{ Banner }

Intellectual Property & Technology Blog

The Ghost in the Text: What Claude's New Watermark Actually Protects

Anthropic's move is a compliance response to the EU AI Act, not a breakthrough in AI detection, and it leaves three questions unanswered.

On August 2, 2026, the day Article 50(2) of the EU AI Act took effect, Anthropic announced that it will begin embedding invisible watermarks in text generated by new Claude models and will work toward implementing this feature in models released before August 2, 2026. The mark lives in the statistics of the writing itself, the small, repeated word choices a model makes across a response, not a visible tag or footer. It survives copy and paste, may survive light editing, and will likely not survive heavy rewriting, translation, or blending with other text. In addition, Anthropic will embed signatures in the metadata of files processed by its models, using an open standard, Coalition for Content Provenance and Authenticity (C2PA).

Article 50(2) requires generative AI providers to mark synthetic text, audio, image, and video in a machine-readable format other systems can detect. Anthropic signed the EU's Code of Practice on that obligation and, rather than build an EU-only version, is rolling the watermark out worldwide. Non-compliance carries fines up to 15 million euros or 3 percent of global turnover, whichever is higher. A global rollout given that exposure is the more defensible engineering choice, not a generous one.

The Industry Isn't Moving Together

Google's SynthID has watermarked Gemini text for some time and Google has open-sourced the method. Microsoft, Amazon, Mistral, and Cohere signed the same EU Code Anthropic did. OpenAI has moved slower on text: it shelved an earlier plan in 2024 after internal research found nearly a third of ChatGPT users would use the product less if watermarked, and has since focused its provenance work on images through C2PA instead. Meta declined to sign the Code at all, citing legal uncertainty for model developers. This is not an industry consensus. It is a handful of companies with the most EU exposure moving first.

Three Questions Nobody Has Answered

How the watermark actually works is not fully public. Anthropic describes a pattern embedded “at the model level” in word choice and phrasing, detectable in aggregate but invisible sentence by sentence. That tracks with statistical watermarking research that has circulated for years, but Anthropic has not published a technical specification, and detection tools are still “forthcoming.”

How the EU will enforce this is untested. National market surveillance authorities, not the EU AI Office, hold primary responsibility, and no one has tested the fine structure yet. The Code of Practice behind the technical standard is voluntary. What a regulator will accept as compliant marking, versus what a company claims, has no track record.

And what counts as an “AI output” is not settled. The Act exempts assistive edits, such as grammar correction, that do not substantially alter meaning. Anthropic's own guidance concedes the mark can appear on text Claude merely proofread or translated, and can be absent from text Claude generated outright if the passage was short or heavily edited afterward. A mark that is both over-inclusive and under-inclusive is a compliance artifact, not a provenance tool.

What Businesses Should Do Now

Assume that any product built on an AI model will carry this kind of marking, whether or not your business ever touches the EU. Tell employees now that unauthorized use of AI tools is about to become far easier to detect, by compliance teams and by customers who never approved AI use in the first place. Visibility cuts both ways.

  • Marcus  Burnside
    Senior Counsel

    Marcus Burnside advises technology companies, private equity-backed businesses, and foreign clients on intellectual property strategy, AI governance, and data privacy. His practice sits at the intersection of three areas most ...