
Anthropic has now explained how Claude’s coming text watermark will work, and the update is useful because it clears up some of the confusion around AI detection, privacy and what a watermark can actually prove.
In a new technical explainer, Anthropic says future Claude models will generate text that carries a statistical watermark. The company is doing this to comply with the EU AI Act and the General-Purpose AI Code of Practice, which now requires major AI providers serving the European market to mark AI-generated content.
The important detail is that Claude is not adding visible labels, hidden characters or extra metadata inside normal text. Anthropic says the watermark works by changing the source of randomness used when Claude chooses between words that are already equally reasonable. To a reader, the output should look the same. To someone with the correct detection key, the pattern can help estimate whether Claude was likely involved in writing the text.
That means this is very different from a watermark on an image or a document. It is not a stamp in the corner. It is also not a tracking code that points back to a specific user. Anthropic says the watermark carries no identifying information and cannot be traced to a person, organization or chat.
That privacy point matters. Some users hear AI watermark and immediately think every Claude output will carry a personal tag. Anthropic is saying that is not how its system works. The watermark is meant to identify likely model involvement, not the user behind the prompt.
The company also says the watermark will not make Claude slower or more expensive because it does not require extra tokens. It says internal testing found no practical impact on output quality, creativity or readability. Anthropic also points to Google’s SynthID-Text research, which tested a similar approach with Gemini traffic and found no statistically significant difference in user ratings.
There are limits, and Anthropic is unusually clear about them. The watermark works better on longer passages because there are more word choices to analyse. It is weaker on short text, heavily factual passages, proofreading tasks and code, where there may be fewer safe alternatives for the model to choose from. A complete rewrite can also remove much of the signal.
That is why the phrase likely involved is doing a lot of work here. A Claude watermark cannot prove that a human did not write something. It cannot prove that another AI system did not write it. It cannot distinguish between Claude writing a full essay and Claude heavily editing a human draft. It only helps answer whether Claude was probably involved at some point.
This is an important follow-up to the broader Claude watermark story, where the EU’s new rules were already pushing AI companies toward content marking. The update makes the trade-off clearer. Regulators want transparency, companies want a method that does not ruin output quality, and users want reassurance that watermarking does not become surveillance.
The EU context is also important. The European Commission’s General-Purpose AI Code of Practice is meant to help model providers comply with AI Act obligations around transparency, copyright and safety. Anthropic, Google, Microsoft, OpenAI and others are listed as signatories, which means Claude’s watermark is likely only one part of a wider industry shift.
We are already seeing that shift across media types. Google is keeping invisible SynthID and C2PA signals even as it lets users remove some visible AI watermarks from generated media, a shift we also explored in Google’s own watermark debate. Claude’s text watermark sits in that same trust debate: should AI content be marked in a way people can see, or in a way machines can verify?
There is no perfect answer yet. Visible labels are easy for readers but can be ugly, removable or politically sensitive. Invisible watermarks are cleaner, but they require detection tools and public trust in the company holding the key. AI detection software has also had a messy history, especially when schools, employers or platforms use it too confidently.
Anthropic says it will soon offer a watermark detection API. That will be the next practical test. If only Anthropic can reliably check the watermark, the system may be useful for formal verification but less useful for ordinary readers. If broader tools can check it safely, watermarking could become part of a more mature AI provenance system.
For now, the takeaway is simple. Claude’s watermark is not a visible label, not a user tracker and not a magic lie detector. It is a statistical signal designed to help identify likely Claude involvement in longer AI-generated text. That may be useful, but it will need careful handling, especially in schools, journalism, legal work and workplaces where a false accusation can do real harm.







