Policy & Regulation

Anthropic starts watermarking Claude’s text, and users aren’t happy

Anthropic has started embedding invisible watermarks in text produced by Claude, a change driven by European regulation rather than by any request from users. And one that a lot of people using Claude at work have noticed with some alarm.

Every Claude model released after 2 August 2026 carries the technology automatically, TechCrunch reported on 11 August. It applies across the Claude platform API, Claude, Claude Code, Claude Cowork and Claude Tag. The company plans to extend it to older models.

The mark is woven into the model’s token selection as text is generated, so it lives in the words themselves rather than in file metadata. Files get the separate C2PA open standard instead.

Because the watermark is part of the text, it will travel with the text when it’s copied and pasted elsewhere, and may persist through some editing.

Anthropic, via TechCrunch

That sentence is doing a lot of work, and the vague part is deliberate. “May persist through some editing” is not a threshold. Nobody outside Anthropic knows how much rewriting removes the signal, and TechCrunch’s reporter asked without getting an answer.

Reporting elsewhere suggests the mark degrades under heavy editing, paraphrasing, translation, or mixing with other writing, and that short passages may not carry enough signal to detect reliably, as Gizmodo noted. So it’s a probabilistic indicator over a decent volume of text, not a fingerprint on a sentence.

Why AI text watermarking arrived now

The driver is the EU AI Act’s Transparency Code, which took effect on 2 August and requires AI companies to mark generated or edited content so other systems can identify it. OpenAI, Google, Meta and Microsoft have committed to comparable practices under the same guidelines. Our policy coverage tracks how that regime is landing.

The reaction has been sharper than Anthropic likely expected. Forbes covered the backlash, and TechCrunch followed with a piece on users angry that the marks could expose them using Claude in jobs and classes where it isn’t permitted.

Worth separating two claims here. A watermark shows text passed through one particular model. It doesn’t show who wrote the underlying ideas, how much a person edited afterwards, or whether any rule was broken. A point TechTimes made directly: the mark proves processing, not authorship.

The two objections to AI text watermarking

The complaints that followed were more specific than a general privacy objection, and they split along two lines.

The first came from people who say they use Claude to proofread writing they produced themselves. Under a mark applied at generation time, a proofread paragraph and a generated one carry the same signal, which is exactly the ambiguity the technology cannot resolve.

The second came from developers, who worried that adding a cryptographic signature to code would, in their words, “degrade the output”. TechCrunch reported the reaction across X and Reddit, and noted the posts were not one-sided: plenty of users argued the disclosure was overdue.

One poster complained of hypocrisy in watermarking an editorial product that was generated by using other people’s work.

Reported user reaction, via TechCrunch

That last argument is the sharpest one available, and it lands. A model trained on text scraped without consent is now stamping its own output as machine-made, which is a defensible position on provenance and an awkward one on consistency.

Worth noting there is no opt-out. Forbes reported the policy applies to all Claude models and products worldwide, Claude Code and Claude Cowork included.

That distinction matters most for the people with the least power to argue it. A student or employee flagged by a detector is rarely in a position to explain the difference between “Claude touched this” and “Claude wrote this”, and institutions have a poor track record of making that distinction carefully.

The open question is enforcement. If detection tools reach schools and employers before anyone agrees what a positive result means, the failure mode isn’t privacy. It’s confident accusations built on a signal that was never designed to carry them.

Get the daily rundown

One email each weekday with the AI news that matters, every claim linked to its primary source.

Free, one email each weekday, unsubscribe in one click. We never sell or share your address.

Rundowns AI Desk

The Rundowns AI desk covers artificial intelligence research, tools, business and policy. Every factual claim we publish links to the primary source it came from, so readers can check it themselves.

Leave a Reply

Your email address will not be published. Required fields are marked *