Anthropic has started building hidden watermarks into the text its newest Claude models generate. It is also attaching signed provenance data to generated image files. The rollout applies worldwide, not only inside the European Union, according to a report from Search Engine Journal citing Anthropic’s own support documentation.
Anthropic put its name on the EU’s Article 50(2) transparency code covering AI generated content, signing on as a maker of both the models and the tools built around them. The European Commission counted roughly 190 organizations in the signatory group as of late July. OpenAI, Meta, Google, Microsoft, and Mistral joined Anthropic on the same provider track, covering machine readable marking and detection.
The contrast with OpenAI matters here. OpenAI dropped its own watermarking plan in September 2024, after an internal survey found nearly 30 percent of ChatGPT users said they would use the product less with watermarking added. Anthropic is moving the opposite way, under legal commitment rather than product preference.
That regulatory framing undersells the mechanism itself. Anthropic says the mark survives ordinary copying and pasting and, in the company’s words, “may persist through some editing.” That means it can move from a chat window into a finished, published page untouched. Anthropic has not said any search engine currently reads or scores these marks, and this article makes no such claim either. The stake worth tracking, separate from Anthropic’s own framing, is what happens if a marker durable enough to survive copy and paste eventually becomes something a detector, possibly including a search engine, can check against a page after it publishes.
Marking covers output from supported models reached through the API, the Claude apps, Claude Code, Cowork, and Tag, plus access routed through Microsoft Foundry, AWS, and Google Cloud. Any Claude model Anthropic introduced in the EU from August 2, 2026 forward carries the watermark starting at launch. Earlier models sit in a transition period, and Anthropic says it is working to extend marking to them, with no date attached.
Image outputs carry a separate proof layer: signed C2PA metadata attached to generated .svg, .png, and .jpg files, showing how each one was produced and whether it was later changed.
Anthropic is specific about what a hit proves and what it does not. A positive detection means the model may have touched the content at some stage; it does not establish that Claude produced the writing, or who used the tool. Anthropic’s own limitations note that proofreading, translation, summarizing, or file conversion can leave a mark even when the original ideas and wording came from a human writer. A missing mark carries just as little certainty, since an older model, heavy edits, or a short passage can leave text with no detectable signal.
Roger Montti’s August 3 breakdown of Article 50’s exemptions found two that bear on edited copy. Routine editing that does not meaningfully change the input’s meaning can sit outside the marking requirement. Text that has gone through genuine human review, with an editor accountable for it, can also skip disclosure. A Claude mark can sit inside a story its publisher has no legal obligation to flag.
How much editing removes a watermark is not specified in Anthropic’s support article, and the company had not answered a TechCrunch request for clarification as of publication. GPTZero co-founder Alex Cui has said publicly that text watermarks like these can be broken, noting that free tools got past Google DeepMind’s SynthID and heavy paraphrasing stripped marks entirely in his own testing. Cui was demonstrating a general method used across frontier labs, not Anthropic’s system, since Anthropic has not published its own detector. Jonas Geiping, who studies watermarking at Germany’s ELLIS Institute in Tübingen, said paraphrasing can remove a mark, but not every attempt succeeds.
Anthropic’s limitations list two ordinary cases that still produce marked text: someone who writes a piece entirely on their own, then sends it to Claude for one last polish pass, and someone adapting somebody else’s article into another language. Both end up with marked output despite doing the original thinking themselves. Any workflow that reads a positive hit as proof of AI authorship carries that same blind spot forward.
Cui’s broader point cuts in two directions: a public check works for anyone verifying a page, and it works just as well for anyone trying to defeat the mark. Google has kept its own SynthID checker private to its products, a tool Search Engine Journal reported had reached Google Search in May. Anthropic, by contrast, has committed to opening detection to outside users and third parties, though it has not described that access yet.
Search teams should document their editing process now, before a client, an editor, or a platform starts treating a detector result, from Anthropic or anyone else, as grounds to flag finished copy.
Search Engine Journal, reporting by Matt G. Southern, published August 11, 2026.