Plain AI Daily

Claude's Text Watermark Explained: Can Anyone Tell You Used Claude?

By 8 min read

Anthropic says future Claude models will hide an invisible watermark inside the text they write, to comply with the EU AI Act. You cannot see it, it costs you nothing, and it carries nothing about you. It only shows Claude was probably involved, and only in longer passages.

If you have ever wondered whether anyone can tell that Claude wrote your email, Anthropic just answered it in more detail than any AI company has before. On August 14, 2026 it published how Claude's text watermark works, confirming that "future Claude models will generate text that contains a watermark." The reason is regulatory, not commercial: the EU now requires AI providers serving its market to mark AI-generated content, and Anthropic is applying the mark worldwide rather than only in Europe.

The practical news for you is mostly reassuring, with one caveat worth understanding. Nothing about Claude's writing changes, nothing is added to your text, and the mark says nothing about who you are. What it can eventually do is tell someone holding Anthropic's key that Claude was probably involved in a long piece of writing.

Key Takeaways

  • It is invisible and adds nothing to the text. Anthropic says "nothing is added to the text and there are no hidden characters." A watermarked reply reads identically to an unwatermarked one.
  • It cannot be traced to you. Anthropic states the watermark "carries no identifying information and can't be traced to a specific person, organization, or chat."
  • It is free and does not slow Claude down. No extra tokens are produced, so Anthropic says the model costs the same to use and runs at effectively the same speed.
  • It is not switched on for everything yet. The post covers "future Claude models." Anthropic says models launched before August 2, 2026 fall under an EU transition period and will get watermarking "over the coming months."
  • Nobody can check it today. Detection needs Anthropic's key. Anthropic says a watermark detection API is coming and that it is "in the process of working out the details."
  • It proves less than people assume. Anthropic is blunt: the watermark can only say Claude was "likely involved," and "cannot distinguish 'Claude wrote this' from 'Claude heavily edited this.'"
  • Short passages and code barely carry it. The mark lives in choices between equally good words, so facts, exact answers, and most code have little room for it.
  • This is an industry-wide change. Anthropic says it signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026 alongside roughly 190 signatories, and that other major model developers will implement their own watermarks.

What Is a Text Watermark, in Plain Terms?

It is a pattern hidden in Claude's word choices, not a mark stamped on the page. Anthropic's own explanation is unusually readable: a model writes one word at a time, and at each step several words would do the job equally well. In "the weather today was cold and...", both "overcast" and "grey" are fine, and normally a random number settles it. Watermarking replaces that randomness with a pattern generated from a secret key, so the sequence of words is still random-looking but is checkable afterwards by whoever holds the key.

Anthropic offers a board-game analogy that lands better than most technical writing: imagine a game of Monopoly where, instead of rolling dice, players read their moves off the digits of pi starting at a random point. The moves are still effectively random and the game plays the same, but afterwards, if you knew the digits, you could work out that this game used pi. The method itself is a version of SynthID-Text, which Anthropic says Google DeepMind published in a Nature paper in 2024, and which belongs to a family of approaches going back to a 2022 proposal by the researcher Scott Aaronson.

Is Your Claude Text Watermarked? What Actually Carries the Mark

Less of your writing than you would guess. The watermark can only live where Claude had a genuine choice between words that are equally good, so anything with one correct answer leaves it nothing to work with. Here is what Anthropic says about each case:

What you asked Claude to doIs it watermarked?What Anthropic says
Write something from scratchYes, most strongly"The more Claude writes, the more decisions it has to make, and the more space there is for a watermark"
Translate a documentYes"A translation produced by Claude carries a watermark, because in this case every word is chosen by Claude"
Proofread your own writingBarely, if at all"Nearly all the words are the person's, there's very little (if anything) for the watermark to attach to"
Fix grammar and punctuation onlyProbably notThe watermark "can only live in the handful of corrections, which might be too few to register"
Write factual or reference textSparselyWhere one word is the only right answer, "the watermark would have nothing to act on"
Write codeMostly notCode "has generally less watermarking"; comments inside code can carry it
A short replyToo short to detectDetection "doesn't work well on small samples"; confidence grows with length
Images and files (.png, .jpg, .svg)No watermark, a label insteadA C2PA content credential in the file's metadata, "not embedded or hidden"

The pattern to take away: the watermark tracks how much of the writing was Claude's, not whether you used Claude at all. Ask it to polish two paragraphs you wrote and there is essentially nothing to find. Ask it for a 1,500-word draft and there is.

Can Anyone Actually Tell You Used Claude?

Not right now, and even later the answer is a probability rather than a verdict. Checking the mark requires Anthropic's key, and Anthropic has not yet released the tool: it says only that it "will soon be offering a watermark detection API" and is still working out the implementation. Until that exists, no teacher, employer or editor can test text against Claude's watermark, whatever a detection service claims.

When it does exist, Anthropic is careful about what it will and will not answer:

Question someone might askCan the watermark answer it?
Was Claude likely involved in this text?Yes, as a likelihood, on a long enough passage
Did a human write this?No. It "doesn't confirm whether the text was human-written"
Was this written by a different AI?No. Another AI would use a different key or a different method
Did Claude write it, or just edit it heavily?No. It "cannot distinguish" the two
Who wrote it, or from which account?No. The watermark holds no identifying information
Does this change who owns the text?No. Anthropic says it "doesn't change a user's rights under our terms"

Worth separating from all of this: the AI-detector services people already run essays through, such as Pangram, do not work this way at all. Anthropic notes they have no key and instead look for stylistic tells, and it gives two amusing examples of what those tools hunt for -- the "this isn't X, it's Y" construction, and the word "quietly" appearing far more often than it should. That approach guesses from style. The watermark checks a signature. Only the second one is what Anthropic is building.

Does It Cost You Anything or Change the Writing?

No on both counts, and Anthropic has published evidence rather than just an assurance. It says internal testing showed "no impact of watermarking on the content, level of creativity, or readability of Claude's text," and that a watermarked reply is indistinguishable from an unwatermarked one to a reader. It also cites the original SynthID-Text research, in which Google DeepMind served a watermarked model to a slice of real Gemini traffic and found no statistically significant difference in thumbs-up and thumbs-down ratings, plus a controlled study where human raters comparing answers side by side saw no quality difference.

On price and speed, the mechanism does the arguing: because the watermark changes which word is chosen rather than adding words, no extra tokens are generated. Anthropic states plainly that "watermarking has a negligible impact on the speed of models, and because it produces no extra tokens, the model is the same price to serve and use." Nothing on your bill or your plan changes, whether you are on free Claude with Sonnet 5 or a paid tier.

Why Anthropic Is Doing This

Regulation, and it says so directly. Anthropic writes that it is "implementing watermarking to comply with the EU AI Act," having signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026 with around 190 total signatories. As of August 2, 2026, the EU requires AI providers serving its market to mark AI-generated content.

The detail most people will actually feel is geographic. Anthropic is switching this on for everyone, everywhere, not just for European users: "We're applying watermarking globally at launch because we don't yet have a durable way to scope it by region," adding that it will keep evaluating other approaches. So a rule written in Brussels is arriving in your chat window in Ohio or Osaka, and Anthropic expects company -- it says other major model developers that signed the same code "will be implementing their own watermarks."

Google is already ahead of it on the image side. Every image the Gemini app generates carries an invisible SynthID watermark plus a visible one, which is covered in our guide to Nano Banana and Gemini image generation. Text has been the gap, and this is the industry closing it.

Should You Care?

Barely, if you use Claude to help with your own writing. Editing, proofreading, brainstorming and short answers carry little or no watermark, nothing about you is recorded, and no tool exists today that could check. Carry on.

Yes, if you submit long AI-drafted text somewhere it is not allowed. A full draft written by Claude is exactly the case the watermark is built to catch, and Anthropic says light editing probably will not remove it. The honest reading is that AI-written coursework and AI-written applications get meaningfully more checkable in the next year than they were last year.

Worth watching, if you care about privacy. The commitment that the watermark holds no identifying information and cannot be tied to a person, organisation or chat is a strong one, and it is the claim to keep an eye on as the detection API actually ships.

Do not change what you pay for because of this. No plan gets a watermark-free Claude, no price moves, and every major provider is heading the same way. If you were weighing a subscription for other reasons, our guide to which AI chatbot is worth paying for covers what actually differs between them.

The bottom line: Claude's text watermark is a quiet, invisible change that costs you nothing, tells no one who you are, and cannot yet be checked by anybody. What it does is make heavily AI-written text traceable back to Claude in a way that stylistic guesswork never could. If your use of Claude is help rather than authorship, there is nothing here to worry about. If it is authorship, the era of nobody being able to tell is ending.

Keep up without the jargon

Frequently Asked Questions

Does Claude watermark everything it writes?

No. Anthropic says the watermark only attaches to words Claude itself chooses, and only where more than one word would work equally well. Facts, exact answers, most code and light proofreading of your own writing leave little or nothing for it to mark.

Can my teacher or my boss tell I used Claude?

Not yet, and not easily later. Checking the watermark needs Anthropic's key. Anthropic says it will offer a detection tool soon but has not launched one, and even then the result is a likelihood on a long passage, not proof about a short one.

Does the Claude watermark identify me personally?

No. Anthropic states the watermark carries no identifying information and cannot be traced to a specific person, organisation or chat. Nothing in the watermark or its key would let anyone recover who typed the prompt or what else was said in that conversation.

Does watermarking make Claude's writing worse or slower?

Anthropic says no on both counts. It reports no impact on content, creativity or readability in internal testing, and because the watermark adds no extra words, it produces no extra tokens, so it does not slow responses down or cost more to use.

Can I remove the watermark by editing the text?

Partly. Anthropic says light editing probably will not remove it completely, but a full rewrite that replaces every word will. It adds the obvious caveat: at that point it is arguable whether the text is still AI-generated at all.

What about images and files Claude makes?

Those get a different treatment. Anthropic says supported files such as .png, .jpg and .svg carry a C2PA content credential, a signed note in the file's metadata saying Claude made or processed it. Nothing inside the image changes, and it holds no personal information.

Do older Claude models watermark their text?

Not yet. Anthropic says the EU law gives a transition period for models launched before August 2, 2026, and that it is working to add watermarking to those models, rolled out over the coming months. It publishes no date.

Get the plain-English AI brief

One email. What changed in AI and what it means for you.