does claude watermark its output, and can a client detect it?
claude now signs its own work. quietly, invisibly, by default. the useful question is not whether you can hide it. it is what a detected mark actually proves about the thing you handed over.
since 2 august 2026, anthropic marks claude's output by default: an imperceptible watermark inside generated text, and signed c2pa provenance metadata inside generated image files. it applies worldwide, not only in the eu. the mark signals that content passed through claude. it is not proof of authorship, and its absence is not proof a human wrote it.
that last sentence is the whole post, and it is the part every take on this gets backwards. a mark is a signal in one direction only. it can raise a question. it cannot settle one.
what changed on 2 august 2026
anthropic turned on machine-readable marking across claude to meet the eu ai act's transparency rules, and chose to apply it everywhere rather than only in europe. the obligations come from article 50(2) of the ai act, which requires that ai outputs be marked in a machine-readable format and detectable as artificially generated.
the article 50 transparency obligations became applicable on 2 august 2026 (the next web, 12 aug 2026). anthropic signed the eu's code of practice on transparency of ai-generated content and switched marking on the same day, worldwide rather than eu-only (euronews, 11 aug 2026). any claude model launched on or after 2 august 2026 supports marking at launch, and models released before that date are still being updated (anthropic support docs, aug 2026). those older models are reported to have until 2 december 2026 to carry the mark (techcrunch, 11 aug 2026). coverage spans five claude surfaces, the platform api, claude, claude code, claude cowork and claude tag, plus aws, google cloud and microsoft foundry (anthropic support docs, aug 2026).
so this is not a setting on one product. it is the default across every surface you actually work in. if you are not sure which of those you are using for what, i mapped that in which claude surface for which task.
what the mark proves, and what it does not
a positive result is weak evidence and a negative result is no evidence at all. that asymmetry is the only thing you need to hold onto, and it applies to all three of the mechanisms people are now mixing up.
| the mechanism | what a hit proves | what a miss proves |
|---|---|---|
| text watermark | the content may have been processed by claude. anthropic's word, not a hedge i added. | nothing. heavy editing, very short answers and pre-august models can all leave no trace. |
| c2pa file metadata (.svg, .png, .jpg) | the file carries signed provenance from the system that generated it. | nothing. file metadata can be lost on re-export or re-compression, which is the known limit of metadata-based provenance. |
| third-party "ai detector" | a probability score produced by statistical guessing, not by reading any real mark. | nothing, for the same reason. it never had a mark to read. |
anthropic's own framing: a detected mark tells you the content "may have been processed by claude." not that claude wrote it. not that a person did not.
anthropic has also said fuller detection details are coming in later technical documentation. read plainly: there is no general-purpose public checker for anyone to point at your draft today. plan for the world where there is one, not for the gap.
does editing remove it?
partly, and unreliably, which is the worst of both outcomes. anthropic says the mark travels with the text when it is copied and pasted, and may persist through some editing, but heavy editing degrades it. so a light polish probably keeps the mark, a rewrite probably kills it, and you will never know which side of that line you landed on.
that is exactly why "will they be able to tell" is the wrong question to organise your work around. you cannot answer it, the answer changes with every model release, and building a delivery process on top of an unanswerable question is how people end up in a room they cannot defend. the durable version of this is deciding your disclosure policy on purpose.
four things to change in the work you deliver
none of this is dramatic. it is four small pieces of hygiene that were already good practice and are now load-bearing.
- write down your ai-use policy. one paragraph in your contract or scope: how you use ai, what stays human, who is accountable for the result. written before anyone asks beats improvised after.
- keep a human on the send. nothing ships under your name that you have not read and would defend in a room. the mark does not change accountability. it only makes the question likelier to be asked out loud.
- stop treating detector results as verdicts. in either direction. if a client comes to you with a result, the honest answer is that a hit is a signal and a miss is silence, and then you talk about the actual work.
- check the metadata on files you hand over. generated images carry signed provenance now. know what is attached to the assets you deliver, the same way you already check licensing and usage rights.
this is the diligence skill from anthropic's own ai fluency framework, arriving as a product default instead of a suggestion. i broke that framework down in the 4Ds of ai fluency. diligence was always the least glamorous of the four. it just became the one with a technical enforcement mechanism behind it.
common questions
does claude put a watermark on everything it writes?
since 2 august 2026, yes, by default. generated text carries an imperceptible watermark and generated files such as .svg, .png and .jpg carry signed c2pa provenance metadata. any claude model launched on or after that date supports marking at launch, models released before it are still being updated, and marking is applied worldwide across the platform api, claude, claude code, claude cowork and claude tag.
can my client or a brand tell that i used claude to write something?
only if they run a detector against the mark, and even then the result is a signal rather than proof. anthropic says a detected mark means the content may have been processed by claude, and that it is not fully conclusive. fuller detection details are still coming in later technical documentation, so there is no general-purpose public checker today. the safer assumption for professional work is that ai involvement is discoverable, and to set your disclosure policy on that basis instead of on whether anyone can catch you.
does editing or rewriting claude's text remove the watermark?
it can. anthropic says the mark travels with copied and pasted text and may persist through some editing, but heavy editing degrades it. very short responses and content from models released before 2 august 2026 may carry no detectable mark at all. that is why a clean result establishes nothing: absence of a mark is not evidence a human wrote it.
do i still need to disclose ai use if the content is already marked?
yes, where it matters. machine-readable marking is a provenance signal for systems, not a disclosure to the person paying you. it does not tell a client how much of the work was ai-assisted, what you reviewed, or who is accountable for the result. decide disclosure on what the client needs to know and what you are willing to sign your name to, and treat the marking as a reason to write that policy down rather than a substitute for having one.
the takeaway
claude marking its output does not make ai-assisted work risky. it makes vague ai-assisted work risky, which is a different problem with an easy fix. the people who lose here are the ones who were quietly hoping nobody would ask. the people who are fine are the ones who already had an answer, already read what they shipped, and already knew which parts were theirs.
decide your policy this week, before a client decides it for you. and if you want the sharper version of the underlying skill, it is knowing when the output is wrong in the first place: how to tell when ai is confidently wrong.
want the setup, not the guesswork?
the ai builder toolkit is the set of claude skills that do this work with you, including the draft-and-review steps you sign off on before anything leaves your desk. install them and run them in claude today. no course, no call.
see the toolkitprefer to work it out with other people in the room? the ai builders lounge is free to join.
or just follow along. new field notes most weeks on x, instagram, and tiktok.