The Claude Watermark Is Real. The Thing You're Worried About Isn't.
It marks the text. It doesn't carry your prompt, your client, or a percentage of who wrote what. Your actual exposure is sitting in local disclosure rules nobody at your firm has inventoried.
TL;DR: New Claude models now weave an invisible watermark into the text they generate, and it applies worldwide, not just in Europe. The trigger is the EU AI Act. The watermark says “a model handled this.” It carries no prompt content and nothing privileged. Your real exposure isn’t the mark. It’s whether your people are disclosing AI use where local rules require it.
A partner forwarded me a screenshot yesterday with three words attached: “Is this real?”
The screenshot was one of those threads that collects a few million views and roughly zero verification. Anthropic is watermarking everything. Your documents are tagged. Something about Europe.
I get why it landed. If you run a firm, the words “invisible watermark” and “court filing” in the same sentence produce a specific kind of stomach drop. So I went and read the source material instead of the thread about the thread.
It’s real. It’s also narrower than it sounds, and the part that should concern you isn’t the part people are worried about.
What actually changed on August 2
The EU AI Act’s transparency provisions, Article 50, became applicable on August 2, 2026. One of them requires providers of generative AI systems to mark their outputs in a machine-readable way so the content can be detected as artificially generated.
Alongside the law, the European Commission published a voluntary Code of Practice on Transparency of AI-Generated Content. Signing it is optional. The underlying obligation isn’t. Roughly 190 organizations signed by the end of July, and the provider section reads like a roll call: Anthropic, OpenAI, Google, Meta, Microsoft, Mistral, Cohere.
Penalties run up to 15 million euros or 3 percent of worldwide annual turnover.
So this isn’t one vendor’s product decision. It’s a regulatory floor that most of the industry agreed to stand on at the same moment.
No, it isn’t only a Europe thing
This is where the threads got it half right and the follow-up commentary got it wrong.
I assumed at first there’d be a geographic split. EU users marked, US users not. There isn’t one. Anthropic’s documentation has a section headed “Regions,” and it says marking applies to output from supported models wherever Claude is offered, worldwide.
The reason is architectural. The watermark is applied at the model level, not at the account or region level. Once it’s in the model’s sampling behavior, it ships with the model. Same output in Chicago as in Frankfurt.
Timing matters for your files. Models launched on or after August 2, 2026 carry marking from day one. Systems already on the market got a grandfathering window and have until December 2, 2026. Which means work your team produced this spring may carry nothing at all, and work they produce this fall will.
Two mechanisms, and the difference is where the bad advice comes from
Files get signed provenance metadata following the C2PA standard. Images mostly. Metadata is fragile by design. Convert the format or take a screenshot and it’s gone.
Text works differently. The watermark is woven into the text itself, into the pattern of word choices, not into a wrapper around it. Anthropic’s own language is that because the watermark is part of the text, it travels when the text is copied and pasted, and may persist through some editing.
Read that hedge closely. May persist through some editing.
Here’s what that means at your desk. Paste a drafted section into Word, format it, export to PDF, and the mark probably rides along, because you never touched the words. Have an associate genuinely rewrite it, cut two paragraphs, restructure the argument, and the signal degrades badly. Detection is a statistical confidence score across a long passage, not a stamp on page one. Short passages don’t carry enough signal to be reliable at all.
Which produces a slightly funny result. The documents most likely to be detectably marked are the ones nobody did much work on.
Does the mark say how much of the document is AI?
No. And this is the question your sharpest partner will ask about four minutes into the conversation, so have the answer ready.
Detection as described today is binary. It checks whether text carries a mark. It doesn’t report a proportion, doesn’t tell you which passages, doesn’t hand anyone a percentage. Anthropic has also said the detection mechanics are still being written up, so treat this as unfinished rather than resolved.
Run the arithmetic on a document you’d actually recognize. Say an associate had Claude tighten two paragraphs of a twenty-page brief. That’s roughly 200 words against eight thousand. Two, maybe three percent. Detection works by counting statistically favored word choices across a passage and asking whether the count runs above chance, so a test across the whole brief finds that signal drowned by the human writing around it. Nothing surfaces.
That’s true today. I wouldn’t write a policy that assumes it stays true.
The published research is already ahead of the shipping product. Sliding-window methods score every possible span and report the strongest one instead of averaging across the document, which finds a contiguous block that whole-document scoring misses. Separately, there’s live academic work on estimating what share of a mixed document came from a model. A 2025 paper on exactly that problem uses legal briefs as its worked example, imagining a rule capping AI-generated content at ten percent in high-stakes filings. Nobody has it working reliably yet, and the authors show the proportion isn’t always mathematically recoverable at all. But that’s the direction, and the people building it have your documents in mind.
Smoke alarm, not a meter. It tells you something burned. Not how much.
Is Anthropic out on a limb? No.
Someone will ask whether this is one company being unusually pious. It isn’t.
OpenAI signed the same Code of Practice, in the same provider section, and carries the same Article 50 obligation for outputs used in the EU. Google signed as well and has been vocal about SynthID, its watermarking technology, and about pushing C2PA adoption alongside Apple, ElevenLabs, Nvidia and OpenAI.
There is a real asymmetry, though, and it’s about disclosure rather than obligation. Anthropic has published plain documentation saying text watermarking is on, describing how it works and where it fails. Much of the industry’s visible watermarking effort has gone into images, audio and video, where the techniques are more mature. OpenAI in particular has been reluctant on text watermarking for years, reportedly out of concern about accuracy and about users simply leaving.
I’d hold that loosely. The legal obligation is identical and implementations are moving fast. What I can say confidently is that Anthropic has documented its text approach in more detail than its competitors have. That’s a difference in what’s been said, not necessarily in what’s being done.
The four things to tell your partners
It marks, it doesn’t leak. The watermark signals that a model generated the text. It carries no prompt content, no client information, nothing privileged. For most of the room, this ends the conversation.
A mark isn’t proof, and no mark isn’t proof either. Anthropic says this outright: a detected mark means content may have been processed by Claude, not that Claude authored it. Absence of a mark establishes nothing about authorship.
A mark doesn’t mean the thinking wasn’t yours. This one surprises people. If an associate writes a brief herself and runs it through Claude to catch typos or tighten a paragraph, the output can carry a mark. The ideas are still hers. The mark only says a model handled the text.
Conversion doesn’t clean text, but real editing degrades it. Word to PDF preserves the words, so it preserves the mark. Substantive revision is what actually thins the signal.
The third one deserves the most airtime, because it inverts the anxiety. The mark is not a verdict on who did the thinking.
The objection from the smartest person in the room
Someone will ask whether you can just defeat it. Run the output through a second model, swap a couple of words per sentence, done.
Technically, largely yes. Substitution attacks the statistical signal directly, and the published work on paraphrase attacks found these schemes hold up under light editing and come apart under systematic rewriting.
Don’t do it. And this isn’t a sermon. Article 50 prohibits deliberately removing or altering AI markings, so stripping a mark off something you file turns a passive fact into an affirmative act. Acts have intent. Intent is what puts you in front of a disciplinary panel rather than a docket clerk. There’s also a practical problem: synonym swapping mangles legal prose. Consideration, material, reasonable. Those are terms of art. A thesaurus doesn’t know that.
What to do Monday morning
Tell your people what the watermark is and isn’t, in one paragraph. Most of the worry circulating in your firm right now is about privilege and confidentiality, and it’s misplaced. Kill it early.
Inventory your disclosure obligations by jurisdiction. Standing orders and local rules on AI use in filings are the actual exposure, and they vary judge to judge.
Put in writing that stripping or obscuring a mark is prohibited firm-wide. No exceptions for a rushed filing.
Notice what isn’t on that list: changing tools. This isn’t a procurement problem.
For a while the anxious question about AI in legal work was “can anyone tell?” That question is closing. The better one was always whether you’d be comfortable saying so out loud.
If you enjoyed this article, please share it with others.
Yesterday was bath day for Magnus. This cartoon accurately depicts what happens. He gets clean and I get soaked. The second photo is him drying off on the couch.




