Plain AI Daily

Claude's Text Watermark Explained: Can Anyone Tell You Used Claude?

By 17 min read

Anthropic hides an invisible watermark in the text Claude writes, to comply with the EU AI Act. It costs you nothing and carries nothing about you. As of September 28, 2026 five models mark their text, and the newest of them, Sonnet 5.5, is on the free plan. Every listed model tags the files it generates. The rest are due by December 2, 2026.

If you have ever wondered whether anyone can tell that Claude wrote your email, Anthropic has answered it in more detail than any AI company has before. On August 14, 2026 it published how Claude's text watermark works, confirming that Claude models will generate text containing an invisible watermark. The reason is regulatory, not commercial: the EU now requires AI providers serving its market to mark AI-generated content, and Anthropic is applying the mark worldwide rather than only in Europe.

The list has grown, and it now has a deadline. Anthropic revised its help centre article on marking on September 16, 2026, added an Opus 5.5 row on September 22, 2026, and a Sonnet 5.5 row on September 28, 2026. That last one is the first time a watermarked model has been available on the free plan: Fable 5.1, Mythos 5.1, Opus 5, Opus 5.5 and Sonnet 5.5 watermark their text, and every model on Anthropic's list attaches a Content Credential to files it generates -- including Sonnet 5, Haiku 4.5 and the whole 4.x range. Anthropic also set an end date for the rest: models released before August 2, 2026 will be covered "with all covered by December 2, 2026."

The practical news for you is still mostly reassuring. Nothing about Claude's writing changes, nothing is added to your text, and the mark says nothing about who you are.

Key Takeaways

  • Five models watermark their text, and the newest is free. Anthropic's model table marks Fable 5.1, Mythos 5.1, Opus 5, Opus 5.5 and, since September 28, 2026, Sonnet 5.5. Sonnet 5, Sonnet 4.6, Sonnet 4.5, Haiku 4.5, Fable 5, Mythos 5 and the Opus 4.x models are not marked yet.
  • Files are a different story: every model on the list tags them. All 15 models in Anthropic's table carry Content Credentials (C2PA) on generated files, Sonnet 5 and Haiku 4.5 included. If Claude made you an image, it is tagged whichever model you were on.
  • There is now a deadline: December 2, 2026. Anthropic says it is adding watermarks to output from models released before August 2, 2026, "with all covered by December 2, 2026." That is the first date it has published for the older models.
  • Opus 5 on AWS, Google Cloud and Microsoft Foundry started September 14, 2026. Anthropic's footnote: text watermarking there "will be gradually available on cloud partner surfaces starting September 14, 2026 and fully available within one week."
  • Detection exists now, in private preview. Since September 1, 2026 Anthropic has run a detection API for "eligible organizations as required under EU law" -- regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations and EU civil society groups -- plus enterprises with their own compliance obligation.
  • For files there is a free public checker. claude.com/check-files reads a file's content credential in your browser. Anthropic says "your file stays on your device" and "is never stored." It does not check text.
  • It is invisible and adds nothing to the text. Anthropic says "nothing is added to the text and there are no hidden characters." A watermarked reply reads identically to an unwatermarked one.
  • It cannot be traced to you. Anthropic states the watermark "carries no identifying information and can't be traced to a specific person, organization, or chat."
  • It is free and does not slow Claude down. No extra tokens are produced, so Anthropic says the model costs the same to use and runs at effectively the same speed.
  • It proves less than people assume. Anthropic is blunt: the watermark can only say Claude was "likely involved," and "cannot distinguish 'Claude wrote this' from 'Claude heavily edited this.'"
  • Short passages and code barely carry it. The mark lives in choices between equally good words, so facts, exact answers, and most code have little room for it.
  • This is an industry-wide change. Anthropic says it signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026 alongside roughly 190 signatories, and that other major model developers will implement their own watermarks.

Which Claude Models Are Watermarked Today

Five for text, and all of them for files. Anthropic replaced its one-line "currently supported" sentence with a three-column table on September 16, 2026, added a row for Claude Opus 5.5 on September 22, 2026, and a row for Claude Sonnet 5.5 on September 28, 2026. The columns matter: marking text and marking files are separate commitments with separate coverage. Here is the table as Anthropic publishes it, read September 28, 2026:

ModelText watermark, Claude's own appsText watermark via AWS / Google Cloud / Microsoft FoundryContent Credentials on files
Claude Fable 5.1YesYesYes
Claude Mythos 5.1YesYesYes
Claude Opus 5.5YesYesYes
Claude Opus 5YesYes, from September 14, 2026Yes
Claude Sonnet 5.5YesYesYes
Claude Fable 5NoNoYes
Claude Mythos 5NoNoYes
Claude Opus 4.8NoNoYes
Claude Opus 4.7NoNoYes
Claude Opus 4.6NoNoYes
Claude Opus 4.5NoNoYes
Claude Sonnet 5NoNoYes
Claude Sonnet 4.6NoNoYes
Claude Sonnet 4.5NoNoYes
Claude Haiku 4.5NoNoYes

Anthropic's own footnote on the Opus 5 cloud-partner cell: text watermarking there "will be gradually available on cloud partner surfaces starting September 14, 2026 and fully available within one week." A "No" above is an empty cell in Anthropic's table rather than a written denial, and Anthropic pairs the table with a commitment rather than a gap: it is adding watermarks to models released before August 2, 2026 "with all covered by December 2, 2026."

The practical reading for an ordinary Claude user changed again with this revision. If you are on Pro, Max, Team or Enterprise and you type into Claude, you are often talking to Opus 5 or Opus 5.5, and both mark what they write. The free plan is no longer the exception. Anthropic says anyone can use Sonnet 5.5 on Claude.ai, and Sonnet 5.5 marks its text, so a free user who selects it is now writing watermarked text. A free user still on Sonnet 5 is not: that model marks files only, and has until December 2, 2026 before it must do more. Since Anthropic has not said which Sonnet is the default, the model menu next to the send button is the only way to know which of the two you are on. And if you asked Claude for an image or a file on any plan, that file is tagged today.

Where the Marking Applies

Everywhere Claude runs, once a model supports it, because the watermark is applied by the model rather than by the app. Anthropic's help centre lists the surfaces: "Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag," and adds that when supported models are reached "through AWS, Google Cloud, or Microsoft Foundry they will carry watermarks."

That has one consequence worth spelling out. Anthropic says watermarking "will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from," and that because the mark is part of the text, "it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing." There is no per-app setting and no per-region setting: marking applies "wherever Claude is offered, worldwide."

What Is a Text Watermark, in Plain Terms?

It is a pattern hidden in Claude's word choices, not a mark stamped on the page. Anthropic's own explanation is unusually readable: a model writes one word at a time, and at each step several words would do the job equally well. In "the weather today was cold and...", both "overcast" and "grey" are fine, and normally a random number settles it. Watermarking replaces that randomness with a pattern generated from a secret key, so the sequence of words is still random-looking but is checkable afterwards by whoever holds the key.

Anthropic offers a board-game analogy that lands better than most technical writing: imagine a game of Monopoly where, instead of rolling dice, players read their moves off the digits of pi starting at a random point. The moves are still effectively random and the game plays the same, but afterwards, if you knew the digits, you could work out that this game used pi. The method itself is a version of SynthID-Text, which Anthropic says Google DeepMind published in a Nature paper in 2024, and which belongs to a family of approaches going back to a 2022 proposal by the researcher Scott Aaronson.

Is Your Claude Text Watermarked? What Actually Carries the Mark

Less of your writing than you would guess. The watermark can only live where Claude had a genuine choice between words that are equally good, so anything with one correct answer leaves it nothing to work with. Here is what Anthropic says about each case:

What you asked Claude to doIs it watermarked?What Anthropic says
Write something from scratchYes, most strongly"The more Claude writes, the more decisions it has to make, and the more space there is for a watermark"
Translate a documentYes"A translation produced by Claude carries a watermark, because in this case every word is chosen by Claude"
Proofread your own writingBarely, if at all"Nearly all the words are the person's, there's very little (if anything) for the watermark to attach to"
Fix grammar and punctuation onlyProbably notThe watermark "can only live in the handful of corrections, which might be too few to register"
Write factual or reference textSparselyWhere one word is the only right answer, "the watermark would have nothing to act on"
Write codeMostly notCode "has generally less watermarking"; comments inside code can carry it
A short replyToo short to detectDetection "doesn't work well on small samples"; confidence grows with length
Images and files (.png, .jpg, .svg)No watermark, a label insteadA C2PA content credential in the file's metadata, "not embedded or hidden," checkable free at claude.com/check-files

The pattern to take away: the watermark tracks how much of the writing was Claude's, not whether you used Claude at all. Ask it to polish two paragraphs you wrote and there is essentially nothing to find. Ask it for a 1,500-word draft and there is.

Can Anyone Actually Tell You Used Claude?

Some organisations can, since September 1, 2026, and the answer they get is a probability rather than a verdict. Anthropic now says it is "releasing a detection API in private preview." Checking text still requires Anthropic's key, so a general-purpose "is this Claude?" website is not what shipped -- this is an application-gated API with a named eligibility list.

Who can get access todayAnthropic's wording
Regulators and law enforcement"eligible organizations as required under EU law"
Media and fact-checkersNamed in the same list
Independent researchersNamed in the same list
Educational organisationsNamed in the same list
EU civil society groupsNamed in the same list
Enterprises with their own EU obligation"enterprises who are similarly obligated to verify watermarking for their own compliance with the Act"
Everyone elseNot yet. Anthropic says it "plans to expand access to the detection API over time" and takes registrations of interest

Files are the exception, and there the tool is free and public. Anthropic runs a Claude Content Checker at claude.com/check-files where you drop a file and it reads the content credential. Its own description of what happens: "Your file stays on your device," "the checker only reads the attached credential, not the file itself," and "your file is never stored or used for any other purpose." It only works on files. As Anthropic puts it on that page: "The tool does not check text."

When someone does run text through the detection API, Anthropic is careful about what it will and will not answer:

Question someone might askCan the watermark answer it?
Was Claude likely involved in this text?Yes, as a likelihood, on a long enough passage
Did a human write this?No. It "doesn't confirm whether the text was human-written"
Was this written by a different AI?No. Another AI would use a different key or a different method
Did Claude write it, or just edit it heavily?No. It "cannot distinguish" the two
Who wrote it, or from which account?No. The watermark holds no identifying information
Does this change who owns the text?No. Anthropic says it "doesn't change a user's rights under our terms"

Worth separating from all of this: the AI-detector services people already run essays through, such as Pangram, do not work this way at all. Anthropic notes they have no key and instead look for stylistic tells, and it gives two amusing examples of what those tools hunt for -- the "this isn't X, it's Y" construction, and the word "quietly" appearing far more often than it should. That approach guesses from style. The watermark checks a signature. Only the second one is what Anthropic is building.

Does It Cost You Anything or Change the Writing?

No on both counts, and Anthropic has published evidence rather than just an assurance. It says internal testing showed "no impact of watermarking on the content, level of creativity, or readability of Claude's text," and that a watermarked reply is indistinguishable from an unwatermarked one to a reader. It also cites the original SynthID-Text research, in which Google DeepMind served a watermarked model to a slice of real Gemini traffic and found no statistically significant difference in thumbs-up and thumbs-down ratings, plus a controlled study where human raters comparing answers side by side saw no quality difference.

On price and speed, the mechanism does the arguing: because the watermark changes which word is chosen rather than adding words, no extra tokens are generated. Anthropic states plainly that "watermarking has a negligible impact on the speed of models, and because it produces no extra tokens, the model is the same price to serve and use." Nothing on your bill or your plan changes, whether you are on free Claude with Sonnet 5 or a paid tier.

Why Anthropic Is Doing This

Regulation, and it says so directly. Anthropic writes that it is "implementing watermarking to comply with the EU AI Act," having signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026 with around 190 total signatories. As of August 2, 2026, the EU requires AI providers serving its market to mark AI-generated content.

The detail most people will actually feel is geographic. Anthropic is switching this on for everyone, everywhere, not just for European users: "We're applying watermarking globally at launch because we don't yet have a durable way to scope it by region," adding that it will keep evaluating other approaches. So a rule written in Brussels is arriving in your chat window in Ohio or Osaka, and Anthropic expects company -- it says other major model developers that signed the same code "will be implementing their own watermarks."

Google is already ahead of it on the image side. Every image the Gemini app generates carries an invisible SynthID watermark plus a visible one, which is covered in our guide to Nano Banana and Gemini image generation. Text has been the gap, and this is the industry closing it.

Should You Care?

Barely, if you use Claude to help with your own writing. Editing, proofreading, brainstorming and short answers carry little or no watermark, and nothing about you is recorded. One thing did change on September 16: if you are on a paid plan and using Opus 5, your text is now marked, where a week ago it was not. The same is true of Opus 5.5 from its first day, September 22, 2026.

Yes, if you submit long AI-drafted text somewhere it is not allowed. A full draft written by Claude is exactly the case the watermark is built to catch, Anthropic says light editing probably will not remove it, and detection is no longer hypothetical -- it is a shipped API with educational organisations on the eligibility list. AI-written coursework got meaningfully more checkable on September 1.

Yes, if you receive files and need to know where they came from. claude.com/check-files is free, needs no account, and does the check in your browser. That is a genuinely useful tool for anyone handling images they did not make.

Worth watching, if you care about privacy. The commitment that the watermark holds no identifying information and cannot be tied to a person, organisation or chat is a strong one, and it is the claim to keep an eye on now that the detection API is live rather than promised.

Do not change what you pay for because of this. No plan gets a watermark-free Claude, no price moves, and every major provider is heading the same way. If you were weighing a subscription for other reasons, our guide to which AI chatbot is worth paying for covers what actually differs between them.

The bottom line: Claude's text watermark costs you nothing and tells no one who you are, but it is no longer unverifiable and no longer rare. Four models mark their text, including Opus 5 and Opus 5.5 on every paid plan; every listed model tags the files it makes; and Anthropic has committed to covering the rest by December 2, 2026. If your use of Claude is help rather than authorship, there is nothing here to worry about. If it is authorship, the era of nobody being able to tell has already ended.

Sources

Corrections and Updates

September 28, 2026: this page said that if you are on Free "you are talking to Sonnet 5, which does not mark text yet." Anthropic added a fifteenth row, Claude Sonnet 5.5, on September 28, 2026, ticked in all three columns -- and it says anyone can use Sonnet 5.5 on Claude.ai, so a free user who selects it does write watermarked text. Five models now mark text. Summary, Key Takeaways, two FAQ answers, the model table and the free-plan paragraph corrected.

September 22, 2026: this page said three Claude models watermark their text and that Anthropic's table listed 13 models. Anthropic added a fourteenth row, Claude Opus 5.5, on September 22, 2026, ticked for text watermarks on its own surfaces and on cloud partners and for Content Credentials on files. Four models now mark text.

September 17, 2026: this page said Opus 5 was not watermarked and that "the everyday Claude you use is probably not watermarked yet." Both are now wrong. Anthropic revised its marking article on September 16, 2026 and replaced its two-model sentence with a table that marks Opus 5 for text watermarks, adds cloud-partner coverage for it "starting September 14, 2026," gives Content Credentials on generated files to all 13 listed models including Sonnet 5 and Haiku 4.5, and sets a deadline of December 2, 2026 for every model released before August 2, 2026. The summary, Key Takeaways, two FAQ answers, the model table and the closing verdict were corrected in this edit.

September 8, 2026: this page said nobody could check a Claude watermark. That stopped being true a week ago. It read "Nobody can check it today" and "Anthropic has not yet released the tool," citing Anthropic's original wording that it "will soon be offering a watermark detection API." Anthropic amended that post in place on September 1, 2026 -- the note at its foot reads "Provided up to date information on the watermarking detection API" -- and it now says: "We are releasing a detection API in private preview." Access is gated to regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations, EU civil society groups and enterprises with their own EU compliance obligation. The summary, Key Takeaways, two FAQ answers, the detection section and the closing verdict were all corrected in this edit.

September 8, 2026: this page did not say which models are watermarked. It repeated Anthropic's launch phrasing, "future Claude models," which is not an answer for a reader asking whether their own chat is marked. Anthropic's help centre now names them: "Models currently supported include Fable 5.1 and Mythos 5.1." A new model table was added, and the older-models FAQ now points out that Sonnet 5 (June 30, 2026) and Opus 5 (July 24, 2026) both launched before Anthropic's August 2, 2026 cutoff and so sit in the transition group.

September 8, 2026: a free public checker for files exists and this page missed it. The page said only that Anthropic would be "providing our own" tool. It has: claude.com/check-files, which reads a file's content credential in the browser without uploading it.

Keep up without the jargon

Frequently Asked Questions

Does Claude watermark everything it writes?

Not yet, but nearly. Anthropic's table marks Fable 5.1, Mythos 5.1, Opus 5, Opus 5.5 and Sonnet 5.5 for text watermarks; Sonnet 5 and the 4.x models are not marked yet. It says all models released before August 2, 2026 will be covered by December 2, 2026.

Can my teacher or my boss tell I used Claude?

It is now possible in principle, which it was not in August. Anthropic's detection API is in private preview, and its eligible list names educational organisations. You have to apply, access is granted for EU compliance reasons, and the result is a likelihood on a long passage.

Does the Claude watermark identify me personally?

No. Anthropic states the watermark carries no identifying information and cannot be traced to a specific person, organisation or chat. Nothing in the watermark or its key would let anyone recover who typed the prompt or what else was said in that conversation.

Does watermarking make Claude's writing worse or slower?

Anthropic says no on both counts. It reports no impact on content, creativity or readability in internal testing, and because the watermark adds no extra words, it produces no extra tokens, so it does not slow responses down or cost more to use.

Can I remove the watermark by editing the text?

Partly. Anthropic says light editing probably will not remove it completely, but a full rewrite that replaces every word will. It adds the obvious caveat: at that point it is arguable whether the text is still AI-generated at all.

What about images and files Claude makes?

Every model on Anthropic's list now tags them, and you can check them yourself for free. Supported files such as .png and .jpg carry a C2PA content credential in the metadata. Anthropic's Claude Content Checker at claude.com/check-files reads it in your browser without uploading the file.

Do older Claude models watermark their text?

Opus 5 and Opus 5.5 both do, and Sonnet 5.5 joined them on September 28, 2026. Anthropic marks each new model from launch, and Opus 5 for cloud partners since September 14, 2026. Sonnet 5, Sonnet 4.6, Sonnet 4.5, Haiku 4.5 and the Opus 4.x models are not marked yet.

Get the plain-English AI brief

One email. What changed in AI and what it means for you.