Claude watermark:
What is it, and can it be removed?

Here is the complete explanation in plain English—no coding, statistics or EU legal background required.

The essentials in one minute.

Three answers prevent the most common misunderstandings.

Yes, Claude watermarks text

New supported models embed an invisible watermark directly in the text they generate.

No, you cannot see it

It is not a logo, hidden spaces or unusual characters. The text looks completely normal.

It does not prove authorship

Claude may only have corrected, translated or shortened text originally written by a person.

Claude uses two types of content marking.

Text receives an invisible signal. Supported image files can receive a signed record of their history.

Invisible watermark in text

The watermark is embedded while Claude generates its response. It can remain when the text is copied into Word, email or another program.

You will not find it by searching for strange characters.

Signed provenance in files

Supported SVG, PNG and JPG files can contain signed information showing that Claude processed the file.

The record describes the file's history—not whether the image is true.

How can an invisible watermark exist in ordinary text?

This illustration shows a principle from published research. Anthropic has not disclosed whether Claude uses this exact method.

1

Claude chooses one token at a time

Several natural words may fit. A hidden rule can gently influence the choice without changing the meaning.

2

Many small choices form a pattern

One word proves nothing. Across a longer passage, many small choices can form a pattern that is unlikely to appear by chance.

3

You only see normal text

The colours do not exist in the document. To a reader, it is an ordinary sentence, and copying does not necessarily remove the pattern.

4

A specialized detector looks for the pattern

The detector must know Anthropic's signal. A generic AI detector that guesses from writing style is not the same thing.

Technical explanationTokens, secret keys and statistical detection

Which system does Claude use? The exact answer is not public. Anthropic's description fits a generative text watermark: the signal is embedded while the model chooses the next tokens. Anthropic has not said whether its system uses green-token lists, tournament sampling or a different proprietary method.

01

The model calculates possible tokens

For each new token, the model creates a probability distribution. For example, “clear” may be more likely than “simple.” Temperature, top-p and top-k affect how freely the system can choose.

02

A key influences the selection

A secret key and the preceding text can produce a pseudorandom signal. The selection process then gives some suitable tokens a slight preference. Meaning can be preserved even though the pattern of choices changes.

03

The detector reconstructs the signal

A matching detector uses the same key or a derived verification system. It scores the token sequence and compares the result with a threshold. This is a statistical judgment—not a hidden ID inside every word.

Two known research approaches

Green lists: A key divides possible tokens pseudorandomly, and the model gives “green” tokens a small boost. A detector checks whether unusually many of them appear.

SynthID-Text: Several likely tokens compete in a key-controlled tournament. The winner becomes the next token, and a later score looks for the relationship between token choices and pseudorandom values.

What Anthropic has confirmed

  • The watermark is invisible and embedded at model level.
  • It normally survives copying and may persist through some editing.
  • Anthropic has not published the algorithm, key design, minimum length, detection threshold or error rates.
  • We therefore cannot state that Claude uses SynthID or a green-list system.

Why use a token pattern? It can follow the text through copying, while file metadata is easily lost. The trade-off is that short or highly predictable text provides fewer useful choices. Translation, substantial rewriting and mixing with other text can weaken the signal. A responsible detector should therefore allow an “uncertain” result and publish limits for false positives and false negatives.

How to interpret a detection result.

When Anthropic's detector becomes available, it can look for Claude's signal. It cannot determine who wrote the text.

Watermark detected
What you can sayClaude probably processed the text.

Claude may have written it, but may also only have corrected, translated, shortened or reformatted it.

What you cannot sayIt does not identify the original author.

It also does not show how much Claude changed, whether the text is correct, or whether anyone cheated.

No watermark detected
What you can sayThe detector did not find a confident signal.

The text may be too short, come from an older model, or have been translated, rewritten or mixed with other text.

What you cannot sayIt does not prove that a person wrote the text.

Claude or another AI tool may still have been used.

Remember: A Claude watermark is evidence of processing—not proof of authorship.

Can you detect Claude's watermark yet?

Not with an official public Claude detector. Anthropic says a way to check the signal is coming, but has not released the tool or a date.

COMING LATER

Anthropic's watermark detector

It is intended to look for the specific signal Claude embeds in text or supported files.

  • Knows Anthropic's own signal
  • Can indicate Claude processing
  • Is not publicly available yet
AVAILABLE NOW

Generic AI detector

Usually estimates from writing style and language patterns. It does not detect Claude's watermark.

  • Can produce false results
  • Cannot prove authorship
  • Should not support an accusation on its own

What happens when the text is changed?

Text uses an invisible pattern. Supported image files use signed provenance metadata. They respond differently to editing.

What you doWhat may happen
Invisible pattern in text
You copy and paste the textThe watermark normally remainsThe words and their order are still the same.
You edit smaller sectionsThe watermark may remain detectableEnough unchanged text can preserve the pattern.
You translate or substantially rewrite itThe watermark may become undetectableMany of the original token choices are replaced.
You check only a short excerptThe result may be uncertainThere may be too little text to measure a pattern.
Signed provenance in SVG, PNG and JPG files
You keep the original fileThe provenance can be verifiedIf the file was created through a supported Claude feature.
You take a screenshot or re-export itThe provenance may disappearThe new file may not contain the original metadata.

Where does Claude watermarking apply?

Anthropic describes coverage by launch date, product and region—not with a public list of model names.

Models

Claude models released on or after August 2, 2026 support marking at launch. Anthropic is working to add support to older models.

Products

It covers supported models in Claude, Claude Code, Cowork, Tag, the API, AWS, Google Cloud and Microsoft Foundry.

Worldwide

Anthropic says marking is used wherever Claude is offered—not only in the European Union.

August 2, 2026EU rules started applying
August 10, 2026Anthropic updated its explanation
December 2, 2026Transition deadline for relevant older systems

What does this mean for you?

The practical meaning depends more on the situation than on the watermark itself.

Personal use

You do not need to add a visible “written by AI” label to every private text. Anthropic's technical marking happens inside the system.

Publishers and businesses

Professional publication on matters of public interest may require visible disclosure of AI use. Substantial human review can affect that obligation.

Products built with Claude

The built-in watermark does not automatically satisfy every rule. A product may still need to tell users that they are interacting with AI.

Writing in Danish? Fix spelling and grammar.

Paste your Danish text into SkrivSikkert and correct common mistakes.

Correct my Danish text

Frequently asked questions.

Does Claude watermark text now?

Yes. Anthropic says supported models released on or after August 2, 2026 embed an invisible watermark in generated text. Support for older models is still being added.

Which Claude models are watermarked?

Anthropic does not publish a named model list on its marking page. The reliable distinction is the release date: new models released on or after August 2, 2026 support marking at launch.

Can I check my text now?

Not with an official public Claude detector. Anthropic says detection tools and technical guidance are coming, but has not announced a date.

Does a watermark prove that Claude wrote the text?

No. A watermark can show that Claude processed the text. Claude may have written everything, but may also only have corrected, translated or shortened something you wrote.

What if Claude only corrected grammar or translated?

The final output can still receive a watermark. A detection result must not automatically be treated as proof that Claude was the original author.

Can the watermark disappear after editing?

It can survive copying and some edits. Substantial rewriting, translation, short excerpts or mixing with other text can make it undetectable.

Must all AI text carry a visible label under EU rules?

No. A provider's machine-readable watermark is normally invisible. A separate visible disclosure may apply to professionally published AI text about matters of public interest, especially without substantial human review.

Sources and further reading.

Start with Anthropic's official explanation. The remaining links cover EU rules, the open file standard and the research behind this guide.

Research behind this guide