Brand & Creative

Anthropic Is Watermarking Claude's Output

August 11, 2026

Anthropic's new watermarks flag anything Claude touched, not just what Claude wrote, and that distinction is the one brand teams should worry about.

Anthropic Is Watermarking Claude's Output
Credit:
powered by

Make State of Brand one of your go-to sources on Google

Google Icon
Add State of Brand on Google

The Register reported on Monday that Anthropic will embed marks in the text and files Claude produces, with the EU AI Act as the stated driver. Thomas Claburn's write-up is here.

The marks Anthropic describes do not distinguish between text Claude wrote and text Claude was handed to fix. Brand teams put a lot of copy through the second category.

What was announced

Anthropic has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, and set out its plans in a help-center article.

Text carries an embedded watermark, applied at model level, which Anthropic describes as woven into the words themselves and imperceptible to readers. Because it sits in the text rather than in a file wrapper, it survives copy and paste, and Anthropic says it may survive some editing. Files get signed provenance metadata built on the C2PA standard, covering types such as .svg, .png and .jpg.

The scope reaches further than the EU framing suggests. Models launched in the EU on or after August 2, 2026 support marking at launch, and Anthropic says it is working to retrofit older models during the transition period the law allows. Marking then applies wherever Claude is offered, worldwide, so a US team with no European customers is covered anyway. It also extends to Claude accessed through AWS, Google Cloud and Microsoft Foundry, which shuts the obvious side door.

Anthropic says it will help third parties detect the marks and will publish documentation explaining how.

Processed, not written

Anthropic's own limitations section says a detected mark shows that content was processed by Claude, not that Claude wrote it. The examples it gives are proofreading, translation, summarizing and converting files. Output carries a mark even when the argument and most of the sentences came from a person.

A great deal of brand work goes through that pipe. A founder's post, drafted by them and tightened by a model. A release written by the comms team and translated for four markets. A brief somebody labored over, summarized for the executive readout. A logo opened, resized and re-exported.

To a detector, all of it looks the same as something generated from a cold prompt. Most in-house teams lean on the distinction between AI-written and AI-assisted when they describe work as human-made, and a mark is not built to draw it.

The exposure sits in the gap

No brand is going to be damaged for using AI. That argument is over and audiences have largely stopped caring.

What creates risk is the distance between what you have implied and what a detector says. Contracts promising human-authored copy. Careers pages built on craft. Editorial standards claiming AI is used only for research. A public position against AI slop, with marked content in the feed. A freely available detection tool turns each of those from a private arrangement into a claim someone else can check.

Today's AI detectors are unreliable enough that accusations rarely stick, and they get contested on principle. A mark placed by the vendor, with the vendor publishing the method for finding it, is a stronger artifact. Anthropic is clear that it proves nothing on its own. It would still survive a news cycle.

The scheme may not hold

Text watermarking is unproven at scale, and Anthropic has published nothing on how the marks resist removal. Researchers have already broken image watermarking, and tools for stripping C2PA metadata are on GitHub today. Anthropic's claim that the watermark does not affect meaning or quality appears to rule out the word-choice-and-placement approach that would be the obvious method, which leaves the technique unexplained. The Register's skepticism on all of this is well earned.

Erosion through ordinary use looks likelier than deliberate evasion. Anthropic concedes that marks may vanish when text is heavily edited or paraphrased, when a passage is too short to carry a reliable signal, or when metadata is stripped by a format conversion, a re-save or a screenshot. That is a description of a normal content workflow.

The signal is therefore strong enough to embarrass and weak enough to game, which is an uncomfortable position for anyone hoping the question goes away on its own.

What to do about it this quarter

Start by mapping where Claude sits in your stack, including the places you cannot see. Translation vendors, transcription, CMS plug-ins, design exports, and whatever happens at your agency between brief and delivery. Since the API and the cloud partners are in scope, "we don't use the Claude app" is not an answer to anything.

Write your disclosure position down. Decide what counts as AI-assisted in your organization and what you are willing to say publicly. A policy you chose beats one you improvised after a reporter ran a detector over your blog.

Contract language needs attention in both directions. Client agreements that promise human-authored deliverables are worth rereading, and so are the AI clauses you impose on agencies and freelancers, which tend to be vague in ways that get awkward once marks are detectable.

Audit the claims as well as the content. The liability lives on the about page, in RFP responses and in award submissions, anywhere you have said something about how the work gets made.

If you deploy Claude inside your own product, put Article 50 in front of legal. Anthropic states plainly that its marking is meant to support your transparency obligations, not to discharge them.

None of it becomes operational until the detection documentation lands, which makes the next few months the cheap time to get this in order.

Provenance runs both ways

The standard that reveals AI involvement can also establish that a file left your studio untampered with. Synthetic brand impersonation is a live problem and it is getting worse. C2PA was built for exactly that job, long before anyone thought of it as an AI disclosure tool.

Brands that treat marking purely as a compliance headache will spend the next year fielding awkward questions about their own content. The alternative is to start using the marks.

Outlever Logo

If this caught your attention, that’s not accidental.


Decoration line

The best editorial systems don’t happen by accident. Outlever builds them.

Partial view of green concentric circles with a solid green dot on the outermost circle on a light background.Concentric green circles with a single solid green dot on a dashed circle on a light background.Minimalist design with faint curved lines and scattered small green dots on a white background.

Come back for the reason it lands.


Subscribe for the kind of thinking that makes people stop, read and come back.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.