SAN FRANCISCO, 11 AUG 2026 — Every piece of text a current Claude model writes now carries an invisible mark, and every image or SVG it generates carries a cryptographic receipt. The marking happens at the model, so it applies whether the text came from the API, the chat app, Claude Code or a cloud partner's endpoint.
We reported the commitment itself when it was made, and the short version has not changed: the file half is real cryptography and the text half has no public detector. Here is what is actually marked, what the law demands, who else is doing it, and whether anyone outside these companies can read the results.
What Claude marks, how, and since when
Anthropic's own documentation is the authority here, and it is unusually specific.
For text, the company embeds "an imperceptible watermark directly into the text itself" which "won't change the meaning, quality, or readability". It "will travel with the text when it's copied and pasted elsewhere, and may persist through some editing". Crucially it operates at model level, applying "no matter which Claude product or surface the text comes from".
For files, Claude attaches signed provenance metadata following the C2PA standard to supported types — .svg, .png and .jpg — which "lets you detect whether the file has been tampered with".
Why: Article 50 of the EU AI Act became applicable on 2 August 2026. The dates line up exactly, and Anthropic does not pretend otherwise.
What C2PA metadata actually is
C2PA — the Coalition for Content Provenance and Authenticity — is an open standard for attaching a cryptographically signed manifest to a file. The manifest records who created the content, when, with which tool, and what was done to it since; the signature makes the record tamper-evident.
It is not a watermark. Nothing is hidden inside the pixels. It is a receipt that travels with the file. Strip the manifest, and the file has no provenance at all, rather than a false one. This is both its strength and its weakness: a simple screenshot destroys it.
What the EU AI Act actually requires
Article 50 is the transparency provision, and it is four obligations rather than one.
Providers of systems people interact with must make clear it is an AI, unless that is obvious. Providers of synthetic-content generators must mark outputs "in a machine-readable format that is detectable as artificially generated or manipulated", using solutions that are "effective, interoperable, robust and reliable as far as this is technically feasible". Deployers of emotion-recognition or biometric systems must tell the people exposed to them. And deployers publishing deepfakes, or AI-generated text on matters of public interest, must disclose it.
Penalties run to €15 million or 3 per cent of worldwide annual turnover, whichever is higher.
Two exemptions matter more than they look. Artistic and satirical work needs only appropriate disclosure. And AI-generated text that has been human-edited, with editorial responsibility assigned, is exempt from the deployer disclosure duty — which is a description of ordinary journalism, and of how this article was produced.
Who else is marking, and what they mark
Anthropic is not first and the field is not converging on one method.
| Approach | Can you check it? | |
|---|---|---|
| Anthropic | Embedded text watermark; C2PA on SVG, PNG, JPG | C2PA yes. Text: no public detector yet |
| SynthID across image, audio, video, text | Verification in Gemini; a Detector portal behind a waitlist | |
| OpenAI | SynthID audio embedded in GPT-Live output via ChatGPT Voice and the API | A developer verification API is offered |
| Others | Apple, ElevenLabs, Kakao and NVIDIA named as SynthID partners | Depends on the surface |
Google has made the interesting move of recruiting rivals like OpenAI onto its SynthID scheme rather than competing with them on standards. Interoperability is one of Article 50's four criteria, and a shared scheme is the cheapest way to claim it.
The law in this region
ASEAN has no single instrument, and the spread between members is wide.
Vietnam has the hard mandate. The 2025 Law on Artificial Intelligence, No. 134/2025/QH15, took effect on 1 March 2026. It requires AI-generated or edited audio, images and video that simulate real people or recreate real events to be labelled in an easily recognisable manner, and — the part that echoes Brussels — Article 11 clause 4 requires marking "in a machine-readable format as prescribed by the Government". The duty sits with deployers. Cinematographic and artistic works get a softer form of the requirement.
Singapore has guidance, not law. The Model AI Governance Framework for Generative AI, published by IMDA and the AI Verify Foundation, recommends that users be able to tell they are looking at AI-generated content and that digital watermarking and cryptographic provenance be explored. It is voluntary and not legally binding.
Indonesia is legislating around the edges. Its draft copyright amendments would require works with material AI involvement to disclose that involvement — a provenance duty arriving through authorship law rather than AI law.
The ASEAN Guide on AI Governance and Ethics, agreed in 2024, sets shared principles for the region but binds nobody.
Can you read any of these marks?
Yes, for files. No, for text. The difference is everything.
For files with C2PA credentials, yes and it is straightforward. The Content Credentials inspector at verify.contentauthenticity.org — where contentcredentials.org/verify now redirects — will show a file's signed manifest, including whether a tool recorded it as AI-generated. Adobe's software and several cameras write these credentials natively.
For SynthID, Google offers verification inside Gemini for supported image, video and audio files, with a separate Detector portal rolling out to journalists and researchers through a waitlist.
For Claude's text watermark, there is currently no way for you to check. Anthropic says it is working to enable users and third parties to detect the marks and will publish technical documentation. Until that documentation lands, the mark exists but the public cannot read it.
What a mark can and cannot tell you
Anthropic's own caveats are the honest place to start, and they are stronger than most coverage suggests.
A detected mark "is not fully conclusive" and "does not, on its own, confirm the full provenance". And the reverse matters more: "lack of a detected mark doesn't mean the content wasn't AI-generated or processed", particularly where text has been heavily edited or came from an older model.
The test is one-directional: a hit is evidence, but a miss is nothing at all. Any policy written as "if it has no watermark it is human" is broken before it is enforced, and that is the shape of policy schools and employers are currently reaching for.
Robustness is the other problem, and it is not theoretical. Research summarised by the Cloud Security Alliance puts the cost of defeating watermarking schemes at under $50 per attack, and notes public tools that already defeat Google's SynthID detector on images it produced. Article 50 asks for solutions that are effective, interoperable, robust and reliable "as far as this is technically feasible" — and that last clause is doing an enormous amount of work.
What this means in practice
If you publish, understand the exemption: text that a human has edited, with editorial responsibility assigned, is outside the deployer disclosure duty. That is not a loophole; it is the law recognising that an edited, bylined, accountable piece of writing is a human publication regardless of what drafted a sentence in it.
RECATOOLS articles are AI-assisted and always have been, disclosed on our disclaimer page. They are researched against primary sources, edited, fact-checked and bylined by a named desk that carries responsibility for them. This one included. The invisible mark Anthropic now embeds will be present in drafts of pieces like this. It says nothing about whether the reporting is sound. That is the point.
What to watch
Keep an eye out for Anthropic's detection documentation. Until it is published, the text watermark is a compliance artefact, not a public tool, and no one outside the company can audit the claim.
Whether Vietnam's implementing decree specifies a format. "Machine-readable as prescribed by the Government" is a placeholder, and whether it lands on C2PA, SynthID or something local decides whether the region's first hard mandate is interoperable with anything.
And whether anyone tests the marks adversarially in public. A scheme nobody can check is also a scheme nobody can falsify, and both halves of that are bad.