For about a year I have been deleting em dashes from everything I publish, because somewhere in 2025 that piece of punctuation became shorthand for "a machine wrote this". My drafting runs with Claude in the loop, so I strip the tell and restructure the sentence, every time. As of last week the ritual is quaint. Anthropic announced that Claude now watermarks its text invisibly, at the model level, in a way that survives copy and paste. The tell has moved from the punctuation into the words.
Most of the commentary since has been a detection story: can teachers catch students, can you strip the mark, will Google punish it. For anyone running a marketing organisation, that is the least interesting layer of the news.
What did Anthropic actually announce?
Two marking mechanisms, on different technical foundations. Text generated by Claude carries an invisible watermark woven into the output itself, designed to survive copy and paste without changing meaning or readability. Files in supported formats (.png, .jpg, .svg) carry signed provenance metadata using the C2PA standard. Marking applies to every Claude product and cloud channel, with no way to turn it off. Models launched on or after 2 August 2026 mark at launch, older models follow over the coming months, and the EU deadline for those is 2 December 2026.
The date is not an accident. Article 50 of the EU AI Act became applicable on 2 August 2026 and requires providers to mark generative outputs in a machine-readable format. Anthropic chose to comply worldwide, and it has company: OpenAI, Google, Microsoft, Meta and Mistral signed the same code, and among the major labs only xAI did not.
How does the text watermark work?
On 14 August Anthropic published the mechanism: a version of SynthID-Text, the approach Google DeepMind published in 2024. Wherever the next word is a low-stakes choice, "overcast" or "grey", a secret key together with the preceding words settles which one Claude picks. A detector holding that key can check whether a passage is consistent with the choices Claude would have made. The detection API is promised "soon", with no word on who gets access. So the marks exist today, and nobody outside Anthropic can read them yet.
The mark survives copy and paste because it lives in the word choices, and it dissolves under a full rewrite because a rewrite replaces the words. A translation done by Claude carries a full watermark, since every word in it is Claude's; a translation done by a person mostly will not. Alex Cui, CTO of detection firm GPTZero, adds that determined paraphrasing defeats current text watermarks, Google's included.
Does a watermark prove the content is AI-written?
No. Anthropic's own explainer says the mark "cannot distinguish 'Claude wrote this' from 'Claude heavily edited this'". A mark can sit on a paragraph a human wrote and lightly reworked with a model, and text a model produced outright can arrive clean after a thorough human rewrite. Any policy built on the assumption that the mark answers "who wrote this" will be the wrong policy.
One asset, a dozen pairs of hands
Follow one campaign asset through a normal week: drafted with Claude, tightened in Word, translated for three markets, paired with an image from Firefly, trimmed by an agency, syndicated into a partner newsletter. The published result is a braid of human and machine work, carrying whatever marks happened to survive the route.
Provenance state per asset is the same class of problem as consent state per record. Marketing organisations learned to track consent per record and sub-processors per vendor once GDPR made both auditable, and both got an owner. Provenance has no owner, so nobody can say which published assets carry machine-readable marks, or what those marks claim.
Image provenance has a coalition. Text has vendor keys.
Text watermarking in 2026 looks like image provenance did in 2019: proprietary keys, no coalition. For images, Anthropic adopted C2PA, the open standard from the coalition Adobe co-founded in 2021 with Arm, BBC, Intel, Microsoft and Truepic. Firefly signs its output, OpenAI signs its generated images, and LinkedIn already renders Content Credentials on images that carry them.
For text, no shared standard exists. Each vendor holds its own key and runs its own detection service, and Anthropic has said nothing about its marks being readable by anyone else's detector. A marketing organisation running three AI vendors will publish text carrying three provenance schemes with the same maths and three different keys, none of which its own team can read.
| Tool | What it marks | Scheme | Readable today |
|---|---|---|---|
| Claude | Generated text | Anthropic key, SynthID-Text method | No. Detection API promised, no date |
| Claude | .png, .jpg, .svg files | C2PA | Yes, any C2PA reader |
| Adobe Firefly | Generated images | C2PA, as Content Credentials | Yes, any C2PA reader |
| Google Gemini | Generated text | Google key, SynthID | Google's own detector, for Google's marks |
| OpenAI ChatGPT | Generated images | C2PA | Yes, any C2PA reader |
| OpenAI ChatGPT | Generated text | Announced, no method published | No |
Legal reads the marks before your audience does
No search engine has announced ranking consequences for watermarked text, and Google's Search Central guidance has judged AI content on quality since February 2023. Anyone telling you that watermarks will tank your search visibility is speculating.
The nearer-term pressure is contractual. Procurement teams already send AI-use questionnaires, and provenance marks give them teeth: "no AI is used in our deliverables" becomes a claim a client can eventually test against the files. Agency disclosure clauses and indemnities on AI-assisted work turn auditable the moment detection tooling ships. Claude users said so within days (TechCrunch, 12 August), and the complaint was about being misread: a mark on work they had directed and edited, claiming more than it can prove.
The AI Act's duty on organisations to label AI-generated text is narrow. It covers text published to inform the public on matters of public interest, and it falls away where the text has been through human review or editorial control by someone with the authority to approve, alter or reject it. The Commission's guidance adds that spell-checking does not count. Read from a marketing seat, that is an operating-model test dressed as a legal one, the same shape as the Cyberbeveiligingswet reaching marketing through procurement rather than through a marketing rule: who, by name, holds editorial authority over what goes out.
Anthropic has promised a detection API without saying who gets it. A fully public detector invites adversarial testing until the mark is defeated, so access will more likely be gated, and verification will sit with platforms, regulators and specialist detection firms. Those platforms are already ahead of the marks: LinkedIn's "seems like AI slop" button, added at the end of July, reads style rather than watermarks.
In Value Gravity™ terms, provenance lands in the governed foundation of the stack, next to consent and access. No single tool at the experience layer will solve it for you.
Five questions to ask before the detection tools arrive
1. Which tools in our stack mark their output today? The table above is a starting inventory. Someone should own it and revisit it quarterly, because it will grow.
2. Where does our workflow strip marks, and is that deliberate? Human rewriting and translation remove text watermarks, and image optimisation strips metadata on upload. Today that is an accident of plumbing. Once marks are expected, silent stripping starts to look like a decision, so it should be one.
3. What do our agency and freelance contracts say about AI-assisted deliverables? If the answer is nothing, that was survivable while the claims were untestable. It ages badly from here.
4. What is our answer when a client, journalist or platform asks whether this content is AI-assisted? Decide it now, in one sentence, for the whole organisation. Improvising after a detector has flagged the files is the bad version of this conversation.
5. Who owns this? Provenance sits between brand, legal and marketing operations, which in practice means it sits nowhere. It needs a name attached before the first questionnaire arrives.
This piece was made the way most of my work is made now: my argument, my structure, a model in the loop, my name on the result. When the detection API arrives it will light up, and that is fine. The mark can say a machine touched the text. Accountability for what the text claims still travels with the name above it.
Frequently asked questions
What did Anthropic announce about watermarking Claude content?
On 11 August 2026 Anthropic announced that Claude marks its output in two ways: an invisible watermark embedded in generated text, designed to survive copy and paste without changing meaning or readability, and C2PA signed provenance metadata in supported file formats (.png, .jpg, .svg). Marking applies across all Claude products worldwide, including the API and cloud partner platforms. Models launched on or after 2 August 2026 mark at launch, earlier models follow over the coming months, and no opt-out is described. On 14 August Anthropic published how the text watermark works and promised a detection API.
How does the Claude text watermark work, and can it be removed?
Anthropic uses a version of SynthID-Text, the method Google DeepMind published in 2024. Wherever the next word is a low-stakes choice, a secret key combined with the preceding words settles which word Claude picks, and a detector holding the key can check whether a passage is consistent with those choices. Light editing generally leaves the mark in place, a complete rewrite removes it, short passages cannot be tested reliably, and code carries little watermark outside comments. A translation done by Claude carries a full watermark; a translation done by a person mostly does not. Independent detection specialists report that determined paraphrasing defeats current text watermarks. There is no public detection tool yet, so organisations currently publish marked content that neither they nor their clients can read.
Why is Anthropic watermarking Claude output now?
Article 50 of the EU AI Act became applicable on 2 August 2026 and requires providers of generative AI systems to ensure outputs are marked in a machine-readable format and detectable as artificially generated; systems on the market before that date have until 2 December 2026. Anthropic chose to apply its marking worldwide rather than only in Europe. OpenAI, Google, Microsoft, Meta and Mistral have committed to the same transparency code, and among the major labs only xAI did not sign it, so per-vendor marking is becoming the industry default.
Does the Claude watermark prove content was written by AI?
No. Anthropic's own explainer says the mark cannot distinguish "Claude wrote this" from "Claude heavily edited this". A mark can sit on human writing that was edited or summarised with the model, and machine-written text can lose its mark through a thorough human rewrite. The mark is a processing signal. It says nothing about who wrote the text.
Do EU rules require companies to label AI-assisted marketing content?
Mostly not, on the current text. The AI Act's deployer duty to disclose AI-generated text applies to text published to inform the public on matters of public interest, such as politics, public administration, public health, environmental protection and consumer safety, and it does not apply where the text has undergone human review or editorial control by a person or entity with the authority to approve, alter or reject it. The Commission's guidance states that spell-checking and similar formal checks do not count as editorial control. Ordinary commercial marketing content will rarely fall inside the duty, but the exemption test makes named editorial ownership the operative question, and this is analysis rather than legal advice.
What is C2PA?
C2PA is the Coalition for Content Provenance and Authenticity, an open technical standard for signed content provenance metadata. Adobe co-founded the coalition in 2021 with Arm, BBC, Intel, Microsoft and Truepic, building on Adobe's Content Authenticity Initiative from 2019, and implements the standard as Content Credentials. Anthropic has adopted C2PA for Claude's image output, joining Firefly, OpenAI, camera manufacturers and platforms such as LinkedIn that already read or write the format.
Do AI watermarks affect SEO or Google rankings?
There is currently no evidence that watermarked text affects search rankings. Google's published position on AI-generated content has been quality-based rather than origin-based since February 2023, and no search engine has announced ranking consequences tied to provenance marks. The realistic near-term impact of watermarking is contractual and reputational, through client questionnaires, agency agreements and disclosure policy, rather than through search visibility.
What should marketing teams do about AI watermarking now?
Five things, none of them tooling: maintain an inventory of which tools in the stack mark their output; map where the content workflow strips marks and decide whether that is intended; review agency and freelance contracts for AI-assisted deliverable language; agree one organisational answer to "is this content AI-assisted" before being asked; and give provenance a single owner, because today it sits between brand, legal and marketing operations.
This is analysis for marketing and technology leaders. Confirm your own EU AI Act obligations with qualified counsel.