Claude research

How Claude watermark works

A conceptual explanation of Claude’s keyed statistical watermark: token choice, sparse signal, short text, factual writing, proofreading, code, and translation.

Published
Last verified
Review
Reviewed against primary sources

Claude’s documented text watermark is statistical. It is not a character that you can search for, highlight, or delete. This page explains the idea Anthropic published. It does not reverse-engineer a detector and does not explain how to defeat one.

Conceptual flow

  1. 01Context from preceding tokens
  2. 02Several plausible next-token choices
  3. 03Keyed randomness influences which plausible token is selected
  4. 04A sparse pattern can accumulate across enough generated text
  5. 05A detector with the key can evaluate likelihood

Why it is statistical rather than inserted-character

Anthropic says nothing is added to the text. The model still picks among words it would have considered anyway. What changes is the source of randomness for those low-stakes choices: a key plus a few preceding words, rather than an ordinary random draw. Someone with the key can later ask whether the sequence of choices looks consistent with that keyed process, and assign a likelihood — not a certainty.

Sparse signal

The watermark has something to act on only when more than one next token would be about equally good. There is no fake probability meter on this page because we do not operate the key.

Effect of text length

Anthropic says detection does not work well on small samples, because there are fewer word choices. Confidence described in that documentation increases as a passage gets longer.

Constrained and factual text

If the next token is effectively unique — a scientific name, a sum, a required identifier — the watermark has little or no room. Factual passages therefore tend to carry a sparser signal.

Proofreading

Only tokens Claude actually chooses can carry the pattern. If a human wrote almost every word and Claude fixed punctuation, there may be too little Claude-generated text to register.

Code

Exact syntax is a constrained case. Anthropic says the watermark generally is not applied where a different token would break the program. Comments and other arbitrary names may still be nudged.

Translation

A Claude translation is described as watermarked because Claude chooses each word in the target language.

Relation to SynthID-Text

Anthropic says Claude uses a version of the SynthID-Text approach published by Google DeepMind in 2024. That paper describes a family of keyed token-choice methods. Citing it does not mean every experimental result in the paper was independently reproduced on Claude here.

Sources

  1. How Claude’s text watermarking works — Anthropic

    Published August 14, 2026. Accessed August 15, 2026.

    Primary source for the statistical text-watermark mechanism, hidden-character denial, detection-key dependency, and limitations.

  2. How Claude marks AI-generated content — Anthropic / Claude Help Center

    Accessed August 15, 2026.

    Primary source for launch timing, product surfaces, C2PA file provenance, and mark-detection limitations.

  3. Scalable watermarking for identifying large language model outputs — Nature (Google DeepMind SynthID-Text)

    Published October 23, 2024. Accessed August 15, 2026.

    Peer-reviewed description of the SynthID-Text family of methods. Anthropic states Claude uses a version of this approach; this paper is not a Claude product specification.