What just happened
Starting with future Claude models, every piece of text Claude generates will carry an invisible watermark - a statistical pattern that lets anyone with the right key estimate the likelihood that Claude wrote it. The change is not optional: the EU AI Act took effect on August 2, and Anthropic is one of roughly 190 signatories to the EU Code of Practice on Transparency of AI-Generated Content.
Watermarking will roll out globally at launch, because Anthropic says it has no durable way to scope it by region. Older Claude models get the same treatment over the coming months, under a transition period in the EU law.
How the watermark works
LLMs like Claude pick one word at a time. Given “The weather today was cold and…”, the next word is almost certainly “overcast” or “grey”, not “sugary”. When either word is equally good, the choice is settled by a random number.
The watermark changes only the source of that randomness. Instead of an arbitrary random number generator, Claude uses a secret key plus the preceding words to settle the choice. The words are still random - and still drawn from candidates Claude would naturally consider. It will not push Claude toward a word it would never pick, like “nubilous”.
But the sequence now has a fingerprint. Anyone holding the key can check whether the pattern of choices is consistent with Claude’s keyed randomness, and assign a probability that the text came from Claude.
The technique is a version of SynthID-Text, published by Google DeepMind in a 2024 Nature paper, part of a family of approaches that goes back to Scott Aaronson’s 2022 proposal.
The Monopoly analogy
Anthropic’s own analogy is a game of Monopoly. Players usually roll dice for randomness. Imagine instead that the randomness comes from the digits of pi, starting at a fixed position. The game plays out identically - the moves are still random for all practical purposes. But if you see the full sequence of moves and know pi, you can work out that pi, not dice, decided the game. The game is, in a sense, watermarked.
The point: nothing about the experience changes. The meaning, creativity, and readability of Claude’s output stay the same. Google DeepMind tested SynthID-Text on live Gemini traffic and found no statistically significant difference in thumbs-up ratings; human raters could not tell watermarked and unwatermarked answers apart.
What the watermark does not do
- No quality impact, no extra tokens, no extra cost. Watermarking does not slow models down or change pricing.
- No hidden characters. Nothing is added to the text at all - only the source of randomness changes.
- No user identification. The watermark cannot be traced to a person, an organization, or a chat. It only says Claude was likely involved.
- Not a human detector. It answers one question: how likely was Claude involved? It cannot prove text is human-written, and cannot detect other AI models’ output.
Where watermarks are thin
Watermarking works by exploiting low-stakes word choices - and some text has almost none.
- Facts: After “Isaac Newton’s most famous work was called Principia…”, the next word has one right answer: “Mathematica”. No watermark can attach there.
- Proofreading: If Claude only fixes grammar and punctuation in human text, the watermark has almost nothing to live in. The more Claude writes, the stronger the signal.
- Code: Exact code has to be exact - “2 + 2 =” must be followed by “4”. Watermarking mostly skips those tokens, though it can appear in arbitrary parts like comments. Net effect on real code: negligible.
Translations are different: Claude chooses every word, so translations are fully watermarked.
What this means for the industry
This is the moment AI provenance stops being a feature and becomes regulation. When the EU requires marking and nearly 200 signatories - including Anthropic and other major model developers - commit to it, provenance infrastructure becomes table stakes for every frontier lab. Expect detection APIs to become a standard product surface: Anthropic says a watermark detection API is coming.
The economics matter too. Because watermarking adds zero tokens and zero latency, compliance costs are near zero - which is exactly why this approach wins over visible markers or post-hoc detector tools like Pangram, which guess from stylistic tells and are fundamentally different from a key-based check.
What you should do now
- If you rely on AI writing: treat light edits as still detectable - only a full rewrite removes the watermark, and at that point the text is arguably no longer AI-generated.
- If you build on AI APIs: plan for watermark metadata as a standard field in outputs, and watch for the detection API to build verification into your workflow.
- For images and files: Claude will attach C2PA content credentials - signed metadata notes readable by any C2PA-aware tool - for supported file types like PNG, JPG, and SVG.
- For teams in regulated industries: document whether content is AI-assisted. The watermark will make these claims checkable.
The watermark is one more sign of a structural shift we have been tracking: the AI industry is moving from raw capability races to questions of trust, provenance, and economics. The agent funding winter showed how quickly the market can turn; mandatory watermarking shows regulators can move just as fast.