Securafy AI Lab

Claude Now Watermarks AI Text — What It Means

Written by Jillian O. | Aug 20, 2026, 12:00:00 PM

Does AI-Generated Text Really Carry A Hidden Mark Now?

Yes. Anthropic has confirmed that text generated by supported Claude models carries an embedded, invisible watermark, woven into the text itself rather than attached as metadata that can be stripped away. This is not a product experiment — it is compliance with a binding European regulation that Anthropic says applies to Claude "wherever Claude is offered, worldwide," not only to European users (Claude Help Center). If you run marketing or content operations and have not thought about what that means for your team, this is the moment to start.

I want to be direct about the frame I am not going to use here. The instinct, when you hear "watermark," is to ask whether you are about to get caught. That is the wrong question. Marking is infrastructure for provenance — a way of making "how was this made" a checkable property of content instead of a claim someone makes about it. Securafy uses AI in our own work, including in how we produce content like this. The question worth asking is not whether AI use is detectable. It is whether your disclosure posture is one you chose deliberately, or one decided for you by silence.

What Exactly Did Anthropic Commit To?

Anthropic signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content "as a provider of both generative AI models and generative AI systems" (Claude Help Center). Three details matter more than the headline itself.

Coverage is broad by product: marking applies to Claude Platform (the API), Claude the consumer product, Claude Code, Claude Cowork, and Claude Tag — essentially everywhere Claude generates output. It is also broad by geography — the support page states plainly that marking "works everywhere you use Claude," applying "wherever Claude is offered, worldwide," meaning a US business with zero European customers still gets watermarked output, because the mark is applied at the model level rather than gated by request origin. And there is a timeline: Claude models launched on or after August 2, 2026 support machine-readable marking at launch; models launched earlier are in a transition period, with Anthropic "working to add marking support" to those as well.

TechCrunch's reporting corroborates the compliance driver directly: "EU AI Act's Transparency Code, which took effect on August 2, requires AI companies to mark AI-generated or edited content in a way other systems can identify them," noting Anthropic confirmed the change "in an updated support page" rather than a product launch (TechCrunch). This is not Anthropic deciding, on its own initiative, that marking is a good idea. It is a European regulation setting a technical standard that a US company now applies to US customers by default, because building two versions of a model — one marked, one not — is not a serious option at scale.

Why Should A US Business Care About A European Regulation?

Because the pattern, not the specific rule, is the thing to notice. The EU AI Act's Article 50 requires providers of generative AI systems to ensure outputs are "marked in a machine-readable format and detectable as artificially generated or manipulated," an obligation that applies regardless of where the provider is located whenever the output is used in the EU (EU AI Act Article 50, official text). Anthropic chose to apply marking globally rather than build a fractured product, so a regulation written for one jurisdiction now shapes a tool your team uses daily, whether or not you have ever sold anything to a European customer.

This is not new in tech policy — European privacy rules reshaped US data practices for a decade — but it is new for content tooling, and it arrives through the vendor layer rather than through anything your business decided. You cannot opt out by ignoring the regulation, because you are not the regulated party; the model provider is, and it has already made the call. What you retain control over is what happens once content leaves your team: disclosure decisions, review process, and how you talk about your own work.

How Does The Watermark Actually Work, And What Can It Not Tell You?

For text, Anthropic embeds the mark directly in the generated text rather than in a separate file or header. TechCrunch quotes the support page directly: "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing. Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from" (TechCrunch). For generated files — Anthropic names .svg, .png, and .jpg — it instead attaches signed provenance metadata built on the Coalition for Content Provenance and Authenticity's open standard, letting a file be checked for tampering after the fact (C2PA).

Anthropic is explicit about two limitations worth taking at face value. A detected mark is a signal, not proof: Claude may have been used to proofread, translate, or reformat someone else's writing, so a mark does not tell you Claude authored the underlying ideas. The absence of a mark proves nothing either — heavy editing, translation, short passages, or an older unmarked model can all produce content with no detectable trace (Claude Help Center). TechCrunch notes the open question plainly: "It's not clear how much editing users need to do to remove the watermark," and the outlet says it asked Anthropic to clarify (TechCrunch). Treat "editing removes it" as unproven, not as a plan.

Content typeWhat Anthropic usesWhat survives editing
Generated textWatermark embedded in the text itselfMay persist through copy-paste and some editing, per Anthropic
Generated files (e.g., images)Signed C2PA provenance metadataCan be stripped by format conversion, re-saving, or screenshots

Is This Really About Whether You Get Caught Using AI?

No, and treating it that way leads your team to the wrong plan. Marking does not tell anyone whether your work is accurate, well-reasoned, or good — it says something about how the text was produced, full stop. A watermarked draft that a subject-matter expert reviewed, corrected, and stands behind is not weaker than an unmarked one; the mark and the quality are unrelated questions. Reading this as a detection risk invites defensive habits like light rewrites meant to "launder" a mark out of a document, a poor use of anyone's time and, per Anthropic's own caveat above, not even reliably effective.

The people actually exposed by this shift are not the ones using AI openly. They are the ones who used it quietly while implying, explicitly or by omission, that the work was produced entirely by hand — because provenance marking turns a private choice into a discoverable fact, and the damage comes from the gap between what was implied and what is verifiable, not from the tool itself. For a firm doing regulated work, that gap is sharper still. A statement about how a deliverable was produced can function as a representation to a client or examiner, and representations that turn out false carry consequences well beyond an awkward conversation.

What Should A Business Actually Do About This This Quarter?

Start by knowing, asset by asset, what you have. Most companies cannot say with confidence which published pages, decks, or client deliverables involved meaningful AI drafting versus light AI-assisted editing versus none — and you cannot set a disclosure policy for something you have not inventoried. That does not require a forensic audit; a short pass through what marketing, sales, and client-facing teams produced last quarter, with an honest tag on each piece, is enough to start.

From there, decide where disclosure is expected versus unnecessary, and write the answer down rather than leaving it to individual judgment in the moment. A regulatory filing, a signed client deliverable, and a routine social post are not the same instrument and should not carry the same default. Part of that line is already drawn for you: the EU AI Act's Article 50(4) requires labeling AI-generated text published on matters of public interest unless it has gone through human review with a named party holding editorial responsibility — a useful model even for US teams outside that rule's direct reach (EU AI Act Article 50, official text).

Brief your team plainly that "clean it up and it's ours" is not a strategy, because editing is not a reliable way to remove a mark and was never a sound basis for disclosure policy regardless. Keep human review exactly where it already belonged: the thing that makes output publishable in the first place, unchanged by any of this. NIST's AI Risk Management Framework makes the same point institutionally, noting "trustworthy AI depends upon accountability" and that "accountability presupposes transparency," while its companion generative AI profile pushes organizations toward documenting model use, provenance, and review decisions rather than treating disclosure as an afterthought (NIST AI Risk Management Framework, NIST Generative AI Profile). Documenting your own review process is exactly the governance step covered in our guide to building an AI acceptable use policy, which pairs with the broader habit of treating AI outputs like any other unverified input, discussed in our piece on how employees can safely use ChatGPT, Copilot, and other AI tools at work.

How Does This Connect To Governance Work Securafy Already Recommends?

This is not a standalone issue; it is a specific, timely instance of a governance gap most SMBs already carry. We have written before about why AI adoption without governance is a liability rather than a shortcut, and content provenance is simply the newest example of that argument (why AI without governance is risk). The same discipline that should govern where employees paste sensitive client data into a chat tool should govern what your organization says publicly about how its content gets made — see our related coverage of securing AI agents and Copilot before they become shadow IT. And if leadership has not formalized who signs off on AI-assisted deliverables before they go out the door, that gap is worth closing regardless of watermarking, as we outline in our leadership playbook for AI adoption.

Where Securafy helps directly is turning this from a vague policy statement into something your team can execute: building a real content inventory and disclosure matrix instead of a one-line memo nobody follows, training the people who touch published content — marketing, sales enablement, client services — on where disclosure is expected and why, and building the review checkpoint into your existing publishing workflow rather than a separate compliance step that gets skipped under deadline pressure. The goal is not a policy binder. It is a habit your team can sustain without you personally checking every asset before it goes out.

Where To Go From Here

Provenance marking is not going away, and it is not confined to Europe. The useful move is deciding, in writing, where your organization discloses AI assistance and where it does not — before an unmarked assumption gets tested by a client, a regulator, or a reporter.

If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.

If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.