AI
Anthropic Adds Invisible Watermarks to Claude AI Text
Anthropic now embeds invisible watermarks in Claude's generated text and C2PA signed metadata in images, across the API, Claude Code, Cowork, and Tag.

Anthropic has begun embedding machine-readable marks in everything Claude produces, pairing an invisible watermark woven into generated text with cryptographically signed metadata on images. The company detailed the system in a support document published this month, and it applies automatically. Users do not turn it on, and they cannot turn it off.
An invisible signal inside the text itself
The text layer is the more technically ambitious of the two. Rather than appending a disclosure or hiding a tag in formatting, Claude weaves an imperceptible watermark directly into the words it generates. Anthropic says the mark does not change the meaning, quality, or readability of a response, and readers will not notice it. Crucially, the company says the watermark travels with the text when it is copied and pasted elsewhere, which is exactly where past provenance schemes have fallen apart.
That copy-paste survivability is the detail worth dwelling on. Metadata-based labels die the moment content leaves the platform that applied them. A watermark carried in the statistical texture of the text itself has a chance of surviving the trip through an email, a document, or a content management system.
C2PA metadata for images
For files, Anthropic is taking the standards route. Claude now attaches signed provenance metadata to supported file types, specifically .svg, .png, and .jpg, following the Coalition for Content Provenance and Authenticity (C2PA) open standard, the same framework adopted by Adobe, Microsoft, Google, and camera makers including Leica and Sony. A C2PA manifest is cryptographically signed, so a verifier can confirm both that the file came from Claude and that the manifest itself has not been forged.
Where the marks apply
Coverage is broad by design. Anthropic says marking applies everywhere Claude runs: the Claude Platform API, the Claude apps, Claude Code, Claude Cowork, and Claude Tag, its Slack integration. Claude models launched on or after August 2, 2026 support machine-readable marking at launch, and Anthropic says retroactive support for existing models is in progress. In short, Anthropic now marks Claude output across five product surfaces and three image formats, with every model launched since August 2, 2026 watermarked from day one.
What it means for detection
The immediate beneficiaries are the people who have to make judgment calls about provenance: teachers, editors, hiring managers, and platform moderators. Statistical AI-text classifiers have well-documented false positive problems, and they degrade with every new model generation. A cryptographic or embedded mark is a categorically stronger signal, and a growing set of AI watermark detection tools already checks documents and images for exactly these kinds of embedded signals and C2PA credentials. Anthropic says it will publish details on its own detection mechanisms in forthcoming technical documentation.
Watermarking will not settle every dispute, but it moves AI-content detection from statistical guesswork toward verifiable evidence, and that is the largest shift the detection field has seen since ChatGPT launched.
The honest caveats
Anthropic is unusually direct about the limits. A detected mark provides a signal that content came from Claude, but it is not fully conclusive, and the absence of a mark proves nothing. Content that is heavily edited, paraphrased, translated, or mixed with human writing after generation may carry no detectable mark at all. A determined bad actor can still launder text through a paraphraser.
That framing is the right one. Provenance marking raises the cost of passing AI output off as human work and gives honest actors a way to verify origin. It does not make deception impossible, and Anthropic, to its credit, is not claiming otherwise. The open question is whether OpenAI and Google follow with text watermarks of their own. Google has shipped SynthID for images and audio; nobody has deployed text watermarking at this scale before. Someone had to go first.
About the author
Derek Fung
**Derek Fung** is a cybersecurity and cloud computing reporter at *Tech Forum*, covering the infrastructure that powers Canada's digital economy. His investigative reporting on security threats and cloud trends keeps IT leaders informed and prepared.