Research protocol

Does Claude Hide Watermarks in Unicode? Evidence & Testing

Official Anthropic statements plus an AI Watermark Center protocol for inspecting copied Claude text for observable Unicode. Independent sample collection is in progress; no dataset is published yet.

Published
Last updated
Last verified
Review
Reviewed against primary sources

Collecting

Study ID
awc-claude-hidden-unicode-001
Independent dataset
Collecting
Research question
What observable Unicode and formatting characteristics appear in the collected Claude text outputs?

Official provider documentation

What the company currently publishes. Not an AWC measurement.

AWC observations

Unicode or embedded-metadata inspection of owned/permissioned samples. Scoped to that sample.

Provider-verified results

Manual use of an official verifier. Not independent SynthID detection by AWC.

Limitations

Small samples are exploratory. not-detected is not human authorship.

Dataset

Status
draft
Version
None — not published
Public samples
0
Exploratory collection target
24 cells (operational plan, not a statistical N). Actual genuine samples: 0.
Downloads
No download. Dataset pending.

Raw provider outputs stay private unless a sample is explicitly flagged for publication. Test fixtures are not research samples.

Official Anthropic documentation

Anthropic’s 14 August 2026 announcement states that nothing is added to the text and that there are no hidden characters in the watermark mechanism. The same article says watermarking is not extra appended tokens: it changes the source of randomness used when the model chooses among already-plausible next words. That is official provider documentation, not an AI Watermark Center measurement.

AI Watermark Center observations

Research question

What observable Unicode and formatting characteristics appear in the collected Claude text outputs? The study does not score Anthropic’s keyed/statistical marking, does not treat Unicode findings as that marking, and does not treat a clean Unicode report as an authorship verdict.

Exploratory collection design

The 24-sample design is an exploratory collection plan chosen to provide variation across prompt classes and languages. It is not statistically representative of all Claude output. Internal target: 24 genuine outputs (six prompt classes × four languages). Results will be worded as “in this sample” or “among the collected outputs.” Unicode findings are not statistical-watermark detection.

What will be recorded for each sample

  • Stable ID (CLD-TXT-0001 through CLD-TXT-0024)
  • Claude model, only if known from the interface or API — otherwise unknown
  • Surface (Claude web/app, Claude API, or other known Anthropic surface)
  • Collection date
  • Prompt class and language
  • Exact UTF-8 raw export (private by default)
  • Unicode-engine findings: zero-width, special whitespace, bidi, unexpected controls, formatting, variation selectors, private-use, replacement characters
  • Whether NFC/NFD/NFKC/NFKD changed the string — not treated as watermarking

Intended sample groups

  • General prose
  • Factual answer
  • Creative writing
  • Translation
  • Proofreading
  • Code / technical response
  • Languages: English, Arabic, French, Spanish

Limitations

This is an exploratory sample, not statistically representative of all Claude usage. Collection surface and copy/export paths may affect encoding. Only observable Unicode is measured. Anthropic’s statistical / keyed watermark is not tested. Model coverage is limited to samples where the model is actually known. Findings will reflect each sample’s collection date.

What this experiment will not claim

Findings will be about inspectable Unicode, not about whether Anthropic’s statistical watermark is present. Raw Claude outputs stay private unless separately approved. Later reports will use aggregate statistics from genuine samples only.

Sources

  1. How Claude’s text watermarking works — Anthropic

    Published August 14, 2026. Accessed August 15, 2026.

    Primary source for the statistical text-watermark mechanism, hidden-character denial, detection-key dependency, and limitations.

  2. How Claude marks AI-generated content — Anthropic / Claude Help Center

    Accessed August 15, 2026.

    Primary source for launch timing, product surfaces, C2PA file provenance, and mark-detection limitations.