AGI Soon As Possible · Deep reads on AI & tech
Article

Claude-generated text now carries a watermark: how Anthropic implements EU AI Act Article 50, and where it stops

2026-08-12 · 9 min read

Anthropic states in its official support documentation that Claude weaves an imperceptible watermark directly into generated text and attaches signed C2PA provenance metadata to generated files. The basis is the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, which Anthropic has signed, and Claude models launched in the EU on or after August 2, 2026 support machine-readable marking at launch. Marking covers output across Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, and it applies worldwide wherever Claude is offered rather than only in the EU. ASAP works from Anthropic's own documentation to separate what these marks prove from what they do not.

Two different techniques go into text and into files

Anthropic's marking system is built from two complementary techniques, a watermark woven into generated text and signed C2PA provenance metadata attached to generated files. Because the two technologies behave differently, what each can be expected to deliver differs as well.

The text watermark is embedded imperceptibly into the text when a supported Claude model generates it. Anthropic states that users will not see it and that it does not change the meaning, quality, or readability of Claude's response. The important property is that because the watermark is part of the text, it travels with the text when it is copied and pasted elsewhere and may persist through some editing. Watermarking is applied at the model level, so it is present no matter which Claude product or surface the text came from.

Files rely on a different lineage of technology. When Claude generates a supported file type such as .svg, .png, or .jpg, it attaches signed provenance metadata following the Coalition for Content Provenance and Authenticity open standard, used across the industry to record content provenance. A present signed metadata label signals that a file was processed by Claude and makes tampering detectable.

Coverage spans products and clouds alike. Marking applies to output from Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, and embedded watermarks apply when supported models are accessed through AWS, Google Cloud, or Microsoft Foundry. Anthropic notes explicitly that signed provenance metadata may not be supported on every platform, depending on the features each platform offers.

An EU rule whose scope of application is worldwide

The legal starting point is European. Anthropic signed the EU AI Act's Article 50(2) Code of Practice as a provider of both generative AI models and generative AI systems, and the support article describes how it plans to put those commitments into practice. The model cutoff is written in EU terms as well: Claude models launched in the EU on or after August 2, 2026 support machine-readable marking at launch.

The sentence on regions, however, is not limited to the EU. Marking applies to output from supported models wherever Claude is offered, worldwide. The regulation came from one jurisdiction and the implementation is global.

That choice illustrates the familiar diffusion path of compliance. Emitting different output by region would require branching a model-level watermark on geography, and the branch itself introduces new complexity and new failure points. A single global application is simpler to build and requires no additional work when similar rules spread to other jurisdictions. The practical result is that a rule written in the EU changes the properties of output delivered to users outside it.

The dates carry a second reading. The gap between the August 2 cutoff and the August 11 documentation update suggests this is a compliance item timed to a regulatory deadline rather than a feature emerging from a product roadmap. Anthropic noting that the law includes a transition period for models launched before August 2, 2026, and that work on those models is in progress, points the same way.

A mark indicates processing history, not authorship

The most misreadable part of the documentation is what a mark means. Anthropic states plainly that a detected mark provides a signal that content was processed by Claude but is not fully conclusive. The word used throughout is processed, not authored.

The example given in the documentation makes the distinction concrete. People often use Claude to proofread, translate, summarize, or convert files, and the output can carry a Claude mark even if the underlying ideas, text, or data originated from another source. Human writing run through Claude for polish carries the mark.

That single fact undercuts any attempt to use the mark as a verdict. If a school, a newsroom, or a hiring manager treats the presence of a mark as proof of AI authorship, misjudgments follow structurally. Writing that passed through Claude once for spelling carries a mark, while text generated entirely by AI and then retyped by hand carries none. The mark reports that content passed through Claude, and it does not answer the separate question of who wrote it.

The documentation blocks the opposite misreading in advance too. A lack of a detected mark does not mean the content was not AI-generated or processed. Anthropic lists five cases where a mark may be absent: content generated by a model released before marking was supported; text that has been heavily edited, paraphrased, translated, or mixed into other writing; a passage too short to leave a reliable signal; a file whose metadata was stripped through format conversion, re-saving, screenshots, or other means; and output produced through a platform, feature, or file type where a particular marking type was not supported.

The missing detection tool is the unfinished half of the announcement

A marking system is only as useful as its reader, and the reading half of Anthropic's system is not public as of August 2026. Of the two halves, the one that embeds and the one that reads, only the first has shipped.

Anthropic says it is working to enable users and other third parties to detect Claude's embedded watermarks and provenance metadata, and that details on detection mechanisms will come in forthcoming technical documentation. Detection checks whether a piece of text or a file carries a supported Claude mark, and a found mark indicates that the content may have been processed by Claude.

Until the reading half exists, the marks do no practical work. Anyone who needs to verify content today has nothing to run, and that state ends only when the technical documentation arrives. The load-bearing component of this announcement has not been published yet.

Publishing detection also carries a return problem. Watermark robustness rests partly on removal methods being unknown, and a published detection method hands anyone attempting removal an immediate test bench for confirming success. It is consistent with that tension that Anthropic writes only that the watermark may persist through some editing and offers no figure for how much editing it withstands. Nowhere in the documentation is there a survival rate by editing intensity or any comparable metric.

What teams building on Claude should check

Anthropic's documentation includes a section addressed to developers, stating that anyone who deploys Claude in their own product should independently assess what Article 50 requires of those products and services. Anthropic states that, consistent with its commitments under the EU Code, its goal is to support customers in meeting their own transparency obligations and that it will share technical guidance on marking and detection as it becomes available.

The practical message is about where responsibility sits. A model provider embedding marks does not discharge the obligations of the service built on top of it. A company shipping into the EU market has to determine separately whether its own product falls under Article 50, and what Anthropic provides is input to that judgment rather than the conclusion.

Organizations that handle content should revisit their internal policy language. A rule that decides AI usage by the presence or absence of a mark institutionalizes both directions of error described above. The mark is a signal rather than evidence, as Anthropic's own documentation states, and any policy needs a clause stating that detection results are not used as sole grounds for a determination.

Open questions: robustness figures and marks from other providers

The largest gap in the August 2026 documentation is numerical, because no figure is published for how much editing the watermark survives or at what rate. The documentation says the watermark survives copying and pasting and may persist through some editing, but publishes no figure for how much editing it survives or at what rate. The limitation that very short passages leave too little text for a reliable signal is stated, yet no threshold length appears. Whether the forthcoming technical documentation carries these numbers will determine how much this system can actually do.

The scope of models in transition is open as well. Models launched before August 2, 2026 fall under a legal transition period and marking support is in progress, but no model list and no timing are given. Content generated in the meantime circulates unmarked, and that window becomes a later problem of how to interpret unmarked content.

The last open item is the boundary of the system itself. Claude's marks attach only to Claude output. Content from other models sits outside the scheme, and the more unmarked content circulates, the less a mark's presence or absence discriminates. Files have room to converge because C2PA is a shared standard several providers can meet, while text watermarks differ by vendor, which means detection would have to be run per provider. Provenance checking at the text layer needs a common specification to work in practice, and the industry has not reached that stage.

Source: ASAP summary based on Anthropic's official support documentation "How Claude marks AI-generated content" (updated August 2026)

ASAP — AGI Soon As Possible

AI & tech,
read in depth

Beyond the headlines — into the context and the structure

AGI Soon As Possible · asapai.co.kr

← All posts