What A Claude Watermark Can & Can’t Tell You About Authorship

Aug 15, 2026 02:00 AM - 2 hours ago 1

Anthropic shared its plans this week to people matter generated by Claude models successful accordance pinch Article 50 of the EU AI Act. The guidance arrived immediately.

Writers who usage Claude to edit their ain activity person objected to that activity carrying a mark. At the aforesaid time, developers raised a different group of concerns, and some sides person spent the week arguing astir wherever watermarking belongs.

What’s Being Said, And What The Documents Say

Forbes reported really group were objecting to their ain activity becoming detectable arsenic AI-assisted. TechCrunch found akin feelings connected Reddit, alongside users arguing backmost astatine the complainers. Meanwhile, Decrypt shared that open-source projects are emerging to bypass aliases disrupt these watermarks.

Some reports propose that the marking strategy is already successful use. Anthropic’s thief page states that models launched successful the EU from August 2 onward will support marking astatine launch, and that activity connected earlier models is successful progress. The page names nary exemplary that presently carries a mark.

Forbes points retired that users cannot opt out, and Anthropic’s thief page doesn’t mention this action either. What the sum mostly leaves retired is that marking is uneven by design. Anthropic acknowledges that marked contented whitethorn not transportation a detectable mark, and the Code doesn’t require watermarking of free-form matter shorter than 200 tokens.

What Article 50(2) Requires

Article 50(2) requires providers of generative AI systems to people outputs specified arsenic audio, images, videos, and matter successful a machine-readable measurement to bespeak that they are artificially generated aliases manipulated.

Providers person to make those marks effective, interoperable, robust, and reliable, arsenic acold arsenic that is technically possible. What counts arsenic imaginable depends connected the type of content, the costs of the work, and wherever the exertion mostly stands.

The marking work does not use to the grade a strategy only assists pinch modular editing, aliases does not substantially change the input information aliases its meaning. The Commission’s guidelines exclude definite outputs from this rule, including root codification and short sequences of numbers, symbols, aliases letters.

The Code of Practice connected Transparency of AI-generated Content offers a voluntary compliance framework. By the extremity of July, astir 190 organizations had signed up. Signatories successful Section 1 see Google, Meta, Microsoft, OpenAI, and Anthropic, while Section 2 includes Getty Images, Lenovo, and Lufthansa.

Article 50(2) puts the marking work connected the provider. Meanwhile, Article 50(4) imposes an further responsibility to explanation deepfakes and AI-generated texts published arsenic public-interest information. The European Commission clarifies that deployers cannot trust solely connected the provider’s machine-readable people to fulfill their disclosure duties. Article 50 carries 4 exemptions successful total, which Roger Montti covered connected August 3.

Why Implementation Is Uneven

Google says SynthID marks matter generated done the Gemini app and web experience. It signed the Code connected July 24 and named Apple, ElevenLabs, Kakao, NVIDIA, and OpenAI arsenic partners successful watermarking that useful crossed systems. In the aforesaid post, Google said it was concerned that adding much rules while the exertion is still evolving could undermine Europe’s competitiveness goals.

OpenAI’s page connected contented provenance lists C2PA metadata and SynthID for supported images, and SynthID for supported audio, which it added connected July 31. They intend to support further contented types complete time, but presently do not database matter arsenic a supported format.

Anthropic names nary exemplary that presently carries a mark. It says marking will screen output from supported models worldwide, crossed its API, apps, and developer tools.

Meta and Microsoft are signatories of Section 1, though SEJ didn’t find immoderate circumstantial policies connected text-marking successful their charismatic materials arsenic of August 13.

What A Mark Does Not Establish

Claude mightiness not beryllium the original writer of watermarked matter because users often proofread, translate, summarize, aliases person files, which tin present a people moreover if the ideas aliases words originate elsewhere. Additionally, the contented whitethorn person changed aft Claude processed it.

Anthropic lists 5 reasons why marked contented mightiness not show a detectable mark:

  • The exemplary predates support for marking.
  • The matter was heavy edited, paraphrased, translated, aliases integrated into different writing.
  • The transition is excessively little to nutrient a reliable signal.
  • File metadata was removed done format conversion, re-saving, aliases screenshots.
  • The aboveground did not support that circumstantial marking type.

The Code applies watermarking to free-form matter longer than 200 tokens. Its glossary refers to thing shorter arsenic very short text, expecting this cutoff to alteration arsenic methods improve.

For audio, images, video, and matter successful files circulated online, the Code mostly requires 2 abstracted marks because nary azygous method meets each 4 requirements. Since free-form matter cannot transportation metadata, the Code accepts 1 furniture of watermarking for this format, noting that watermarking successful this format whitethorn beryllium little reliable than for longer passages.

The Commission’s last Guidelines from July 20 database AI-generated translations among examples covered by the Article 50(2) exception, alongside grammar correction and spellchecking. Anthropic states that translated output tin still carnivore a Claude mark. Therefore, a detected people does not needfully mean that Article 50(2) required marking that output.

Researchers Scrubbed And Spoofed The Watermarks They Tested

At ICML 2024, researchers from ETH Zurich’s SRI Lab showed that querying a watermarked exemplary via its nationalist API allows an attacker to infer capable astir the strategy to region aliases spoof the marks the insubstantial antecedently considered safe. The costs was nether $50, astatine an mean occurrence complaint supra 80%. A abstracted research covered existing text, successful which astatine slightest 74% of bully paraphrases of non-watermarked worldly were detected arsenic watermarked, pinch an expected false-positive complaint of 1 successful 1,000.

At ICML 2025, different squad reported astir complete occurrence against 7 caller watermarking methods, astatine $0.88 per cardinal tokens. Their paraphrasing onslaught targets watermark tokens without needing entree to the watermarking algorithm aliases model.

The Code asks the companies that motion to trial really good their marking holds up against deliberate attempts to copy, remove, regenerate, aliases change it, and lists paraphrasing and translator among the mundane handling a people should survive. Neither insubstantial tested Anthropic’s implementation, which the institution has not described successful method detail.

Who Can Check A Mark

The Code mandates that companies watermarking output must connection a measurement for group to verify it

Anthropic will assistance users and outer parties successful identifying its marks and plans to merchandise method specifications later. Google’s SynthID page offers guidance connected verifying images, videos, and audio successful Gemini and says its SynthID Detector accepts image, video, and audio uploads, which are being tested pinch journalists and media professionals. Google has besides open-sourced SynthID’s matter watermarking. SEJ covered that verification reaching Search successful May, wherever it applies to images.

OpenAI’s verification instrumentality supports images and audio. Currently, nary of these devices let the nationalist to verify text. OpenAI stated that their image and audio verification devices do not corroborate contented was not generated by OpenAI erstwhile nary signals are detected.

Why This Matters For Search Professionals

Content teams vessel AI-assisted transcript to customer sites each day. A increasing stock of that transcript now leaves Claude carrying a machine-readable mark, which travels pinch the matter erstwhile it’s pasted into a CMS and published.

Google signed the aforesaid Code, on pinch Microsoft and Meta. These watermarks beryllium to beryllium publication by machines, and the companies that determine which ranks are among those that tin publication them. Whether marked contented is treated immoderate otherwise erstwhile it’s crawled, indexed, aliases surfaced has not been stated by anyone.

Then there’s the mundane problem. Using Claude to cleanable up your ain draught tin put a people successful your ain writing. A discovery says AI whitethorn person processed the text, not that it wrote it. A miss says almost nothing, because older models, short passages, and heavy edited matter each travel backmost clean. But group whitethorn still spot a discovery deed arsenic impervious anyway.

Looking Ahead

Watermarking is happening faster than we tin publication it. Anthropic hasn’t shared its detector yet, while Google’s covers images, videos, and audio, and OpenAI’s covers images and audio.

This spread creates immoderate concern. Clients, universities, and marketplaces will soon commencement asking for impervious that contented is human-made, moreover earlier we person a clear measurement to supply that answer. The apt script is simply a marketplace filled pinch AI-detection claims based connected signals that weren’t meant to reply this mobility successful the first place.

Interoperability is the cardinal facet present successful determining really wide this thought spreads. If checking tin beryllium done easy by anyone successful a azygous step, alternatively than having to query each supplier separately, past marks will move from specified compliance devices to meaningful signals that platforms, publishers, and hunt engines tin usage astatine scale.

More Resources

  • Google Ads Now Requires Disclosure Labels On AI-Generated Content
  • Google Claims AI Training Is Fair Use In New Governance Paper
  • Google May Be Penalizing AI-Generated Content As Thin Content

Featured Image: Cast Of Thousands/Shutterstock

Category AI Search
Follow Us On Google
More