Claude models launched on or after Aug. 2 embed an invisible mark in everything they write. It’s woven into the text itself, so it travels when you copy and paste. You didn’t opt in, you can’t see it, and you can’t turn it off.
Anthropic confirmed on Tuesday that it’s watermarking Claude’s output and published a support page with the details. The trigger is Article 50 of the EU AI Act, which took effect August 2, along with the Code of Practice on Transparency of AI-Generated Content. About 190 organizations signed the code, though only 82 signed the section that covers marking. Anthropic, Google, OpenAI, Meta, Microsoft and Mistral are on that list.
The rule was written in Brussels, but the effect lands on anyone using Claude anywhere.
Here’s how text watermarking works. When Claude writes a sentence, it’s constantly choosing among words that would all work fine. The watermark tilts those choices toward a pattern Anthropic’s software can recognize. Nothing is hidden between the letters or in the spaces. The pattern is the word choices, which is why it survives copy and paste.
Until now, a claim that you used AI rested on a hunch or on a style detector that guesses from tone and rhythm. This is different: a statistical test with a computable error rate.
Two things follow. First, a single sentence is too short to mark. Second, and this one the internet got wrong: when I ask Claude to fix the punctuation in a paragraph I wrote, Claude has to reproduce my words, so there’s nowhere to put a watermark.
Radio host Erick Erickson announced that he’d “ditched Grammarly for Claude for proofreading,” and now his own writing “will be watermarked that Claude did the work.” Depending on the extent of Claude’s input, he could be safe, because minor proofreading edits (i.e., punctuation) don’t make room for a watermark.
Watermarking text raises several issues, though. A mark means Claude modified the text, not that Claude wrote it. Have it summarize or condense a memo you wrote yourself and it comes back marked, though every idea in it is yours. Beatrice Nolan noted in Fortune that a flat AI label treats someone generating a thousand fake news videos the same as a writer cleaning up a paragraph. Worse, the absence of a mark proves nothing. The results of older models, and other non-marking models, all come back “clean.”
Removal is harder than the workaround crowd assumes. Paraphrasing degrades the signal but rarely erases it, because a rewrite keeps enough of the original wording to rebuild the statistic. Researchers who tested this on similar schemes found watermarks still detectable after a strong human paraphrase, once there was enough text to work with.
Anthropic hasn’t shipped a detector. Yet. It hasn’t published a false positive rate, and hasn’t said how many words it takes. The mark is going into text that no one outside the company can read, but the marks are still consequential because they don’t expire. The essay a college freshman turns in this fall is still marked when she’s a junior and someone finally has a tool to read it.
Technical problems aside, it’s important to highlight the core problem that watermarks aim to solve. Chris Best, Substack’s CEO, put it eloquently in the July post that coined Claudefishing:
“The core problem is not people using AI, or the quality of its output. Not everything made with AI is slop, and not all slop is made with AI. The problem is when there is a mismatch between a reader’s expectation and reality, especially when they unwittingly invest their attention in something with no human thought on the other end. That’s Claudefishing.”
That’s a harm worth addressing, and it’s the one a watermark can’t reach. A mark can’t tell slop from careful work. It tells you a model was involved. What that means depends on how it was used.
Personally, I use Claude and have mixed feelings about watermarks. On the one hand, AI use should be disclosed appropriately. On the other hand, anyone determined to hide their AI use can still do so by using xAI (no watermark on Grok), or open-weight models that carry no watermarks. So what impact will the mark have in practical terms?
My conclusion is to judge the outcome, not the tool. I used Claude extensively in writing and researching this column, as I described in AI coach or AI ghostwriter, and I’m pleased with the result. Where do you stand?
Read the full article here

