Yes, Claude watermarks text
New supported models embed an invisible watermark directly in the text they generate.
Here is the complete explanation in plain English—no coding, statistics or EU legal background required.
Three answers prevent the most common misunderstandings.
New supported models embed an invisible watermark directly in the text they generate.
It is not a logo, hidden spaces or unusual characters. The text looks completely normal.
Claude may only have corrected, translated or shortened text originally written by a person.
Text receives an invisible signal. Supported image files can receive a signed record of their history.
The watermark is embedded while Claude generates its response. It can remain when the text is copied into Word, email or another program.
You will not find it by searching for strange characters.
Supported SVG, PNG and JPG files can contain signed information showing that Claude processed the file.
The record describes the file's history—not whether the image is true.
This illustration shows a principle from published research. Anthropic has not disclosed whether Claude uses this exact method.
Several natural words may fit. A hidden rule can gently influence the choice without changing the meaning.
One word proves nothing. Across a longer passage, many small choices can form a pattern that is unlikely to appear by chance.
The colours do not exist in the document. To a reader, it is an ordinary sentence, and copying does not necessarily remove the pattern.
The detector must know Anthropic's signal. A generic AI detector that guesses from writing style is not the same thing.
Which system does Claude use? The exact answer is not public. Anthropic's description fits a generative text watermark: the signal is embedded while the model chooses the next tokens. Anthropic has not said whether its system uses green-token lists, tournament sampling or a different proprietary method.
For each new token, the model creates a probability distribution. For example, “clear” may be more likely than “simple.” Temperature, top-p and top-k affect how freely the system can choose.
A secret key and the preceding text can produce a pseudorandom signal. The selection process then gives some suitable tokens a slight preference. Meaning can be preserved even though the pattern of choices changes.
A matching detector uses the same key or a derived verification system. It scores the token sequence and compares the result with a threshold. This is a statistical judgment—not a hidden ID inside every word.
Green lists: A key divides possible tokens pseudorandomly, and the model gives “green” tokens a small boost. A detector checks whether unusually many of them appear.
SynthID-Text: Several likely tokens compete in a key-controlled tournament. The winner becomes the next token, and a later score looks for the relationship between token choices and pseudorandom values.
Why use a token pattern? It can follow the text through copying, while file metadata is easily lost. The trade-off is that short or highly predictable text provides fewer useful choices. Translation, substantial rewriting and mixing with other text can weaken the signal. A responsible detector should therefore allow an “uncertain” result and publish limits for false positives and false negatives.
When Anthropic's detector becomes available, it can look for Claude's signal. It cannot determine who wrote the text.
Claude may have written it, but may also only have corrected, translated, shortened or reformatted it.
It also does not show how much Claude changed, whether the text is correct, or whether anyone cheated.
The text may be too short, come from an older model, or have been translated, rewritten or mixed with other text.
Claude or another AI tool may still have been used.
Remember: A Claude watermark is evidence of processing—not proof of authorship.
Not with an official public Claude detector. Anthropic says a way to check the signal is coming, but has not released the tool or a date.
It is intended to look for the specific signal Claude embeds in text or supported files.
Usually estimates from writing style and language patterns. It does not detect Claude's watermark.
Text uses an invisible pattern. Supported image files use signed provenance metadata. They respond differently to editing.
Anthropic describes coverage by launch date, product and region—not with a public list of model names.
Claude models released on or after August 2, 2026 support marking at launch. Anthropic is working to add support to older models.
It covers supported models in Claude, Claude Code, Cowork, Tag, the API, AWS, Google Cloud and Microsoft Foundry.
Anthropic says marking is used wherever Claude is offered—not only in the European Union.
The practical meaning depends more on the situation than on the watermark itself.
You do not need to add a visible “written by AI” label to every private text. Anthropic's technical marking happens inside the system.
A detection result can show Claude processing, but not cheating. Ask which tool was used and whether it checks an official Claude signal or only guesses from writing style.
Professional publication on matters of public interest may require visible disclosure of AI use. Substantial human review can affect that obligation.
The built-in watermark does not automatically satisfy every rule. A product may still need to tell users that they are interacting with AI.
Paste your Danish text into SkrivSikkert and correct common mistakes.
Correct my Danish textYes. Anthropic says supported models released on or after August 2, 2026 embed an invisible watermark in generated text. Support for older models is still being added.
Anthropic does not publish a named model list on its marking page. The reliable distinction is the release date: new models released on or after August 2, 2026 support marking at launch.
Not with an official public Claude detector. Anthropic says detection tools and technical guidance are coming, but has not announced a date.
No. A watermark can show that Claude processed the text. Claude may have written everything, but may also only have corrected, translated or shortened something you wrote.
The final output can still receive a watermark. A detection result must not automatically be treated as proof that Claude was the original author.
It can survive copying and some edits. Substantial rewriting, translation, short excerpts or mixing with other text can make it undetectable.
No. A provider's machine-readable watermark is normally invisible. A separate visible disclosure may apply to professionally published AI text about matters of public interest, especially without substantial human review.
Start with Anthropic's official explanation. The remaining links cover EU rules, the open file standard and the research behind this guide.