Claude’s text watermark, explained
By Claude Watermark Research · Reviewed
Anthropic is embedding an imperceptible statistical watermark into text from Claude models launched on or after 2026-08-02, worldwide, with no opt-out. As of 2026-08-11, no shipped Claude model carries it — every current model launched before the cutoff. Anthropic has also not published detection tooling, so no third party can currently verify whether any passage is marked.
Which models carry it
| Model | Status |
|---|---|
| Claude Opus 5 · Current flagship. | Not watermarked |
| Claude Sonnet 5 | Not watermarked |
| Claude Fable 5 | Not watermarked |
| Claude Opus 4.8 | Not watermarked |
| Claude Haiku 4.5 | Not watermarked |
We update this table the day Anthropic ships any model. Check your own text →
How the mark actually works
It is not metadata, and it is not hidden characters. During generation, the model picks each next token from a probability distribution. A watermark biases that pick: among tokens that are near-equivalent in quality, a secret key nudges the choice toward a particular subset. Across a long enough passage the resulting pattern is statistically detectable by anyone holding the key.
The technique is the same family as Google DeepMind’s SynthID-Text, which uses a multi-layer tournament sampling scheme to spread the signal out while preserving quality.
The consequence that matters: the watermark is the word choice. That is why it travels through copy-paste, and why every tool advertising “Claude watermark removal” by deleting zero-width Unicode characters is addressing something else entirely.
Timeline
- 2 August 2026
- Cutoff date. Claude models launched on or after this date carry the mark.
- 10–11 August 2026
- Anthropic publishes its help-centre article; coverage and backlash follow.
- Not yet announced
- Detection tooling. Anthropic says technical documentation is forthcoming.
- Not yet announced
- Backfill to models released before the cutoff. Anthropic says it is 'working to add marking support'.
What Anthropic admits it can’t do
The help-centre article is unusually candid. A detected mark signals content “may have been processed by Claude” but is “not fully conclusive”. A missing mark “doesn’t mean the content wasn’t AI-generated or processed”. Marks may not survive heavy editing, paraphrasing, translation, format conversion, screenshots, or being mixed into other writing, and very short passages carry no reliable signal at all.
There is also a false-attribution problem Anthropic acknowledges directly: give Claude your own writing to proofread, translate or summarise, and the output carries the mark even though the ideas and material are yours.
Why it was announced now
Anthropic signed the EU AI Act Code of Practice; Article 50 sets transparency obligations for synthetic content. Notably, Article 50 contains an explicit carve-out for systems performing “an assistive function for standard editing” that do not substantially alter input data — so Anthropic is going further than the regulation strictly requires, and applying it globally rather than only in the EU.
Questions
- Which Claude models are watermarked right now?
- None in production. The policy covers models launched on or after 2 August 2026, and every currently shipped model — Opus 5, Sonnet 5, Fable 5, Opus 4.8, Haiku 4.5 — launched before that date.
- Is the watermark invisible characters?
- No. It is distributional: the model's choice among near-equivalent next tokens is biased by a secret key, so the mark is carried by word choice itself. This is why it survives copy-paste, and why no tool that deletes zero-width characters can remove it.
- Can I opt out or pay to disable it?
- No. Anthropic applies marking at the model level, globally, across claude.ai, the API, Claude Code, Cowork and Tag. There is no regional exemption and no paid tier that disables it.
- Does the watermark prove Claude wrote something?
- No, and Anthropic says so directly: a detected mark means content 'may have been processed by Claude' and is 'not fully conclusive'. Text you wrote yourself and asked Claude to proofread carries the same mark as text Claude wrote from scratch.
- What removes it?
- Rewriting. Because the signal lives in word choice, resampling the text with a different, unwatermarked model destroys it — this is the paraphrase attack, the best-documented removal vector in the research literature. Deleting characters does nothing.
See what’s actually in your text. Free, unlimited, no account. Runs in your browser — nothing is uploaded.
Open the checkerClaude Watermark is independent and has no affiliation with Anthropic. Claude is a trademark of Anthropic PBC. This page describes publicly announced behaviour and links to Anthropic’s own documentation.