthropic is explicit about a subtle limitation: detection could indicate that content was processed by Claude, not that Claude originated every idea or sentence. A human draft sent through Claude for proofreading, translation, summarization, or restructuring could leave the same signal.
That makes the mark a provenance clue, not an authorship verdict. It should never be used alone to accuse a student, employee, contractor, or publisher of passing off generated work as human. The right question is what the system observed, with which model, at what confidence, and whether the surrounding record supports the conclusion.
This is the same evidence problem behind the California AI transparency law and the EU AI Act labeling rules for creators: a technical signal can support disclosure, but it cannot replace context and due process.
The detector gap blocks independent auditing
At publication time, Anthropic says third-party detection tools and technical documentation are still to come. That means an outside researcher cannot yet run a clean public test across models, edits, languages, formats, and delivery surfaces.
The useful benchmark will not be a single “Claude or not” score. It should measure at least four things: detection after ordinary editing, false positives on human text, false negatives after aggressive rewriting, and whether benign uses such as translation are distinguishable from full generation. Results should also be broken out by model and language. One global accuracy number would hide the failure modes that matter.
What publishers and developers should log now
- Record the exact model. “Claude” is not enough during a staggered rollout. Store the model identifier and date.
- Keep the original artifact. Preserve source image files and metadata before resizing, compression, or social distribution.
- Separate generation from editing. Log whether Claude wrote, translated, summarized, proofread, or merely formatted the material.
- Do not automate punishment. Require human review and corroborating evidence before a detector result triggers a consequential decision.
- Retest each delivery path. Copy-paste, CMS cleanup, image optimization, screenshots, and platform uploads can affect different marks.
Publishers should continue making visible disclosures when context requires them. Machine-readable provenance is useful for tools and platforms, but it is not a reader-facing explanation. Our report on a disclosure label disappearing as filtered media travelled shows why the visible and technical layers both matter.
My verdict: useful infrastructure, incomplete evidence
Anthropic’s marking plan is more serious than a decorative “made with AI” badge. It addresses text at the model level and image files through a standard provenance format. Applying the supported marks worldwide also avoids a confusing Europe-only split.
But a mark without an inspectable detector is not yet an accountability system. Until Anthropic publishes the tools, confidence guidance, and failure data, treat the Claude watermark as a future audit signal. Do not treat it as proof of authorship, and do not promise customers that every current Claude output can be identified.
Read the primary source
- Read Anthropic’s official explanation of Claude’s machine-readable content marking.
- Review the European Commission’s Code of Practice on marking and labelling AI-generated content.
Would your organization use a watermark result as a clue, or has it quietly become a verdict?
Checked August 11, 2026. Rollout scope, supported surfaces, marking methods, and detection limitations come from Anthropic’s support documentation. Independent detector performance was not available at publication time.