Anthropic's invisible watermark for Claude text is here — with limits

By: Anton Kratiuk | today, 01:19
Anthropic's invisible watermark for Claude text is here — with limits

Anthropic has detailed how watermarking will work in text generated by Claude, its AI chatbot. The system embeds invisible patterns during text generation — no visible tags, no extra characters — and a detection key can surface them later. With EU rules on AI disclosure kicking in from August 2026, the timing is deliberate.

How it works

The watermark operates by nudging word choices during generation. When Claude can express the same idea using several near-equivalent words or phrases, it picks according to a hidden statistical pattern. That pattern is imperceptible to a human reader but detectable by a tool with the right key.

Anthropic built this on SynthID-Text, a method Google DeepMind published in Nature in 2024. Google's own A/B tests on Gemini — covering around 20 million users — found no measurable impact on text quality or readability. Anthropic says Claude's output will read the same as before.

The gaps worth knowing

The watermark is not tamper-proof. A complete rewrite — swapping out most words — strips it. Light editing typically preserves it, though that depends on text length and how much Claude actually changed. If Claude is only lightly touching up a human-written draft, the resulting watermark coverage may be thin.

Code is a weaker case still. When Claude writes functional code, it has far fewer word-choice options — the syntax has to work. TechCrunch reports that watermarking applies mainly to comments and non-functional text within code, which means a determined developer could produce unwatermarked outputs with minimal effort.

There is also no public timeline yet for a detection API — the tool that publishers, platforms, and educators would actually need to check whether a piece of text came from Claude.

Bigger picture

Anthropic says other major AI developers have signed the EU's AI code of practice and plan their own marking systems. Article 50 of the EU AI Act requires machine-readable labeling for AI-generated content from August 2, 2026, with an extension to December 2, 2026 for older, legacy models. Non-compliance carries penalties of up to €15 million or 3% of global annual turnover.

For US users, there is no equivalent federal mandate yet — but enterprise customers, media companies, and academic institutions have independent reasons to care about provenance. A watermark that survives casual editing is a meaningful step; one whose detection API has no release date is a tool no one can use yet.