Anthropic confirmed this week that every Claude model released on or after August 2, 2026 now carries an invisible, machine-readable watermark in all generated text and signed C2PA provenance metadata on supported image files, applied globally across every product surface and cloud partner. The company disclosed that it is embedding an invisible statistical watermark directly into generated text and applying that mark worldwide, not only in Europe, making Claude the first major frontier AI lab to deploy production-scale text watermarking across all its products at once. The move was triggered by a hard regulatory date: the transparency obligations under Article 50 of the EU AI Act took effect on August 2, 2026, and non-compliance can trigger fines of up to 15 million euros or three percent of total global annual turnover, whichever is higher.
The system uses two distinct techniques. For text, Anthropic inserts an imperceptible pattern directly into generated output, invisible to readers but detectable by machines and able to travel with the text even after it has been copied and pasted elsewhere; according to the company, it does not change the meaning, quality, or readability of a response. Supported files, including.svg,.png, and.jpg images, carry signed provenance metadata based on the open C2PA standard developed by the Coalition for Content Provenance and Authenticity; the signature indicates that Claude processed the file and can reveal later tampering. The same C2PA scheme has been adopted by Adobe, the BBC, and a number of camera manufacturers to label the origin of images. Critically, Anthropic chose to apply the marking globally; nothing in the EU Code of Practice requires marking text generated for a developer in Bangalore or Boise, and the practical result is that there is no region where users receive unmarked output.
The gap between the announcement and any means of independent verification is the sharpest tension in the policy. Anthropic has not said which token-selection, semantic, or structural scheme it uses, so claims about its exact algorithm remain speculation. An Anthropic engineer confirmed on August 12 that a text detection API is coming and that the model itself is not aware it is being watermarked, while conceding that "it's not perfect, you can edit it, but it's a first step." The company plans to publish more technical guidance on watermark detection, supported file types, and implementation details as its marking system becomes available. Independent analysts have already mapped the fragility of the approach: Claude-generated text may lose the signal if it is heavily edited, paraphrased, translated, or mixed with other writing, and short passages may not contain enough text for a reliable signal.
Skeptics question whether the scheme can bear the institutional weight it is about to be asked to carry. The strongest criticism is not that paying customers deserve unmarked output; it is that a system producing a probabilistic, authorship-agnostic signal is about to be treated by schools, employers, and platforms as proof, and while Anthropic documented that limitation clearly, almost nobody downstream will read it. The Register noted that open-source C2PA removal tools already exist for files, and that Anthropic itself is hedging about the utility of its marking method, noting that a detected mark is not conclusive evidence that Claude produced the content and that the absence of marks cannot guarantee that AI was not involved. Regulators themselves expect providers to rely on a multi-layered strategy combining digitally signed metadata, imperceptible watermarking, and, in some cases, fingerprinting or logging as a fallback, since the Code of Practice makes clear that no single marking technique is sufficient on its own.
What Anthropic has built is a floor, not a ceiling, and the regulatory community, the research community, and the company itself will all find out at the same time how well it holds.