Claude research

Claude Watermark

A researched explainer of Claude’s statistical text watermark: visibility, hidden characters, detection, limitations, and how it differs from C2PA file credentials.

Published
Last verified
Review
Reviewed against primary sources

Does Claude use a watermark?

Yes, according to Anthropic, for supported new models. The 14 August 2026 announcement says future Claude models generate text containing a watermark so that, with a key, someone can estimate the likelihood that Claude was involved in writing the text. Help Center documentation says Claude models launched in the EU on or after 2 August 2026 support machine-readable marking at launch. Older outputs are not assumed to be marked. Model-specific status requires verification. Anthropic documents marking by launch date and support, not as a guarantee that every historical Claude output is watermarked.

What kind of watermark does Claude use?

A statistical, token-generation watermark. Anthropic describes it as a version of Google DeepMind’s SynthID-Text approach (Nature, 2024). The watermark changes the source of randomness used when the model picks among already-plausible next words. It is not a logo, footer, or metadata field inside the string.

Is Claude’s watermark visible?

No. Anthropic says the difference between watermarked and un-watermarked text is not distinguishable to readers and that internal testing showed no practical impact on quality or readability.

Does Claude insert hidden characters?

Anthropic states there are no hidden characters and that nothing is added to the text. If copied Claude text contains zero-width characters, those are a separate paste/editor question, not evidence of the official watermark.

How does the statistical watermark work?

Language models often have several acceptable next tokens. The watermark uses a key plus preceding context to settle low-stakes choices among those candidates. Over a long enough passage, that can leave a pattern visible to a detector that has the key. See the dedicated mechanism page for the conceptual flow.

Which Claude outputs are marked?

Help Center documentation says embedded watermarks apply to generated text from supported models across Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, and when those models are accessed through listed cloud partners. Some platforms or features may not support certain marking types. We do not maintain an unsupported model-by-model table.

Does Claude watermark translations?

Anthropic says yes, because in a translation Claude chooses every word.

What about proofreading?

The watermark applies to words Claude chooses. Light grammar-only edits of human text may leave too few Claude-chosen tokens for a usable signal.

What about code?

Where the next token is tightly constrained, Anthropic says the watermark generally is not applied. Comments and other arbitrary identifiers may still carry some signal; exact syntax generally will not.

What about Claude-generated files?

Supported generated files may carry C2PA Content Credentials. That is a separate file-metadata system, not the statistical text watermark.

Can the watermark identify an individual user?

Anthropic says no. The watermark is described as carrying no identifying information about a person, organisation, or chat.

Can the watermark prove text was written entirely by Claude?

No. Anthropic says a watermark can only determine that Claude was likely involved, and cannot distinguish “Claude wrote this” from “Claude heavily edited this.” Lack of a detected mark also does not prove the text was not AI-generated.

How is Claude watermarking different from AI detection?

A watermark check uses a provider key. Generic AI detectors guess from style. Those methods are not the same, and this site does not rank commercial detectors.

How can Claude watermarking currently be checked?

Anthropic says it will offer a watermark detection API and is working out implementation details. AI Watermark Center cannot currently verify the statistical watermark. Hidden Unicode can be inspected separately and honestly labelled.

Current limitations

  • Weaker on short text.
  • Sparser on factual passages with few interchangeable tokens.
  • Limited on proofreading and much code.
  • Heavy rewriting can remove the statistical pattern.
  • Older models may not yet be marked.
  • File credentials can be stripped by screenshots or re-saves.

Official sources

The claims above follow Anthropic’s announcement and Help Center article, accessed 15 August 2026. The SynthID-Text paper is cited only as the published method family Anthropic says it used a version of.

Sources

  1. How Claude’s text watermarking works — Anthropic

    Published August 14, 2026. Accessed August 15, 2026.

    Primary source for the statistical text-watermark mechanism, hidden-character denial, detection-key dependency, and limitations.

  2. How Claude marks AI-generated content — Anthropic / Claude Help Center

    Accessed August 15, 2026.

    Primary source for launch timing, product surfaces, C2PA file provenance, and mark-detection limitations.

  3. Scalable watermarking for identifying large language model outputs — Nature (Google DeepMind SynthID-Text)

    Published October 23, 2024. Accessed August 15, 2026.

    Peer-reviewed description of the SynthID-Text family of methods. Anthropic states Claude uses a version of this approach; this paper is not a Claude product specification.