Anthropic to Watermark Claude’s AI-Generated Text to Comply With the EU AI Act
Anthropic detailed a token-level watermarking scheme for Claude's text, built on Google DeepMind's SynthID-Text method, to comply with the EU AI Act's transparency mandate.
Anthropic said on August 14, 2026 that future Claude models will generate text carrying an invisible watermark, a change the company says is needed to comply with the European Union’s AI Act. The watermark adds no visible characters and cannot be seen by a reader. Anthropic says it also has no measurable effect on the quality of Claude’s answers.
Table Of Content
The change follows an EU requirement that took effect August 2, 2026: AI providers serving the EU market must mark AI-generated content so it can be identified. Anthropic said it, along with several other major AI model providers and roughly 190 total signatories, signed the EU’s Code of Practice on Transparency of AI-Generated Content in July 2026. Anthropic said other major model developers who signed the same code of practice will roll out their own watermarks too, so the underlying requirement is not specific to Claude.
How the watermark works
Large language models generate text one word at a time, picking each next word from a list of statistically likely candidates. Anthropic’s own example: in the sentence “The weather today was cold and…”, the next word is very unlikely to be “sugary,” but “overcast” and “grey” are both quite plausible. In cases like that, where either choice reads naturally and the meaning barely changes, the model’s pick is normally settled by an arbitrary random number.
Anthropic’s watermark swaps out that source of randomness. Instead of an arbitrary random number generator, the choice is settled using a secret cryptographic key combined with the words that came immediately before. The model still appears to choose at random from a reader’s point of view, but the sequence of choices now forms a statistical pattern that is undetectable without the key, and recoverable by anyone who holds it. Anthropic describes the underlying technique as a version of Google DeepMind’s SynthID-Text approach, published in a Nature paper in 2024, which itself builds on a watermarking proposal Scott Aaronson made in 2022.
Anthropic says the same principle does not extend cleanly to code: as The Register noted in its coverage of the announcement, the watermarking method cannot simply start swapping method names the way it can swap an adjective in a sentence. That is a narrower canvas to work with than prose, since renaming an identifier is far more likely than swapping “grey” for “overcast” to change what a program actually does.
What Anthropic claims about quality and cost
Anthropic said internal testing found no impact on the content, creativity, or readability of Claude’s text. It also cited the original SynthID-Text paper, in which Google DeepMind served a watermarked model to a portion of Gemini traffic and found no statistically significant difference in thumbs-up and thumbs-down ratings compared with an unwatermarked model. In a separate controlled study, human raters comparing watermarked and un-watermarked answers side by side reported no difference in quality.
The Register put a version of Anthropic’s own example to Claude Opus 4.8 directly. Rather than settling on a single low-stakes adjective, the model produced a full paragraph of scene-setting prose about cold, crisp air and a pale sky, a reminder that chat-tuned models optimized for engagement do not always resemble the plain autocomplete framing Anthropic uses to explain how watermarking works underneath.
On cost, Anthropic said watermarking produces no extra tokens, so serving a watermarked response costs the same as an unwatermarked one and has a negligible effect on speed.
Detection, privacy, and limits
Anthropic said it will “soon” offer a watermark detection API and is still working out the implementation details, a detail also picked up in BleepingComputer’s coverage of the announcement. That mechanism is different from third-party AI detection tools like Pangram, which sxz.io covered when Substack rolled it out to readers in July 2026. Anthropic says tools like Pangram work by spotting stylistic “tells” in AI writing, such as a fondness for the “this isn’t X, it’s Y” construction or overusing the word “quietly,” rather than checking for a cryptographic signature.
Anthropic was direct about the watermark’s limits. “Light editing probably won’t remove the watermark completely; a complete rewrite where every word is replaced will,” the company said, adding that at that point “it’s arguable whether the text can any longer be described as AI-generated.” Even a successful detection only proves so much: a watermark “can only determine that Claude was likely involved with the content at some point,” Anthropic said, and “it cannot distinguish ‘Claude wrote this’ from ‘Claude heavily edited this.'” A detected watermark also does not change who owns a given output or who is legally responsible for it, according to the company.
On privacy, Anthropic said the watermark carries no identifying information and cannot be traced back to a specific user, organization, or conversation. Translations are watermarked too, since every word in a translation is chosen by Claude.
Rollout and scope
The watermark applies to future Claude models going forward. Models released before August 2, 2026 fall under the EU’s transition period, and Anthropic said it is working to extend watermarking to those models “over the coming months.” Despite the EU-driven mandate, Anthropic said the watermark will apply to Claude’s output worldwide at launch, not just to EU users, because it does not yet have “a durable way to scope it by region.”
Text is not the only output Anthropic is marking. When Claude produces an image or other supported file type, it now attaches a small, cryptographically signed content credential to the file’s metadata, using the open C2PA standard also used by camera makers and photo-editing software to record how a file was produced. Anthropic says nothing about the file itself changes and the credential is not embedded or hidden the way the text watermark is; it only indicates that Claude was involved in producing the file, again without identifying who asked for it.
Anthropic’s watermarking scheme is one way of meeting the specific marking duty that sxz.io detailed earlier this month: Article 50(2) of the EU AI Act requires providers of generative AI systems to mark synthetic text, audio, image, and video output in a machine-readable format, using techniques like metadata tagging or watermarking, so automated systems can detect that the content was artificially generated. Systems already on the market before August 2, 2026 have until December 2, 2026 to meet that specific requirement, a grace period that lines up with the “coming months” timeline Anthropic gave for watermarking its older Claude models. Anthropic’s post makes clear that watermarking is one piece of a wider compliance push that other major AI labs are now working through in parallel, on a deadline set by EU regulators rather than by the labs themselves.








No Comment! Be the first one.