Blog · AI Text Watermark · 25 Sep 2026
Blog
AI Text Watermark

AI text with awatermark:what it means

Anthropic marks text from its Claude models with a pattern nobody can see. What it is, where its limits are and why your own review still matters more.

Get in touch
Enquiry
Nikolai Schöbel und Jeremias Burger, Co-Founder Scalableloops

Let's talk about your project.

First we check whether the project fits your business model. Then you get a proposal with phases and effort.

Talk about AI use or call: +49 151 1576 5566
Blog · AI Text Watermark

Since 2 August 2026, text from new Claude models carries an invisible watermark. It lives in the choice of words, not in hidden characters, and it travels with the text when you copy it. You can't see it, your customers can't see it, and according to Anthropic only authorised bodies such as regulators, media and fact-checkers can currently check for it. For your business, that means the provider's watermark does not replace your own disclosure where the EU AI Act requires one, and it certainly does not replace someone reading, checking and taking responsibility for the text.

In brief
  • Claude marks text through a statistical pattern in word choice that survives copy and paste.
  • According to Anthropic it costs nothing extra and does not change quality; for now only authorised bodies may check it.
  • Heavy rewriting and short texts weaken the signal; a match does not prove the whole text was written by AI.
  • Where the disclosure duty under Article 50 of the EU AI Act applies, it remains your job.
Published 25 Sep 2026Nikolai Schöbel and Jeremias Burger8 min read
Nikolai SchöbelJeremias Burger

Nikolai Schöbel and Jeremias Burger

Co-founders of Scalableloops GmbH. Nikolai Schöbel leads online marketing and AI strategy, Jeremias Burger the AI architecture. Both build AI systems and train teams on them in their own agency work.

On this page
  1. How does a watermark in AI-generated text work?
  2. What exactly Anthropic marks in Claude
  3. Who can tell whether a text came from Claude?
  4. Does the watermark survive rewording and translation?
  5. Do Google and OpenAI do this too?
  6. Does the provider's watermark replace your own disclosure?
  7. What it means for your website, emails and quotes
  8. Frequently asked questions
  9. How to use AI texts safely in your business
  10. Where the information on this page comes from
Basics

How does a watermark in AI-generated text work?

A language model writes word by word. At every point there are several words that would fit equally well. That is where a text watermark comes in: a secret key nudges the choice between these equivalent options slightly in one direction. A single word gives nothing away. Across many words, though, a statistical pattern emerges that detection software with the matching key can recognise.

Anthropic describes its method in exactly these terms: the key and a few preceding words determine which word the model picks in low-stakes choices. Google's SynthID Text follows the same basic principle and adjusts the probabilities the model uses to select the next word.

One point matters for understanding it: these are not hidden special characters that you could find and delete in a text editor. The pattern sits in the words themselves. That is why it survives when you copy a text and paste it into an email, a quote or your website's CMS.

0

extra characters in the text: according to Anthropic, the Claude watermark lives entirely in the choice of words.

Anthropic, How Claude's text watermarking works
Claude

What exactly Anthropic marks in Claude

New Claude models released from 2 August 2026 mark their text from day one. Anthropic cites Article 50 of the EU AI Act as the reason but applies the marking worldwide: in the Claude app, in the API and through the cloud platforms of AWS, Google Cloud and Microsoft. According to Anthropic, older models are to follow by 2 December 2026.

Anthropic says that in internal tests the watermark changed neither content, creativity nor readability. Because no extra words are generated, the provider says usage does not cost more either. The watermark also contains no information about users, companies or chat histories. All three points come from the provider itself; they cannot be verified independently at the moment because the detection tool is not public.

Where there is little room in word choice, the method does not work: in program code, maths and factual passages that allow only one correct wording. For files such as PNG or JPEG, Anthropic takes a different route, namely signed provenance data based on the C2PA standard.

Detection

Who can tell whether a text came from Claude?

Not you, at least not yet. According to Anthropic, text detection is available in a limited preview only to authorised organisations, as EU law provides: for example supervisory authorities, law enforcement, media, fact-checkers, independent researchers and educational institutions. Wider access has been announced, but without a date.

How to read a match matters even more. Anthropic itself says a detected watermark only shows that Claude may have processed the content. It does not prove that the whole text came from AI, because a human text that was corrected, translated or summarised can also carry the pattern. Conversely, a missing watermark does not prove that a person wrote it. A commentary on heise therefore warns against false security and against unjustified accusations towards people whose text was merely edited.

Limits

Does the watermark survive rewording and translation?

Partly. According to Anthropic, light editing probably won't remove the pattern completely, while a full rewrite in which every word is replaced will. Tech outlets such as ComputerBase sum it up this way: extensive changes, paraphrasing or translation can make the signal unrecognisable.

With translations, it depends on who translates. If Claude translates, the model chooses every word and therefore marks the translation too. If a text runs through a different tool, detectability drops. Google documents the same for SynthID Text: thoroughly rewritten or translated texts sharply reduce the detector's confidence.

Short texts are the third weak spot. A subject line or a two-line message contains too few word choices for a reliable signal. The longer a text, the more reliable the result.

SituationWhat happens to the watermark
Copying and pasting textStays intact because it lives in the words
Light corrections, a few words swappedAccording to Anthropic, probably still detectable
Completely rewordedSignal is lost
Translated by ClaudeThe translation carries its own watermark
Translated or rewritten with another toolSignal becomes much weaker
Very short textToo little material for a reliable result
Program code, unambiguous factsLittle room for choice, the method barely works
Other providers

Do Google and OpenAI do this too?

Google DeepMind marks text from the Gemini app with SynthID Text and released the method as open source together with Hugging Face in October 2024. Its own documentation lists the same limits as for Claude: less effective for factual answers, much weaker after thorough rewriting or translation.

In 2024, OpenAI confirmed that it had developed its own text watermark and described it as highly accurate, provided there is enough text. It was not released at the time. The company gave two reasons: translation or rewording with another model can get around the pattern, and people who write in a foreign language with AI could be disproportionately affected. Whether OpenAI uses a text watermark today is something we could not confirm from public primary sources.

Law

Does the provider's watermark replace your own disclosure?

No. The EU AI Act separates two roles. Providers such as Anthropic must ensure under Article 50(2) that outputs are marked in a machine-readable format and detectable as artificially generated. The watermark is exactly that obligation. Deployers, meaning companies that use AI, have obligations of their own.

Two of them often affect businesses. Under Article 50(1), people must be told that they are interacting with an AI system, for example a chatbot on your website, unless this is obvious anyway. Under Article 50(4), it must be disclosed when AI-generated text is published to inform the public on matters of public interest. This does not apply if the text has undergone human review or editorial control and a person or company holds editorial responsibility. These obligations have applied since 2 August 2026.

An invisible pattern that your readers cannot see does not count as disclosure to those readers. Whether and where your business has to disclose depends on the individual case. This article is not legal advice; for a binding assessment, please consult a lawyer.

Provider watermarkYour own disclosure
Who is responsible?The AI provider (Art. 50(2))Your business as deployer (Art. 50(1) and (4))
Visible to whom?Only to detection software with the keyTo readers, customers, conversation partners
What does it do?Machine-readable signal of possible AI useOpen information that AI was involved
Is it lost through editing?Yes, with heavy rewritingNo, you set it deliberately
Does it replace the other?NoNo
In practice

What it means for your website, emails and quotes

For most businesses the watermark changes little day to day. A quote or customer email that you draft with Claude and then check and send yourself looks exactly the same as before. Nobody will be able to tell from the text that AI helped.

What pays off is shifting your attention away from the watermark and towards the content. A language model can get figures, dates, prices or product features wrong, and that has nothing to do with the watermark. Publishing an AI draft on your website without checking it risks false statements under your own name. Checking it thoroughly and putting it into your own words also meets the condition that Article 50(4) attaches to the exemption: human control and clear responsibility.

Trying to strip the watermark on purpose, on the other hand, gets your business nowhere. The disclosure duty depends on actual AI use and on editorial responsibility, not on whether a pattern can be detected.

  1. 01

    Draft

    Step 1

    AI provides structure and a first wording; you set the context and the goal.

  2. 02

    Fact check

    Step 2

    Every figure, every price, every date is checked against your own records.

  3. 03

    Revision

    Step 3

    The text gets your tone and your examples; filler phrases go.

  4. 04

    Approval

    Step 4

    A named person takes responsibility for the text before it is published or sent.

Frequently asked questions

Frequently asked questions

Can I check myself whether a text carries a Claude watermark?

Not at the moment. According to Anthropic, text detection is available in a limited preview only to authorised organisations such as authorities, media, fact-checkers and researchers. Wider access has been announced.

Does the watermark make my texts worse?

According to Anthropic, no: in internal tests content, creativity and readability stayed the same, and usage does not cost more. This cannot be verified independently at the moment because the detection tool is not public.

Can the watermark be removed?

Heavy rewriting, translation with a different tool or very short texts weaken the signal. For your legal obligations this makes no difference, though, because disclosure depends on actual AI use and on editorial responsibility.

Do I have to label AI texts on my website?

That depends on the individual case. Article 50(4) of the EU AI Act requires disclosure for AI texts that inform the public on matters of public interest, unless the text has undergone human review and someone holds editorial responsibility. For binding answers, get legal advice.

Does a detected watermark prove that a text came from AI?

No. Anthropic explicitly calls it an indication, not proof. A human text that Claude only corrected or translated can carry the pattern too. Conversely, a missing watermark does not mean a person wrote it.

Does ChatGPT mark its texts as well?

In 2024 OpenAI confirmed it had its own text watermark but did not release it at the time. We could not find evidence of current use in public primary sources. Google marks Gemini texts with SynthID Text.

What now

How to use AI texts safely in your business

  1. 01

    List where you use AI

    Write down where AI produces text today: website, blog, emails, quotes, chatbot.

  2. 02

    Clarify obligations

    Check for each place whether Article 50 of the EU AI Act applies, for example for a chatbot or public information texts.

  3. 03

    Set a review step

    Decide who checks and approves AI drafts for content before they leave your business.

  4. 04

    Train your team

    Show your team how to check, revise and take responsibility for AI drafts instead of just copying them.

The watermark tells you that an AI may have helped write a text; whether the text is right and sounds like you is still your call.

or call: +49 151 1576 5566

Further reading

Projekt-Detail

    Got a project in mind?

    We reply personally. First a use-case check, then an architecture proposal.

    Start your inquiry