What Anthropic has published about Claude's watermark
Published ; updated
Anthropic says Claude uses a version of SynthID-Text. Its Help Centre now lists which models carry the text mark, four so far, and says every model released before 2 August will be covered by 2 December. Text detection is in private preview for eligible organisations. Its public file checker reads C2PA credentials. Declawd has not accessed the private text detector, and the reviewed public pages give no production key, exact configuration, decision rule or error rates. Declawd cannot directly score or exclude Claude's production watermark.
Claim labels
An official statement records what Anthropic says without treating its internal tests as independently verified. A legal source records the Act, guidance or voluntary Code. A reported result belongs to a paper or report that we did not rerun. A reproduced observation is a dated inspection or measurement we performed. An inference is a reasoned possibility. An unknown is not answered by the public record.
Pages
Official statement, published 14 August and checked 24 September 2026. Anthropic's technical post identifies the text mark as a version of SynthID-Text. A private key and a few preceding words affect the random choice among suitable next words. Anthropic says no characters or extra tokens are added.
The earlier Help Centre page also covers signed C2PA provenance on supported SVG, PNG and JPEG files. C2PA is file metadata. It is separate from the text watermark. The page describes supported marking as worldwide across Claude's listed products, API and cloud partner routes. The earlier review recorded an Internet Archive capture dated 10 August, four days before the technical post. That historical observation bounds when the page was public, rather than supplying a publication date. The archive request timed out on 8 September, so that snapshot was not newly verified in this review.
The two pages use broad product language and then qualify where a detectable text mark can occur:
Scroll horizontally to see all columns
| Output | Published position |
|---|---|
| Proofreading | The Help Centre says proofread output can carry a Claude mark. The technical post says only Claude-chosen words carry the text watermark, so light correction may be too sparse to detect. |
| Translation | A translation produced by Claude carries the text watermark because Claude chooses its words. Later translation of already marked text is a separate editing case and may weaken detection. |
| Summarisation and file conversion | The Help Centre says these operations can produce a Claude mark. It does not identify which carrier is present in every case. |
| Code | Claude Code is in product scope. Exact code may offer few eligible choices, while comments and discretionary wording may carry the text mark. |
| Length | Anthropic says confidence rises with more Claude-written text. It gives no minimum or measured curve. |
A detected mark can therefore mean that Claude processed text, not that Claude wrote the original. An absent mark is inconclusive too.
Reported result. The 2024 SynthID-Text paper describes the sampling method and a live experiment covering nearly 20 million responses. It does not describe Claude's production configuration, key or detector.
Anthropic also says the watermark and key carry no user, organisation or chat identifier, add no tokens or price, have negligible speed cost and do not harm quality. Those are vendor statements. Declawd has not reproduced the privacy, performance, robustness or quality tests behind them.
The no-identifier statement is about Claude's design, not about everything that can be built from the same broad family. TrellisMark at revision 3f0157d is an independent research system that encodes a 30-bit user address into text and exactly ranks it across the full address space. Its repository calls this a surveillance capability and says no lab has announced deployment. It does not contradict Anthropic's statement or show that Claude carries an identifier. It shows why a method-family name alone does not settle the privacy properties of one deployment.
Reported result. Claims of even quality or robustness deserve a language qualifier. A preprint posted on 20 August 2026 audits six open watermarking schemes on three open-weight generators across eleven languages and reports detection and quality gaps that fall mainly between language families. It tests open schemes rather than Claude's, so it says nothing about Anthropic's configuration. It does show that a watermark's behaviour is not one number that carries across languages. Declawd has not reproduced it.
Editing and detection
Official statement, checked 24 September 2026. Anthropic says light editing probably leaves some of the mark, while a complete rewrite in which every word is replaced removes it. Its technical post, updated on 1 September, and Help Centre now describe text detection in private preview. Access is offered to eligible organisations, including regulators, media, researchers and educational organisations, and enterprises with relevant compliance obligations. An interest form is linked, and Anthropic says it plans to expand access over time.
The reviewed public pages still give no production key, exact SynthID configuration, tokeniser and detector contract, threshold, output scale, false-positive or false-negative results, or reliable-length floor. Declawd has not accessed the private preview or measured its results. An independent cleaner needs compatible detector access and a documented decision rule before it can establish what the detector returns after an edit.
Anthropic's public file checker checks Claude-issued C2PA Content Credentials and explicitly excludes text watermark detection. The page says it runs in the browser and keeps the file on the device. This is published product behaviour, which Declawd has not independently validated. The Help Centre's separate link to platform detection documentation returned HTTP 404 during this review.
Reported result. Interpreting a detector result also requires a base rate. An amendment to an open SynthID-Text evaluation reports a same-model Bayesian detector at 73.58 per cent sensitivity and 2.78 per cent false positives on texts of 200 tokens or more, and works through an illustrative 1 per cent prevalence: a positive predictive value of 21.1 per cent, so most flags would be wrong. The prevalence is an illustration, not a deployment estimate, and the detector, key and Qwen model are the authors' own rather than Google's or Anthropic's. The arithmetic applies to any detector whose error rates and the prevalence of marked text are known. Declawd has not reproduced it.
Duties
Legal source. Article 50(2) of the EU AI Act requires providers of covered systems to mark generated or manipulated audio, image, video and text output in a machine-readable form, subject to its exceptions and technical feasibility. Article 50(4) separately covers visible disclosure by deployers publishing certain public-interest text. Its duty does not apply where the text has undergone human review or editorial control and a person or organisation holds editorial responsibility. Provider marking and reader-facing labelling are not the same duty.
The Commission lists Anthropic as a Section 1 signatory to the voluntary Code of Practice. The Code allows a detection solution to be a public specification, software or a cloud service. Access to a less reliable free-form-text detector may temporarily be limited to verified experts. Anthropic now describes restricted private-preview access. Its public pages do not say whether this uses the Code's temporary exception for lower-reliability text detection.
The Code applies its free-form-text watermarking commitment above 200 tokens. That is a generic application floor, not a published minimum for Claude's detector. Section 1 signatories also commit to an interoperability solution by 2 February 2027. The four routes are a standard access method, a public signpost, a shared consortium detector or a comparable alternative. This is a voluntary Code commitment, not a separate statutory deadline.
The Code describes signed, downloadable detection results carrying a content hash, detector identifier and timestamp. An upload service should use submitted content only for detection and delete the verbatim content immediately, subject to narrow security exceptions. Anthropic's reviewed public pages do not document whether its private text API implements those controls.
The Commission's Article 50 guidelines put source code, machine-readable specifications, APIs and software libraries outside the provider marking duty. They also describe standard editing and non-substantial alteration exceptions, including qualifying grammar correction, spelling checks, minor stylistic polishing, translation and formatting. Anthropic's broader product scope is a different rule: Claude Code is covered, although its technical post says exact code may offer few eligible word choices.
This summary is not legal advice and does not assess compliance.
Scope
Official statement. Anthropic says the watermark is worldwide because it does not have a durable way to scope marking by region. Models launched on or after 2 August 2026 support marking at launch, while older models are being updated over the following months.
Official statement, checked 24 September 2026. The Help Centre now has a table of models. Four carry text watermarks: Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5. All four are marked on Claude's own surfaces and on cloud partner routes, although for Opus 5 the partner routes were being switched on from 14 September. Every listed model, down to Haiku 4.5, adds C2PA credentials to supported files it creates, which Anthropic limits to platforms that offer Claude's file generation. The Platform release notes announce Fable 5.1 and Mythos 5.1 on 1 September and say their generated text carries Anthropic's watermark. That entry also describes C2PA credentials on supported image, video and audio files produced through code execution and retrieved through the Files API. The Opus 5.5 entry of 22 September says nothing about marking, so the Help Centre table is the only reviewed source that lists Opus 5.5 as marked.
That table is the model-by-model record the earlier review could not find. Anthropic says it is adding watermarks to output from models released before 2 August, with all of them covered by 2 December 2026, and ties that date to its commitments under the Code of Practice. One of the four model assignments in Declawd's original corpus has already changed: Opus 5 is now listed with text watermarks. Sonnet 5, Haiku 4.5 and Fable 5 are listed with C2PA credentials but not yet with text watermarks. The model-versioning documentation still separates fixed weights from serving infrastructure, including sampling logic, which can change without a new model identifier. That fits a mark being added to Opus 5 at serving time, but the documentation does not say how it was done.
Reproduced observation, checked 24 September 2026. The public Models API documentation listed nine capability groups and created_at. It did not document a marking or provenance capability. We inspected the published schema, not a live authenticated GET /v1/models response. No conclusion about enablement follows from that omission.
Press
Reported result. Ars Technica reported on 13 August that Anthropic's reply did not answer its questions about detector timing, false-positive and false-negative testing, or editing exemptions. That is a historical account of the questions asked in August. Anthropic's 1 September update now supplies a private-preview access route, while the reviewed public pages still give no error-rate results.
Reported result. TechCrunch, on 15 August, added a little more of what Anthropic has said: a detection API is planned with no date attached, a complete rewrite that replaces every word removes the mark, and code carries so little of it that only comments are likely to. The piece reports no error rate, threshold or minimum length. Its planned-API wording is superseded by Anthropic's September private-preview announcement.
Bytes
Reproduced observation. The Declawd audit found none of the tested hidden Unicode classes in 457,045 collected characters. Anthropic's later statement that no hidden characters are added is compatible with that result. The scan cannot validate SynthID-Text, because a keyed word-choice pattern can sit in ordinary ASCII.
All four sampled model assignments pre-date 2 August and came through one collection route. By 24 September the Help Centre listed one of them, Opus 5, with text watermarks, and the other three with C2PA credentials only. The files were collected before any of that, so the original corpus is useful as a frozen test of a hidden-character theory, not as evidence that any model is marked or unmarked today.
Gaps
Anthropic has now identified enabled models. A direct test still needs raw response bodies, authoritative model IDs, fixed requests and access to a compatible detector with a documented decision rule. A strong result would preserve signed detector receipts, controls, lengths, edits and a procedure another team can rerun.
Until those pieces exist, the boundary is simple: Declawd explains and tests its own public watermark. It does not detect Claude's.
The 24 September source review records the URLs, response hashes, findings and capture failures behind this update.
Read the byte-level scan, or read what current cleaners remove.