Anthropic marks what Claude touches, not what it wrote
Ricardo Argüello, August 17, 2026
CEO & Founder
General summary
Anthropic signed the EU AI Act's Article 50(2) code of practice, and since August 2, 2026 the text Claude produces carries an invisible watermark, worldwide and across every Claude surface. Anthropic's own limitations note makes the point most coverage skipped: a detected mark means Claude processed the content, not that Claude wrote it.
- Models launched on or after August 2, 2026 ship with marking on, and Anthropic is retrofitting older ones, worldwide rather than only in the EU
- It applies when you reach Claude through AWS, Google Cloud or Microsoft Foundry, so it does not depend on your having a direct Anthropic contract
- The text mark is a statistical bias in token selection keyed to a secret Anthropic holds: it survives copy-paste and light editing, and degrades under paraphrase
- Proofreading, translating or summarizing human-written text leaves the same mark as generating from scratch, and no detector currently separates the two
- The detection API is announced but not yet callable, so nobody outside Anthropic can verify anything right now
Imagine your print shop starts pressing an invisible watermark into every sheet that runs through its machines. It does not distinguish a document they drafted from one you wrote and only sent over to be copied. Both come out marked. And you signed a client agreement promising that document would be your own work. The watermark accuses you of nothing, but it leaves open a question nobody could ask before.
AI-generated summary
Anthropic signed the EU AI Act’s Article 50(2) code of practice. Since August 2, 2026, the text Claude produces carries an invisible watermark.
Nearly all the coverage ran the same headline: AI content is detectable now. That is not what the announcement says.
The mark identifies who touched the text, not who wrote it
Anthropic is the one making this clear, in its own limitations note. A detected mark means the content passed through Claude. It does not mean Claude wrote it.
Ask Claude to fix the spelling in a paragraph you wrote, and the output comes back marked. Ask it to translate a statement your comms team drafted, marked. Summarize an internal report, same. Convert a file, same.
To a detector, a document your people wrote and merely sent out for translation looks a lot like one generated from a cold prompt.
This is where it stops being a technology story and becomes a contract problem.
Your company has already put things in writing on the assumption that nobody could check. Human-authored content clauses. RFP responses where somebody committed that deliverables are not AI-generated. Editorial policies stating AI is used for research only. Careers pages selling craft.
None of those promises were written expecting verification. Something now points in that direction, even if it does not yet point well.
What Anthropic switched on, with dates
Worth separating the confirmed from the repeated.
Models launched on or after August 2, 2026 ship with marking enabled, and Anthropic says it will extend support to earlier ones, per TechCrunch. It applies globally rather than only to European traffic, and across the whole product surface: the API, Claude, Claude Code and Claude Cowork.
The detail most readers skip: it applies when you reach Claude through AWS, Google Cloud or Microsoft Foundry, according to Euronews. Which means it does not depend on you holding a contract with Anthropic at all. If your software vendor calls Claude from Bedrock, what they hand you arrives marked.
Technically it is not metadata. It is a statistical bias in the model’s word selection, checkable against a key Anthropic holds. Each individual choice looks ordinary; the pattern emerges across enough text. That is why it survives copy-paste, and why paraphrase degrades it. Generated files carry something different: signed C2PA metadata, which a screenshot or a re-save strips entirely.
The regime behind this is not symbolic. Article 50 became enforceable on August 2, 2026, and non-compliance runs to 15 million euros or 3% of global annual turnover, whichever is higher.
There is genuine technical disagreement about how well the mark holds, and it deserves an honest hearing. Engineers in the announcement threads pointed out that running a passage through a second model with a rewrite instruction erases the signal in seconds. It sounds like a fatal objection and it mostly is not: it catches the careless, which is most people, and misses anyone deliberately hiding. You just need to be clear about which of those two you care about.
Nobody outside Anthropic can read the mark yet
This is the part that changes the conversation, and it barely made the coverage.
Anthropic announced a detection API. It is not callable yet, with no published pricing or access tier. In the meantime, one company holds the key.
Andrea Saez tried building a detector from the outside, using n-gram frequency analysis and z-score testing, roughly what a real detector would look for. She ran it against her own writing. It flagged every other word red. Not because a watermark was there, but because natural language repeats function words at predictable intervals, and without the key that looks identical to a signal.
Her conclusion matters more than the experiment: no one outside Anthropic can realistically verify this today.
That is the asymmetry. You cannot audit your own exposure. A vendor tells you they do not use AI and you have no way to check. It runs the other way too: you cannot demonstrate that the report your team wrote is clean, because the only possible referee is not open for business.
The sharpest comment I read on the announcement reduced it to one question: who gets the decoder. Public, and this is provenance and transparency. Licensed to selected platforms and partners, and it is an enforcement mechanism. Today it is neither, and it stays neither until Anthropic decides.
It is the same gap we hit when Satya Nadella framed the reverse information paradox: his trust-boundary answer assumes you already know what needs protecting. Almost no company does.
What you can actually do this quarter
The upside of detection not existing yet is that this is the cheap quarter to get your house in order. Once the API ships, the conversation turns reactive.
At IQ Source, when a client asks what to do about this, we do not start with the watermark. We start with four questions:
Where does Claude actually sit in your operation? Not where you think it sits. Where it sits. That includes your agencies, your software vendors, whoever handles translation, whoever drafts proposals. The answer is almost always wider than management assumes, and that distance is the finding.
What did you already put in writing? Live contracts, RFP responses, editorial policy, terms with regulated clients. Go read the documents, not anyone’s memory of them. If the phrase “human-authored” turns up anywhere, that is the first file to open.
Where do those two lists collide? That is your real exposure, and it is rarely where people look for it. In practice the most common collision point is not drafting at all. It is translation and copy-editing, which almost nobody counts as “using AI” and which leaves exactly the same mark.
What are you willing to say out loud? That is a positioning decision, not a legal one. An AI use policy you can defend is worth more than a human-authorship promise you cannot verify yourself.
That work is discovery, not implementation. It is precisely what AI Maestro’s Process Reality Map produces: a written account of how your operation actually runs, before anyone decides what to automate or what to declare. Without that map, any AI policy you publish is a statement of intent.
It fits the pattern we have been writing about for months: the model is a commodity and governance is the moat. Anthropic’s copyright settlement already showed that the line that matters is not drawn by the vendor but by what you can document. The watermark is that same problem from the other side. It does not change what you do. It changes what can be proven about what you do.
The watermark is not the story
The story is that comfortable ambiguity is ending.
For three years, “do you use AI?” was a question you answered with whatever landed best, because nobody could check. That window is closing. Slowly, and through an imperfect implementation, but closing.
And what gets exposed will not be the AI use. Few clients punish that anymore. What gets exposed is the distance between what your company does and what your company signed saying it did.
You measure that distance before anyone else can.
Let’s map where AI actually sits in your operationFrequently Asked Questions
Claude's watermark is a statistical bias in the model's word choices, verifiable against a key Anthropic holds. It shows the text was processed by Claude, not that Claude authored it. Proofreading, translating or summarizing human-written text leaves an identical mark.
Yes. Anthropic applies Claude's watermarking worldwide rather than only to EU traffic, across the API, Claude, Claude Code and Claude Cowork. It also applies when you consume Claude through resellers such as AWS, Google Cloud or Microsoft Foundry.
Claude's watermark survives copy-paste and light editing because it lives in word selection rather than metadata. It degrades under paraphrase: running a passage through a second model with a rewrite instruction strips the signal. It catches the careless, not the deliberate.
Before public detection exists, a company should map where Claude actually sits in its operation, including agencies, vendors and translation work, then compare that against written commitments already made in contracts, RFP responses and editorial policies on AI use.
Related Articles
Anthropic Reviewed 141,006 Runs and Found 3 Real Hacks
Anthropic disclosed three cases where Claude broke into real companies during evaluations. It found them by reading old transcripts, not by monitoring.
Fable 5 Is Back, But the Government Already Audits Anthropic
The U.S. Commerce Department suspended Fable 5 over a jailbreak and returned it in exchange for pre-release access to Anthropic's future models.
Amodei Told the Senate to Audit AI Before It Turns Lethal
Dario Amodei asked the Senate for mandatory testing of frontier AI models, comparing them to airplanes. Your company should be demanding the same thing
Anthropic's J-Space Can Now Audit Claude's Intent
Anthropic published the J-space: an internal layer that audits what Claude is thinking before it answers, catching deception, fabrication, and hidden goals.
Anthropic measured its own AI. Can you prove yours?
Anthropic says Claude writes most of its merged code and its engineers ship 8x more per quarter. The new line isn't who uses AI, but who can prove output.
Karp Attacked AI Pricing on CNBC. A Bill Proved Him Right.
Alex Karp accused OpenAI and Anthropic of extracting value through token pricing. Days later Pylon's CEO watched his bill jump from $400K to $1.4M.