Claude Mastery Pro+ ~8 min read Updated · August 2026

Claude now marks everything it writes.

Quietly, and worldwide, Anthropic started embedding an invisible watermark in Claude’s text and signed provenance metadata in the files it generates. There is no opt-out, it applies wherever Claude is sold, and it is going to end up in a workplace conversation you should be ready for. Here is what is actually marked — and, just as important, what a detected mark does and does not prove.

01 What changed, in one paragraph

Anthropic has signed the EU AI Act’s Article 50(2) Code of Practice on Transparency of AI-Generated Content, as a provider of both generative AI models and generative AI systems. In practice: Claude models launched on or after August 2, 2026 support machine-readable marking at launch. Text gets an embedded watermark; supported generated files get digitally signed provenance metadata. Models released before that date sit in a transition period and are being retrofitted. Anthropic is not limiting this to Europe — the marks apply wherever Claude is offered, worldwide.

The part people miss

Marking happens at the model level, not at the app level. That means it does not matter whether the words came out of the Claude app, Claude Code, Claude Cowork, Claude Tag, the API, or a supported Claude model running on AWS, Google Cloud, or Microsoft Foundry. Same model, same mark. Some platforms and file types will not support every marking type, but you should assume text is marked by default rather than hunting for the surface that is not.

02 The two mechanisms

Mechanism one · text
An imperceptible watermark woven into the words. You cannot see it, and Anthropic says it does not change the meaning, quality, or readability of the response. Because it lives in the text itself rather than in a file wrapper, it travels with copy and paste — pasting Claude’s paragraph into Word, Slack, or your CMS carries it along — and it may survive some editing.
Mechanism two · files
Signed provenance metadata on generated files such as .svg, .png, and .jpg. This follows the C2PA open standard used across the industry. A signed label signals the file was processed by Claude and also lets you detect whether it has been tampered with since.
Coming · detection
Anthropic says it will support users and third parties in detecting its marks, as the Code requires, with technical documentation still forthcoming. So today the marks exist but the public detection tooling does not fully. Treat any product claiming to definitively detect “Claude text” right now with suspicion.

03 What a mark does not prove

This is the section to read twice, because the naive version of this story — “now we can catch people using AI” — is wrong in both directions, and Anthropic says so in its own documentation.

A detected mark is a signal, not a verdict. Claude is constantly used to proofread, translate, summarize, and convert work that a human wrote. All of that output can carry a mark while the ideas, the argument, and most of the sentences originated with a person. Content can also be edited, excerpted, or blended with other material after Claude touched it.

No mark is not an alibi either. Anthropic lists the ways marked content stops being detectable: it came from a model released before marking support; the text was heavily edited, paraphrased, translated, or mixed into other writing; the passage is simply too short to carry a reliable signal; a file’s metadata was stripped by format conversion, re-saving, or a screenshot; or the platform, feature, or file type did not support that marking type.

If your organisation is tempted to build a rule around this — “marked text will be treated as misconduct” — you are building it on a signal the vendor explicitly says is not fully conclusive, in either direction. That is a policy that will produce false accusations against your best translator and clean bills of health for the person paraphrasing everything.

04 What to actually do about it

The five-minute version

  • Assume the mark, then decide if you care. For 95% of work — drafts, internal notes, summaries, code comments — nothing changes. Marked text is not tainted text.
  • Know where it matters: academic submissions, legal filings, journalism, competitive tenders, and anywhere a client contract says human-authored. That is the short list worth a conversation, not a blanket policy.
  • Rewriting to defeat a watermark is a tell. If your process involves deliberately paraphrasing to strip a signal, the honest fix is disclosure, not laundering.
  • For images: if you need the C2PA metadata to survive, avoid re-saving through tools that strip metadata and never ship a screenshot of the original.
  • If you build on Claude: Anthropic is clear that you must independently assess what Article 50 requires of your product. Their marking supports your obligations; it does not discharge them.

05 The bigger frame

This is the first of these transparency obligations to land on a tool most knowledge workers actually use daily, and it will not be the last — Microsoft shipped watermarking for AI-generated content in Microsoft 365 Copilot on a similar timeline. The direction of travel is that AI-assisted work becomes traceable by default. The organisations that handle this well will be the ones that already decided, out loud, where AI assistance is fine and where it needs saying. If you have that conversation, the watermark is a non-event. If you do not, it will have the conversation for you.

Related reading in this track: Writing with Claude for the drafting workflow this now sits underneath, and Fable 5’s safeguards and your data for the rest of the data-and-policy picture.

Try it now

Pull up the last three things you sent that Claude helped with. For each, answer one question: would it matter to the recipient that AI was involved? The pieces where the answer is yes are your entire disclosure policy — write it down before someone asks. Open Claude →

This week’s challenge

Draft two sentences for your team: one naming where AI assistance is expected and unremarkable, one naming where it must be disclosed. Circulate them. You will have a better AI policy than most companies with a binder — and you will have written it before the tooling forced you to.

Questions people actually ask

Claude watermarking, answered

Does Claude watermark the text it writes?
Yes. Anthropic says Claude models launched on or after August 2, 2026 weave an imperceptible watermark directly into generated text. It is applied at the model level, so it is present no matter which Claude product the text came from, and it travels with the text when it is copied and pasted. Models released before that date are still being updated during a transition period.
Can I turn it off?
No. Anthropic’s documentation describes marking as applying to output from supported models everywhere Claude is offered, worldwide, and does not describe a user-facing opt-out. It also applies when supported Claude models are accessed through AWS, Google Cloud, or Microsoft Foundry.
Why is Anthropic doing this?
It has signed the EU AI Act’s Article 50(2) Code of Practice on Transparency of AI-Generated Content, as a provider of both generative AI models and generative AI systems. Rather than marking only European output, Anthropic says the marks apply wherever Claude is offered.
Does a detected watermark prove a document was written by AI?
No. Anthropic is explicit that a detected mark is a signal, not proof. Claude may only have proofread, translated, summarized, or converted work someone else wrote, and marked content can be edited or combined with other material afterwards. Equally, the absence of a mark does not prove content is human-written.
What about images and files?
Supported generated file types such as .svg, .png, and .jpg get signed provenance metadata following the C2PA open standard. That metadata signals the file was processed by Claude and lets you detect whether it has been tampered with. It can be stripped by format conversion, re-saving, or screenshotting.
Will the watermark survive if I edit the draft?
Sometimes. Anthropic says the watermark may persist through some editing because it is part of the text itself, but lists heavy editing, paraphrasing, translation, and very short passages among the reasons a mark may not be detectable.
Up next in Claude Mastery

Connector security: power, governed

What MCP connectors and Computer Use can actually reach, and the governance setup that makes the deep end safe to use. Read the lesson →