What Anthropic has said about watermarking
12 August 2026
Anthropic says supported Claude models will put an imperceptible watermark into generated text. It also says that finding the mark is not conclusive and failing to find it proves very little. The method, detector, error rates, supported model identifiers and minimum useful length are still unpublished.
What the help page says
Anthropic's Help Centre page was last modified on 10 August 2026. It describes plans for two separate forms of marking. Generated text will carry an embedded watermark. Supported image files will carry signed C2PA metadata. C2PA is file metadata; it is not the text watermark.
The page says Claude models launched in the EU on or after 2 August 2026 will support marking at launch. Elsewhere on the same page, the date rule appears without the EU qualification. Anthropic says it is still adding support to older models. It says users and third parties will be able to detect the marks, but it has not explained how.
For a supported model, Anthropic says the mark applies across its own products, the API and its cloud partners, worldwide. A detected mark may mean that Claude processed the content. It does not establish that Claude wrote the original, because proofreading, translation and file conversion may also produce marked output. Heavy editing can make a mark undetectable.
Why 2 August appears
Article 50(2) of the EU AI Act requires providers of covered systems to mark generated or manipulated audio, image, video and text output in a machine-readable form, subject to stated exceptions and technical feasibility. The obligations apply from 2 August 2026. Providers of covered content-generating systems already on the market before that date have until 2 December 2026.
The law does not prescribe a watermarking method. Anthropic has signed the voluntary Code of Practice and uses the same two dates in its rollout wording. Its decision to apply marking worldwide is a product choice described on the help page, not a worldwide extension of EU law.
No current model is named
Anthropic defines support by launch date and does not name one marking-enabled model. The four model assignments in our byte-level scan all predate 2 August. All four therefore fall into the older-model group, where Anthropic says support is still in progress.
This does not prove that those models are unmarked. Anthropic may retrofit an older model and update the page later. It means that a claim about a specific current model needs evidence that is not in the published documentation.
We also could not verify the model names independently. The collection harness assigned them and each subagent repeated them, but we could not inspect an API response header.
The Unicode story came from somewhere else
In June 2026, a researcher found that the Claude Code client altered the date inside its system prompt under certain base-URL and timezone conditions. The client changed an apostrophe to one of three lookalike characters and could change hyphens in the date to slashes.
That finding concerns input sent to the model. The new help page concerns output generated by the model. It does not tell us how the output watermark works.
Our scan found none of the tested hidden-Unicode classes in the 457,045 characters that reached disk. That result covers those 120 files and that collection path only. It does not rule out a mark carried by word or token choice, and it does not cover six requested non-ASCII space characters that reached disk only as ordinary spaces.
Published methods do not identify Claude's method
Research systems such as the Kirchenbauer green-list method and SynthID-Text alter token selection during generation. Their marks can be present in plain ASCII text, so a character scan would never see them. They show that a text watermark need not use unusual characters.
They do not describe Claude. Anthropic names no mechanism and publishes no detector. A Unicode cleaner can remove unusual characters, while a rewrite can change word choices, but neither operation can certify that an official Claude check would now pass. There is no published official check to compare against.
What would answer the question
Anthropic's technical documentation and detector would answer this directly. Until those arrive, an independent test would need fixed prompts, models on both sides of the launch-date rule, raw responses and a method another team can rerun. We have collected the earlier-model side: four assignments on one route. We found no hidden Unicode there. We did not discover or remove Claude's watermark.
Read the byte-level scan, or read how this site's published watermark works.
Sources: How Claude marks AI-generated content (Anthropic Help Centre, page last modified 10 August 2026); Regulation (EU) 2024/1689, Article 50; EU Code of Practice FAQ; Claude Code prompt steganography (30 June 2026); A Watermark for Large Language Models (Kirchenbauer and others, 2023); Scalable watermarking for identifying large language model outputs (Dathathri and others, 2024); scan evidence at san-digital/claude-watermark-audit.
Published by San Digital Limited, independently of Anthropic. Do not use this article or any score on this site to make authorship, employment, education, disciplinary, legal or forensic decisions.