AI Watermarks Are Live

From now on, the text and images you generate or simply pass through Claude will carry an invisible watermark. We might as well just call this “False Positives for Everyone.”

On August 2, Article 50 of the EU AI Act became enforceable, and Anthropic’s answer has already shipped. Every Claude model launched on or after that date embeds an imperceptible watermark directly into generated text, and the watermark stays with it when the text is copied and pasted somewhere else. Generated files (.svg, .png, .jpg) carry signed provenance metadata under the C2PA open standard. The marking applies everywhere you use Claude, from the API to Claude Code to Cowork, worldwide.

There are two layers. The C2PA file layer targets the disaster everyone can picture (the doctored viral image); by Anthropic’s own admission it is fragile. The marks can vanish when “metadata was stripped through format conversion.” A screenshot defeats it. The text watermark kind of deals with synthetic text at scale, which is the real threat, but Anthropic concedes the technique has serious limitations: “Claude may not be the original author. People often use Claude to proofread, translate, summarize, or convert files. The output can carry a Claude mark even if the underlying ideas, text, or data originated from another source.”

A student who pastes their 100% human-written essay in for proofreading gets a Claude mark on their original text. The mark records an encounter with Claude. Every school, employer, and platform that finds it will read it as a verdict about authorship, a verdict Anthropic itself disclaims in writing: a detected mark “is not fully conclusive.”

The EU has done it again! Fines reach 15 million euros (or 3% of global annual revenue) and adherence to the EU’s Code of Practice is the safe harbor. Anthropic did what the law demands, and did so honestly (by disclosing the basic limitations of the technology).

Once again, regulators have forced a solution that creates far more problems than it can ever solve. It will flag the innocent and miss the determined. Worse, it hands institutions a probabilistic signal they will treat as proof.

From now on, the text and images you generate or simply pass through Claude will carry an invisible watermark. Anthropic says detection tools are “forthcoming.” That’ll be when the fun really starts. We might as well just call this “False Positives for Everyone.”

Comments