Does Claude Watermark Its Text? How the Watermark Works and What It Means for You
6 October 2026 · 7 minute read
Yes. Since mid-August 2026, Claude watermarks the text it writes. The watermark is invisible: a secret key nudges some of Claude's word choices, so the text carries a statistical pattern that Anthropic's detector can recognise and a reader cannot see. It applies in the Claude apps, Claude Code, Claude Cowork, Claude Tag and the API, in every region, and there is no opt-out. Only approved organisations can run the detector, and Anthropic's free checker at claude.com/check-content examines files, not text.
When did Anthropic start watermarking Claude's text?
Anthropic announced the watermark in mid-August 2026 (press coverage began on 11 August) and published a detailed explainer dated 14 August 2026, updated on 1 September with details of the detection API. The trigger was regulation: in July 2026 Anthropic signed the EU Code of Practice on Transparency of AI-Generated Content, which asks AI providers to mark AI-generated text.
The watermark is not limited to Europe. In Anthropic's words: "We're applying watermarking globally at launch because we don't yet have a durable way to scope it by region." New models ship with it and older ones are being added in stages. According to heise, Fable 5, Sonnet 5 and Opus 4.8 began marking their output on 30 September 2026, and the remaining older models follow by 2 December, which lines up with the end of the EU grace period for existing AI systems.
How does Claude's text watermark work?
Claude writes one word at a time, and at many points several words would do equally well: "begin" or "start", "also" or "as well". Normally a random number settles each of those choices. With the watermark, Anthropic explains, "Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick."
A single choice means nothing. Over hundreds of words, the choices add up to a pattern that is very unlikely to happen by chance, and anyone holding the key can test for it. Without the key the text simply reads normally. It is the same broad idea as Google DeepMind's SynthID Text. Because the mark lives in the wording itself, it is not metadata and not a property of a file: it travels with the words wherever they are pasted.
| Kind of text | What to expect | What Anthropic says |
|---|---|---|
| Long prose (articles, emails, essays) | Carries the pattern; more words give a detector more to work with | The low-stakes choices it uses "occur many times over a piece of generated text" |
| Short text (a caption, a headline) | Carries it, but hard to detect | "Detecting a watermark also doesn't work well on small samples" |
| Factual passages | Sparser | Fewer word choices can be steered "without decreasing the accuracy of the text" |
| Code | Generally less | Code "in very many cases has to be exact"; comments can carry it |
| Translations by Claude | Carries it | Because "every word is chosen by Claude" |
Which Claude products and models carry the watermark?
Anthropic's help article on marking AI-generated content lists the Claude Platform (API), Claude, Claude Code, Claude Cowork and Claude Tag, in all regions, plus Claude models served through cloud partners (Amazon Bedrock, Google Cloud and Microsoft Foundry). There is no plan setting or API parameter that turns it off. Whether your text is marked depends on the model that wrote it. As of 6 October 2026:
| Model | Text watermark |
|---|---|
| Fable 5.1, Mythos 5.1, Opus 5.5, Opus 5, Sonnet 5.5 | Yes |
| Fable 5, Opus 4.8, Sonnet 5 | Yes (rollout on Amazon Bedrock completes by 12 October) |
| Mythos 5, Opus 4.7, Opus 4.6, Opus 4.5, Sonnet 4.6, Sonnet 4.5, Haiku 4.5 | Not yet; older models are due by 2 December |
Anthropic updates the table in its help article as models are added, so check there for the latest status.
Is edited Claude text still watermarked?
Usually, yes. Anthropic's own answer is short: "Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will." A Claude draft you have tidied up is still mostly Claude's word choices, so it can still carry a detectable signal. Text you write yourself carries none, because the watermark marks Claude's writing, not yours.
Detection has limits on the other side too. It works poorly on short samples and less well on factual writing, so a few sentences give a detector little to go on. Researchers have also pointed out that watermarks like this one can in principle be imitated (so-called spoofing). A detection result is statistical evidence, not proof, and it is best read alongside other context.
How can you check whether text was written by Claude?
Right now, most people cannot. Anthropic's watermark detection API is in private preview for a limited list of organisations: regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations and EU civil society groups, plus enterprises that need to verify content for their own compliance. Anthropic says it plans to expand access over time and runs an interest form, but as of 6 October 2026 there is no public text checker.
The free tool at claude.com/check-content answers a different question. It looks for a C2PA Content Credential, a signed label Claude attaches to image, video and audio files it produces, and it runs in your browser. Its own page is plain about the limit: "The tool does not check text." General AI detectors, which guess from writing style, are not Anthropic's watermark detector either. For files and designs, see whether Claude Design exports carry content credentials.
What does the EU AI Act have to do with it?
Article 50 of the EU AI Act, the transparency rules, has applied since 2 August 2026. It requires providers of generative AI to mark their output in a machine-readable way. The European Commission's FAQ on Article 50 gives systems already on the market before that date a grace period, so the marking duty applies to them "only as from 2 December 2026", and says that "Content generated prior to 2 August 2026 does not need to be labelled retroactively."
Breaches of the transparency rules can draw fines of up to EUR 15 million or 3% of global turnover, according to Clayton Utz. The marking duty sits with the provider (Anthropic, here), which is why the watermark is built into the model rather than offered as a setting. Other large AI providers reportedly signed the same code of practice, so marked AI text is not unique to Claude.
What does the watermark mean for marketers, students and businesses?
Marketers and freelancers
Copy that Claude drafts carries the pattern, and light editing probably leaves it detectable. Most readers and clients have no way to check text for it today, but media organisations, regulators and enterprises with compliance duties can apply for detector access. The practical answer is the one that applied before August: follow any AI-disclosure terms in your client contracts and be open about how copy was produced.
Students
Educational organisations are on Anthropic's list of eligible detector users, so an institution may be able to check submitted work. Follow your course's AI policy and declare any use. Two points matter if you write in a second language: a translation Claude produces does carry the watermark, and the public worry after launch, reported by TechCrunch, was exactly about people who use Claude to proofread or translate being wrongly flagged. If a result is ever raised with you, it is fair to ask which tool produced it.
Businesses and developers
Text your product generates through the Claude API is watermarked too, including on cloud partners, and there is no switch to turn it off. Code is barely affected: Anthropic says the watermark has "a negligible effect on the actual code produced". If your organisation must verify content for its own compliance, it can apply for detection API access.
Frequently asked questions
Is text Claude wrote before August 2026 watermarked?
No. The watermark is added at the moment Claude writes, so text from before the rollout reached a given model carries none, and older chats are not marked after the fact. The EU rules do not require old content to be labelled retroactively either.
Do images and files Claude creates carry a watermark too?
Files carry a different mark. When Claude produces a supported file such as a .png, .jpg or .svg in the Claude apps or the API, it attaches a C2PA Content Credential, a signed label in the file's metadata. That is what claude.com/check-content reads.
Does text in a Claude Design carry the watermark?
Anthropic does not mention Claude Design by name. The Claude Design watermark guide covers what is known, and what is not, about designs and their exports.
Can I turn the watermark off?
No. Anthropic offers no opt-out on any plan, and there is no setting or API parameter for it. It is part of how the models write, and the models not yet covered are scheduled to carry it by 2 December 2026.
More plain-English guides
Guides to Claude Design exports, platform image sizes and AI content provenance, written for creators and marketers rather than developers.
Browse the guides