Does Claude watermark its output?
Yes. Claude models launched on or after 2 August 2026 weave an
imperceptible statistical watermark into generated text, and attach signed C2PA
provenance metadata to generated .svg, .png and
.jpg files[1][10]. It applies wherever Claude is offered,
worldwide — not only in the EU — across the API, the Claude platform, Claude Code,
Claude Cowork and Claude Tag[1]. Since 1 September 2026 a detection API
exists, but in private preview for organisations that EU law obliges to check, so an
ordinary reader still has no way to test a piece of
text[1][10]. Files are different: the
free Claude Content Checker reads the C2PA credential on a file
today[1][11].
What is actually marked
| Output | Method | Can you verify it? |
|---|---|---|
| Text | Watermark woven into the text itself | Private preview only |
| Files: .svg, .png, .jpg | Signed provenance metadata, C2PA standard | Yes, any C2PA verifier |
How the text watermark works
Anthropic describes it as woven directly into the text itself, imperceptible, and without changing the meaning, quality or readability of the response[1]. Because the mark is part of the text rather than metadata attached to it, it travels when the text is copied and pasted, and may persist through some editing[1].
On 14 August 2026 Anthropic published the mechanism. Claude's watermark is a version of SynthID-Text, the scheme Google DeepMind published in Nature in 2024, in a family of approaches going back to a 2022 proposal by Scott Aaronson[10]. All of them work the same way: when the model reaches a point where several next words would do equally well — Anthropic's example is "overcast" versus "grey" — the choice is normally settled by a random number, and watermarking replaces that randomness with a function of a secret key and the preceding words[10]. The words stay random to a reader. Someone holding the key can check whether the sequence leans the way the key would push it. More on how this class of watermark works.
Two things follow that are worth stating in Anthropic's own terms. Nothing is added to the text and there are no hidden characters, so there is nothing to strip. And the mark carries no identifying information: Anthropic says nothing in the watermark or its key would let anyone recover anything about a user, their organisation or their chats[10].
Where the mark is thin or absent
Because it can only use choices that are genuinely free, the watermark is sparser wherever the wording is forced. Anthropic names three cases: factual passages, where a specific word is required for accuracy; proofreading, where the mark can only live in the handful of corrections and may be too few to register; and code, which mostly has to be exact, leaving comments and arbitrary naming as the places a mark can sit — with a negligible effect on the code itself[10]. Detection also works poorly on short samples, and gets more confident as a passage gets longer[10].
Which models
Models launched on or after 2 August 2026 support marking at launch. Since 16 September 2026 Anthropic's help article carries a table of which model does what. Three models carry the text watermark: Claude Fable 5.1, Mythos 5.1 and Opus 5, on Anthropic's own surfaces and through the cloud partners, with Opus 5's cloud-partner rollout starting 14 September 2026 and complete within a week[1]. The other ten models in the table — Fable 5, Mythos 5, Opus 4.5, 4.6, 4.7 and 4.8, Sonnet 4.5, 4.6 and 5, and Haiku 4.5 — are listed for Content Credentials on files only, not for the text watermark[1]. Anthropic says it is adding watermarks to the models released before 2 August 2026, with all of them covered by 2 December 2026[1]; its explainer of 14 August had said only "over the coming months"[10]. So an unmarked response does not tell you much: it may predate the change, or come from a model still in transition.
Which surfaces
All of them. Anthropic's help article lists the API, the Claude platform, Claude Code, Claude Cowork and Claude Tag, and says the watermark is applied at the model level, so it is present whichever product or surface the text came from[1]. Reaching Claude through a cloud platform does not change that: the same article states that embedded watermarks apply when supported models are accessed through AWS, Google Cloud or Microsoft Foundry[1].
Signed provenance metadata is added when Claude creates a file, so on a cloud platform it applies only where that platform offers Claude's file generation features[1]. That replaced a vaguer sentence on 1 September 2026, which said only that metadata may not be supported on every platform depending on the features each one offers. Since 16 September 2026 the article also names where the rule lands: the Claude apps and the Claude Platform API, including Claude Platform on AWS and Claude in Microsoft Foundry[1]. Google Cloud is not in that list. If the route you use cannot make files, there is no metadata to find. The text watermark is unaffected either way.
Can anyone check for it?
Since 1 September 2026, yes, but almost certainly not you. Anthropic is releasing a watermark detection API in private preview[10]. It names who can have it: organisations required to check under EU law — regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations and EU civil society groups — and enterprises under the same compliance obligation. Access is by application through a form, and Anthropic says it plans to widen access over time[1][12].
Read that as a change of kind, not a small one. Until 1 September the site could say no detector existed anywhere. Now one does, and the question has become who is allowed to run it. If you have been accused of something and the institution accusing you is not on that list, it does not hold a Claude watermark result, whatever it implies. What to do about that.
Files are the exception. Anthropic runs a free Claude Content Checker that reads the C2PA credential on a file in your browser, without uploading it[1][11]. It accepts images, video and audio — the page lists JPG, PNG, GIF, WEBP, TIFF, HEIC, AVIF, SVG, DNG, JXL, MP4, MOV, AVI, WAV, MP3, M4A and FLAC, up to 100 MB[11]. It does not take text, so it cannot answer the question most people arrive with.
What it does not tell you
This is the part worth reading twice, and it comes from Anthropic rather than from critics. A detected mark signals that content may have been processed by Claude. It is not fully conclusive and does not on its own establish provenance, because Claude may not be the original author — people use it to proofread, translate, summarise and convert files[1].
The absence of a mark tells you even less. Content can be AI-generated and unmarked if it came from an older model, was heavily edited, is very short, or had its metadata stripped[1].
Can you turn it off?
Anthropic's help article describes no opt-out[1]. We have not found one documented anywhere else.
Can you remove it?
Only by rewriting it, and not with the tools currently selling that. Anthropic's answer is direct: light editing probably will not remove the watermark completely, and a complete rewrite where every word is replaced will[10]. Where the line falls between those two is not published. The long answer, including what does nothing.
Sources
Last verified against primary sources: