From August 2026 onward, anything Claude writes for you will carry a mark you cannot see, cannot strip out by copying and pasting, and that Anthropic says “may persist through some editing.”
That is what it means in practice now that Anthropic has signed the EU AI Act Code of Practice covering transparency for AI-generated content. Watermarks will be baked into text produced by new Claude models, and files will arrive with signed provenance metadata attached.
The rule came from the EU, but it isn’t stopping at the border
Any Claude model that launches in the EU on or after August 2, 2026 arrives with the labeling already built in. What’s striking is the treatment everywhere else: it’s identical. Anthropic is applying it globally, spanning the API, Claude, Claude Code, Claude Cowork and Claude Tag.
Generated text carries an embedded watermark. Generated files carry digitally signed provenance metadata. The law grants existing models a transition period, though Anthropic says retrofitting them is already underway.
Tools that let users and third parties verify the labels are on the way. Anthropic hasn’t said when. That gap matters: a mark nobody can read yet is a mark that does nothing yet.
Developers embedding Claude in their own products must work out for themselves which Article 50 requirements apply to whatever they’ve shipped, according to Anthropic.
Two labels doing two separate jobs
The text watermark is invisible and, per Anthropic, leaves the meaning, quality and readability of the output untouched. It survives copy and paste. Because it’s applied at the model level, whichever Claude product you happen to be using makes no difference to whether it’s there.
Files work another way. Supported formats — .svg, .png and .jpg images among them — receive signed provenance metadata built on C2PA, the open standard from the Coalition for Content Provenance and Authenticity. That signature attests that Claude touched the file and can expose tampering after the fact.
Cloud partners including AWS, Google Cloud and Microsoft Foundry should pass the text watermarks through as well. The signed metadata may not make the trip, since those platforms may not support it.
Anthropic is unusually blunt about what this proves
Finding a watermark does not establish that Claude wrote the content. That caveat is Anthropic’s own, not a critic’s. People use Claude for proofreading, translation and summarizing all day long, which means a human’s ideas can emerge at the far end wearing a machine’s label.
An absent watermark tells you even less. The model may predate watermarking. The text may have been heavily edited or translated. The passage may be too short to detect reliably. A format conversion may have stripped the metadata — or someone may simply have taken a screenshot.
So you’re left with a signal that can throw a false positive when a person did the thinking, and a false negative for at least five perfectly ordinary reasons. Read the fine print before treating a detection result as evidence of anything.
The one thing worth testing
All of it turns on how the marks hold up through editing, reformatting and translation — precisely the three moves a student or a spammer makes by reflex.
Should the watermark come through intact, checking for a known mark beats what’s currently on the market. Detectors such as Pangram lean on proprietary methods that never explain what triggered a result. Hunting deliberately for a watermark is a different kind of claim than a probability score with no receipts. Third-party detectors could add support for Anthropic’s mark and get a firmer signal out of it.
Google shipped this already, and OpenAI is sitting on something better
Google Deepmind open-sourced SynthID and wired it into the Gemini models. It nudges probability values during token prediction to leave a watermark without degrading text quality, and it works across languages. Where it falters is text edited after generation — the very weak point Anthropic will have to answer for.
OpenAI’s position is the strange one. For roughly two years the company has had a text detector with 99.9 percent accuracy and has never shipped it. The stated reasons: users beat it easily through translation or rewriting, and it risks stigmatizing certain groups. The unstated one, most likely, is that a public detector would be bad for OpenAI’s business.
Why the accuracy caveats matter more than the standard
In education, a detector that can’t be trusted isn’t a nuisance. It’s a false cheating allegation attached to a real person’s record.
And there are real reasons to want to know how much AI went into a piece of work. Studies show heavy reliance on these tools can weaken critical thinking and writing skills, especially among students using them as a shortcut instead of a learning aid. Nor is it confined to campuses: scammers are enrolling fake students at US colleges, running the coursework through AI and collecting financial aid.
The customers most likely to notice
Claude has a following in knowledge work and among school and college students, partly because even the older models turn out prose that doesn’t read like a machine wrote it. That’s exactly the user base a working detector makes uncomfortable.
Schools and universities are already fighting over AI in academic work. Anthropic has now volunteered to make its own output easier to flag, globally, ahead of any requirement to do so outside the EU. Watch whether the verification tools arrive before August 2026 or after. Until they do, every Claude output past that date carries a mark that only Anthropic can read.


















STAY ALWAYS UP TO DATE