The text written by Claude will soon be possible to recognize even without characteristic revolutions and AI detectors. Anthropic will embed a hidden statistical watermark in future models that does not add special symbols, metadata or visible marks. The reader will not notice any difference, but the holder of the special key will be able to assess the probability of Claude's participation in the creation of the text.
Anthropic introduces such a system for the sake of the requirements of European AI legislation. The company, along with other developers, signed the European Code of Practice on AI-powered Content Transparency in July 2026. The new Anthropic marking mechanisms are going to be included around the world, since the company cannot yet reliably restrict the operation of the watermark only by European users.
The water sign does not work at all as the usual signature on the photo. Claude generates text sequentially and at each step selects the following token from several suitable options. When a few words are equally well suited in meaning, a regular model can choose the option with the help of randomness. The watermark system changes the source of such randomness and links the choice with the secret key and previous words.
As a result, a statistical drawing gradually appears in the long text. The text itself remains ordinary, and the words do not contain hidden symbols. If you check the sequence with a special detector and know the key, you can determine how much the choice of words corresponds to the work of Claude with the watermark included. Anthropic uses a variant of SynthID-Text technology, which Google DeepMind described in scientific work in Nature in 2024.
According to Anthropic's internal tests, the mechanism does not impair the quality, readability or creative abilities of the model. SynthID-Text also tested for parts of Gemini traffic. Google DeepMind found no statistically significant difference in user estimates between and without watermark responses. The system does not create additional tokens, so the cost of generation does not increase, and the effect on the speed of Anthropic calls negligible.
The watermark does not contain a user ID, company or specific dialog. According to the found label, it is impossible to establish who sent the request Claude and from which account the text appeared. The detector will be able to speak only about the probability of the Anthropic model's participation in creating a fragment.
The method has serious limitations. The shorter the text, the more difficult it is to reliably detect the statistical figure. In actual answers, the space for choice is also less. If Claude writes the title of Newton's book Principia Mathematica, the model cannot replace the correct word with another just for the sake of the watermark. A similar problem arises with the program code, formulas, and other fragments, where a particular token affects the correctness of the result.
The weakest of all water signs is manifested in the light editing of the human text. If the user asks to fix a few typos and commas, Claude changes too few words for the detector to confidently see the characteristic sequence. When translating the situation is reversed. The model re-selects almost every word, so the translation receives a full-fledged watermark.
The defense also does not make the text invulnerable to rewriting. A small editing, according to Anthropic, usually will not destroy the signal completely, but complete reformulation can remove it. The detector will not be able to distinguish the text, completely written by Claude, from the material that the model has greatly reworked.
Regular users will not be able to check such texts yet. Anthropic is preparing a separate API for watermark detection and promises to reveal details later. Old Claude models, released before August 2, 2026, received a transition period. The company plans to gradually add markings for them in the coming months.
For images and other supported files, Anthropic chose a different approach. PNG, JPG and SVG created or processed Claude will receive cryptographically signed C2PA data in file metadata. This signature reports about the participation of Claude, but does not change the contents of the picture and also does not store information about the user.
As a result, the usual services that try to guess the origin of the text in style and typical phrases of neural networks, get a fundamentally different competitor. The Anthropic watermark is not the characteristic Claude language, but the statistical sequence of solutions laid down directly during generation. Completely proving the authorship of this method will still not be able, but a long, almost unedited text, it will become noticeably easier to associate with Claude.
Anthropic introduces such a system for the sake of the requirements of European AI legislation. The company, along with other developers, signed the European Code of Practice on AI-powered Content Transparency in July 2026. The new Anthropic marking mechanisms are going to be included around the world, since the company cannot yet reliably restrict the operation of the watermark only by European users.
The water sign does not work at all as the usual signature on the photo. Claude generates text sequentially and at each step selects the following token from several suitable options. When a few words are equally well suited in meaning, a regular model can choose the option with the help of randomness. The watermark system changes the source of such randomness and links the choice with the secret key and previous words.
As a result, a statistical drawing gradually appears in the long text. The text itself remains ordinary, and the words do not contain hidden symbols. If you check the sequence with a special detector and know the key, you can determine how much the choice of words corresponds to the work of Claude with the watermark included. Anthropic uses a variant of SynthID-Text technology, which Google DeepMind described in scientific work in Nature in 2024.
According to Anthropic's internal tests, the mechanism does not impair the quality, readability or creative abilities of the model. SynthID-Text also tested for parts of Gemini traffic. Google DeepMind found no statistically significant difference in user estimates between and without watermark responses. The system does not create additional tokens, so the cost of generation does not increase, and the effect on the speed of Anthropic calls negligible.
The watermark does not contain a user ID, company or specific dialog. According to the found label, it is impossible to establish who sent the request Claude and from which account the text appeared. The detector will be able to speak only about the probability of the Anthropic model's participation in creating a fragment.
The method has serious limitations. The shorter the text, the more difficult it is to reliably detect the statistical figure. In actual answers, the space for choice is also less. If Claude writes the title of Newton's book Principia Mathematica, the model cannot replace the correct word with another just for the sake of the watermark. A similar problem arises with the program code, formulas, and other fragments, where a particular token affects the correctness of the result.
The weakest of all water signs is manifested in the light editing of the human text. If the user asks to fix a few typos and commas, Claude changes too few words for the detector to confidently see the characteristic sequence. When translating the situation is reversed. The model re-selects almost every word, so the translation receives a full-fledged watermark.
The defense also does not make the text invulnerable to rewriting. A small editing, according to Anthropic, usually will not destroy the signal completely, but complete reformulation can remove it. The detector will not be able to distinguish the text, completely written by Claude, from the material that the model has greatly reworked.
Regular users will not be able to check such texts yet. Anthropic is preparing a separate API for watermark detection and promises to reveal details later. Old Claude models, released before August 2, 2026, received a transition period. The company plans to gradually add markings for them in the coming months.
For images and other supported files, Anthropic chose a different approach. PNG, JPG and SVG created or processed Claude will receive cryptographically signed C2PA data in file metadata. This signature reports about the participation of Claude, but does not change the contents of the picture and also does not store information about the user.
As a result, the usual services that try to guess the origin of the text in style and typical phrases of neural networks, get a fundamentally different competitor. The Anthropic watermark is not the characteristic Claude language, but the statistical sequence of solutions laid down directly during generation. Completely proving the authorship of this method will still not be able, but a long, almost unedited text, it will become noticeably easier to associate with Claude.