{
  "_comment": [
    "Every claim on the site cites a key from this file. cite() raises on an",
    "unknown key, so a page cannot ship an unsourced claim.",
    "",
    "'primary' means the organisation being described said it themselves.",
    "Secondary sources are still usable, but a claim resting only on secondary",
    "reporting must be labelled as reported rather than confirmed.",
    "",
    "'fetched' is the date the URL was last read end to end and the claims",
    "checked against it. tools/watch_watermarks.py re-reads these and flags",
    "changes; it does not edit prose on its own."
  ],
  "anthropic-help": {
    "n": 1,
    "url": "https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content",
    "title": "How Claude marks AI-generated content",
    "publisher": "Anthropic",
    "date": "2026-08, updated 2026-09-16",
    "fetched": "2026-09-20",
    "primary": true,
    "claims": [
      "Claude models launched on or after August 2, 2026 support marking at launch.",
      "Anthropic is working to add marking to earlier models during a transition period.",
      "Marking applies wherever Claude is offered, worldwide.",
      "Covers the API, Claude platform, Claude Code, Claude Cowork and Claude Tag.",
      "Cloud partners: when supported Claude models are accessed through AWS, Google Cloud or Microsoft Foundry they will carry watermarks. Content Credentials (C2PA) are added when Claude creates a file, so they apply only where a platform offers Claude's file generation features. Since 16 September 2026 the page names where that is: in the Claude apps and the Claude Platform (API), including Claude Platform on AWS and Claude in Microsoft Foundry. Google Cloud is not in that list.",
      "Watermarking is applied at the model level, so it is present no matter which Claude product or surface the text comes from.",
      "Text: an imperceptible watermark woven directly into the text itself.",
      "The mark does not change the meaning, quality or readability of the response.",
      "It travels with copy and paste, and may persist through some editing.",
      "Files get Content Credentials: signed provenance metadata following the C2PA standard. The page's examples of a supported file type are 'a PNG or JPEG'; until the 16 September 2026 edit it listed '.svg, .png, .jpg', and .svg no longer appears on this page. The newsroom explainer (anthropic-watermark-explainer) and the Content Checker page (anthropic-content-checker) still give .png, .jpg and .svg as examples.",
      "Watermark detection is in private preview. It is available to eligible organisations as required under EU law — the page names regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations and EU civil society groups — and to enterprises similarly obligated to verify watermarking for their own compliance with the Act. Anthropic says it plans to expand access to the detection API over time, and takes registrations through a Claude Watermark Detector Access Request Form at https://forms.gle/9tGA33hPJJwtHsMk9.",
      "A detected mark signals content may have been generated or processed by Claude and is not fully conclusive; Claude may not be the original author, because people use it to proofread, translate, summarise and convert files.",
      "Absence of a mark does not confirm content is not AI-generated: a model before marking was supported for that model, heavy editing, very short outputs and stripped metadata all produce unmarked content.",
      "A table headed 'Which Claude models support watermarking', added on 16 September 2026, lists which models carry which mark. Text watermarks in Claude output on first-party surfaces: Claude Fable 5.1, Claude Mythos 5.1 and Claude Opus 5. Text watermarks in cloud partner output (AWS, Google Cloud, Microsoft Foundry): the same three, with a footnote that for Claude Opus 5 text watermarking is gradually available on cloud partner surfaces from 14 September 2026 and fully available within one week. Content Credentials (C2PA) in files: all thirteen models in the table — Fable 5.1, Fable 5, Mythos 5.1, Mythos 5, Opus 5, Opus 4.8, Opus 4.7, Opus 4.6, Opus 4.5, Sonnet 5, Sonnet 4.6, Sonnet 4.5 and Haiku 4.5. The ten models other than Fable 5.1, Mythos 5.1 and Opus 5 are listed for Content Credentials only, not for the text watermark.",
      "Anthropic says it is adding watermarks to outputs from models released before August 2, 2026, with all covered by December 2, 2026.",
      "To check whether a file carries a Claude-issued Content Credential, the page directs readers to the free Claude Content Checker at https://claude.com/check-content.",
      "For how Claude marks files and how to verify Claude-issued Content Credentials, the page links a 'Content Credentials on generated files' section. Since the 16 September 2026 edit that link points at https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool#content-credentials-on-generated-files (see anthropic-docs-c2pa); until then it pointed at https://platform.claude.com/docs/en/build-with-claude/watermark-detection, which returned 404 throughout.",
      "For people who build with Claude, Anthropic says it will share technical guidance on its marking and detection approach as it becomes available."
    ],
    "notes": "Re-read end to end on 13 August 2026 after the watcher flagged a content change. The flagged change was noise: the only difference from the archived copy of 13 August 06:27 UTC is the relative timestamp the help centre prints under the title, which moved from 'Updated yesterday' to 'Updated this week'. The article body is byte-identical, and matches every archived snapshot back to 11 August 22:41 UTC. The re-read did find a real error of ours. This article carries a 'Cloud partners' bullet stating that embedded watermarks apply through AWS, Google Cloud and Microsoft Foundry, and it was present in every snapshot checked, including 11 August 16:15 UTC — before the 12 August review ran. That review nevertheless recorded, in data/watermarks.json and in two site passages, that the article does not list those surfaces and that no source we hold addresses them. It generalised from the TechCrunch article, which genuinely does not mention them, to the Anthropic page, which does. Corrected on 13 August 2026. Re-read end to end again on 15 August 2026; the watcher reports it unchanged and every claim above still stands word for word. Note that this article is now the narrower of Anthropic's two: the newsroom explainer of 14 August (see anthropic-watermark-explainer) names the scheme and promises a detection API, where this one still says only that detection details are forthcoming. Flagged again on 16 August 2026 and re-read end to end. Noise: the article body and the help centre's navigation sidebar are byte-identical to the archived snapshots of 13 August 06:27, 14 August 13:04, and 15 August 19:07 and 20:45 UTC. The only difference anywhere in the page is the 'Related Articles' list at the foot, which rotated — 'Claude is providing incorrect or misleading responses' and 'Log in to your Claude account' were replaced by 'Report, block, and remove content from Claude' and 'Claude Cowork architecture overview'. That is a list of other links, which is the noise pattern REVIEW.md names. Every claim above still stands word for word, and detection is still only promised: the page continues to say details will come in forthcoming technical documentation, with no date. Flagged again on 18 August 2026 and re-read end to end. Noise. This time the page's visible text was diffed word by word against the Internet Archive snapshot of 17 August 15:29 UTC, and the article body is identical across the whole of it, from the opening line about having signed the Article 50(2) Code of Practice to the closing paragraph for people who build with Claude. Every difference is page chrome, and there are four: the HTML title suffix changed from 'Claude Help Center' to 'Anthropic Help Center'; the help centre's relative timestamp moved from 'Updated this week' to 'Updated over a week ago'; and the 'Related Articles' list at the foot rotated again, gaining 'Claude is providing incorrect or misleading responses. What's going on?' and dropping 'Covered Models'. A renamed title suffix and a rotating list of other links are the noise pattern REVIEW.md names. All thirteen claims above still stand word for word, and detection is still only promised: the page still says 'We'll share details on detection mechanisms in forthcoming technical documentation', with no date. Flagged again on 19 August 2026 and re-read end to end. Noise. The page's visible text was diffed word by word against the Internet Archive snapshot of 17 August 15:29 UTC, which is still the newest one the archive holds, and the article body is word-identical across all 957 words of it, from the opening line about having signed the Article 50(2) Code of Practice to the closing paragraph for people who build with Claude. Every difference on the page is chrome, and there are four: the HTML title suffix ('Claude Help Center' to 'Anthropic Help Center', already recorded on 18 August), the relative timestamp ('Updated this week' to 'Updated over a week ago', also already recorded), and two edits to the help centre's navigation sidebar — the article 'How do I use the Workbench?' is now 'How do I use the playground?', and 'Sharing Prompts in the Claude Console' has been dropped. Those two sidebar edits are not in the 17 August snapshot; whether they landed before or after yesterday's read cannot be settled, because the archive holds no snapshot of this page after 17 August. Either way a renamed and a removed entry in a list of other help articles is the noise pattern REVIEW.md names. The 'Related Articles' list at the foot also rotated, back to exactly its 17 August composition: 'Covered Models' returned and 'Claude is providing incorrect or misleading responses' left, the reverse of yesterday's rotation. All thirteen claims above still stand word for word, and detection is still only promised, with no date. One thing recorded for the next reviewer because it reads like a change and is not: the summary bullet at the top of the page says 'Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch', carrying an EU qualifier that the 'What's covered' section below does not ('Claude models launched on or after August 2, 2026 support marking at launch') and that claim 1 above therefore does not either. That wording is not new — it is in the 17 August snapshot word for word — and the 'Regions' bullet still says marking applies to output from supported models 'wherever Claude is offered, worldwide', which is what the site states. Flagged again on 20 August 2026 and re-read end to end. Noise. No archived copy could be compared today: the Internet Archive served its 'Temporarily Offline' page to both its CDX and availability endpoints throughout this review, and archive.today answered 429, so today's judgement is made from the live page rather than shown by diff. Two things support it. All thirteen claims above were checked one by one against the live text and every one still stands word for word — the 'What's covered' bullets on models, products, cloud partners and regions, both marking techniques, the detection paragraph and the whole limitations list — from the opening line about having signed the Article 50(2) Code of Practice to the closing paragraph for people who build with Claude. And the article's own relative timestamp still reads 'Updated over a week ago', unchanged from 18 and 19 August; that line tracks the article's last-updated time, so an edit to the body today would be expected to have reset it. What did move is chrome. The 'Related Articles' list at the foot rotated again, and today's rotation is yesterday's run backwards: 'Claude is providing incorrect or misleading responses. What's going on?' returned and 'Covered Models' left. The navigation sidebar has also changed, though by how much cannot be established, because no earlier note transcribed it in full; today it carries 'Why Claude switched models in your conversation with Fable 5', 'Claude Fable 5 on your plan' and 'Age assurance on Claude', none of which any earlier note mentions. A rotating list of other help articles is the noise pattern REVIEW.md names. Detection is still only promised: the page still says 'We'll share details on detection mechanisms in forthcoming technical documentation', with no date. Flagged again on 22 August 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive holds a snapshot of this page from 21 August 11:09 UTC whose visible text hashes to 18c523db6365615d, which is exactly the digest the watcher recorded on 21 August, so it is demonstrably the same copy yesterday's review read. Diffed word by word against it, today's page is word-identical for its first 3,502 words — the whole of the help centre's navigation sidebar and the whole of the article body, from the opening line about having signed the Article 50(2) Code of Practice through the closing paragraph for people who build with Claude — and word-identical again after the diff, through the 'On this page' list and the footer. The only difference anywhere on the page is the 'Related Articles' list at the foot, which rotated: it dropped 'Report, block, and remove content from Claude', 'Can I use my Outputs to train an AI model?' and 'Claude Cowork architecture overview', and gained 'Log in to your Claude account', 'Age assurance on Claude' and 'Covered Models'. That is a list of other links, which is the noise pattern REVIEW.md names. Note for the next reviewer that the navigation sidebar, which moved on 19 and 20 August and could not be compared then, is word-identical to yesterday's copy today, so none of today's change is there. All thirteen claims above still stand word for word, the article's relative timestamp still reads 'Updated over a week ago' as it has since 18 August, and detection is still only promised: the page still says 'We'll share details on detection mechanisms in forthcoming technical documentation', with no date. Flagged again on 23 August 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's newest snapshot of this page is still the one of 21 August 11:09 UTC, and its visible text still hashes to 18c523db6365615d, which is the digest the watcher recorded on 21 August, so it is demonstrably the same copy the 22 August review diffed against. Diffed word by word against it, today's page is word-identical for its first 3,509 words — the whole of the help centre's navigation sidebar and the whole of the article body, from the opening line about having signed the Article 50(2) Code of Practice through the closing paragraph for people who build with Claude — and word-identical again for its last 55 words, through the 'On this page' list and the footer. The only difference anywhere on the page is the 'Related Articles' list at the foot, which rotated: it dropped 'Claude is providing incorrect or misleading responses. What's going on?', 'Can I use my Outputs to train an AI model?' and 'Claude Cowork architecture overview', and gained 'Model availability in Claude for Government' and 'Covered Models'. One thing recorded because it reads like a change and is not: 'Report, block, and remove content from Claude' now appears twice in that list, which is the widget printing the same link twice rather than anything about this article. A rotating list of other links is the noise pattern REVIEW.md names. All thirteen claims above still stand word for word, the article's relative timestamp still reads 'Updated over a week ago' as it has since 18 August, and detection is still only promised: the page still says 'We'll share details on detection mechanisms in forthcoming technical documentation', with no date. Flagged on 24 August 2026 and again on 25 August 2026 — the hash moved from 2c23bbb63bc5271e to b642b34bc4305896 and then to 2b8630121bc0966a; the 24 August proposal was left unreviewed that day, and both flags were resolved together by today's read. Noise, and shown rather than judged: the Internet Archive holds a snapshot of this page from 23 August 23:57 UTC whose visible text hashes to exactly 2c23bbb63bc5271e, the digest the watcher held before the first move, so it is demonstrably the copy the 23 August review read. Diffed word by word against it, today's page differs in three places, and the article body appears in none of them. The help centre's navigation sidebar gained 'Understanding your Pro or Max plan invoices' and 'Understanding your Team plan invoices' and renamed 'Where can I find full receipts and invoices for my Claude API and Console payments?' to 'Understanding your Claude API invoices'. The article's relative timestamp moved from 'Updated over a week ago' to 'Updated over 2 weeks ago', which is the same last-updated time restated as it recedes, and is itself evidence the body has not been edited. And the 'Related Articles' list at the foot rotated: the duplicated 'Report, block, and remove content from Claude' pair and 'Model availability in Claude for Government' left, and 'Claude is providing incorrect or misleading responses. What's going on?', 'Can I use my Outputs to train an AI model?' and 'Log in to your Claude account' arrived, with 'Get started with Claude for Government' and 'Covered Models' staying. A renamed sidebar entry and a rotating list of other links are the noise pattern REVIEW.md names; the intermediate 24 August hash will have been a different arrangement of the same chrome, though which arrangement cannot be shown, because no archive snapshot captured it. All thirteen claims above still stand word for word, including the 'Cloud partners' bullet naming AWS, Google Cloud and Microsoft Foundry and the 'Regions' bullet saying marking applies wherever Claude is offered, worldwide, and detection is still only promised: the page still says 'We'll share details on detection mechanisms in forthcoming technical documentation', with no date. Flagged again on 26 August 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 23 August 23:57 UTC hashes to exactly 2c23bbb63bc5271e, the digest the watcher held before the 24 and 25 August moves, so it is demonstrably the copy the 25 August review diffed against and found substantively unchanged. Diffed word by word against it, today's page differs in eleven places, and the article body appears in none of them. The help centre's navigation sidebar gained 'Get started with Claude Science', 'Understanding your Pro or Max plan invoices' and 'Understanding your Team plan invoices', and renamed 'Where can I find full receipts and invoices for my Claude API and Console payments?' to 'Understanding your Claude API invoices'. The article's relative timestamp moved from 'Updated over a week ago' to 'Updated over 2 weeks ago', which is the same last-updated time restated as it recedes and is itself evidence the body has not been edited. The 'Related Articles' list at the foot rotated: the duplicated 'Report, block, and remove content from Claude' entry left, 'Claude is providing incorrect or misleading responses. What's going on?' arrived, and 'Covered Models' was replaced by 'Get started with Claude Compliance API integrations'. And the 'On this page' contents widget dropped its three sub-headings - 'What's covered', '1. Embedded watermarks in text' and '2. Signed provenance metadata' - so it now lists only the five top-level ones; all three of those headings are still in the body, which is how you can tell the widget changed and the article did not. A renamed sidebar entry and a rotating list of other links are the noise pattern REVIEW.md names. The body is 957 words, the same count recorded on 19 August. All thirteen claims above still stand word for word, including the 'Cloud partners' bullet naming AWS, Google Cloud and Microsoft Foundry and the 'Regions' bullet saying marking applies wherever Claude is offered, worldwide, and detection is still only promised: the page still says 'We'll share details on detection mechanisms in forthcoming technical documentation', with no date. One thing is recorded for the next reviewer rather than acted on. Above the 'Machine-readable marks in Claude-generated content' section the article carries a summary headed 'Anthropic's commitments under the EU AI Act's Code of Practice on Transparency of AI-Generated Content', whose first bullet reads 'Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch'. That 'in the EU' qualifier appears in none of the claims above, which follow the 'What's covered' section further down ('Claude models launched on or after August 2, 2026 support marking at launch') and the 'Regions' bullet ('Marking will apply to output from supported models wherever Claude is offered, worldwide'). The summary is not new - it does not appear in the diff against 23 August, so it has been on the page at least that long - and nothing on the site turns on the difference, because the site's worldwide statement rests on the 'Regions' bullet rather than on this one. It is recorded because the claims list does not capture it, and a future reader who met that bullet on its own might think the site had overstated the scope. Flagged again on 29 August 2026 and re-read end to end. Noise, and it can be shown rather than judged: the page's visible text was diffed word by word against the Internet Archive snapshot of 26 August 07:10 UTC, which hashes to exactly b45d64036c351f8c, the watcher's own old baseline for this source. The article body is identical across the two copies, word for word and still 957 words, from 'Anthropic has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content' down to 'Did this answer your question?'. Every difference is furniture. The left-hand navigation sidebar gained 'Claude Team plan for scientists' and 'Set up Claude for Teachers for your school or district' and reordered its Claude Cowork entries; the 'Related Articles' list at the foot lost 'Claude is providing incorrect or misleading responses', 'Model availability in Claude for Government' and 'Get started with Claude Compliance API integrations', and gained 'Can I use my Outputs to train an AI model?', 'Claude Cowork architecture overview' and 'Covered Models'. A growing sidebar and a rotating list of other links are the noise pattern REVIEW.md names, and the new sidebar entries are explained by Anthropic's newsroom post of 27 August opening a Claude team plan for scientists, which is the ordinary way the help centre's index grows. All thirteen claims above still stand word for word, the relative timestamp under the title still reads 'Updated over 2 weeks ago' exactly as it did on 26 August, and detection is still only promised: the page still says 'We'll share details on detection mechanisms in forthcoming technical documentation', with no date. The 'in the EU' qualifier recorded on 26 August is still where it was, in the summary above the article and not in the 'What's covered' and 'Regions' bullets the claims follow. Flagged again on 31 August 2026 and re-read end to end. Noise, and this is the cleanest demonstration of it the file holds. The Internet Archive's two newest snapshots of this page, of 29 August 07:13 and 18:31 UTC, both hash to exactly 5c476e996723fea4, which is the digest the watcher held before today's move, so they are demonstrably the copy the 30 August review read. Diffed word by word against them, today's page differs in exactly one word out of 3,616: the relative timestamp under the title reads 'Updated over 3 weeks ago' where it read 'Updated over 2 weeks ago'. That line restates the same last-updated time as it recedes, and is itself evidence the body has not been edited. Nothing else on the page moved at all — not the left-hand navigation sidebar, not the 'On this page' widget, and, for the first time in this file's record, not even the 'Related Articles' list at the foot, which is word-identical to 29 August. The article body is 957 words, the same count recorded on 19, 26 and 29 August, and all thirteen claims above still stand word for word, including the 'Cloud partners' bullet naming AWS, Google Cloud and Microsoft Foundry and the 'Regions' bullet saying marking applies wherever Claude is offered, worldwide. Detection is still only promised: the page still says 'We'll share details on detection mechanisms in forthcoming technical documentation', with no date. The 'in the EU' qualifier recorded on 26 August is still where it was, in the summary above the article and not in the 'What's covered' and 'Regions' bullets the claims follow. Flagged again on 1 September 2026 and re-read end to end. Noise, and this time the cause was pinned down from the help centre's own metadata rather than from an archive diff, because the Internet Archive's CDX endpoint timed out on all six attempts for this URL today. The article itself has not been touched. The help centre's sitemap gives it a lastmod of 10 August 2026 19:03:20 UTC, which has not moved; the relative timestamp under the title still reads 'Updated over 3 weeks ago', the same words as on 31 August, so unlike most flags on this page that is not what moved this time; the body is still 957 words, the count recorded on 19, 26, 29 and 31 August; and all thirteen claims above still stand word for word, including the 'Cloud partners' bullet naming AWS, Google Cloud and Microsoft Foundry and the 'Regions' bullet saying marking applies wherever Claude is offered, worldwide. Four separate fetches during this review all hashed to 1327a87cddf90017, the watcher's new digest, so this is a real change to the page rather than a per-request flake. What moved is the navigation sidebar that every page of the help centre carries. The sidebar links 353 distinct English articles while the sitemap lists 352, and the one article in the sidebar but not yet in the sitemap is 'Assign a program to workspaces in Claude Console' (article 16764810), whose own page carries dateModified 2026-08-31T20:52:28Z and reads 'Updated today'. It was published after the 31 August check and its subject is Claude Console verification programs, not marking, provenance or detection. Every article in the sitemap does appear in the sidebar, so nothing was unpublished. Detection is still only promised: the page still says 'We'll share details on detection mechanisms in forthcoming technical documentation', with no date. Flagged again on 2 September 2026 and re-read end to end. **Real, and it is the change REVIEW.md names as the one that would matter most.** The page's own JSON-LD gives dateModified 2026-09-01T17:59:47Z, and the relative timestamp under the title reads 'Updated today'. Four fetches during this review all hashed to 03bc8d60e71f0b83, the watcher's new digest, so it is a real edit and not a per-request flake. The body grew from 957 words — the count recorded on 19, 26, 29 and 31 August and on 1 September — to 1,111. The diff was run word by word against the Internet Archive snapshot of 29 August 18:31 UTC, which hashes to 5c476e996723fea4, exactly the digest this file recorded for that snapshot, so it is demonstrably the pre-change copy. Six changes, and four of them are substantive. (1) The commitments bullet 'We'll help you detect Claude's marks. We'll support users and other third parties to detect Claude's marks, as the Code requires, and we'll share details in forthcoming documentation.' is replaced by 'Watermark detection is in private preview.', with the eligibility list and the access request form. (2) A new sentence in the Models bullet: 'Models currently supported include Fable 5.1 and Mythos 5.1.' (3) The Cloud partners bullet is rewritten: signed provenance metadata no longer 'may not be supported on every platform, depending on the features each platform offers' but 'is added when Claude creates a file, so it applies only where a platform offers Claude's file generation features'. That gives the rule we had recorded as an open question. (4) The 'Detecting Claude's marks' section, previously 'We'll share details on detection mechanisms in forthcoming technical documentation.', now names the free Claude Content Checker at claude.com/check-content for files, links a 'Content Credentials on generated files' docs page, and repeats the private-preview paragraph. The two non-substantive changes are the heading 'Detecting Claude's marks' becoming 'Detect Claude's marks' and one 'also' becoming 'other'. Two things a future reviewer should know. First, the docs page the article links, https://platform.claude.com/docs/en/build-with-claude/watermark-detection, returned HTTP 404 on every attempt today, from urllib and from a browser user-agent, on both platform.claude.com and docs.claude.com, and it appears in neither host's sitemap, both of which list the same 3,467 URLs and none matching watermark, provenance, c2pa or content-credential. So the technical documentation is linked but not published, and nothing on this site should say it exists. Second, the help centre sitemap's lastmod for this article still reads 2026-08-10T19:03:20Z, unmoved, while the body demonstrably changed. The 1 September note used that unmoved lastmod as evidence the article had not been touched. Today shows that inference does not hold: this sitemap's lastmod does not track content edits, and the page's own dateModified is the field to read. Flagged on 3 and 4 September 2026 and re-read end to end on 4 September. Noise. The article's own dateModified in the page metadata is still 2026-09-01T17:59:47Z, unchanged since the 2 September read, so the article itself has not been edited. The Internet Archive's snapshot of 2 September 10:56 UTC hashes to exactly 03bc8d60e71f0b83, the watcher's old baseline, so the before copy is demonstrably the one the 2 September review verified. Diffed word by word against it, today's page differs in exactly three places and none of them is in the article: the help centre's left-hand navigation gained 'Create surveys for your organization', its entry 'Use live artifacts in Claude Cowork' lost the word 'live', and the relative timestamp under the title moved from 'Updated today' to 'Updated this week'. A navigation list of other articles is the noise pattern REVIEW.md names. All seventeen claims above stand word for word, including the private-preview detection paragraph, the two models named as currently supported (Fable 5.1 and Mythos 5.1), and the link to the free Claude Content Checker at https://claude.com/check-content. The registration form is still https://forms.gle/9tGA33hPJJwtHsMk9. Flagged again on 5 September 2026 and re-read end to end. Noise, and shown rather than judged. The article's own dateModified in the page metadata is still 2026-09-01T17:59:47Z, unchanged since the 2 September read, so the article itself has not been edited. The Internet Archive holds a snapshot of 4 September 21:26 UTC — taken after that day's watcher run, so it is not the watcher's own baseline copy, but it is the nearest archived copy to it. Diffed word by word against it, today's page differs in exactly one place out of 3,824 words: the help centre's left-hand navigation gained the article 'Turn on data retention for a Workspace in a zero data retention organization'. Diffed further against the snapshot of 2 September 19:15 UTC, the copy from the day the article last changed, every difference is still furniture: four header link labels recased ('Anthropic' to 'Claude', 'Docs' to 'docs', 'Notes' to 'notes', 'Get Support' to 'get support'), five navigation entries added or removed, the relative timestamp under the title moving from 'Updated yesterday' to 'Updated this week', and the 'Related Articles' list at the foot rotating. The article body appears in neither diff. A navigation list of other articles is the noise pattern REVIEW.md names. All seventeen claims above stand word for word, verified against the live HTML: the private-preview detection paragraph with its eligibility list, the registration form at https://forms.gle/9tGA33hPJJwtHsMk9, the free Claude Content Checker at https://claude.com/check-content, the 'Content Credentials on generated files' link to https://platform.claude.com/docs/en/build-with-claude/watermark-detection, and Fable 5.1 and Mythos 5.1 as the models currently supported. Flagged again on 9 September 2026 and re-read end to end. Noise. The article's own dateModified in the page metadata is still 2026-09-01T17:59:47Z, unchanged since the 2 September read, so the article itself has not been edited, and the body is still 1,111 words, the count recorded on 2 September. No archive copy of the watcher's own baseline exists: the Internet Archive's newest snapshot of this page is 4 September 21:33 UTC, which predates the 5 and 7 September runs. Diffed word by word against that snapshot, today's page differs in exactly two places out of 3,826 words and neither is in the article. The help centre's left-hand navigation gained 'Turn on data retention for a Workspace in a zero data retention organization', which the 5 September note already recorded as arriving that day, and the relative timestamp under the title moved from 'Updated this week' to 'Updated over a week ago'. That timestamp restates the same last-updated time as it recedes and is itself evidence the body has not been edited; it is the only one of the two that can have moved the hash since 7 September. All seventeen claims above were checked one by one against the live HTML and stand word for word, including the private-preview detection paragraph with its eligibility list, the registration form at https://forms.gle/9tGA33hPJJwtHsMk9, the free Claude Content Checker at https://claude.com/check-content, and Fable 5.1 and Mythos 5.1 as the models currently supported. The 'Content Credentials on generated files' link still points at https://platform.claude.com/docs/en/build-with-claude/watermark-detection, which still returns HTTP 404, as it has since 2 September; https://docs.claude.com/en/docs/build-with-claude/watermark-detection 302-redirects to that same URL and lands on the same 404. The technical documentation is therefore still linked but not published, and nothing on this site should say it exists. Flagged again on 10 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 9 September 05:31 UTC hashes to exactly 5e71a1881b3c996d, the watcher's old baseline, so it is demonstrably the copy the 9 September review read. Diffed word by word against it, today's page differs in exactly one place out of 3,832 words, and it is not in the article: the help centre's rating widget at the foot now prints the alt text of its three faces, 'Disappointed Reaction Neutral Reaction Smiley Reaction', after 'Did this answer your question?'. The article's own dateModified in the page metadata is still 2026-09-01T17:59:47Z, unchanged since the 2 September read, and the body is still 1,111 words, the count recorded on 2 September. All seventeen claims above were checked one by one against the live HTML and stand word for word, including the private-preview detection paragraph with its eligibility list, the registration form at https://forms.gle/9tGA33hPJJwtHsMk9, the free Claude Content Checker at https://claude.com/check-content, and Fable 5.1 and Mythos 5.1 as the models currently supported. The 'Content Credentials on generated files' link still points at https://platform.claude.com/docs/en/build-with-claude/watermark-detection, which still returns HTTP 404, as it has since 2 September; https://docs.claude.com/en/docs/build-with-claude/watermark-detection still 302-redirects to that same URL and lands on the same 404. The technical documentation is therefore still linked but not published, and nothing on this site should say it exists. Flagged again on 11 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 9 September 23:24 UTC hashes to exactly b2377441140d98a0, the watcher's old baseline, so it is demonstrably the copy the 10 September review read. Diffed word by word against it, today's page differs in exactly one place out of 3,837 words, and it is not in the article: the help centre's left-hand navigation gained 'Get started with smart reports', under the Claude Cowork analytics entries. A navigation list of other articles is the noise pattern REVIEW.md names. Two fetches during this review both hashed to 36368e4bc2c6ea04, the watcher's new digest, so the change is real and not a per-request flake. The article's own dateModified in the page metadata is still 2026-09-01T17:59:47Z, unchanged since the 2 September read, and the body is still 1,111 words, the count recorded on 2 September. All seventeen claims above were checked one by one against the live HTML and stand word for word, including the private-preview detection paragraph with its eligibility list, the registration form at https://forms.gle/9tGA33hPJJwtHsMk9, the free Claude Content Checker at https://claude.com/check-content, and Fable 5.1 and Mythos 5.1 as the models currently supported. The 'Content Credentials on generated files' link still points at https://platform.claude.com/docs/en/build-with-claude/watermark-detection, which still returns HTTP 404, as it has since 2 September; https://docs.claude.com/en/docs/build-with-claude/watermark-detection still 302-redirects to that same URL and lands on the same 404. The technical documentation is therefore still linked but not published, and nothing on this site should say it exists. Re-read on 12 September 2026; the watcher reports this page unchanged, and a hand fetch reproduced its visible-text hash 36368e4bc2c6ea04 at 3,837 words, identical to the copy read on 11 September. All 17 claims above were checked against the live text and stand, including the cloud-partner sentence naming AWS, Google Cloud and Microsoft Foundry, the private-preview paragraph and its Google Form link, the Claude Content Checker link and the 'Content Credentials on generated files' link. The page's dateModified is still 2026-09-01T17:59:47Z. Flagged again on 15 September 2026 and re-read end to end. Noise. No archive copy could be compared today: the Internet Archive's CDX endpoint served its 'Temporarily Offline' page on five attempts and its availability endpoint answered 429, so the judgement is made from the live page and the help centre's own metadata. Two fetches during this review both hashed to 97b8a1df36385868 at 3,812 words, the watcher's new digest, so the change is real and not a per-request flake. The article's own dateModified in the page metadata is still 2026-09-01T17:59:47Z, unchanged since the 2 September read, and the body is still 1,111 words, the count recorded on 2 September, so the article itself has not been edited. Two pieces of chrome account for the move. The help centre's left-hand navigation gained 'Let team members run smart reports for specific groups' (article 16948886), which is the one article linked from this page that the help centre sitemap does not yet list; its own page carries dateModified 2026-09-14T18:28:22Z and reads 'Updated today', so it was published after the 12 September check, and its subject is Claude Cowork smart reports, not marking, provenance or detection. And the relative timestamp under the title reads 'Updated over 2 weeks ago' where the 9 September note recorded 'Updated over a week ago', which is the same 1 September edit restated as it recedes and is itself evidence the body has not been touched. A navigation list of other articles is the noise pattern REVIEW.md names. All seventeen claims above were checked one by one against the live text and stand word for word, including the 'Cloud partners' bullet naming AWS, Google Cloud and Microsoft Foundry, the private-preview detection paragraph with its eligibility list, the registration form at https://forms.gle/9tGA33hPJJwtHsMk9, the free Claude Content Checker at https://claude.com/check-content, and Fable 5.1 and Mythos 5.1 as the models currently supported. The 'Content Credentials on generated files' link still points at https://platform.claude.com/docs/en/build-with-claude/watermark-detection, which still returns HTTP 404, as it has since 2 September. The technical documentation is therefore still linked but not published, and nothing on this site should say it exists. Flagged again on 18 September 2026 and re-read end to end. **Real, and it changes what the site says about which models are marked.** The page's own dateModified is 2026-09-16T21:23:48Z, the relative timestamp under the title reads 'Updated yesterday', and the body grew from 1,111 words, the count recorded since 2 September, to 1,263. Two fetches during this review both hashed to b0e6ded5ee42dbb6 at 3,994 words, the watcher's new digest, so the change is real and not a per-request flake. The diff was run word by word against the Internet Archive snapshot of 16 September 20:26 UTC, taken an hour before the edit; it hashes to dd1aebe5faaf291f rather than the watcher's 15 September baseline of 97b8a1df36385868, but its article body is the 1,111-word text every note since 2 September describes, so it is a sound before copy. The substantive changes are these. (1) A new section, 'Which Claude models support watermarking', carries a table with three columns — text watermarks in Claude output on first-party surfaces, text watermarks in cloud partner output (AWS, Google Cloud, Microsoft Foundry), and Content Credentials (C2PA) in files. Only Claude Fable 5.1, Claude Mythos 5.1 and Claude Opus 5 are ticked for the text watermark, on both first-party and cloud partner surfaces; a footnote says Opus 5's text watermarking is gradually available on cloud partner surfaces from 14 September 2026 and fully available within one week. Ten further models — Fable 5, Mythos 5, Opus 4.8, 4.7, 4.6 and 4.5, Sonnet 5, 4.6 and 4.5, and Haiku 4.5 — are ticked for Content Credentials in files only. The table was read from the page's HTML, because in the stripped text a lone tick cannot be placed in a column. (2) Below the table: 'Consistent with our commitments under the Code, Anthropic is adding watermarks to outputs from models released before August 2, 2026, with all covered by December 2, 2026.' That is the first date Anthropic has given for the transition; the 14 August explainer still says only 'over the coming months'. (3) The sentence 'Models currently supported include Fable 5.1 and Mythos 5.1' is gone from the Models bullet, replaced by a pointer to the table, and the 'Existing models are in progress' bullet gained the same pointer. (4) The Cloud partners bullet now says where Content Credentials apply: 'in the Claude apps and the Claude Platform (API), including Claude Platform on AWS and Claude in Microsoft Foundry'. Google Cloud is not in that list. (5) The file-type example in the Content Credentials section changed from '.svg, .png, .jpg' to 'a PNG or JPEG', so .svg no longer appears on this page; the newsroom explainer and the Content Checker page, both re-read today, still say '.png, .jpg, or .svg', so the site's file-type list now cites those two alongside this page. (6) 'lets you detect whether the file has been tampered with' was removed from the sentence about the signed metadata label, which now says only that a present label signals a file was processed by Claude; the site's C2PA page no longer attributes a tamper-detection statement to Anthropic. The remaining changes are wording: 'signed provenance metadata' became 'Content Credentials (C2PA)' throughout, 'planning to put those commitments into practice' became 'putting', the detection paragraph now says 'generated or processed by Claude', and the limitations list says 'before marking was supported for that model'. The 'Related Articles' list at the foot rotated too, which is noise. Everything else stands: the private-preview detection paragraph with its eligibility list and the registration form at https://forms.gle/9tGA33hPJJwtHsMk9, the free Claude Content Checker at https://claude.com/check-content, the 'Regions' bullet saying marking applies wherever Claude is offered, worldwide, and the 'in the EU' qualifier in the summary above the article, recorded on 26 August. (7) The 'Content Credentials on generated files' link no longer points at the 404 URL recorded since 2 September. It now points at https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool#content-credentials-on-generated-files, a section of the Claude Platform docs page for the code execution tool, which returns HTTP 200 and was read end to end today; it is recorded as the new source anthropic-docs-c2pa. The old URL https://platform.claude.com/docs/en/build-with-claude/watermark-detection still returns 404. That docs section covers files only; no technical documentation for detecting the text watermark has been published, and nothing on this site should say it has. Applied to the site: data/watermarks.json (both Anthropic rows), the 'Which models' and cloud-partner passages on /claude/, the files rule on /for-developers/, the file-type list and the tamper sentence on /c2pa/ and the scanner page. Flagged again on 20 September 2026 and re-read end to end. Noise, and shown rather than judged. The article's own dateModified in the page metadata is still 2026-09-16T21:23:48Z, unchanged since the 18 September read, so the article itself has not been edited, and the body is still 1,263 words, the count recorded on 18 September. A hand fetch reproduced the watcher's new digest b018f219a49beade at 4,003 words. The Internet Archive holds no snapshot of this page after 17 September, so the watcher's own 18 September baseline copy could not be retrieved; the diff was run instead against the snapshot of 17 September 11:21 UTC, which is 3,994 words — the count the 18 September note records for its own copy — and which carries the post-16 September body, so it is a sound before copy. Diffed word by word against it, today's page differs in exactly two places out of 4,003 words, and the article body is in neither. The help centre's left-hand navigation gained 'Invite people outside your organization to an artifact' (article 16989529), read out of a DocsSidebar list item in the HTML. And the relative timestamp under the title moved from 'Updated today' to 'Updated this week', which restates the same 16 September edit as it recedes and is itself evidence the body has not been touched. A navigation list of other articles is the noise pattern REVIEW.md names. All eighteen claims above were checked one by one against the live text and stand word for word, including the 'Which Claude models support watermarking' table, the December 2, 2026 date for covering models released before August 2, 2026, the 'Regions' bullet saying marking applies wherever Claude is offered, worldwide, the 'Cloud partners' bullet, the 'PNG or JPEG' file-type example, and the private-preview detection paragraph with its eligibility list. The three link targets inside the article body were read out of the HTML rather than the visible text, because a re-pointed link never shows in a visible-text diff, and all three are unchanged: https://claude.com/check-content, https://forms.gle/9tGA33hPJJwtHsMk9, and the 'Content Credentials on generated files' link at https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool#content-credentials-on-generated-files. No technical documentation for detecting the text watermark has been published, and nothing on this site should say it has."
  },
  "anthropic-watermark-explainer": {
    "n": 10,
    "url": "https://www.anthropic.com/news/claude-text-watermark",
    "title": "How Claude's text watermark works",
    "publisher": "Anthropic",
    "date": "2026-08-14, updated 2026-09-01",
    "fetched": "2026-09-20",
    "primary": true,
    "claims": [
      "Claude's text watermark is a version of the SynthID-Text approach published by Google DeepMind in a Nature paper in 2024.",
      "It belongs to a family of approaches going back to a proposal by Scott Aaronson in 2022, all of which change only the source of the randomness used to pick among candidate words.",
      "Nothing is added to the text and there are no hidden characters.",
      "Watermarking requires no extra tokens, is not more expensive, and has negligible impact on model speed.",
      "The watermark carries no identifying information and cannot be traced to a specific person, organization or chat; nothing in the watermark or its key would let anyone recover information about a user, their organization or their chats.",
      "Using the key, one can only answer 'What is the likelihood this was partly written by Claude?' It does not confirm that text was human-written, and cannot tell whether text was written by a different AI.",
      "Detection does not work well on small samples; confidence about Claude's involvement increases as a passage gets longer.",
      "Watermarking is sparser on factual passages where a specific word is required for accuracy. For proofreading, the watermark can only live in the handful of corrections, which might be too few to register.",
      "Code generally carries less watermarking because exact output is required; the watermark can be used where the choice of term is arbitrary, such as in comments, with a negligible effect on the code produced.",
      "Anthropic says it is releasing a detection API in private preview, currently available to eligible organisations as required under EU law — regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations and EU civil society groups — and to enterprises similarly obligated to verify watermarking for their own compliance with the Act. It says it plans to expand access over time, and links a form to register interest. The page carries a dated note: 'Updated Sep 1, 2026: Provided up to date information on the watermarking detection API.'",
      "Light editing probably will not remove the watermark completely; a complete rewrite where every word is replaced will.",
      "A translation produced by Claude carries a watermark, because in that case every word is chosen by Claude.",
      "A watermark can only determine that Claude was likely involved with the content at some point. It cannot distinguish 'Claude wrote this' from 'Claude heavily edited this'.",
      "Watermarking is applied globally at launch because Anthropic does not yet have a durable way to scope it by region; it will continue to evaluate approaches.",
      "Anthropic signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026, along with several other major model providers and around 190 total signatories.",
      "For supported file types (.png, .jpg, .svg) Claude attaches a C2PA content credential in the file's metadata; Anthropic says it will provide its own tool where a file can be dropped in and checked.",
      "Anthropic reports no impact on the content, creativity or readability of Claude's text in internal testing, and cites the SynthID-Text paper's comparison of thumbs-up and thumbs-down ratings on Gemini traffic and a controlled human-rater study, neither of which found a quality difference.",
      "AI detection software such as Pangram works differently, reading stylistic tells, because those providers do not hold Anthropic's key.",
      "The watermark does not change who owns an output, who is legally responsible for it, or a user's rights under Anthropic's terms; it is applied only where Claude was involved in processing the content or file.",
      "Older models: the EU law includes a transition period for Anthropic models launched before August 2, 2026, and Anthropic is working to add watermarking for those models as well, saying this will be rolled out over the coming months."
    ],
    "notes": "New source, found on 15 August 2026 by following a change to Anthropic's newsroom index. Read end to end that day. This is the first time Anthropic has described the mechanism of its text watermark rather than only its effects, and it supersedes two things the site previously said: that Anthropic had not published the scheme's details, and that we could not assert its implementation matched Google's. Anthropic now names SynthID-Text directly. It does NOT mean a detector exists: the article says a detection API is coming soon with details still being worked out, and gives no date, so the tracker's detector column stays 'none'. Re-read end to end again on 16 August 2026. The watcher only baselined this page on 16 August rather than diffing it — it was added to sources.json on 15 August after that day's run, and a first sighting is a baseline rather than a change — so it had no previous hash to compare against and would not have reported a change had one occurred. It was therefore checked by hand rather than trusted. Every claim above still stands, and the detection answer is unchanged word for word: 'We will soon be offering a watermark detection API. We're in the process of working out the details of its implementation.' Still no date, so the detector column stays 'none'. From 17 August the watcher has a baseline for this page and will diff it normally. Flagged on 20 August 2026 — the first change the watcher has reported here since it acquired a baseline — and re-read end to end. Noise, with one thing recorded rather than resolved. All nineteen claims previously listed were checked one by one and every one still stands word for word, including the detection answer: 'We will soon be offering a watermark detection API. We're in the process of working out the details of its implementation.' Still no date, so the tracker's detector column stays 'none'. The byline is still 14 August 2026. What moved the hash is almost certainly the 'Related content' list at the foot, which today shows 'Improving Fable 5's biology safeguards', the Cuéllar appointment and the cybersecurity-incidents post — a rotating list of other newsroom posts, which is the noise pattern REVIEW.md names. The thing recorded: the answer under 'What about older Claude models?' ends 'This will be rolled out over the coming months', and no earlier version of this file recorded that section at all, so this file has never said either way whether the sentence was there. Whether it is new today could not be settled, because the Internet Archive was offline and archive.today answered 429. It is therefore added above as claim 20 on the strength of having been read on the live page today, not as a dated change. Nothing on the site was wrong without it — the site said only that Anthropic is working to add marking to earlier models during a transition period, citing anthropic-help, which the help article still says — but the site was silent on timing, so the clause was added to the 'Which models' section of /claude/ and to the Anthropic text row's scope in data/watermarks.json on 20 August 2026. If a later reviewer can reach an archive, it is worth settling when this sentence appeared. Flagged again on 22 August 2026 and re-read end to end. Noise, and this read also closes the question left open on 20 August. The Internet Archive was reachable today and holds snapshots of this page going back to 14 August 19:48 UTC, the day it was published. Diffed word by word against that publication-day copy, today's page differs in six places, and the sentence under 'What about older Claude models?' is not one of them: 'This will be rolled out over the coming months' was already there on 14 August, so it was never new, and claim 20 above rests on the article as published rather than on a single live read. Five of the six differences are copy fixes made in the first day, all of them in place by 15 August 11:44 UTC: a missing word restored in the heading 'How does watermarking affect Claude's outputs?', 'watermaking' corrected to 'watermarking', 'Detecting a watermarking' corrected to 'Detecting a watermark', and the full stops moved inside the closing quotes on 'roll' and 'watermarked'. None of them touches a claim. The sixth is today's, and it is chrome: the site-wide footer gained a 'Leadership' link, which the archive places between its snapshots of 19 August 11:56 and 19 August 22:19 UTC. From 15 August 11:44 to today the article body is word-identical across every snapshot the archive holds, so it has not been substantively edited since publication. All twenty-one claims above still stand word for word, and the detection answer is unchanged: 'We will soon be offering a watermark detection API. We're in the process of working out the details of its implementation.' Still no date, so the tracker's detector column stays 'none'. Two things recorded for the next reviewer. First, Anthropic's newsroom index was flagged the same day and read: its newest post is still this one, of 14 August 2026, and the index's visible text is word-identical to the archive's snapshots of 15 to 19 August apart from that same footer 'Leadership' link, so no new Anthropic announcement has appeared and nothing there needed following. Second, an oddity that is not resolved: the watcher's own digests for this page on 16 to 21 August — d4294e5fe84d8918, then 82d412babc9def75 — match no archived copy, while today's live text is byte-identical to the archive's snapshot of 21 August 18:39 UTC. Something small differs between what the watcher fetches and what the archive stored, and what it is could not be established. It does not affect today's read, which was made against the live page and confirmed by diff, but it is the likely reason this page keeps being flagged. Flagged on 25 August 2026 — the hash moved from 50f771a01462ca44 to d04e4f3e4c9463d8 between the 24 and 25 August runs — and re-read. Noise, shown rather than judged, and the whole change is accounted for by a single insertion. The Internet Archive's snapshot of 23 August 16:08 UTC hashes to exactly 50f771a01462ca44, the old baseline, which is also the digest the watcher recorded on 22 August when this page was last read claim by claim, so the before copy is demonstrably the one the 22 August review verified. Diffed word by word against it, today's page differs in exactly one place: the 'Related content' card at the foot for 'Improving Fable 5's biology safeguards' gained its forty-word teaser paragraph, beginning 'We're making updates to Claude Fable 5's biology safeguards in a way that substantially reduces false positives'. The article body does not appear in the diff at all, and today's live text hashes identically to the archive's snapshots of 24 August 18:43 and 25 August 06:18 UTC. A teaser on a card linking to a different newsroom post is a list of other links, which is the noise pattern REVIEW.md names. All twenty-one claims above therefore still stand — the body is word-identical to the copy they were verified against — and the detection answer is unchanged word for word: 'We will soon be offering a watermark detection API. We're in the process of working out the details of its implementation.' Still no date, so the tracker's detector column stays 'none'. Two things recorded for the next reviewer. First, the newsroom index was flagged the same day and read: its newest dated post is still this one, of 14 August 2026, and its diff against the archive's snapshot of 23 August 23:57 UTC — which hashes to exactly the watcher's old baseline for it, 8ec4c023d2434ac0 — shows only the featured carousel rotating, with the 'Inviting hard questions' and 'Redeploying Fable 5' cards replaced by cards for this article and the Fable 5 biology-safeguards post, so no new Anthropic announcement has appeared. Second, the oddity recorded on 22 August, that the watcher's 16 to 21 August digests matched no archived copy, did not recur: today the watcher's baselines for both this page and the newsroom matched archived snapshots exactly, and the live page matched two more. Flagged again on 26 August 2026 and re-read end to end. Noise, shown rather than judged, and the whole change is the 'Related content' list at the foot rotating. The Internet Archive's snapshot of 24 August 19:53 UTC hashes to exactly d04e4f3e4c9463d8, the watcher's old baseline, so the before copy is demonstrably the one the 25 August review verified. Diffed word by word against it, today's page differs in exactly two places, both inside that list: a card for 'Funding better evaluations of AI's impact on wellbeing' was inserted at the top with its teaser, 'We're launching a $5 million grant program to fund independent research into how AI impacts users' wellbeing', and the card for 'Investigating three real-world incidents in our cybersecurity evaluations' dropped off the bottom. The article body does not appear in the diff at all. All twenty-one claims above therefore still stand - the body is word-identical to the copy they were verified against - the byline is still 14 August 2026, and the detection answer is unchanged word for word: 'We will soon be offering a watermark detection API. We're in the process of working out the details of its implementation.' Still no date, so the tracker's detector column stays 'none'. The newsroom index was flagged the same day and read, and this time its change was substantive rather than chrome. The archive's snapshot of 25 August 15:05 UTC hashes to exactly 8f33f645644bbbb7, the watcher's old baseline for it, and the diff against today shows one new post at the top of the list - 'Funding better evaluations of AI's impact on wellbeing', Announcements, 25 August 2026 - with 'Anthropic is donating another $20 million to Public First Action' of 21 July falling off the bottom of the ten-item list, and one category label changing from 'Economic Research' to 'Economics'. That post was read end to end at https://www.anthropic.com/news/wellbeing-research-grants. It announces a $5 million grant program funding independent, open-source evaluations of how AI affects users' wellbeing, and says nothing about watermarking, provenance or detection: its only two occurrences of 'watermark' are in its own 'Related content' card pointing back to this article, and its only 'Transparency' is a footer link. So no new Anthropic announcement bears on this site, and nothing here changed. Flagged again on 29 August 2026 and re-read end to end. Noise. Today's page is word-identical to the Internet Archive snapshot of 27 August 22:31 UTC, which hashes to exactly 538bed44a34ee780, the watcher's new digest, so the page reached its current state by then and has not moved since. Diffed further against the snapshot of 25 August 06:18 UTC, the newest the archive holds from before the change: the first 2,220 words - headline, byline, and the whole body through both footnotes - and the last 180 words of site footer are word-identical, and every difference falls inside the three-card 'Related content' list between them. That list held 'Improving Fable 5's biology safeguards', 'Mariano-Florentino (Tino) Cuéllar to join Anthropic as Chief Global Affairs Officer' and 'Investigating three real-world incidents in our cybersecurity evaluations' on 25 August; today it holds 'Previewing the Model Hardware Standard', 'Expanding our support for scientists' and 'Funding better evaluations of AI's impact on wellbeing'. All twenty-one claims above therefore still stand, the byline is still 14 August 2026, and the detection answer is unchanged word for word: 'We will soon be offering a watermark detection API. We're in the process of working out the details of its implementation.' Still no date, so the tracker's detector column stays 'none'. The newsroom index was flagged the same day and its change was substantive rather than chrome. The archive's snapshot of it from 26 August 07:10 UTC hashes to exactly ef3a6de09edcb308, the watcher's old baseline for the index, and the diff against today shows two new posts of 27 August, 'Previewing the Model Hardware Standard' and 'Expanding our support for scientists' - the same two cards that arrived here - with the two oldest items of the ten-item list, 'A research agenda for the Economic Futures Research Fund' and 'Ask Claude about the Anthropic Economic Index', both of 22 July, falling off the bottom. Both new posts were read end to end. The first opens a research preview of a shared specification for AI agents to operate laboratory and manufacturing instruments; the second opens 10,000 free and discounted Claude seats to verified scientists. Neither says anything about watermarking, provenance or detection: in each, the only two occurrences of 'watermark' are in its own 'Related content' card pointing back to this article, and the only 'Transparency' is a footer link. So again no new Anthropic announcement bears on this site. Flagged again on 1 September 2026, together with the newsroom index, which was flagged the same day. Both were read end to end, and both moves have one cause: a single new post, 'Improving our alignment and security efforts', dated 31 August 2026. The watcher had held the newsroom at digest b03e507f76a6f3db and this page at 538bed44a34ee780 since 29 August, and the 31 August check still saw both, so the post landed after it. No archive diff was run today: the Internet Archive's CDX endpoint timed out on every attempt, so the diff was established against Anthropic's own newsroom instead. On this page the post enters the three-card 'Related content' strip at the foot, which now reads 'Improving our alignment and security efforts', 'Previewing the Model Hardware Standard' and 'Expanding our support for scientists', where on 31 August it read the latter two plus 'Funding better evaluations of AI's impact on wellbeing'. On the newsroom index the post enters the top of the ten-item list, which is still ten items long and still ends at the two posts of 27 July, 'Our position on open-weights models' and the Cognizant partnership. The article itself is unchanged: the byline is still 14 August 2026, the run from the headline to the 'Related content' strip is 2,197 words, and all twenty claims above still stand, with the detection answer word for word as before - 'We will soon be offering a watermark detection API. We're in the process of working out the details of its implementation.' Still no date, so the tracker's detector column stays 'none'. The new post was read end to end. It reports on the two evaluation incidents in which Claude models reached the live internet, and describes the containment, monitoring and alignment changes made since. It says nothing about this site's subject: watermark, SynthID, C2PA, provenance, marking and Article 50 return nothing anywhere in its body, and its four occurrences of 'detect' are all about detecting unsafe model actions during evaluations. Flagged again on 2 September 2026 and re-read end to end. Real, and the same change as the help centre's. The page now carries its own dated line at the foot of the body: 'Updated Sep 1, 2026: Provided up to date information on the watermarking detection API.' The answer under 'Other questions' to 'How do I check if a piece of text was written by Claude?' has been replaced. It read, word for word as this file recorded it through 1 September, 'We will soon be offering a watermark detection API. We're in the process of working out the details of its implementation.' It now reads 'We are releasing a detection API in private preview. It is currently available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups). It is also available for enterprises who are similarly obligated to verify watermarking for their own compliance with the Act. We plan to expand access to the detection API over time. You can register interest in access here.' The 'here' links to https://forms.gle/9tGA33hPJJwtHsMk9, the same form the help centre links. The byline is still 14 August 2026; the run from the headline to the 'Related content' strip is 2,265 words where it was 2,197 on 1 September, and the 68-word growth is accounted for by the replaced answer and the new update line. No archive diff was run today: the Wayback availability API does list snapshots of this URL for 31 August 13:28 and 1 September 23:07 UTC, but both the id_ and the ordinary replay endpoints timed out on every attempt, so the before-state rests on this file's own verbatim record, on Anthropic's own dated update note, and on two other Anthropic pages saying the same thing today. Claim 15 is deliberately left as it stands: this page still says of the file checker 'we'll be providing our own where you can drop a file and check', in the future tense, while the help centre now links a live one. Both are Anthropic's own words; the tool itself is recorded under anthropic-content-checker. Flagged again on 9 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 7 September 14:35 UTC hashes to exactly b3ec50749a9857eb, the watcher's old baseline, so it is demonstrably the copy the 7 September review read. Diffed word by word against it, today's page differs in exactly one word out of 2,577: the site-wide footer's 'Solutions' list gained 'Commerce'. The article body does not appear in the diff at all. All twenty claims above therefore still stand, the byline is still 14 August 2026, the dated line at the foot still reads 'Updated Sep 1, 2026: Provided up to date information on the watermarking detection API', and the answer to 'How do I check if a piece of text was written by Claude?' is unchanged word for word, still linking https://forms.gle/9tGA33hPJJwtHsMk9. Claim 15 still stands as recorded: this page still says of the file checker 'we'll be providing our own where you can drop a file and check', in the future tense, while the help centre links a live one. That same one-word footer insertion is the whole of the change on anthropic-fable-mythos-51 and on the newsroom index, both flagged the same day, so three of today's nine proposals have one cause. Flagged again on 10 September 2026 and re-read end to end. Noise. No archived copy of the watcher's own baseline exists: the Internet Archive's newest snapshot of this page is still the one of 7 September 14:35 UTC, which hashes to b3ec50749a9857eb, the baseline the 9 September review diffed against. Diffed word by word against it, today's page differs in exactly two places out of 2,576 words, and both are in the site-wide footer: the 'Solutions' list gained 'Commerce', which the 9 September note already recorded as arriving that day, and the 'Programs' list renamed 'Research Labs' to 'Scientists', which is today's change. The article body appears in neither. All twenty claims above therefore still stand, the byline is still 14 August 2026, the dated line at the foot still reads 'Updated Sep 1, 2026: Provided up to date information on the watermarking detection API', and the answer to 'How do I check if a piece of text was written by Claude?' is unchanged word for word, still linking https://forms.gle/9tGA33hPJJwtHsMk9. Claim 15 still stands as recorded: this page still says of the file checker 'we'll be providing our own where you can drop a file and check', in the future tense, while the help centre links a live one. That one-word rename in the footer is the whole of the change on anthropic-fable-mythos-51 and on Anthropic's newsroom index, both flagged the same day, so three of today's six proposals have one cause. Re-read on 11 September 2026; the watcher reports this page unchanged, and its visible-text hash, bc2434f2b774412c at 2,576 words, is identical to the copy read on 10 September. The private-preview detection paragraph and the future-tense file checker sentence stand word for word. Anthropic's newsroom index was flagged the same day and read end to end: diffed against the Internet Archive snapshot of 9 September 18:14 UTC, which hashes to exactly 071eb466cb34afbf, the watcher's old baseline, the index gained one post — 'Detecting and countering misuse of AI: September 2026', dated 10 September, at https://www.anthropic.com/threat-intelligence-report-september-2026 — and its featured grid dropped this explainer and 'The Making of Claude Code' to make room; the explainer is still listed lower down under 14 August. The new post is a threat-intelligence report. Its one use of the word watermark describes an influence operation stripping watermarks from other organisations' media, and it says nothing about Claude's text watermark, provenance metadata, C2PA, Article 50 or the detection API, so it changes nothing on this site. Re-read on 12 September 2026; the watcher reports this page unchanged, and a hand fetch reproduced its visible-text hash bc2434f2b774412c at 2,576 words, identical to the copy read on 11 September. All 20 claims above were checked against the live text and stand, including the 'Updated Sep 1, 2026' note, the private-preview detection API paragraph, the 'complete rewrite' sentence and the 'coming months' roll-out for older models. Flagged again on 18 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 15 September 02:49 UTC hashes to exactly bc2434f2b774412c, the watcher's old baseline, so it is demonstrably the copy the 12 and 15 September reads verified. Diffed word by word against it, today's page — which hashes to 8fbc5d5a5f5d0f48 at 2,574 words, the watcher's new digest — differs in three places and the article body appears in none of them: the related-posts block below the article swapped 'Previewing the Model Hardware Standard' for 'Introducing the Life Sciences Verification Program', a 17 September post, and the site-wide footer's Solutions list gained 'Sales', the same one-word footer change that moved the Fable and Mythos 5.1 page today. A rotating list of other links and a shared footer are the noise pattern REVIEW.md names. All 20 claims above stand word for word, including the '(.png, .jpg, or .svg)' file-type example — which matters today, because the help centre's 16 September edit dropped .svg from its own example — the 'over the coming months' roll-out for older models, which the help centre has now firmed up to 2 December 2026, and the 'Updated Sep 1, 2026' note on the detection API. Flagged again on 20 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive snapshot of 17 September 23:46 UTC hashes to exactly 8fbc5d5a5f5d0f48, the watcher's old baseline, so it is demonstrably the copy the 18 September review read. A hand fetch reproduced the watcher's new digest 654a78c3c7d87d5f at 2,532 words. Diffed word by word against the baseline copy, today's page differs in exactly three places and the article body is in none of them. The 'Read more' carousel of other newsroom posts below the article gained 'Partnering with Accenture on embedded evaluation' and dropped 'Improving our alignment and security efforts'. And the site footer's copyright line gained a sentence: '© 2026 Anthropic PBC' became '© 2026 Anthropic PBC. Services in the EU are provided by Anthropic Ireland Limited.' That footer sentence is why three anthropic.com sources were flagged in the same run — it is the only difference on anthropic-fable-mythos-51, and it moved the newsroom index too — so the three flags are one edit to shared chrome rather than three changes. A rotating list of other posts and a footer line are the noise pattern REVIEW.md names. All twenty claims above were checked one by one against the live text and stand word for word, including the private-preview detection paragraph, the dated note 'Updated Sep 1, 2026: Provided up to date information on the watermarking detection API.', the '.png, .jpg, .svg' file-type list, and the older-models paragraph, which still says only 'over the coming months' — undated here, where the help centre has given December 2, 2026 since 16 September."
  },
  "ec-code-practice": {
    "n": 2,
    "url": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
    "title": "Code of Practice on Transparency of AI-generated Content",
    "publisher": "European Commission",
    "date": "2026-06-10",
    "fetched": "2026-09-18",
    "primary": true,
    "claims": [
      "Published 10 June 2026; drafting began 5 November 2025.",
      "Compliance deadline 2 August 2026.",
      "Voluntary tool; adherence is optional, Article 50 compliance is mandatory.",
      "Section 1 requires provider outputs be marked in a machine-readable format and detectable as artificially generated or manipulated.",
      "Technical solutions must be effective, interoperable, robust and reliable as far as technically feasible.",
      "Around 190 companies and organisations had signed by late July 2026.",
      "Confirmed by the Commission and AI Board as an adequate voluntary tool for demonstrating compliance."
    ],
    "notes": "Re-read end to end on 20 August 2026; the watcher reports this page unchanged, and its visible-text hash is identical to every check since 13 August. All seven claims above were checked against the live page and stand: the timeline still gives the 5 November 2025 kick-off plenary and the 10 June 2026 closing plenary and publication of the final code, the page still says the obligations apply from 2 August 2026, that adherence is voluntary while the Article 50 requirements are legal obligations, that Section 1 covers providers' rules for marking and detection, that the technical solutions must be effective, interoperable, robust and reliable as far as technically feasible, that about 190 companies and organisations had signed by the end of July 2026, and that the Commission and the AI Board have confirmed the code as an adequate voluntary tool. The page's own 'Last update' line reads 31 July 2026. Re-read end to end on 2 September 2026 as part of verifying every source the site cites. Not flagged: unchanged at 5f58a2aac7a5b593, under both the ec-code-practice and ec-transparency keys, reproduced by hand at 1,360 words. The page still carries 'Last update 31 July 2026'. All seven claims stand word for word, including 'By the end of July 2026, about 190 companies organisations have signed the code' and the working group 1 wording the site quotes about marks being effective, interoperable, robust and reliable as far as technically feasible. Re-read end to end on 9 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 5f58a2aac7a5b593 under both the ec-code-practice and ec-transparency keys, and a hand fetch reproduced that digest at 1,360 words, the same count recorded on 2 September, so the page's visible text is byte-identical to the copy that read verified. All seven claims stand word for word, including 'By the end of July 2026, about 190 companies organisations have signed the code', the two-section split with Section 1 covering providers' rules for marking and detection, and the working group 1 wording about solutions being effective, interoperable, robust and reliable as far as technically feasible. The page still carries 'Last update 31 July 2026'. Re-read end to end on 10 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 5f58a2aac7a5b593 under both the ec-code-practice and ec-transparency keys, and a hand fetch reproduced that digest at 1,360 words, the same count recorded on 2 and 9 September, so the page's visible text is byte-identical to the copy that read verified. All seven claims stand word for word, including 'By the end of July 2026, about 190 companies organisations have signed the code', the two-section split with Section 1 covering providers' rules for marking and detection, and the working group 1 wording about solutions being effective, interoperable, robust and reliable as far as technically feasible. The page still carries 'Last update 31 July 2026'. Re-read on 11 September 2026; the watcher reports this page unchanged, and its visible-text hash is identical to the copy read on 10 September. The 190-signatory sentence, the two-section split and 'Last update 31 July 2026' were checked against the live text and stand. Re-read on 12 September 2026; the watcher reports this page unchanged, and a hand fetch reproduced its visible-text hash 5f58a2aac7a5b593 at 1,360 words, identical to the copy read on 11 September. All seven claims above were checked against the live text and stand, including the 10 June 2026 closing plenary, the 5 November 2025 kick-off, 'about 190 companies organisations' by the end of July 2026, and the Commission and AI Board confirmation of the code as an adequate voluntary tool. Re-read on 18 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 5f58a2aac7a5b593, and a hand fetch reproduced that digest at 1,360 words, identical to the copy read on 12 September. All seven claims above were checked against the live text and stand, including the 10 June 2026 publication, the 5 November 2025 kick-off, about 190 signatories by the end of July 2026, the 'effective, interoperable, robust and reliable' wording, the adequate-voluntary-tool confirmation and 'Last update 31 July 2026'."
  },
  "deepmind-synthid": {
    "n": 3,
    "url": "https://deepmind.google/models/synthid/",
    "title": "SynthID",
    "publisher": "Google DeepMind",
    "date": "2026",
    "fetched": "2026-09-18",
    "primary": true,
    "claims": [
      "SynthID embeds digital watermarks into AI-generated images, audio, text or video.",
      "Text watermarking is applied in the Gemini app and web experience.",
      "Audio via Lyria and the NotebookLM podcast feature.",
      "For text, SynthID adjusts token probability scores to generate the watermark, without affecting output quality.",
      "Detection route one: upload an image, video or audio clip to Gemini and ask whether it was created or altered by Google AI. The page describes this route for those three modalities only; it does not describe a text route.",
      "Detection route two: the SynthID Detector portal, which is NOT open to the general public. It accepts an image, video or audio file — again, text is not named. The page states Google is collaborating with journalists and media professionals to test it."
    ],
    "notes": "The widely repeated '100 billion pieces of content watermarked' figure is NOT on this page. Do not state it citing this source. Re-read end to end on 13 August 2026; the watcher reports this page unchanged. This file previously recorded detection route one as 'upload content to Gemini and ask', without qualification, and the Gemini text row in data/watermarks.json told readers they could use it on text. The page does not support that: both detection routes it describes are scoped to an image, video or audio file, and neither mentions text. Narrowed to what the page says on 13 August 2026. Whether the Gemini route in fact works on text is unknown to us either way. Re-read end to end again on 20 August 2026; the watcher reports this page unchanged, and its visible-text hash is identical to every check since 13 August. All six claims stand, including the narrowing recorded above: both detection routes the page describes still take an image, video or audio file — 'Simply upload the image, video or audio clip to your chat' for the Gemini route, and 'Just upload an image, video or audio file' for the SynthID Detector portal — and neither names text. The portal is still gated, still described as being tested with journalists and media professionals, and still fronted by an early-tester waitlist. The '100 billion pieces of content' figure is still absent from the page. Re-read end to end on 2 September 2026 as part of verifying every source the site cites. Not flagged: the watcher hashed it unchanged at ad3bb1b385c10367 today, under both the deepmind-synthid and deepmind-synthid-root keys, and a hand fetch reproduced that digest at 1,133 words. All six claims still stand word for word, including the two that matter most and are the easiest to get wrong: both detection routes still take an image, video or audio file and neither names text, and the SynthID Detector portal still says Google is collaborating with journalists and media professionals to test it, with an early tester waitlist rather than open access. The '100 billion pieces of content' figure that secondary coverage repeats is still nowhere on this page, so the note declining to assert it stands. Flagged again on 9 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 7 September 13:17 UTC hashes to exactly ad3bb1b385c10367, the watcher's old baseline under both the deepmind-synthid and deepmind-synthid-root keys, so it is demonstrably the copy the 7 September check saw. Diffed word by word against it, today's page differs in exactly two places, and both are the same eight-word insertion into DeepMind's site navigation: 'AlphaGenome Using AI to understand the human genome' now sits in the Science menu, which the page prints twice, taking it from 1,133 to 1,149 words. The body does not appear in the diff. A navigation list of other models is the noise pattern REVIEW.md names. All six claims still stand word for word, including the two that are easiest to get wrong: both detection routes still take an image, video or audio file — 'Simply upload the image, video or audio clip to your chat' for the Gemini route and 'Just upload an image, video or audio file' for the portal — and neither names text, and the SynthID Detector is still gated, still described as being tested with journalists and media professionals, and still fronted by an early-tester waitlist. The '100 billion pieces of content' figure that secondary coverage repeats is still nowhere on the page. Re-read end to end on 10 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at bcaeb9c8c48539bb under both the deepmind-synthid and deepmind-synthid-root keys, and a hand fetch reproduced that digest at 1,149 words, the count this page reached on 9 September when the AlphaGenome entry entered DeepMind's Science menu, so the visible text is byte-identical to the copy that read verified. All six claims stand word for word, including the two that are easiest to get wrong: both detection routes still take an image, video or audio file — 'Simply upload the image, video or audio clip to your chat' for the Gemini route and 'Just upload an image, video or audio file' for the portal — and neither names text, and the SynthID Detector is still gated, still described as being tested with journalists and media professionals, and still fronted by an early-tester waitlist. The '100 billion pieces of content' figure that secondary coverage repeats is still nowhere on the page. Re-read on 11 September 2026; the watcher reports this page unchanged, and its visible-text hash is identical to the copy read on 10 September. The SynthID Detector section still names images, video and audio only, still describes testing with journalists and media professionals, and still fronts an early-tester waitlist. Re-read on 12 September 2026; the watcher reports this page unchanged, and a hand fetch reproduced its visible-text hash bcaeb9c8c48539bb at 1,149 words, identical to the copy read on 11 September. All six claims above were checked against the live text and stand: the Gemini route still names an image, video or audio clip only, the Detector portal still takes an image, video or audio file and is still being tested with journalists and media professionals, and the audio sentence still names Lyria and the podcast feature of Notebook LM. Flagged again on 18 September 2026, under both the deepmind-synthid and deepmind-synthid-root keys, and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 16 September 03:33 UTC hashes to exactly bcaeb9c8c48539bb, the watcher's old baseline, and its snapshot of 18 September 03:41 UTC hashes to exactly a45868c515d6dee3, the watcher's new digest. Diffed word by word, the two differ only in the words 'DeepMind Institute', inserted three times — once in each of the two copies of the site navigation and once in the footer, under the 'Learn more' entries next to 'The Podcast'. The page is 1,155 words, up from 1,149, and the SynthID content is untouched. All six claims above stand word for word: text watermarking in the Gemini app and web experience, audio via Lyria and the podcast feature of Notebook LM, the Gemini route taking 'the image, video or audio clip', the Detector portal taking 'an image, video or audio file', still not open to the public and still being tested with journalists and media professionals."
  },
  "synthid-text-repo": {
    "n": 4,
    "url": "https://github.com/google-deepmind/synthid-text",
    "title": "google-deepmind/synthid-text",
    "publisher": "Google DeepMind",
    "date": "2024-10",
    "fetched": "2026-09-18",
    "primary": true,
    "claims": [
      "Reference implementation of SynthID Text watermarking and detection, open sourced.",
      "Distributed on PyPI, with examples for Gemma and GPT-2.",
      "Detection can be done with a weighted mean detector, which requires no training, or with a Bayesian detector, which must be trained and must be trained again for each unique watermarking key.",
      "The Bayesian detector's score() returns a per-example score between 0 and 1, with scores closer to 1 indicating higher likelihood that the text was generated with the given watermark; the acceptance threshold is left to the user.",
      "Thresholds are tunable for a target false-positive rate.",
      "The repository states this is a reference implementation for research reproducibility, not designed for production systems, and points to the SynthID Text implementation in Hugging Face Transformers as the production-ready one."
    ],
    "notes": "This is the reason SynthID Text is in a different category from Claude's mark: the detector for the scheme is public, even though Google's own hosted portal is gated. Re-read end to end on 12 August 2026 after the watcher flagged a content change. The flagged change was noise: the README has not been edited since 13 December 2024 and the release list still ends at 0.2.1 of 14 November 2024, so the visible-text hash moved only because star, fork and watcher counts sit in the page text. The re-read did find that this file previously recorded a claim that detection returns watermarked, not watermarked, or uncertain. The repository does not say that. The words uncertain, inconclusive and ambiguous appear nowhere in its README, code or notebooks; the README describes a continuous score with a user-chosen acceptance threshold. The claim and the two site passages resting on it were corrected on 12 August 2026. The watcher flagged this page again on 13 August 2026, and it was noise for the same reason: checked against the GitHub API, the README's last commit is still 13 December 2024, the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is 13 June 2025. Only the star, fork and watcher counts had moved. Flagged a third time on 15 August 2026 and checked against the GitHub API again: README last touched 13 December 2024, newest release still 0.2.1 of 14 November 2024, newest commit to any path still 13 June 2025 (addb4a1). Counts had moved to 982 stars, 92 forks, 26 watchers. Noise again. Flagged a fourth time on 16 August 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). Counts had moved to 1007 stars and 96 forks, with watchers unchanged at 26 — the repository crossed a thousand stars, which is what moved the hash. The six claims above were each re-checked against the README text and all still stand, including that the words uncertain, inconclusive and ambiguous still appear nowhere on the page. Noise again. Flagged a fifth time on 18 August 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). Counts had moved to 1031 stars and 97 forks, with watchers unchanged at 26. The README was then fetched raw from main and read in full, and each of the six claims above re-checked against its text; all still stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in it. Noise again. Flagged a sixth time on 20 August 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). Counts had moved to 1047 stars and 98 forks, with watchers unchanged at 26. The README was fetched raw from main and read in full again, and each of the six claims above re-checked against its text; all still stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in it. Noise again. Flagged a seventh time on 21 August 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). The only count that moved since 20 August is stars, from 1047 to 1052; forks are unchanged at 98 and watchers at 26, so a star count sitting in the page text is the whole of today's hash change. The README was fetched raw from main and read in full again, and each of the six claims above re-checked against its text; all still stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in it. Noise again. Flagged an eighth time on 23 August 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). Noise again, but not for the reason the notes above have been giving, so today's read records what actually moved. The star count is not it. The page prints the star figure rounded — 'Star 1.1k' in the header and 'Stars 1.1k stars' in the sidebar — so the move from 1052 stars on 21 August to 1056 today leaves the page's visible text untouched. Forks and watchers are printed exactly and are both unchanged, at 98 and 26. What moved is the pull-request tab: PR #47, 'Update deprecated GitHub Help link to GitHub Docs', was closed without being merged at 16:35 UTC on 22 August — after that day's watcher run, which is why it surfaced today — and the page's count fell from 6 to 5. The arithmetic confirms it: the API reports 12 open issues and 5 open pull requests, the page prints 'Issues 12 Pull requests 5', and open_issues_count is 17. A pull request closed without a merge changes no file in the repository, so this is noise under the rule REVIEW.md gives for github.com, that only a change to the README or the release list means anything. The page was also fetched four times in the space of a minute and its visible text hashed identically each time, so this is a real change to the page rather than a per-request flake. The README was fetched raw from main and read in full again, and each of the six claims above re-checked against its text; all still stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in it. For the next reviewer: the exact star figures quoted in the notes above were read from the API rather than off the page, so nothing here establishes that the page ever printed them exactly, and the counters actually visible on it are forks, watchers, and the issue and pull-request tabs. Flagged a ninth time on 25 August 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). What moved is the fork count, which the page prints exactly: 98 on 23 August, 99 today. Stars moved from 1056 to 1061, which the page still prints rounded as 1.1k, watchers are unchanged at 26, and the API still reports 12 open issues and 5 open pull requests, so the issue and pull-request tabs are unchanged too. A fork counter in the page text is noise under the rule REVIEW.md gives for github.com, that only a change to the README or the release list means anything. The README was fetched raw from main and read in full again, and each of the six claims above re-checked against its text; all still stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in it. Flagged a tenth time on 29 August 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). What moved is again the fork count, which the page prints exactly: 99 on 25 August, 101 today. Stars moved from 1061 to 1072, which the page still prints rounded as 1.1k, watchers are unchanged at 26, and the API still reports 12 open issues and 5 open pull requests, matching the 'Issues 12 Pull requests 5' the page prints. A fork counter in the page text is noise under the rule REVIEW.md gives for github.com, that only a change to the README or the release list means anything. The README was fetched raw from main and read in full again, and each of the six claims above re-checked against its text; all still stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in it. Flagged an eleventh time on 30 August 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). What moved is again the fork count, which the page prints exactly: 101 on 29 August, 102 today. Stars moved from 1072 to 1074, which the page still prints rounded as 1.1k, watchers are unchanged at 26, and the API still reports 12 open issues and 5 open pull requests, matching the 'Issues 12 Pull requests 5' the page prints. The page's visible-text hash read 24a3e5f5 on a refetch during this review, the same value the watcher flagged, so the fork counter is the whole of the change. A fork counter in the page text is noise under the rule REVIEW.md gives for github.com, that only a change to the README or the release list means anything. The README was fetched raw from main and read in full again, and each of the six claims above re-checked against its text; all still stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in it. Flagged a twelfth time on 31 August 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). What moved is two counters the page prints exactly, where every previous flag moved one: forks went from 102 on 30 August to 103, and watchers from 26 — where they had sat since 15 August, through every check in these notes — to 27. Stars moved from 1074 to 1075, which the page still prints rounded as 'Star 1.1k' and 'Stars 1.1k stars', and the API still reports 12 open issues and 5 open pull requests, matching the 'Issues 12 Pull requests 5' the page prints. The page's visible text hashed to 593e6e29090adafd, the watcher's new digest, on three separate fetches during this review, so this is a real change to the page rather than a per-request flake, and those two counters are the whole of it. Fork and watcher counters sitting in the page text are noise under the rule REVIEW.md gives for github.com, that only a change to the README or the release list means anything. No archive diff was run today: the CDX endpoint timed out on every attempt for this URL, and for this source the GitHub API answers the question the rule actually asks more directly than a snapshot would, which is the method every flag in these notes has used. The README was fetched raw from main and read in full again, and each of the six claims above re-checked against its text; all still stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in the README or anywhere else on the page. Flagged again on 1 September 2026 and checked against the GitHub API once more: the README's last commit is still 13 December 2024, the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025. What moved is one counter, and a different one from the fork and watcher counters that moved on 31 August: the page now prints 'Issues 13 Pull requests 5' where it printed 'Issues 12 Pull requests 5', and the API's open_issues_count of 18, which counts issues and pull requests together, matches. Forks are still 103 and watchers still 27, both unchanged since 31 August, and stars moved from 1075 to 1077 without changing the page at all, because it prints them rounded as 'Star 1.1k' and 'Stars 1.1k stars'. An open-issue counter sitting in the page text is noise under the rule REVIEW.md gives for github.com, that only a change to the README or the release list means anything. No archive diff was run today: the CDX endpoint timed out on every attempt, and for this source the GitHub API answers the question the rule actually asks more directly than a snapshot would. The README was read in full again as the repository page renders it, and each of the six claims above re-checked against its text; all still stand. Flagged again on 2 September 2026 and checked against the GitHub API once more. Noise. The README's last commit is still 13 December 2024, the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025, so no code or prose in the repository has moved. What moved is one counter, and a different one again: the page now prints 'Fork 104' and 'Forks 104 forks' where it printed 103. Issues are still 13, pull requests still 5, watchers still 27, and stars 1078 against the 1077 of 1 September, which does not change the page because it prints them rounded as '1.1k'. A fork counter sitting in the page text is noise under the rule REVIEW.md gives for github.com, that only a change to the README or the release list means anything. The README was fetched raw from main and read in full again — 12,558 characters, sha256 prefix 5fd70fde4e99dcf0 — and each of the six claims above re-checked against its text. All six still stand. Not flagged on 9 September 2026, and read anyway so the pages citing it could carry today's verified date. The page hashes to 2724a6dceb996b51, unchanged since 2 September, and the GitHub API explains why: none of the counters the page prints exactly has moved. Forks are still 104, watchers still 27, and the page still prints 'Issues 13 Pull requests 5', matching the API's open_issues_count of 18. Stars went from 1078 to 1095 without touching the page, because it prints them rounded as 'Star 1.1k' and 'Stars 1.1k stars'. The README's last commit is still 13 December 2024 (25a25de), the newest release is still 0.2.1 of 14 November 2024, and the newest commit to any path is still 13 June 2025 (addb4a1). The README was fetched raw from main and read in full — 12,558 characters, sha256 prefix 5fd70fde4e99dcf0, identical to the 2 September record — and each of the six claims above re-checked against its text. All six stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in it. Re-read end to end on 10 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: the rendered page hashes to 2724a6dceb996b51, unchanged since 2 September, and the GitHub API explains why the counters did not move it. Forks are still 104, watchers still 27, and open issues and pull requests still total 18, the figure behind the page's 'Issues 13 Pull requests 5'. Stars went from 1095 to 1097 without touching the page, because it prints them rounded as 'Star 1.1k'. The README was fetched raw from main and read in full — 12,558 characters, sha256 prefix 5fd70fde4e99dcf0, identical to the 2 and 9 September records — and each of the six claims above re-checked against its text. All six stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in it, that the Bayesian detector must be trained again for each unique watermarking key, and that the repository points to the Hugging Face Transformers implementation as the production-ready one. Re-read on 11 September 2026; the watcher reports this page unchanged, and its visible-text hash is identical to the copy read on 10 September. The Bayesian-detector training note, the Hugging Face Transformers pointer and the absence of the word uncertain were checked against the live text and stand. Flagged and re-read on 12 September 2026. Noise. The page's visible text hashed to d9ebd2cb4bb44f84 at 2,152 words on two hand fetches, the digest the watcher recorded. What moved is two counters the page prints exactly: 'Pull requests 6' where it printed 5, because pull request #50 was opened at 21:17 UTC on 11 September, and 'Fork 103' where it printed 104. Issues are still 13, watchers still 27, and the API's open_issues_count of 19 matches 13 issues plus 6 pull requests. Stars are 1101, which the page still prints rounded as 'Star 1.1k'. The README was fetched raw from main and read in full — 12,558 characters, sha256 prefix 5fd70fde4e99dcf0, identical to the 2, 9 and 10 September records — the last commit on main is still 13 June 2025, and the release list still ends at 0.2.1 of 14 November 2024. All six claims above stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in the README, that the Bayesian detector must be trained again for each unique watermarking key, and that the repository points to the Hugging Face Transformers implementation as the production-ready one. An open pull request is not a change to what the repository states. Flagged and re-read on 15 September 2026. Noise. Two hand fetches both hashed to 79029a7bb392cd3f at 2,152 words, the watcher's digest. What moved is two counters the page prints exactly: 'Issues 14' where it printed 13, because issue #51 ('CSOAI — SynthID AI governance watermarking') was opened at 04:10 UTC on 15 September, and 'Fork 104' where it printed 103. Pull requests are still 6, watchers still 27, and the API's open_issues_count of 20 matches 14 issues plus 6 pull requests. Stars are 1106, which the page still prints rounded as 'Star 1.1k'. The README was fetched raw from main and read in full — 12,558 characters, sha256 prefix 5fd70fde4e99dcf0, identical to the 2, 9, 10 and 12 September records — the README's last commit is still 13 December 2024 (25a25de), the newest commit to any path is still 13 June 2025 (addb4a1), and the release list still ends at 0.2.1 of 14 November 2024. All six claims above stand, including that the words uncertain, inconclusive and ambiguous appear nowhere in the README, that the Bayesian detector must be trained for each unique watermarking key, and that the repository points to the Hugging Face Transformers implementation as the production-ready one. An opened issue is not a change to what the repository states. Flagged again on 18 September 2026 and re-read end to end. Noise. Two hand fetches both hashed to 75e839f354c65d49 at 2,139 words, the watcher's new digest. What moved is two counters the page prints exactly: 'Issues 13' where it printed 14 on 15 September, because issue #51 ('CSOAI — SynthID AI governance watermarking'), which opened that day, now returns 404 from the API and has been removed; and 'Fork 105' where it printed 104. Pull requests are still 6, watchers still 27, stars 1,110 (still printed as 'Star 1.1k'), and the API's open_issues_count of 19 matches 13 issues plus 6 pull requests. The README was fetched raw from main and read in full — 12,558 characters, sha256 prefix 5fd70fde4e99dcf0, identical to every record since 2 September — the newest commit to any path is still 13 June 2025 (addb4a1), and the release list still ends at 0.2.1 of 14 November 2024. All six claims above stand. A removed issue is not a change to what the repository states."
  },
  "techcrunch-anthropic": {
    "n": 5,
    "url": "https://techcrunch.com/2026/08/11/anthropic-says-it-will-watermark-text-generated-by-its-ai-models/",
    "title": "Anthropic says it will watermark text generated by its AI models",
    "publisher": "TechCrunch",
    "date": "2026-08-11",
    "fetched": "2026-09-20",
    "primary": false,
    "claims": [
      "Reports Anthropic will watermark model-generated text to comply with the EU AI Act transparency code, in effect from 2 August 2026.",
      "Reports the surfaces covered are the Claude platform API, Claude, Claude Code, Claude Cowork and Claude Tag.",
      "Reports Black Forest Labs, Google, Meta, Microsoft, OpenAI and Synthesia have committed to adhering to the EU code.",
      "Notes it is unclear how much editing is needed to remove a watermark, and that the reporter asked Anthropic to clarify."
    ],
    "notes": "Re-read end to end on 12 August 2026. This file previously recorded a claim that the article reports coverage of Claude via AWS, Google Cloud and Microsoft Foundry. It does not. Searched the body for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure: none appear, and the single occurrence of Microsoft is in the list of companies committing to the EU code. The claim and the two site passages resting on it were removed on 12 August 2026. Re-read again on 13 August 2026 after a second watcher flag; that flag was noise, from the rotating 'Most Popular' sidebar, and the body still matches the claims above. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated with the same result. Note that the conclusion drawn from this on 12 August — that no source we hold covers the resellers — was wrong, but not because of anything in this article: Anthropic's own help article carries a 'Cloud partners' bullet that the 12 August review missed. See the notes under anthropic-help. Flagged a third time on 15 August 2026 and re-read; noise again, from the rotating 'Most Popular' sidebar. The body is unchanged and still supports the claims above. Flagged a fourth time on 16 August 2026 and re-read; noise again from the same sidebar, which now lists a second TechCrunch piece, about users unhappy that the watermarks will reveal their use of Claude. That is a sidebar link on this page, not a change to this article, and it has not been read or cited here. The body is unchanged and still supports the claims above. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a third time: the only hits are inside the site's own navigation mega-menu, plus the single Microsoft in the body's list of companies committing to the EU code. Flagged a fifth time on 17 August 2026 and re-read; noise again from the same rotating 'Most Popular' sidebar, which by now also lists items on an Apple spyware notification, a Windows zero-day, Made by Google '26, Phia and a Delta in-flight Wi-Fi incident. The body was read in full and still supports all four claims above sentence by sentence, from the opening line about complying with European regulations to the closing list of companies committing to the EU code, and the page carries no editor's note, correction or update timestamp. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a fourth time with the same result: the only Microsoft in the body is in that closing list. Flagged a sixth time on 18 August 2026 and re-read. Noise again, and this time it can be shown rather than judged: the page's visible text was diffed word by word against the Internet Archive snapshot of 17 August 20:26 UTC, and the article body does not appear in the diff at all. Every difference is furniture — a 'Flash Sale' Disrupt ticket promo bar inserted at the top of the page, and three rotations in the 'Most Popular' sidebar, which gained an Instagram wordmark item and a Made by Google '26 item and lost the Delta in-flight Wi-Fi item and the self-link to this article. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and there is still no editor's note, correction or update line. All four claims above still stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a fifth time: Amazon appears only as a topic in the navigation mega-menu, and the only Microsoft in the body is still the one in that closing list. Flagged a seventh time on 19 August 2026 and re-read. Noise, shown rather than judged again: the page's visible text was diffed word by word against the Internet Archive snapshot of 18 August 19:59 UTC, and the article body does not appear in the diff at all. Every difference is the 'Most Popular' sidebar, which gained two Anthropic items — one headlined that Anthropic shares more details about how Claude's new watermarks will work, one about Anthropic setting AI agents loose on the same task — and lost the Windows zero-day and Made by Google '26 items. The Disrupt promo bar at the top is still there. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and there is still no editor's note, correction or update line. All four claims above still stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a sixth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, Amazon appears only as a topic in the navigation mega-menu, and the only Microsoft in the body is still the one in the closing list. Note for the next reviewer that the new sidebar item about further watermark details is a link to a different TechCrunch article. It has not been read and is not cited here, and it is not needed: Anthropic published its own explainer on 14 August, which the site already cites as a primary source. See anthropic-watermark-explainer. Flagged an eighth time on 20 August 2026 and re-read. Noise, judged rather than shown this time: the Internet Archive was serving its 'Temporarily Offline' page to both its CDX and availability endpoints, so no snapshot could be diffed. The body was read in full and all four claims still stand sentence by sentence, from the opening line about complying with European regulations to the closing list of companies committing to the EU code. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and there is no editor's note, correction or update line anywhere on the page. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a seventh time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, Amazon appears only as a topic in the navigation mega-menu, and of the two occurrences of Microsoft one is that same mega-menu topic and the other is the one in the body's closing list. What moved is the 'Most Popular' sidebar, which today lists home batteries, Cursor and GitHub, Stripe and OpenRouter, the Anthropic watermark-details piece, desk gadgets, Apple's App Store cut and the Apple spyware notification; the Anthropic AI-agents item recorded yesterday has gone. The Disrupt promo bar is still at the top. Flagged a ninth time on 21 August 2026 and re-read. Noise, and shown rather than judged again: the Internet Archive was reachable today, and the page's visible text was diffed word by word against its snapshot of 18 August 17:25 UTC, which is the newest one the archive holds. The two copies are word-identical for their first 548 words — the whole of the article body, from the headline through the closing list of companies committing to the EU code, and on through Ivan Mehta's author bio — so the body does not appear in the diff at all. Every difference falls after the bio and is furniture of two kinds. The Disrupt promo bar's copy changed from 'Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $300 today!' to a countdown line, 'In less than 48 hours, your chance to save up to $300 on your tickets will end!'. And the 'Most Popular' sidebar rotated, today listing home batteries, Cursor and GitHub, Etched's valuation, the Relay shutdown, Stripe and OpenRouter, the Anthropic watermark-details piece and desk gadgets; the Apple spyware notification, the Windows zero-day, Made by Google '26, Phia and the 'Some Claude users are mad' item are all gone from it. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and there is no editor's note, correction or update line anywhere on the page. All four claims above still stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated an eighth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, Amazon appears only as a topic in the navigation mega-menu, and of the two occurrences of Microsoft one is that same mega-menu topic and the other is the one in the body's closing list. Flagged a tenth time on 22 August 2026 and re-read. Noise, and shown rather than judged: the page's visible text was diffed word by word against the Internet Archive snapshot of 18 August 17:25 UTC, still the newest one the archive holds. The two copies are word-identical for their first 548 words — the whole of the article body, from the headline through the closing list of companies committing to the EU code, and on through Ivan Mehta's author bio — so the body does not appear in the diff at all. Every difference falls after the bio and is furniture of the usual two kinds. The Disrupt promotion changed: the page now carries a 'Flash Sale' bar at the top offering $100 off a Disrupt 2026 ticket as well as the countdown line recorded yesterday, 'In less than 48 hours, your chance to save up to $300 on your tickets will end!'. And the 'Most Popular' sidebar rotated, today listing a model being trained on living skin, Tesla's solar roof, an Oura lawsuit, home batteries, Cursor and GitHub, Etched's valuation and Stripe's reported acquisition of OpenRouter; the Relay shutdown, the desk-gadgets item and the Anthropic watermark-details piece have all gone from it. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and there is no editor's note, correction or update line anywhere on the page. All four claims above still stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a ninth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, Amazon appears only as a topic in the navigation mega-menu, and of the two occurrences of Microsoft one is that same mega-menu topic and the other is the one in the body's closing list. Flagged an eleventh time on 23 August 2026 and re-read. The flag came from the second of the day's two watcher runs: the overnight run found this page unchanged at b8569727b946a5aa, and the re-run a few hours later recorded a3016f20f1e21b17. Noise, and shown rather than judged: the page's visible text was diffed word by word against the Internet Archive snapshot of 18 August 17:25 UTC, still the newest one the archive holds. The two copies are word-identical for their first 548 words — the whole of the article body, from the headline through the closing list of companies committing to the EU code, and on through Ivan Mehta's author bio — so the body does not appear in the diff at all. Every difference falls after the bio and is furniture of the usual two kinds. The 'Most Popular' sidebar rotated, today listing Michael Polansky training a model on skin that is still alive, Rillet's $100M raise, Tesla's solar roof, the Oura lawsuit, home batteries, Cursor and GitHub, and Stripe's reported acquisition of OpenRouter; the Apple spyware notification, the Instagram wordmark item, the 'Some Claude users are mad' item, the Windows zero-day, Made by Google '26 and Phia have all gone from it. And the Disrupt promotion's body copy changed from 'Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $300 today!' to the countdown line 'In less than 48 hours, your chance to save up to $300 on your tickets will end!'. One correction to the record, which touches nothing on the site: the 22 August note recorded the 'Flash Sale' bar offering $100 off a Disrupt 2026 ticket as having appeared that day, but it is in the 18 August 17:25 snapshot word for word and in the same position, inside the 548 identical words rather than in today's diff, so it was already there on 18 August. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and there is no editor's note, correction or update line anywhere on the page — the only two occurrences of 'update' are both in the body as published, 'an updated support page' and 'will update the story if we hear back'. All four claims above still stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a tenth time: Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, the only match for AWS is the one inside the word 'lawsuit' in a sidebar headline, Amazon appears only as a topic in the navigation mega-menu, and of the two occurrences of Microsoft one is that same mega-menu topic and the other is the one in the body's closing list. Flagged a twelfth time on 24 August 2026 and a thirteenth on 25 August 2026 — the 24 August proposal was left unreviewed that day, and both flags were resolved together by today's read. Noise, and shown rather than judged: the page's visible text was diffed word by word against the Internet Archive snapshot of 18 August 17:25 UTC, still the newest one the archive holds, and the article body does not appear in the diff at all — every hunk is the Disrupt promotion, the 'Most Popular' sidebar or the footer. The promo bar at the top now ends 'Back by popular demand: Save up to $300 on Disrupt' where it read 'Save $300 on your Disrupt 2026 ticket: REGISTER NOW.', the mid-page promotion carries the countdown line 'In less than 48 hours, your chance to save up to $300 on your tickets will end!' in place of the 'Scale faster. Grow your portfolio.' copy, the sidebar rotated — today listing Walmart's Flipkart, Inherent's research-replicating 'teammate', Michael Polansky training a model on living skin, Rillet's $100M raise, Tesla's solar roof, the Oura lawsuit and home batteries — and the footer's topic links swapped 'Made by Google', 'Phia', 'Blacksmith' and 'Pixel Tag' for 'OpenAI', 'Hugging Face', 'Flock' and 'Startup Battlefield'. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and the only two occurrences of 'update' anywhere on the page are the two in the body as published. All four claims above still stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated an eleventh time: Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, the only match for AWS is the one inside the word 'lawsuit' in a sidebar headline, Amazon appears only as a topic in the navigation mega-menu, and of the two occurrences of Microsoft one is that same mega-menu topic and the other is the one in the body's closing list. Flagged a fourteenth time on 26 August 2026 and re-read. Noise, and shown rather than judged: the page's visible text was diffed word by word against the Internet Archive snapshot of 18 August 17:25 UTC, still the newest one the archive holds, and the article body does not appear in the diff at all. It sits inside a single run of 514 words that is word-identical across the two copies, running from the mega-menu through the headline, the byline, all four claims above and the author bio, and every one of the twelve hunks falls outside it. The hunks are the Disrupt promotion at the top of the page, which now reads 'Back by popular demand: Save up to $300 on Disrupt' where it read 'Save $300 on your Disrupt 2026 ticket: REGISTER NOW.'; the mid-page Disrupt promotion, which swapped 'Scale faster. Grow your portfolio. Gain practical expertise.' for 'Don't miss out. The startup community will gather to answer a pivotal question: How do you build sustainably in the AI era?'; the 'Most Popular' sidebar, which today lists Walmart's Flipkart, Inherent's research-replicating 'teammate', Michael Polansky training a model on living skin, Rillet's $100M raise, Nvidia and the harness, Tesla's solar roof and the Oura lawsuit; and the footer's topic links, which swapped 'Made by Google', 'Phia', 'Blacksmith' and 'Pixel Tag' for 'OpenAI', 'Hugging Face', 'Flock' and 'Startup Battlefield'. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and the only two occurrences of 'update' anywhere on the page are the two in the body as published; there is no editor's note or correction. All four claims above still stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a twelfth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, Amazon appears only as a topic in the navigation mega-menu, and of the two occurrences of Microsoft one is that same mega-menu topic and the other is the one in the body's closing list. Note for the next reviewer that the sidebar item recorded earlier about Claude users unhappy that the watermarks will reveal their use of Claude has now rotated off the page. It was a link to a different TechCrunch article, was never read, and is not cited here. Flagged a fifteenth time on 29 August 2026 and re-read. No archive comparison was possible today. Six of the seven CDX queries for this URL timed out; the one that answered asked for snapshots from 20 August onwards and returned an empty list, which is consistent with the newest snapshot the archive holds still being the 18 August 17:25 UTC copy that earlier reviews diffed against, and by the end of the review the endpoint was serving the Internet Archive's own 'Temporarily Offline' page. No snapshot could be fetched, so this was a full read of the page itself rather than a diff. The body was read in full and still supports all four claims above sentence by sentence, from the opening line about complying with European regulations to the closing list of Black Forest Labs, Google, Meta, Microsoft, OpenAI and Synthesia committing to the EU code. The byline is still Ivan Mehta and the timestamp still 5:13 AM PDT on 11 August 2026; there is no editor's note or correction, and the only two occurrences of 'update' anywhere on the page are the two in the body as published, 'confirmed the watermarking in an updated support page' and 'will update the story if we hear back'. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a thirteenth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, Amazon appears only as a topic in the navigation mega-menu, and of the two occurrences of Microsoft one is that same mega-menu topic and the other is the one in the body's closing list. What has moved since 26 August is furniture: the mid-page Disrupt promotion now reads 'Don't miss out. The startup community will gather to answer a pivotal question: How do you build sustainably in the AI era?', the 'Most Popular' sidebar lists Nvidia closing in on a Hugging Face acquisition, the Fitbit founders' Luffu Link band, Hugging Face in talks to be acquired for $13B, the 'stealth model' Ox Alpha, Flock's CEO on surveillance backlash, Walmart's Flipkart and Inherent's research-replicating 'teammate', and the footer topic links now end OpenAI, Hugging Face, Flock and Startup Battlefield. Flagged again on 30 August 2026. The CDX endpoint answered on the third attempt after a timeout and a 503, and the 18 August 2026 snapshot (20260818195956) was fetched and diffed against today's copy: words 13 to 547 are identical, and that run covers the article body in full, from the opening line about complying with European regulations to the closing list of Black Forest Labs, Google, Meta, Microsoft, OpenAI and Synthesia. All eight hunks sit outside the body: the Disrupt 'Flash Sale' banner has gone from the top of the page, the mid-page Disrupt promotion has been rewritten, the 'Most Popular' sidebar has turned over, and the footer topic links have changed. Against yesterday's record the only movement is in that sidebar, which now opens with Hugging Face's $399 open-source Microduck robot and adds Instinct's $350M raise at a $2.5B valuation and Airbound's $37M, while Flock's CEO on surveillance backlash, Walmart's Flipkart and Inherent's research-replicating 'teammate' have dropped off; the Disrupt promotion and the footer links read the same today as they did on 29 August. All four claims above still stand sentence by sentence, including that the article notes it is unclear how much editing is needed to remove the watermark and adds 'We have asked Anthropic to clarify and will update the story if we hear back'. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a fourteenth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, Amazon appears only as a topic in the navigation mega-menu, and of the two occurrences of Microsoft one is that same mega-menu topic and the other is the one in the body's closing list. The byline is still Ivan Mehta and the timestamp still 5:13 AM PDT on 11 August 2026; there is no editor's note or correction, and the only two occurrences of 'update' anywhere on the page are the two in the body as published. The page's visible-text hash held steady at e093461e across three fetches during this review, the same value the watcher flagged. Flagged a seventeenth time on 31 August 2026 and re-read. Noise, and shown rather than judged. The CDX endpoint timed out on four attempts for this URL, but the replay endpoint answered on the second try, and the 18 August 2026 snapshot (20260818195956) — still the newest the archive holds — was fetched and diffed against today's copy. The two share a single word-identical run of 513 words, archive words 35 to 547 against today's words 13 to 525, and that run covers the article body in full: the navigation mega-menu, the headline, the byline, all four claims above, and Ivan Mehta's author bio through to 'View Bio'. All eight hunks sit outside it. The Disrupt 'Flash Sale' banner has gone from the top of the page, the mid-page Disrupt promotion has been rewritten to 'Don't miss out. The startup community will gather to answer a pivotal question: How do you build sustainably in the AI era?', the 'Most Popular' sidebar has turned over, and the footer topic links now end OpenAI, Hugging Face, Flock and Startup Battlefield. Against yesterday's record the only movement is in that sidebar, which today opens with 'Nvidia's AI advantage is moving beyond the GPU' and 'OpenAI, Anthropic, Google, and 100 other companies call for action to defend against rogue AI', with Hugging Face's $399 Microduck robot, Nvidia closing in on a Hugging Face acquisition, Instinct's $350M raise, the Fitbit founders' Luffu Link and Airbound's $37M all held over from 30 August; the Disrupt promotion and the footer links read the same today as they did on 29 and 30 August. All four claims above still stand sentence by sentence, including that the article notes it is unclear how much editing is needed to remove the watermark and adds 'We have asked Anthropic to clarify and will update the story if we hear back'. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a fifteenth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, Amazon appears only as a topic in the navigation mega-menu, and of the two occurrences of Microsoft one is that same mega-menu topic and the other is the one in the body's closing list. The byline is still Ivan Mehta and the timestamp still 5:13 AM PDT on 11 August 2026; there is no editor's note or correction, and the only two occurrences of 'update' anywhere on the page are the two in the body as published. Note for the next reviewer that the new sidebar item about a hundred companies calling for action against rogue AI is a link to a different TechCrunch article. It has not been read and is not cited here, and its subject is AI safety rather than watermarking, provenance or detection. Flagged again on 1 September 2026 and re-read end to end. Noise: the diff is the 'Most Popular' rail, and no archive diff was run today because the CDX endpoint timed out on every attempt, so the comparison is against the list this file recorded on 31 August. The rail now opens with Microsoft testing a fix for the latest hours-long Outlook outage, MapQuest's app going to No. 1 in Navigation after refusing to rename Lake Ontario, and Musk's faster path to more gas turbines, with Nvidia's AI advantage moving beyond the GPU, Hugging Face's $399 Microduck robot, Nvidia closing in on a Hugging Face acquisition and Instinct's $350M raise held over from 31 August; the rogue-AI item about a hundred companies, the Fitbit founders' Luffu Link and Airbound's $37M have dropped off. All four claims above still stand sentence by sentence, including that the article notes it is unclear how much editing is needed to remove the watermark and adds 'We have asked Anthropic to clarify and will update the story if we hear back'. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a sixteenth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, and Amazon appears only as a topic in the navigation mega-menu. Microsoft now appears three times rather than the two recorded before, and the third is the new Outlook item in 'Most Popular'; the other two are the same mega-menu topic and the same occurrence in the body's closing list. The byline is still Ivan Mehta and the timestamp still 5:13 AM PDT on 11 August 2026; there is no editor's note or correction, and the only two occurrences of 'update' anywhere on the page are the two in the body as published. For the next reviewer, the run from the headline through Ivan Mehta's author bio to 'View Bio', which carries all four claims above, is 415 words today. Flagged again on 2 September 2026 and re-read end to end. Noise, and the same rail as every other flag on this source. Two fetches today both hashed to c2aac99050fc7039, so the page is stable, but what moved is the 'Most Popular' rail: it gains Apple's 'shocking evidence' against a former employee accused of stealing data for OpenAI, which now sits at the top, and drops Nvidia's AI advantage moving beyond the GPU. The other six items are the ones recorded on 1 September, in the same order. The article itself is untouched. The byline is still Ivan Mehta and the timestamp still 5:13 AM PDT on 11 August 2026; the run from the headline through the author bio to 'View Bio' is 415 words, exactly the count recorded on 1 September; there is no editor's note and no correction, and the only two occurrences of 'update' anywhere on the page are the two in the body as published. All four claims above still stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated a seventeenth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, and Amazon appears only as a topic in the navigation mega-menu. Worth recording against this source specifically: Anthropic moved its detection API to private preview on 1 September 2026 and TechCrunch has not updated this article to say so, which is the ordinary reason REVIEW.md treats news reporting as secondary. Flagged on 3 and 4 September 2026 and re-read end to end on 4 September. Noise again, from the rotating 'Most Popular' sidebar, which today lists items on Norwegian camera glasses, Uber layoffs, AfterQuery, GoPro, an Apple court filing, an Outlook outage and MapQuest. The body is unchanged and still supports all four claims above sentence by sentence, and the byline is still 11 August 2026, 5:13 AM PDT. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated for the sixth time: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, the single Amazon hit is in the site's navigation, and of the three Microsoft hits the only one in the body is in the list of companies committing to the EU code. Flagged again on 5 September 2026 and re-read end to end. Noise, shown rather than judged. The page's visible text hashes to 58e0058e87c8aeed, exactly the watcher's new digest, and was diffed word by word against the Internet Archive snapshot of 18 August 19:56 UTC, which is still the newest one the archive holds of this article. The article body sits inside a single 514-word span that is identical across the two copies, and does not appear in the diff at all. Every difference is furniture: the Disrupt promo bar at the top changed its wording, the 'Most Popular' sidebar rotated wholesale to Tesla Cybercab, Uber layoffs, AfterQuery, Outlook and MapQuest items — dropping, among others, the second Anthropic watermark item recorded on 19 August — and the topic tag strip at the foot changed. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and there is no editor's note, correction or update line anywhere on the page. All four claims above stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated: none appears in the body, and of the two occurrences of Microsoft one is the navigation mega-menu topic and the other is the closing list of companies committing to the EU code. Flagged again on 7 September 2026 and re-read end to end. Noise, shown rather than judged. The page's visible text hashes to cd6549fc9671e85d, exactly the watcher's new digest, and was diffed word by word against the Internet Archive snapshot of 18 August 19:59 UTC, which is still the newest one the archive holds of this article. The article body sits inside a single 514-word span that is identical across the two copies, running from the site navigation through the closing topic tags and the author bio, and does not appear in the diff at all. Every difference is furniture: the Disrupt promo bar at the top changed from a flash-sale countdown to a stage line-up, the 'Most Popular' sidebar rotated wholesale to Gemini hikers, the Tesla Cybercab investigation, Cybercab fleets, OpenAI Astra, Norway wearables, Uber layoffs and AfterQuery items — dropping, among others, the 'Some Claude users are mad that Anthropic's new watermarks will catch them' item recorded on 5 September — and the trending link strip in the footer changed. The byline is still Ivan Mehta, the timestamp still 5:13 AM PDT on 11 August 2026, and there is no editor's note, correction or update line anywhere on the page. All four claims above stand sentence by sentence. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated: AWS, Bedrock, Google Cloud, Vertex, Foundry and Azure return nothing anywhere on the page, the single Amazon hit is in the navigation, and of the two Microsoft hits one is the navigation mega-menu topic and the other is the closing list of companies committing to the EU code. Flagged again on 9 September 2026 and re-read end to end. Noise. The article body is word-identical to the Internet Archive's snapshot of 18 August 19:59 UTC, the newest it holds: the word-by-word diff against it contains a single 514-word equal run covering the whole story, from the byline through the closing paragraph naming the other signatories to the topic tags, and every difference sits in the promotional banner at the top of the page, the Disrupt event card, the 'Most Popular' list and the footer link row. All four claims above stand, and the byline is still Ivan Mehta, 5:13 AM PDT, 11 August 2026. One thing is recorded for the next reviewer, because it changes what a flag from this source is worth. This page's visible text is not stable between requests: the first fetch of this review hashed to 0e6bf2725ca28830 at 713 words and three further fetches all hashed to e335b2e1119607ef at 714 words, which is the watcher's own new digest, and the only difference between them was the composition of the 'Most Popular' list. A single moved hash here therefore does not establish that anything on the page was edited, and the same holds for decoder-anthropic, which behaved the same way today. Flagged again on 10 September 2026 and re-read end to end. Noise. The Internet Archive's newest snapshot of this page is still the one of 18 August 19:59 UTC. Diffed word by word against it, the article body is a single 514-word equal run covering the whole story, from the byline through the closing paragraph naming the other signatories to the topic tags, and every difference sits in the promotional banner at the top of the page, the Disrupt event card below the byline block, the 'Most Popular' list and the footer link row. All four claims above stand, and the byline is still Ivan Mehta, 5:13 AM PDT, 11 August 2026. One thing is recorded because it qualifies the note of 9 September, which found this page's visible text unstable between requests. It was stable today: four fetches during this review all hashed to 15ec4d7430e92455 at 713 words, which is the watcher's own new digest. So today's flag does record a real change to the page since 9 September, rather than a per-request flake — but the change is in the furniture, not the story. Flagged again on 11 September 2026 and re-read end to end. Noise. The Internet Archive holds no copy of the watcher's old baseline; its newest snapshot is 7 September 13:03 UTC, hashing to cd6549fc9671e85d at 714 words. Diffed word by word against it, the article body is a single 580-word equal run covering the whole story, from the headline through the closing paragraph naming the other signatories to the 'REGISTER NOW' event card, and the only difference on the page is the 'Most Popular' list below it, which rotated in full. All four claims above stand. Four fetches during this review all hashed to 5b4a1a6f27191792 at 718 words, the watcher's new digest, so the page was stable between requests today and the flag records a real change to that list rather than a flake. Flagged and re-read end to end on 12 September 2026. Noise. The Internet Archive snapshot of 11 September 09:24 UTC hashes to 5b4a1a6f27191792 at 718 words, exactly the digest the watcher had on file, so it is a faithful copy of yesterday's page. Diffed word by word against it, the article body is a single 553-word equal run from the headline through the closing paragraph naming the other signatories, and the only differences on the page are the Disrupt event card below the byline, which now reads 'Last day to book an exhibit table is September 18 … BOOK NOW' where it read 'REGISTER NOW', and the 'Most Popular' list, which gained one entry and lost another. All four claims above stand. Two hand fetches during this review both hashed to 55ead7467013ae89 at 723 words, the watcher's new digest, so the page was stable between requests. Flagged again on 15 September 2026 and re-read end to end. Noise, from the 'Most Popular' list below the article, which today leads with a Revolut data breach, OpenAI Pro subscriptions on hold and an IDScan breach, none of which the 12 September copy carried. No archive copy could be compared today, because the Internet Archive answered 'Temporarily Offline' and 429 throughout this review. Two hand fetches both hashed to 590be81e62c8cc70 at 724 words, the watcher's new digest, so the page was stable between requests. The article's own dateModified is still 2026-08-11T15:35:45+00:00, and the Disrupt card below the byline still reads 'Last day to book an exhibit table is September 18 … BOOK NOW' as it did on 12 September. The body was read in full, from the headline through the closing paragraph naming the other signatories, and all four claims above stand: the EU transparency code in effect from 2 August, the five surfaces named, the six other companies committed to the code, and the reporter's note that it is unclear how much editing removes the watermark. The searches for AWS, Amazon, Bedrock, Google Cloud, Vertex, Foundry and Azure were repeated with the same result as before: the only hits are the site's own navigation and the single Microsoft in the body's list of signatories. Flagged again on 18 September 2026 and re-read end to end. Noise. The per-request instability recurred: the watcher recorded c0489379d99a1805, and two hand fetches during this review both hashed to 67a0f19022972fd7 at 741 words, against 724 on 15 September. The article's own dateModified is still 2026-08-11T15:35:45+00:00. The growth is a new promotional bar at the top of every page — 'Disrupt 2026: OpenAI, Anthropic, Replit, and more take over 6 industry stages. 25% off tickets now' and 'Back by popular demand: Save up to $300 on Disrupt' — plus the 'Most Popular' list, which today leads with a Fluxnium nuclear-fuel item and no longer carries the OpenAI Pro or IDScan entries of 15 September; the Disrupt card below the byline still reads 'Last day to book an exhibit table is September 18 … BOOK NOW'. The body was read in full, from the headline through the closing paragraph naming the other signatories, and all four claims above stand: the EU transparency code in effect from 2 August, the five surfaces named, the six other companies committed to the code, and the reporter's note that it is unclear how much editing removes the watermark. Flagged again on 20 September 2026 and re-read end to end. Noise. Two hand fetches both reproduced the watcher's new digest 1615be0ff2432f8a at 745 words, so the change is real and not a per-request flake. No archive copy of the watcher's 18 September baseline exists — the Internet Archive's newest snapshot of this page is 14 September 23:11 UTC — so the diff was run against that instead, and it covers the wider window rather than a single day. Today's page differs from it in six places, and every one of them is in the list of other TechCrunch headlines that runs beside and below the article: the whole set rotated, losing a Revolut data breach, an IDScan breach, an Automattic story and an Apple foldable, and gaining a Cornelis funding round, a Microsoft AI-scraping filing and a Salesforce and Nvidia reasoning model. The article body appears in no hunk. A list of other links is the noise pattern REVIEW.md names. All four claims above were checked against the live text and stand: the EU AI Act transparency code in effect from 2 August 2026, the surfaces list (Claude platform API, Claude, Claude Code, Claude Cowork and Claude Tag), the other signatories including Black Forest Labs, Google, Meta, Microsoft, OpenAI and Synthesia, and the reporter's open question about how much editing removes a watermark."
  },
  "decoder-anthropic": {
    "n": 6,
    "url": "https://the-decoder.com/anthropic-watermarks-all-claude-outputs-globally-with-marks-that-may-persist-through-some-editing/",
    "title": "Anthropic watermarks all Claude outputs globally",
    "publisher": "The Decoder",
    "date": "2026-08-11",
    "fetched": "2026-09-20",
    "primary": false,
    "claims": [
      "Reports marks may not survive heavy editing, translation, format conversion or a screenshot; the format-conversion and screenshot point is made about stripped metadata.",
      "Reports a detected watermark does not establish that Claude wrote the content, because people use it to proofread, translate and summarise human work."
    ],
    "notes": "Re-read end to end on 12 August 2026 after the watcher flagged a content change. This file previously recorded a claim that the article reports the mark identifies only that Claude generated the content and not the individual user. The article does not say that. Searched the body for individual, identifies, who, anonymous, person, account, customer, prompted and privacy: the question of tracing a mark to a specific person or account is not addressed anywhere. The claim and the two site passages resting on it were removed on 12 August 2026. No source we hold addresses user identification either way, so the site now says nothing about it. Re-read again on 13 August 2026 after a second watcher flag. That flag was noise: this page changed twice within five hours, which is the rotating 'Top Stories' and 'Most Popular' blocks in the page text, and the body still supports the claims above. The body does also carry a sentence that text watermarks should work through AWS, Google Cloud and Microsoft Foundry. Whether that sentence is new is unresolved — the Internet Archive holds no snapshot of this article — but it does not matter here, because Anthropic states the same thing directly and the site cites the primary source for it. Flagged twice more and re-read on 15 August 2026; noise again from the same rotating blocks, and the body still supports the claims above. The article does mention SynthID, but only in a closing section about Google DeepMind's own system, not about Claude's — do not read it as this article reporting the scheme Anthropic uses. Anthropic itself said that on 14 August; see anthropic-watermark-explainer. Flagged again on 16 August 2026 and re-read; noise again from the same rotating 'Top Stories' and 'Most Popular' blocks, and the body still supports the two claims above. The searches for individual, identifies, anonymous, person, account and customer were repeated and still return nothing in the body — the only hits anywhere on the page are 'prompted' in the image credit and 'privacy' in the footer links — so this article still says nothing about tracing a mark to a specific person, and neither does the site on its authority. Flagged again on 17 August 2026 and re-read. Noise again: the same rotating blocks ('Top Stories', 'Don't Miss What Matters', 'Most Popular', 'AI Community & Insights'), the byline still Matthias Bastian and the date still 11 August 2026 with no 'updated' line and no appended update paragraph, and both claims above still stand. Two things to record for the next reviewer. First, this particular read was a targeted question-and-answer pass over the fetched page rather than a verbatim transcript of it, because the fetch tool declined to reproduce the body at length; each claim above was checked individually, as were the questions of user identification, whether a detector exists, and whether any date has been given. Second, the closing analysis section carries sentences about OpenAI holding an unreleased text detector and about third-party detectors possibly adding support for Anthropic's watermark. Neither had been recorded in this file before, and whether they are new could not be settled: the Internet Archive was returning 503 to both its availability and CDX endpoints on 17 August, so no snapshot could be compared. Nothing on the site turns on it — neither sentence is cited, and neither says a public detector for Anthropic's watermark exists. On that question the article still says only that Anthropic plans to release verification tools and has not said when. Flagged again on 18 August 2026 and re-read. Noise again, and the limitation recorded above is now lifted: the page was fetched directly and its visible text read in full, rather than through a question-and-answer pass, so this read is against the article's own words. The byline is still Matthias Bastian, the date still 11 August 2026, with no 'updated' line and no appended update paragraph. Both claims above still stand. The limitations section still gives, as reasons a mark may be absent, a model that shipped before watermarking, text that was heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot'; the sentence before it still says a detected watermark does not mean Claude wrote the content, because people use Claude for proofreading, translating and summarising. The searches for individual, identifies, anonymous, person, account and customer were repeated and return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit and 'Privacy Policy' and 'Privacy Manager' in the footer, so this article still says nothing about tracing a mark to a specific person, and neither does the site on its authority. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. The two closing-analysis sentences flagged as unresolved on 17 August — OpenAI sitting on an unreleased text detector, and third-party detectors possibly adding support for Anthropic's watermark — are both still present and still uncited here, and whether they were ever added remains unresolved, because the Internet Archive still holds no snapshot of this article to compare against. What moved the hash today is the usual rotating blocks; for whoever reads this next, today's 'Top Stories' were the items on reverse-engineering LLM prompts from output text, AI-generated books on Amazon, Fable 5 adoption, Nvidia's OpenAI bet and automated AI research. Flagged twice on 19 August 2026 — once overnight and once when the watcher was re-run a few hours later, which is itself the signature of the rotating blocks — and re-read. Noise, and the two questions earlier reviews had to leave open are now closed, because the Internet Archive has acquired snapshots of this article since. It held none on 18 August; it now holds four, from 12 August 11:36 and 13 August 21:54 UTC. The page's visible text was diffed word by word against both. Against 13 August the article body is word-identical. Against 12 August, a day after publication, the body is word-identical apart from two ad-slot placeholder strings ('DEC_D_Incontent-1' and 'DEC_D_Incontent-2') that the archived copy captured where the rendered page shows an ad. Every other difference on the page is the usual rotating 'Top Stories' and 'Most Popular' blocks. So, first: the sentence that text watermarks 'should also work through cloud partners such as AWS, Google Cloud, and Microsoft Foundry, though those platforms may not support signed metadata' was present on 12 August and is not a later addition — that is the question left open on 13 August, and it is now answered. Second: the two closing-analysis sentences flagged as unresolved on 17 August, that OpenAI has been sitting on an unreleased text detector for about two years and that third-party detectors could add support for Anthropic's watermark, were both present on 12 August as well, so neither was added since. Nothing on the site turns on either, and neither is cited, but the pair no longer needs to be carried as unresolved. Both claims above still stand: the limitations passage still gives a pre-watermarking model, heavy editing or translation, too short a passage, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and still says a detected watermark does not mean Claude wrote the content because people use it for proofreading, translating and summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line and no appended update paragraph. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit and 'Privacy Policy' and 'Privacy Manager' in the footer, so this article still says nothing about tracing a mark to a specific person. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. Flagged again on 20 August 2026 and re-read. Noise. The Internet Archive was offline to both its CDX and availability endpoints today, so the word-by-word diffs that closed the two open questions on 19 August could not be repeated — but nothing needed reopening, and both claims above still stand against the live text. The limitations passage still gives a model that shipped before watermarking, text heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and the sentence before it still says a detected watermark does not mean Claude wrote the content because people use it for proofreading, translating or summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line and no appended update paragraph. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit and 'Privacy Policy' and 'Privacy Manager' in the footer. On detection it still says only that Anthropic plans to release verification tools and has not said when. What moved is the usual rotating blocks; today's 'Top Stories' were the items on models not being allowed to reflect on themselves, automated AI research, AI-generated books on Amazon, Fable 5 adoption and Nvidia's OpenAI bet. Flagged again on 21 August 2026 and re-read. Noise, and shown rather than judged: the Internet Archive was reachable today, so the word-by-word diff that could not be run on 20 August was run again, against the snapshot of 13 August 21:54 UTC — still the newest of the four the archive holds. The two copies are word-identical for their first 932 words, which is the whole of the article body and then some: the headline, the key-points list, the body through the limitations passage and the closing analysis, and on through the subscription pitch to the 'Source: Claude' line. The diff begins exactly at the 'Top Stories' block and everything in it is the usual rotating blocks; today's 'Top Stories' were Frontier Radar #4 on China having caught up, models not being allowed to reflect on themselves, AI-generated books flooding Amazon, a study contradicting Anthropic and OpenAI on autonomous AI research, and investor pressure on Nvidia's OpenAI bet. Both claims above therefore still stand against the article's own words: the limitations passage still gives a model that shipped before watermarking, text heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and the sentence before it still says a detected watermark doesn't mean Claude actually wrote the content because people use it for proofreading, translating or summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line and no appended update paragraph — the only two occurrences of 'updated' anywhere in the HTML are inside a comment-widget string table in a script, which the visible-text pass strips. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit ('GPT-Image-2 prompted by THE DECODER') and 'Privacy Policy' and 'Privacy Manager' in the footer. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. One further piece of evidence for the noise verdict, of the kind 19 August also recorded: when the watcher was re-run in dry-run mode a couple of hours after the overnight run, this was the only one of the thirteen watched pages whose hash had moved again in the interval. A page that changes twice in a morning while its body stays word-identical to a snapshot eight days old is changing in its furniture. Flagged again on 22 August 2026 and re-read. Noise, and shown rather than judged again: the page's visible text was diffed word by word against the archive's snapshot of 13 August 21:54 UTC, still the newest of the four it holds. The two copies are word-identical for their first 932 words, the same boundary as yesterday — the headline, the key-points list, the body through the limitations passage and the closing analysis, and on through the subscription pitch to the 'Source: Claude' line. The diff begins exactly at the 'Top Stories' block and everything in it is the usual rotating blocks; today's 'Top Stories' were Frontier Radar #4 on China having caught up, models not being allowed to reflect on themselves, Terence Tao on AI and a crisis in mathematics, investor pressure on Nvidia's OpenAI bet, and an item headlined that Anthropic watermarks Claude's output but critics question the tradeoffs. That last one is a link to a different Decoder article; it has not been read and is not cited here. Both claims above still stand against the article's own words: the limitations passage still gives a model that shipped before watermarking, text heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and the sentence before it still says a detected watermark doesn't mean Claude actually wrote the content because people use it for proofreading, translating or summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line and no appended update paragraph. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit ('GPT-Image-2 prompted by THE DECODER') and 'Privacy Policy' and 'Privacy Manager' in the footer. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. Flagged twice on 23 August 2026 — the overnight run recorded the hash moving from 18a30345d2003605 to 46264d3e6e73bf3c, and a re-run a few hours later recorded it moving on to 2e54ca81b0f83775, which is what the live page hashed to when it was read — and re-read. That signature is itself evidence, and it is the one 19 and 21 August also recorded: a page whose hash moves twice in a morning is moving in its furniture. Noise, and shown rather than judged: the page's visible text was diffed word by word against the archive's snapshot of 13 August 21:54 UTC, still the newest of the four it holds. The two copies are word-identical for their first 932 words, the same boundary as on 21 and 22 August — the headline, the key-points list, the body through the limitations passage and the closing analysis, and on through the subscription pitch to the 'Source: Claude' line. The diff begins exactly at the 'Top Stories' block and everything in it is the usual rotating blocks; today's 'Top Stories' were Frontier Radar #4 on China having caught up, models not being allowed to reflect on themselves, Terence Tao on AI and a crisis in mathematics, the item headlined that Anthropic watermarks Claude's output but critics question the tradeoffs, and Stripe declaring we are living in the singularity and using it as a reason not to IPO. Both claims above still stand against the article's own words: the limitations passage still gives a model that shipped before watermarking, text heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and the sentence before it still says a detected watermark doesn't mean Claude actually wrote the content because people use it for proofreading, translating or summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line and no appended update paragraph — the only occurrence of 'updated' anywhere in the HTML is inside a comment-widget string table in a script, which the visible-text pass strips. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit ('GPT-Image-2 prompted by THE DECODER') and 'Privacy Policy' and 'Privacy Manager' in the footer. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. Flagged on 24 August 2026 and again on 25 August 2026 — the hash moved from 2e54ca81b0f83775 to c223f903e81ee26b and then to 8bd0855db8ac9914; the 24 August proposal was left unreviewed that day, and both flags were resolved together by today's read. Noise, and shown rather than judged: the page's visible text was diffed word by word against the archive's snapshot of 13 August 21:54 UTC, still the newest of the four it holds. The two copies are word-identical for their first 932 words, the same boundary as on 21 to 23 August — the headline, the key-points list, the body through the limitations passage and the closing analysis, and on through the subscription pitch to the 'Source: Claude' line — and every hunk after it is the usual rotating blocks. Today's 'Top Stories' were Frontier Radar #4 on China having caught up, Stripe declaring we're living in the singularity and using it as a reason not to IPO, Sutton calling synthetic data a 'big mistake', world models that ignore human beliefs predicting the wrong actions, and a study explaining why AI agents benefit from 'skills' when they fail; further down, the OpenClaw item left the 'Most Popular' block and an item on Anthropic cutting 80 percent of Claude Code's system prompt arrived. Both claims above still stand against the article's own words: the limitations passage still gives a model that shipped before watermarking, text heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and the sentence before it still says a detected watermark doesn't mean Claude actually wrote the content because people use it for proofreading, translating or summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line anywhere in the visible text. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit and 'Privacy Policy' and 'Privacy Manager' in the footer. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. Flagged again on 26 August 2026 and re-read. Noise, and shown rather than judged: the page's visible text was diffed word by word against the archive's snapshot of 13 August 21:54 UTC, still the newest of the four it holds. The two copies are word-identical for their first 932 words, the same boundary as on 21 to 25 August - the headline, the key-points list, the body through the limitations passage and the closing analysis, and on through the subscription pitch to the 'Source: Claude' line - and all seven hunks fall after it, in the rotating blocks. Today's 'Top Stories' were Frontier Radar #4 on China having caught up, a study explaining why AI agents benefit from 'skills' and when they fail, Stripe declaring we're living in the singularity and using it as a reason not to IPO, Sutton calling synthetic data a 'big mistake', and world models that ignore human beliefs predicting the wrong actions; in 'Most Popular', the OpenClaw item left and an item on Anthropic cutting 80 percent of Claude Code's system prompt arrived. Both claims above still stand against the article's own words: the limitations passage still gives a model that shipped before watermarking, text heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and the sentence before it still says a detected watermark doesn't mean Claude actually wrote the content because people use it for proofreading, translating or summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line anywhere in the visible text. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit and 'Privacy Policy' and 'Privacy Manager' in the footer. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. Flagged again on 29 August 2026 and re-read. Noise, shown twice over. First, the page was fetched five times between 07:03 and 07:22 UTC - once by the watcher and four times during the review - and returned four different visible-text digests, the watcher's 5cd6c96ffe37185e among them and twice. Diffed against each other, the copies agree word for word for their first 976 words, which carry the headline, the key-points list, the body through the limitations passage and the closing analysis, and the only differences anywhere are headlines inside the rotating blocks: 'Ukraine opens its massive labeled battlefield dataset to British firms in a landmark AI weapons partnership' in one copy where another has 'AI chatbots regularly link pregnant users to anti-abortion websites without disclosure'. A page whose hash moves between two fetches ten minutes apart cannot have had its article edited in between. Second, the copy whose hash matches the watcher's was diffed word by word against the Internet Archive's snapshot of 13 August 21:54 UTC, still the newest of the four it holds - the archive's replay endpoint timed out on four attempts before the fifth returned it. The two copies are word-identical for their first 932 words, the same boundary as on every review since 21 August, and all eight hunks fall after it, in the rotating blocks: today's 'Top Stories' were a study explaining why AI agents benefit from 'skills' and when they fail, world models that ignore human beliefs predicting the wrong actions, AI shopping agents not being ready to buy on your behalf, Alibaba's Qwen3.8-Flash-Next, and OpenAI's rogue AI collective breaking out of sandboxes to fight a ghost; 'Most Popular' now carries, among others, Anthropic cutting 80 percent of Claude Code's system prompt and a Microsoft researcher building a neural network out of goats in Age of Empires II. Both claims above still stand against the article's own words: the limitations passage still gives a model that shipped before watermarking, text heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and the sentence before it still says a detected watermark doesn't mean Claude actually wrote the content because people use it for proofreading, translating or summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line anywhere in the visible text. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit and 'Privacy Policy' and 'Privacy Manager' in the footer. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. Flagged again on 30 August 2026. The CDX endpoint answered on the third attempt after two 503s, and the 13 August 2026 snapshot (20260813215438) was fetched and diffed against today's copy: the two are word-identical for their first 932 words, the same boundary as on every review since 21 August, and all five hunks fall after it, in the rotating blocks below the article. Today's 'Top Stories' were AI shopping agents not being ready to buy on your behalf, Alibaba's Qwen3.8-Flash-Next, OpenAI's rogue AI collective breaking out of sandboxes to fight a ghost, Ukraine opening its labelled battlefield dataset to British firms, and AI benchmarks having a trust problem Google wants to fix; against yesterday's record the first three are held over, and the study on when agents benefit from 'skills' and the world-models item have dropped off. 'Most Popular' still carries Anthropic cutting 80 percent of Claude Code's system prompt and the Microsoft researcher's neural network built out of goats in Age of Empires II. The page's visible-text hash moved twice more during this review alone, from 9aeee71c at the watcher's 09:01 fetch to af23af24 and then 3bc4d510, which is those blocks and nothing else. Both claims above still stand against the article's own words: the limitations passage still gives a model that shipped before watermarking, text heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and the sentence before it still says a detected watermark doesn't mean Claude actually wrote the content because people use it for proofreading, translating or summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line anywhere in the visible text. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit and 'Privacy Policy' and 'Privacy Manager' in the footer. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. Flagged twice on 31 August 2026 — the overnight run recorded the hash moving from 9aeee71cfd82c092 to af23af24340b6dd9, and a re-run at the start of this review recorded it moving on to 3bc4d510fc8b32b3. Noise, shown three ways over. First, the page was fetched seven times between the watcher's run and the end of this review and returned five distinct visible-text digests: af23af24340b6dd9, 3bc4d510fc8b32b3, 41e7e0a2778bbb98, a8d545a80ab8c518 three times, and 87f8bfef1a0f1e0b. Second, two of those copies, taken a little over a minute apart, were diffed word by word against each other: they agree exactly for their first 951 words, which carry the headline, the key-points list, the body through the limitations passage and the closing analysis, and every difference between them is a headline inside the rotating blocks below — one copy carries 'Ukraine opens its massive labeled battlefield dataset to British firms' and 'AI benchmarks have a trust problem and Google wants to fix it' where the other carries the Sam Altman AGI item and the rogue-AI-collective item. A page whose hash moves between two fetches a minute apart cannot have had its article edited in between. Third, the copy hashing to a8d545a80ab8c518 was diffed word by word against the Internet Archive's snapshot of 13 August 21:54 UTC, still the newest of the four it holds; the replay endpoint answered on the second attempt. The two are word-identical for their first 932 words, the same boundary as on every review since 21 August, running from the headline through the key-points list, the body, the limitations passage and the closing analysis, the subscription pitch and the 'Source: Claude' line, and all six hunks fall after it, in the rotating blocks. Today's 'Top Stories' were Alibaba's Qwen3.8-Flash-Next, AI shopping agents not being ready to buy on your behalf, AI chatbots regularly linking pregnant users to anti-abortion websites, Sam Altman saying OpenAI will have AGI by the end of 2026 if you accept his definition, and OpenAI's rogue AI collective breaking out of sandboxes to fight a ghost; 'Most Popular' still carries Anthropic cutting 80 percent of Claude Code's system prompt and the Microsoft researcher's neural network built out of goats in Age of Empires II. One thing recorded because it strengthens the verdict: the first two of today's digests, af23af24340b6dd9 and 3bc4d510fc8b32b3, are exactly the two the 30 August review recorded from its own refetches, so this page is cycling through a repeating set of arrangements of the same furniture rather than being edited. Both claims above still stand against the article's own words: the limitations passage still gives a model that shipped before watermarking, text heavily edited or translated, a passage too short for reliable detection, and metadata 'stripped through format conversion or a screenshot' as reasons a mark may be absent, and the sentence before it still says a detected watermark doesn't mean Claude actually wrote the content because people use it for proofreading, translating or summarizing. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line anywhere in the visible text. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, and the only hits for the remaining two terms are 'prompted' in the image credit and 'Privacy Policy' and 'Privacy Manager' in the footer. On detection it still says only that Anthropic 'plans to release verification tools so users and third parties can check the labels, though it hasn't said when'. Flagged again on 1 September 2026 and re-read end to end. Noise, and the page again does not hash stably: three fetches a few seconds apart returned 8752ed13668525fb, c412ac45dde66998 and 53e336f4ed76e772, the last of which is the watcher's new digest, so part of the flagged move is per-request variation rather than an edit. Diffed word by word against each other, the three copies agree exactly for their first 932 words, the same boundary as on every review since 21 August, running from the headline through the key-points list, the body, the limitations passage and the closing analysis, and every difference between them falls after it, inside 'Top Stories'. Today that block carries Alibaba's Qwen3.8-Flash-Next, Sam Altman on OpenAI having AGI by the end of 2026 if you accept his definition, AI shopping agents not being ready to buy on your behalf, AI benchmarks having a trust problem, and the skills that earn top grades being the ones AI can fake best; 'Most Popular' still carries Anthropic cutting 80 percent of Claude Code's system prompt and the Microsoft researcher's neural network built out of goats in Age of Empires II, both held over from 31 August. Both claims above still stand against the article's own words. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line anywhere in the visible text: 'updated' and 'Update' return nothing on the page. The searches for individual, identifies, anonymous, person, account and customer were repeated and all six return nothing anywhere on the page. No archive diff was run today: the CDX endpoint timed out on every attempt. Flagged again on 2 September 2026. Noise, and this time it was settled without reading the article at all, because the page is not stable from one request to the next. Three consecutive fetches during this review returned three different digests — 600638de4f85b95f, 53e336f4ed76e772 and c412ac45dde66998 — at 1,245, 1,245 and 1,246 words. The second of those, 53e336f4ed76e772, is the digest the watcher held before today's flag, so the same URL served both the old and the new state minutes apart. That is per-request rotation in the sidebar and ad slots, exactly the pattern REVIEW.md names for the-decoder.com, and it means a digest move on this source carries no information at all. Both claims above stand unchanged. Flagged on 3 and 4 September 2026 and re-read end to end on 4 September. Noise again, from the same rotating blocks, and the rate of it is the evidence: the watcher recorded 07f1ccd884ce5a4c at 09:03 UTC and the read an hour later hashed to 21747e891ffc95cc, a second change inside the same morning, which is what this page has done since 12 August. The body is unchanged and still supports the two claims above. The searches for individual, identifies, anonymous, person, account and customer return nothing in the body, so this article still says nothing about tracing a mark to a specific person, and neither does the site on its authority. Its two occurrences of SynthID are still in the closing section about Google DeepMind's own system, not about Claude's. Flagged again on 5 September 2026 and re-read end to end. Noise, shown rather than judged. The page's visible text was diffed word by word against the Internet Archive snapshot of 13 August 21:54 UTC, which is still the newest of the four snapshots the archive holds of this article. The first 932 words are word-identical, and that span covers the whole of the article — headline, byline, key points, both labelling methods, the detection limits, the closing analysis and the 'Source: Claude' line. Every difference falls after it, in the rotating 'Top Stories' block, which today leads with GPT-6 Astra, World Labs' Atlas and a US Department of Justice copyright item. The byline is still Matthias Bastian and the date still 11 August 2026, with no 'updated' line and no appended update paragraph, and both claims above stand. Note for the next reviewer that this page's hash is not stable within a single review: the watcher recorded 243adf5e897549e6 this morning and the read a few hours later hashed to 985ff18a0232e96b, which is those same blocks rotating between two fetches, and is why this source is flagged most days. Flagged again on 6 September 2026 and re-read end to end. Noise, and today the page showed it against itself. The watcher's first run this morning moved the digest from 243adf5e897549e6 to 3e46128f294dfbf0; a second run an hour later moved it back to 243adf5e897549e6, the exact value it held before. Three consecutive fetches during the read then returned 985ff18a0232e96b, 243adf5e897549e6 and 985ff18a0232e96b, all at 1,261 words, so the same URL alternates between two states from one request to the next, and a digest move on this source carries no information. Those two states differ in one place only, a single headline at word 982 in the 'Top Stories' block. The visible text was also diffed word by word against the Internet Archive snapshot of 13 August 21:54 UTC, still the newest of the four snapshots the archive holds. The first 932 words are word-identical and that span ends at the 'Source: Claude' line, so it covers the whole article; every later difference is the rotating block, which today leads with GPT-6 Astra and World Labs' Atlas. The byline is still Matthias Bastian and the date still Aug 11, 2026, with no 'updated' line and no appended update paragraph. Both claims above stand. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page, so this article still says nothing about tracing a mark to a specific person, and neither does the site on its authority. Flagged again on 7 September 2026 and re-read end to end. Noise, and the page showed its instability against itself once more: the digest was 243adf5e897549e6 at the last review, fc0ed961a8c6e387 on the watcher's first run this morning, 94a962851170c05c on a second run an hour later, and e1871ac9e11fb65a on the 1,264-word fetch used for this read, four values on one URL within a few hours, so a digest move on this source still carries no information. The visible text was diffed word by word against the Internet Archive snapshot of 13 August 21:54 UTC, still the newest of the four snapshots the archive holds. The first 932 words are word-identical and that span ends at the 'Source: Claude' line, so it covers the whole article; every later difference is the rotating 'Top Stories' and 'Most Popular' blocks, which today lead with GPT-6 Astra and World Labs' Atlas. The byline is still Matthias Bastian and the date still Aug 11, 2026, with no 'updated' line and no appended update paragraph. Both claims above stand. The searches for individual, identifies, anonymous, person, account and customer return nothing anywhere on the page; the one hit for prompted is the image credit and both hits for privacy are footer links, so this article still says nothing about tracing a mark to a specific person, and neither does the site on its authority. Flagged again on 9 September 2026 and re-read end to end. Noise. The article body is word-identical to the Internet Archive's snapshot of 13 August 21:54 UTC, the newest it holds: the word-by-word diff against it contains a 932-word equal run covering the whole story, from the headline through the closing paragraph on schools and universities, and every difference sits in the 'Top Stories' and related-article lists below it. Both claims above stand: the article still reports that a mark may not survive heavy editing, translation, or metadata stripped through format conversion or a screenshot, and still reports that a detected watermark does not establish Claude wrote the content, because people use it to proofread, translate and summarise. As with techcrunch-anthropic, this page's visible text is not stable between requests: two fetches during this review hashed to 38c4be21a3e72569 and to bf450070de7e78b7, the watcher's own new digest, both at 1,266 words, and the only difference between them was the position of one headline in the 'Top Stories' list. Flagged again on 10 September 2026 and re-read end to end. Noise. The Internet Archive's newest snapshot of this page is still the one of 13 August 21:54 UTC. Diffed word by word against it, the article body is a 932-word equal run covering the whole story, from the headline through the closing paragraph on schools and universities, and every difference sits in the 'Top Stories' and 'Most Popular' lists below it. Both claims above stand: the article still reports that a mark may not survive heavy editing, translation, or metadata stripped through format conversion or a screenshot, and still reports that a detected watermark does not establish that Claude wrote the content, because people use it to proofread, translate and summarise. As with techcrunch-anthropic, the instability recorded on 9 September did not recur: four fetches during this review all hashed to 10bca7b9a5210493 at 1,265 words, which is the watcher's own new digest, so today's flag records a real change to the page rather than a flake, and the change is entirely in those two lists. Flagged again on 11 September 2026 and re-read end to end. Noise. The Internet Archive holds no snapshot of this page after 13 August, so the diff was run against its snapshot of 13 August 21:54 UTC, hashing to 1c470877109ce913 at 1,249 words. Against it, the article body is a 932-word equal run covering the whole story, from the headline through the closing paragraph and the newsletter box, and every difference sits in the 'Top Stories' and 'Most Popular' lists below it, which now carry the week's other AI stories. Both claims above stand. The per-request instability recorded on 9 September did recur today: four fetches during this review hashed to 382645ae9639eb29, 11433096dedc06d9, 8adb8f0a16d1551d and 382645ae9639eb29, at 1,260 to 1,265 words, and the watcher itself recorded two different digests in two runs this morning (2ca03f3cdee54624 at about 07:00 UTC and 1231e944b1dbbac8 later). Those lists are served differently per request, so a flag on this source cannot be told from a flake by digest alone; the article body is the thing to diff. Flagged and re-read end to end on 12 September 2026. Noise. The Internet Archive now holds this article — the 13 August 2026 note below saying it held no snapshot is out of date — and the snapshot of 13 August 21:54 UTC was diffed word by word against today's page: the article body is a single 932-word equal run from the headline through 'Source: Claude', and every difference sits in the 'Top Stories' and 'Most Popular' lists below it, which rotated in full. Both claims above stand: the body still says a detected watermark does not mean Claude wrote the content because people use it for proofreading, translating or summarising, and still lists heavy editing, translation, format conversion and screenshots as reasons for a missing mark, with the last two made about stripped metadata. Two hand fetches during this review both hashed to fbfd05a943f14aea at 1,257 words, the watcher's digest, so the per-request instability seen on 9 and 11 September did not recur today. Flagged again on 15 September 2026 and re-read end to end. Noise, from the rotating blocks below the article. No archive copy could be compared today, because the Internet Archive answered 'Temporarily Offline' and 429 throughout this review. Two hand fetches during this review hashed differently — f91d10e988fe5e2f at 1,252 words, the watcher's digest, and then da8e7a23b35b2426 at 1,250 words — and a word-by-word diff between the two puts every difference in the 'Top Stories' list, which swapped one entry for another between requests, so the per-request instability seen on 9 and 11 September recurred today. The article's own dateModified is still 2026-08-11T08:46:16+00:00. The body was read in full, from the headline through 'Source: Claude', and both claims above stand: it still says a detected watermark does not mean Claude wrote the content because people use it for proofreading, translating or summarising, and still lists heavy editing, translation, format conversion and screenshots as reasons for a missing mark, with the last two made about stripped metadata. Flagged again on 18 September 2026 and re-read end to end. Noise, from the rotating blocks below the article. Two hand fetches both hashed to 1409290058cd6e58 at 1,248 words, the watcher's new digest, so the page was stable between requests today; no archive copy was sought. The article's own dateModified is still 2026-08-11T08:46:16+00:00. The body was read in full, from the headline through 'Source: Claude', and both claims above stand: it still says a detected watermark does not mean Claude wrote the content because people use it for proofreading, translating or summarising, and still lists heavy editing, translation, format conversion and screenshots as reasons for a missing mark, with the last two made about stripped metadata. The 'Top Stories' list below it today leads with two GPT-6 Astra items and the 'Most Popular' list with a pxpipe token-cost tool, none of which the 15 September copy carried. Flagged again on 20 September 2026 and re-read end to end. Noise, and this time the flag is a per-request flake rather than an edit. Four hand fetches during this review produced three different digests — aee15fb85d93774a, ef592511472333c7, ef592511472333c7 and aee15fb85d93774a — and none of them is the watcher's new digest 2cd44bea85508502, so this page does not serve the same visible text twice running and the watcher's before-and-after pair does not by itself establish that anything changed. Diffing two of those fetches against each other shows where the instability lives: the teaser strip of other the-decoder articles, which carried 'Two-year university study finds banning AI from classrooms leaves students worse off' in one fetch and 'AI training built on fair use looks shaky when the companies' own people call it \"astonishing theft\"' in the other. Nothing else differs between them. Both claims above were checked against the live text and stand word for word: the list of things that leave no mark — a model that shipped before watermarking rolled out, text that was heavily edited or translated, a passage too short for reliable detection, and metadata stripped through format conversion or a screenshot — and the point that a detected watermark does not establish that Claude wrote the content, because people use Claude to proofread, translate and summarise human work."
  },
  "ec-article-50": {
    "n": 7,
    "url": "https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act",
    "title": "Transparency obligations under Article 50 of the AI Act",
    "publisher": "European Commission",
    "date": "2026",
    "fetched": "2026-09-18",
    "primary": true,
    "claims": [
      "Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.",
      "The marks must be effective, reliable, robust and interoperable.",
      "Article 50 applies from 2 August 2026.",
      "A limited grace period runs to 2 December 2026, but only for AI systems placed on the market before 2 August 2026, and only for the Article 50(2) marking and detection obligation.",
      "A narrow exemption from the marking obligation is envisaged for AI systems whose outputs are used in business-to-business or industrial contexts, subject to conditions set out in the guidelines.",
      "Deployers must clearly label AI-generated or manipulated text published to inform the public on matters of public interest; text that has undergone human review or editorial control does not need to be labelled.",
      "Enforcement is mainly by national market surveillance authorities; the AI Office's role is limited."
    ],
    "notes": "Re-read end to end on 13 August 2026; the watcher reports this page unchanged since 12 August. This file previously recorded a claim that open-source AI systems are not exempt from these transparency obligations, and the Article 50 page stated it as fact. The page does not say it. The string 'open source', in any spacing or hyphenation, does not appear anywhere in its rendered text or its raw HTML, and the only exemptions it describes are the business-to-business and industrial-context one and the human-review one for published text. Since the page has not changed, this claim appears to have been wrong when it was first recorded rather than superseded. The claim and the site sentence resting on it were removed on 13 August 2026. The 2 December 2026 grace period was on the page and missing from this file; it is added above. Re-read end to end again on 20 August 2026; the watcher reports this page unchanged, and its visible-text hash is identical to every check since 13 August. All seven claims stand, including the 2 December 2026 grace period, which the page still scopes to AI systems placed on the market before 2 August 2026 and to the Article 50(2) marking and detection obligation only. The search for 'open source', in any spacing or hyphenation, was repeated against the raw HTML and still returns nothing, so the removal recorded above still holds. The page's own 'Last update' line reads 24 July 2026. Re-read end to end on 2 September 2026 as part of verifying every source the site cites. Not flagged: unchanged at 739b4c9b03deec73, reproduced by hand at 2,874 words. All seven claims stand word for word. The two dates were checked against the FAQ's own answer to 'When does Article 50 of the AI Act start to apply and is there a grace period?', which says Article 50 applies as from 2 August 2026 and that the limited grace period runs to 2 December 2026, only for systems placed on the market before 2 August 2026 and only for the Article 50(2) marking and detection obligation. Enforcement is still 'mainly by national competent market surveillance authorities', with the AI Office limited to systems built on general-purpose models by the same provider or integrated into a very large online platform or search engine. Re-read end to end on 9 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 739b4c9b03deec73, and a hand fetch reproduced that digest at 2,874 words, the same count recorded on 2 September, so the page's visible text is byte-identical to the copy that read verified. All seven claims stand word for word, including the 2 December 2026 grace period, still scoped to AI systems placed on the market before 2 August 2026 and to the Article 50(2) marking and detection obligation only, and the business-to-business and industrial-context exemption, still described as narrow and envisaged subject to conditions in the guidelines. The page still carries 'Last update 24 July 2026'. Re-read end to end on 10 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 739b4c9b03deec73, and a hand fetch reproduced that digest at 2,874 words, the same count recorded on 2 and 9 September, so the page's visible text is byte-identical to the copy that read verified. All seven claims stand word for word. The two dates were checked against the FAQ's own answer to 'When does Article 50 of the AI Act start to apply and is there a grace period?', which still says Article 50 applies as from 2 August 2026 and that the limited grace period runs to 2 December 2026, only for systems placed on the market before 2 August 2026 and only for the Article 50(2) marking and detection obligation. Enforcement is still 'mainly by national competent market surveillance authorities', with the AI Office limited to systems built on general-purpose models by the same provider or integrated into a very large online platform or search engine. The page still carries 'Last update 24 July 2026'. Re-read on 11 September 2026; the watcher reports this page unchanged, and its visible-text hash is identical to the copy read on 10 September. The enforcement wording and 'Last update 24 July 2026' were checked against the live text and stand. Re-read on 12 September 2026; the watcher reports this page unchanged, and a hand fetch reproduced its visible-text hash 739b4c9b03deec73 at 2,874 words, identical to the copy read on 11 September. All seven claims above were checked against the live text and stand, including the 'narrow exemption of the marking obligation … envisaged for AI systems that generate outputs used in “business to business” or “industrial contexts”' sentence, the 2 December 2026 grace period and its scope, and 'Last update 24 July 2026'. Re-read on 18 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 739b4c9b03deec73, and a hand fetch reproduced that digest at 2,874 words, identical to the copy read on 12 September. All seven claims above were checked against the live text and stand, including the 2 December 2026 grace period and its scope, the 'business to business' exemption sentence, the editorial-control carve-out for deployers, the market surveillance enforcement wording and 'Last update 24 July 2026'."
  },
  "openai-provenance": {
    "n": 9,
    "url": "https://openai.com/index/advancing-content-provenance/",
    "title": "Advancing content provenance for a safer, more transparent AI ecosystem",
    "publisher": "OpenAI",
    "date": "2026-05-19, updated 2026-07-31",
    "fetched": "2026-09-18",
    "primary": true,
    "claims": [
      "OpenAI has added C2PA Content Credentials to DALL-E 3 images since 2024, later to ImageGen and Sora.",
      "OpenAI joined the C2PA Steering Committee and is now a C2PA Conforming Generator Product.",
      "SynthID watermarking added to images generated through ChatGPT, Codex or the OpenAI API, via a partnership with Google DeepMind.",
      "Update of 31 July 2026: supported audio generated with OpenAI tools, including through ChatGPT and the OpenAI API, now includes SynthID watermarking.",
      "OpenAI is previewing a PUBLIC verification tool that checks whether an uploaded image was generated on ChatGPT, the OpenAI API or Codex, detecting both Content Credentials and SynthID.",
      "The verification tool now covers supported audio files as well as images.",
      "API access for verification was introduced on 31 July 2026, so developers can build provenance checks into their own workflows.",
      "At launch the tool is limited to content generated by OpenAI.",
      "If no metadata or watermark is detected, the tool deliberately does not conclude that the image was not generated with OpenAI tools, because signals can be stripped.",
      "OpenAI states metadata is not foolproof: it can be stripped, lost through uploads and downloads, or broken by format changes, resizing or screenshots.",
      "Previously used visible watermarks in Sora and an audio watermark in Voice Engine."
    ],
    "notes": "TEXT IS NOT MENTIONED ANYWHERE on this page. The expansion went images then audio. Do not infer that OpenAI watermarks text. Flagged on 19 August 2026 — the first time the watcher has reported a change here — and re-read end to end. Noise. The page's visible text was diffed word by word against the Internet Archive snapshot of 12 August 11:32 UTC, and the article body is identical across the whole of it, from the 'Update July 31, 2026' note at the top to the 'Looking ahead' close. There are exactly two differences on the page, both in the 'Keep reading' list of other OpenAI posts at the foot: it gained 'Introducing ChatGPT for Teens' (Product, 18 August 2026) and lost 'Why teens deserve access to safe AI' (Safety, 16 July 2026). A rotating list of other links is the noise pattern REVIEW.md names, and a newsroom page picking up the previous day's post is the ordinary way it happens. All eleven claims above still stand, and the point that matters most about this source is unchanged: the body was searched for text, writing, word, LLM and language model, and the only hits are the three occurrences of 'context' inside other sentences. Text as a modality is still not mentioned, and the byline date is still 19 May 2026 with the single 31 July 2026 update. Flagged a second time on 20 August 2026 and re-read end to end. Noise, and the same noise as yesterday: the only visible difference from the read of 19 August is the 'Keep reading' list of other OpenAI posts at the foot, which gained 'Offering Zero Data Retention for frontier models' (Company, 19 August 2026) above 'Introducing ChatGPT for Teens' (Product, 18 August 2026) and 'Expanding Daybreak as the Cyber Defense Window Narrows' (Security, 10 August 2026). A newsroom page picking up the previous day's post is the ordinary way this happens, and it has now happened on two consecutive days. All eleven claims above still stand, the byline is still 19 May 2026 with the single 31 July 2026 update note, and the point that matters most about this source is unchanged: the body was searched again for text, writing, word, words, LLM and language model, and the only hits are the three occurrences of 'context' inside other sentences. Text as a modality is still not mentioned. Flagged a third time on 29 August 2026, the first flag since 20 August, and re-read end to end. Noise, and the same noise as the two previous flags: the only difference this review can find from the copy described here on 20 August is the 'Keep reading' list of other OpenAI posts at the foot, which gained 'The Hugging Face incident and the road ahead' (Security, 26 August 2026) and lost 'Expanding Daybreak as the Cyber Defense Window Narrows' (Security, 10 August 2026), leaving 'Offering Zero Data Retention for frontier models' (19 August) and 'Introducing ChatGPT for Teens' (18 August) in place between them. The body was read from the 'Update July 31, 2026' note at the top to the 'Looking ahead' close and each of the eleven claims above re-checked against it; all still stand, and the byline is still 19 May 2026 with that single 31 July 2026 update note. The point that matters most about this source is unchanged: the body, 990 words, was searched again for text, writing, word, words, LLM and language model, and the only hits are the three occurrences of 'context' inside other sentences. Text as a modality is still not mentioned. Unlike 19 and 20 August this was not a word-by-word diff against a snapshot. The Internet Archive holds nothing for this URL after 19 August 17:14 UTC, and no snapshot was fetched for it today: the archive's replay endpoint answered only intermittently through the review - four of the five snapshots wanted for other sources took between two and five attempts - and by the end it was serving its own 'Temporarily Offline' page. So the comparison here is against what is recorded above rather than against a fetched copy, and a reviewer who wants a byte-level check on this page should make one when the archive is healthy. Re-read end to end on 2 September 2026, and there is a wrinkle worth recording. The watcher could not reach this URL at all today — it is the one source whose entry in watch_state.json still reads 'checked 2026-09-01' — so it wrote no proposal and the change went unflagged. It was caught only because this review re-read every cited source to justify the verified dates. Fetched by hand it answers HTTP 200, and three consecutive fetches all hashed to bb84d21cd7219f7c against the e216979b400775b2 the watcher still holds, so the page has genuinely moved since 1 September. The move is noise. The article is untouched: the dateline is still May 19, 2026, the 'Update July 31, 2026' block is word for word as recorded, and all eleven claims above still stand sentence by sentence, including that the verification tool is limited to OpenAI-generated content and draws no conclusion when it detects nothing. What moved is the three-card 'Keep reading' strip at the foot, which now leads with 'Path to Astra: critical capabilities and frontier safeguards', dated Sep 1, 2026, above the Hugging Face incident post of 26 August and the Zero Data Retention post of 19 August. A rotating list of other links is the noise pattern REVIEW.md names. Because the watcher never recorded today's digest, it will flag this URL again on the next successful run; bb84d21cd7219f7c is the digest that flag will be about, and it is already resolved here. Flagged on 3 and 4 September 2026 and re-read end to end on 4 September. Noise, and the same pattern as every previous flag here. The archive diff is weaker than usual and is recorded as such: the Internet Archive holds one snapshot since the last review, 30 August 05:00 UTC, and it hashes to e7149d6a35722034, which matches neither the watcher's old baseline e216979b400775b2 nor today's 54941d40ddfb7c0e, so it establishes the state of the body rather than the exact before copy. Diffed word by word against it, the article body is identical throughout, from the 'Update July 31, 2026' note at the top to the 'Looking ahead' close, and all four differences sit outside it: the 'Keep reading' list at the foot gained 'Safety overview: GPT-6 Astra' (Safety, 3 September 2026) and 'Path to Astra: critical capabilities and frontier safeguards' (Safety, 1 September 2026) and lost 'Offering Zero Data Retention for frontier models' and 'Introducing ChatGPT for Teens'; the site navigation's 'Latest Advancements' list gained 'GPT-6'; and a footer link changed from 'Your privacy choices' to 'Manage Cookies'. All eleven claims above stand. The body was searched again for text, writing, word, LLM and language model, and the only hits are three occurrences of 'context' inside other sentences, so text as a modality is still not mentioned. The byline is still 19 May 2026 with the single 31 July 2026 update. Flagged on 7 September 2026 and re-read end to end. Noise, and the same pattern as every previous flag here. The page's visible text hashes to bd34870aca4e94a7, exactly the watcher's new digest. The Internet Archive has added no snapshot since the last review, so the comparison is again against 30 August 05:00 UTC, which hashes to e7149d6a35722034 as recorded on 4 September. Diffed word by word against it, the first 1,150 words are identical, and that span runs from the headline through the 'Looking ahead' close to the 'Keep reading' heading, so it covers the whole article including the 'Update July 31, 2026' note at the top. Every difference sits outside the body: the 'Keep reading' list gained 'An Alien Mind' (Safety, 6 September 2026), 'Research acceleration: The view inside OpenAI' (Research, 6 September 2026) and 'Safety overview: GPT-6 Astra' (Safety, 3 September 2026) and lost the Hugging Face incident, Zero Data Retention and ChatGPT for Teens items; the site navigation's 'Latest Advancements' list gained 'GPT-6'; and the footer link reads 'Manage Cookies' where the snapshot read 'Your privacy choices'. All eleven claims above stand. The body was searched again for text, writing, word, LLM and language model: the last four do not appear at all, and all three hits for text sit inside the word context, so text as a modality is still not mentioned. The byline is still 19 May 2026 with the single 31 July 2026 update. Flagged again on 9 September 2026 and re-read end to end. Noise, and the same pattern as every previous flag here. The page's visible text hashes to a09eb9b320f3fb9c, exactly the watcher's new digest. The Internet Archive has still added no snapshot since 30 August 05:00 UTC, which hashes to e7149d6a35722034 as recorded on 4 September, so the comparison is again against that copy. Diffed word by word against it, the first 1,150 words are identical, and that span runs from the headline through the 'Looking ahead' close to the 'Keep reading' heading, so it covers the whole article including the 'Update July 31, 2026' note at the top. Every difference sits outside the body, and set against the 7 September note's own diff against the same snapshot, the whole of today's move is one item entering the 'Keep reading' list: 'Funding grants for new research into AI and teen development' (Safety, 8 September 2026) arrived at the top and 'Safety overview: GPT-6 Astra' fell off, leaving 'An Alien Mind' and 'Research acceleration: The view inside OpenAI', both of 6 September. All eleven claims above stand. The body was searched again for text, writing, word, LLM and language model: the last four do not appear at all, and all three hits for text sit inside the word context, so text as a modality is still not mentioned. The byline is still 19 May 2026 with the single 31 July 2026 update. Re-read end to end on 10 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at a09eb9b320f3fb9c, and a hand fetch reproduced that digest at 1,374 words, so the page's visible text is byte-identical to the copy the 9 September review verified, down to the 'Keep reading' list, which still holds 'Funding grants for new research into AI and teen development' of 8 September and 'An Alien Mind' and 'Research acceleration: The view inside OpenAI', both of 6 September. All eleven claims above stand. The body was searched again for text, writing, word, LLM and language model: the last four do not appear at all, and every hit for text sits inside the word context, so text as a modality is still not mentioned — which is what the OpenAI text row in data/watermarks.json rests on. The byline is still 19 May 2026 with the single 31 July 2026 update. Re-read on 11 September 2026; the watcher reports this page unchanged, and its visible-text hash is identical to the copy read on 10 September. The 31 July 2026 audio update stands, and text as a modality is still not mentioned. Unreachable on 12 September 2026. The watcher could not fetch it in its run and left its state entry at 11 September; hand fetches with the watcher's user agent and with a desktop Firefox user agent both returned HTTP 403 with a 5 KB bot-check page, and a third fetcher got 403 too. Nothing was read, so the fetched date above stays at 11 September and every page citing this source keeps its 11 September verified date. An unreachable source is not a change. Flagged again on 18 September 2026 and re-read end to end, the first read since the 12 September 403. Noise. The page returns HTTP 200 to the watcher's user agent again; a hand fetch reproduced the watcher's new digest 39674af4d96f340c at 1,363 words, against 1,374 on 10 September. No archive copy could be compared: the Internet Archive's CDX index lists no snapshot of this URL after 12 September. What moved is the 'Keep reading' list below the article, which now leads with 'Our framework for reporting model misalignment' of 16 September and has dropped 'Research acceleration: The view inside OpenAI', keeping 'Funding grants for new research into AI and teen development' of 8 September and 'An Alien Mind' of 6 September; a rotating list of other links is the noise pattern REVIEW.md names. The body was read in full, from the 31 July 2026 update through 'Looking ahead', and all eleven claims above stand: C2PA Content Credentials since DALL·E 3, the Steering Committee seat and Conforming Generator Product status, SynthID on images through ChatGPT, Codex and the API, SynthID on supported audio since 31 July 2026, the public verification tool covering images and now audio, verification API access, the limit to OpenAI-generated content, the deliberate non-conclusion when nothing is detected, and the visible Sora watermark and Voice Engine audio watermark. The body was searched again for text, writing, word, LLM and language model: the last four do not appear, and all three hits for text sit inside the word context, so text as a modality is still not mentioned. The byline is still 19 May 2026 with the single 31 July 2026 update."
  },
  "claudewatermark-com": {
    "n": 8,
    "url": "https://www.claudewatermark.com/",
    "title": "Claude Watermark Remover and Checker",
    "publisher": "claudewatermark.com",
    "date": "accessed 2026-08-13",
    "fetched": "2026-09-18",
    "primary": false,
    "claims": [
      "Ranks for Claude watermark queries.",
      "Its own copy describes scanning for zero-width spaces, zero-width joiners and other invisible Unicode characters, and replacing em dashes.",
      "Does not claim to detect a statistical watermark.",
      "Refers users to gpthumanizer.io."
    ],
    "notes": "Evidence for the detector audit. Re-read on 20 August 2026; the watcher reports this page unchanged, and its visible-text hash is identical to every check since 13 August. The three claims that rest on the page's own copy stand: it still describes scanning for zero-width spaces, zero-width joiners and other invisible unicode characters and handling em dashes, it still describes no statistical watermark anywhere on the page, and the outbound links in its HTML are still to gpthumanizer.io and gpthumanizer.io/ai-detector. The first claim, that it ranks for Claude watermark queries, is about search results rather than about this page and was not re-checked today. Re-read end to end on 2 September 2026 as part of verifying every source the site cites. Not flagged: unchanged at 013b023d59a54c7c, reproduced by hand at 759 words. All four claims stand. The outbound links were checked rather than assumed, and the only two that are not ad-network hosts go to gpthumanizer.io and gpthumanizer.io/ai-detector, which is claim 3. The detector audit's finding that this site conflates Claude with OpenAI in its own copy is still literally true on the page: its FAQ answer to 'What is a Claude Watermark?' says it is a pattern 'that OpenAI may embed in ChatGPT-generated content'. Nothing here has been updated for Anthropic's 1 September detection announcement; the page still says the implementation 'remains partially undisclosed'. Re-read end to end on 9 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 013b023d59a54c7c, and a hand fetch reproduced that digest at 759 words, the same count recorded on 2 September, so the page's visible text is byte-identical to the copy that read verified. All four claims stand. The outbound links in the raw HTML were checked rather than assumed again, and the only two that are not ad-network hosts still go to gpthumanizer.io and gpthumanizer.io/ai-detector. The page still describes only zero-width spaces, zero-width joiners, other invisible unicode characters and em dashes, and still describes no statistical watermark anywhere. The detector audit's finding still holds literally: its FAQ answer to 'What is a Claude Watermark?' still says the pattern is one 'that OpenAI may embed in ChatGPT-generated content', and its answer to 'Does Claude add watermarks to its text?' still says the implementation 'remains partially undisclosed', eight days after Anthropic opened the detection API to a private preview. The first claim, that it ranks for Claude watermark queries, is about search results rather than about this page and was not re-checked today. Re-read end to end on 10 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 013b023d59a54c7c, and a hand fetch reproduced that digest at 759 words, the same count recorded on 2 and 9 September, so the page's visible text is byte-identical to the copy that read verified. All four claims stand. The outbound links in the raw HTML were checked rather than assumed again, and the only two that are not ad-network hosts still go to gpthumanizer.io and gpthumanizer.io/ai-detector. The page still describes only zero-width spaces, zero-width joiners, other invisible unicode characters and em dashes, and still describes no statistical watermark anywhere. The detector audit's finding still holds literally: its FAQ answer to 'What is a Claude Watermark?' still says the pattern is one 'that OpenAI may embed in ChatGPT-generated content', and its answer to 'Does Claude add watermarks to its text?' still says the implementation 'remains partially undisclosed', nine days after Anthropic opened the detection API to a private preview. The first claim, that it ranks for Claude watermark queries, is about search results rather than about this page and was not re-checked today. Re-read on 11 September 2026; the watcher reports this page unchanged, and its visible-text hash is identical to the copy read on 10 September. It still says the implementation 'remains partially undisclosed'. Re-read on 12 September 2026; the watcher reports this page unchanged, and a hand fetch reproduced its visible-text hash 013b023d59a54c7c at 759 words, identical to the copy read on 11 September. The four claims above stand: the copy still describes zero-width spaces, zero-width joiners and other invisible unicode characters and em-dash handling, the words statistical, probability and token still appear nowhere on the page, and the gpthumanizer.io link is still in the HTML. Re-read on 18 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 013b023d59a54c7c, and a hand fetch reproduced that digest at 759 words, identical to the copy read on 12 September. The four claims above stand: the copy still describes zero-width characters and em-dash handling, still says the implementation 'remains partially undisclosed', the words statistical, probability and token still appear nowhere on the page, and the gpthumanizer.io link is still in the HTML."
  },
  "anthropic-content-checker": {
    "n": 11,
    "url": "https://claude.com/check-content",
    "title": "Check if files were made with Claude",
    "publisher": "Anthropic",
    "date": "accessed 2026-09-05",
    "fetched": "2026-09-18",
    "primary": true,
    "claims": [
      "A tool that checks whether a file carries a C2PA Content Credential pointing to Claude. The page's title is 'Check if files were made with Claude' and its heading 'Check if a file was made with Claude'. The page does not itself call the tool free; 'free' is the help centre's word for it, under anthropic-help.",
      "Anthropic states the tool runs in your browser, that your file never leaves your device, that the checker only reads the attached credential and not the file itself, and that your file is never stored or used for any other purpose.",
      "Supported formats listed on the page: JPG, PNG, GIF, WEBP, TIFF, HEIC, AVIF, SVG, DNG, JXL, MP4, MOV, AVI, WAV, MP3, M4A and FLAC, up to 100 MB.",
      "It takes files only, and the page now says so outright: 'The tool does not check text. Claude marks text with a watermark in the writing itself.' Every format it lists is an image, video or audio file.",
      "The page states that the tool checks a file for a Content Credential from Claude, and that if it finds one, that tells you Claude may have made or processed the file; that it does not tell you who authored the underlying content; and that it carries no identifying information about the user.",
      "Under 'How it works' the page says that when Claude produces a supported file type (such as a .png, .jpg or .svg) it attaches a Content Credential in the form of a small, cryptographically signed note in the file's metadata, saying that the file may have been made or processed with Claude. It names the standard: 'This is an open industry standard called C2PA—the same used by camera manufacturers and in photo-editing software to record where an image came from. Any C2PA-aware tool can read it.'",
      "The tool's own result messages, carried in the page's payload, are 'This file shows signs it was processed by Claude.'; 'We didn’t find any signs this file was processed by Claude.', qualified by 'That doesn’t rule it out. Signals like this can be removed when a file is edited, converted, or compressed.'; and, for an unsupported file, 'This file could not be checked' with 'That file type isn't supported. Check the format list.'",
      "Under the heading 'How can I tell if Claude wrote a piece of text?' the page says: 'Text is checked through a Detection API, which is currently in private preview for eligible organizations as required under EU law.' Its 'Read more about file and text detection here' links the help centre article at https://support.claude.com/en/articles/16266773."
    ],
    "notes": "Added on 2 September 2026, after the help centre article started linking it as 'the free Claude Content Checker'. Read end to end on that date; the page returns HTTP 200 and its visible text hashes to 8d736f4f1443c275 at 717 words. This is the tool the 14 August newsroom explainer said Anthropic would provide, and that explainer still describes it in the future tense while this page is live. Note carefully what it is and is not: it reads C2PA content credentials on files, which is the same thing any C2PA-aware verifier does, and it is not a detector for the text watermark. Text detection remains gated behind the private-preview API. The site should not let the two run together, because 'Anthropic shipped a free public checker' is true of files and false of text. Re-read end to end on 4 September 2026, and the page has changed since 2 September. It now hashes to 4401cfe3474293f9 at 812 words where this file recorded 8d736f4f1443c275 at 717 words two days ago. The watcher did not report this, and could not have: the page was added to sources.json after the 2 September run, the 3 September run's state was never saved, and today's run therefore treated it as a first sighting and baselined it. No diff of the change was possible either, because the Internet Archive holds no snapshot of this URL at all, so what follows is a fresh read of the live page rather than a before-and-after. Three things are different from what this file recorded on 2 September, and it cannot be said which of them are edits and which were simply not recorded that day. The page title is now 'Check if files were made with Claude' and the heading 'Check if a file was made with Claude', where this file recorded 'Check if content is made with Claude'. There is a new section, 'How can I tell if Claude created the text?', which sends the reader to the private-preview Detection API and to the help centre article — the checker now answers the text question itself, and answers it the same way the site does. And a line under 'How it works' points to other providers' tools, linking OpenAI, Google DeepMind and Gemini. The claims above have been rewritten to what the page states today, read end to end. One thing is recorded rather than resolved: the second half of the claim this file carried on 2 September — that a missing signal may mean the content was 'produced by a model, platform or feature that does not support marking' — is not on the page today in those words. What the tool says on a negative result is quoted verbatim above, and it gives one reason, not two: signals can be removed when a file is edited, converted or compressed. The wider reason is the help centre's, and the site cites anthropic-help for it, so nothing on the site rested on the difference. What has not changed is the part that matters: the tool takes files, not text, and every format it lists is an image, video or audio file. Text detection remains the private-preview API. Flagged again on 5 September 2026 and re-read end to end. **Real**, though nothing on the site rested on what moved. The page returns HTTP 200 and its visible text hashes to 3f7af6e7c056bc1f at 787 words, exactly the watcher's new digest, where this file recorded 4401cfe3474293f9 at 812 words on 4 September. No before-and-after diff was possible: the Internet Archive's CDX endpoint still holds no snapshot of this URL at all, so the before-state rests on the claims this file recorded from a live read on 4 September. Three things are different from that record, and the claims above have been rewritten to what the page states today. (1) The line pointing readers to other providers' tools is gone. The 4 September claim 8 recorded that the page linked OpenAI's verification tool, DeepMind's SynthID page and a Gemini help article; today the strings openai, deepmind, synthid and gemini return nothing anywhere in the page's HTML, payload included. That claim has been deleted rather than reworded. Nothing on the site cited it — the site's statements about those providers rest on openai-provenance, deepmind-synthid and synthid-text-repo, which were read directly. (2) A new 'What the tool does' section says outright 'The tool does not check text. Claude marks text with a watermark in the writing itself', linking the help centre article. Until today the site's statement that the checker takes no text rested on the page naming no text input and listing only image, video and audio formats; Anthropic now says it in words. (3) 'How it works' now names the standard — 'an open industry standard called C2PA—the same used by camera manufacturers and in photo-editing software' — and adds that any C2PA-aware tool can read the credential. The text-detection section was also reworded and its heading is now 'How can I tell if Claude wrote a piece of text?'; the answer still sends the reader to the private-preview Detection API and the same help centre article, so nothing about detection changed. The three result messages in the payload were read directly and are quoted above; the first two are word for word what this file recorded on 4 September, and the third, the unsupported-file error, was simply not recorded before. One correction to this file's own record, not to the page: claim 1 carried the word 'free' from 2 September, and the page has never used it. 'Free' is the help centre's word — 'use the free Claude Content Checker' — so the site's prose now cites anthropic-help alongside this key wherever it calls the tool free. What has not changed is the part that matters: the tool takes files, not text, and text detection remains the private-preview API. Re-read end to end on 9 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 3f7af6e7c056bc1f, and a hand fetch reproduced that digest at 787 words, so the page's visible text is byte-identical to the copy the 5 September read verified. All eight claims stand. The seven that are visible on the page were checked against its text, including the full format list and the 100 MB limit, the 'The tool does not check text' sentence, and the private-preview Detection API answer under 'How can I tell if Claude wrote a piece of text?'. The eighth, the three result messages, is not visible without uploading a file and was checked in the page's JSON payload instead, where resultVerified, resultNoCredentials and resultError still carry the wording quoted above. Both help centre links still point at https://support.claude.com/en/articles/16266773. The page still does not use the word free; that remains the help centre's word, as claim 1 records. Re-read end to end on 10 September 2026, not because it was flagged but so that the pages citing it could carry today's verified date. Not flagged: unchanged at 3f7af6e7c056bc1f, and a hand fetch reproduced that digest at 787 words, the same count recorded on 9 September, so the page's visible text is byte-identical to the copy that read verified. All eight claims stand. The seven visible on the page were checked against its text, including the full format list and the 100 MB limit, the 'The tool does not check text' sentence, and the private-preview Detection API answer under 'How can I tell if Claude wrote a piece of text?'. The eighth, the three result messages, is not visible without uploading a file and was checked in the page's payload again, where all three still carry the wording quoted above. Both help centre links still point at https://support.claude.com/en/articles/16266773, and the page still does not use the word free. One thing is recorded because it bears on the three anthropic.com proposals of the same day. Those three moved because the site-wide footer's 'Programs' list renamed 'Research Labs' to 'Scientists'. This page is on claude.com rather than www.anthropic.com, and its footer already reads 'Programs Startups Scientists' today while its digest has not moved since 9 September, so claude.com was already carrying the new label before www.anthropic.com caught up. Re-read on 11 September 2026; the watcher reports this page unchanged, and its visible-text hash is identical to the copy read on 10 September. It still checks files for a Claude Content Credential and still says it cannot tell who wrote a piece of text. Re-read on 12 September 2026; the watcher reports this page unchanged, and a hand fetch reproduced its visible-text hash 3f7af6e7c056bc1f at 787 words, identical to the copy read on 11 September. All eight claims above were checked against the live text and payload and stand, including 'The tool does not check text', the 17-format list up to 100 MB, the three result messages, and the Detection API sentence linking the help centre article. Flagged again on 18 September 2026 and re-read end to end. Noise as far as the site is concerned, though the cause could not be shown: two fetches both hashed to 9eace47b87daaabe at 792 words, the watcher's new digest, against 787 words on 12 September, and the Internet Archive holds no snapshot of this URL after 2 September to diff against. All eight claims above were checked one by one against the live text and payload and stand: the 17-format list up to 100 MB, 'The tool does not check text', the '.png, .jpg, or .svg' example under 'How it works', the C2PA sentence, the private-preview Detection API answer, the three result messages (resultVerified, resultNoCredentials and resultError still carry the wording quoted above), and both help centre links to article 16266773. The tool's content — from 'Check if a file was made with Claude' through 'Your file is never stored or used for any other purpose' — reads exactly as the claims record it, so the five-word growth is in the claude.com header or footer navigation, which the notes have never transcribed. The page still does not use the word free."
  },
  "anthropic-fable-mythos-51": {
    "n": 12,
    "url": "https://www.anthropic.com/claude-fable-and-mythos-5-1",
    "title": "Introducing Claude Fable 5.1 and Claude Mythos 5.1",
    "publisher": "Anthropic",
    "date": "2026-09-01",
    "fetched": "2026-09-20",
    "primary": true,
    "claims": [
      "Under 'Compliance with the EU AI Act', Anthropic says signing the Code of Practice in July 2026, along with 190 other signatories, required it to add a watermark to the outputs of models released after August 2, 2026.",
      "It describes the watermark as invisible to anyone who does not have the detection API, with no practical impact on the quality or content of outputs, and carrying no information about the user, their organisation or their conversations with Claude.",
      "It says the Act also required a way for users to tell whether a text likely contains the watermark, and that Anthropic is therefore rolling out a detection API in private preview, available to eligible organisations as required under EU law and to enterprises similarly obligated, with access expanding over time and interest registered through a form."
    ],
    "notes": "Added on 2 September 2026. The Fable 5.1 and Mythos 5.1 launch post, dated Sep 1, 2026 on Anthropic's newsroom index and headed 'September 2026' on the page itself. It is here for one section, 'Compliance with the EU AI Act', which states the private-preview detection API in the same terms as the help centre and the newsroom explainer, and links the same registration form at https://forms.gle/9tGA33hPJJwtHsMk9. That makes three independent Anthropic pages saying it on the same day, which is why the tracker's detector column moved without waiting for an archive diff. The rest of the post is model capability, pricing and safeguards, and bears on nothing here: synthid, c2pa, provenance and Article 50 return nothing in its body. It also names the two models the help centre now lists as supported, which is the corroboration for that claim. This entry also resolves the anthropic-news proposal of 2 September 2026, since the newsroom index is watched but not cited and has nowhere else to be recorded. The index moved from 6e4172c359c2b8dc to 788ebca4eac83416 because two posts entered it, both dated Sep 1, 2026: this one, which is now the hero card, and 'Developing Enterprise Frontier Safeguards with our customers', which is now first in the ten-item list. The list is still ten items long and still ends at 'Our position on open-weights models' of 27 July. The safeguards post was read end to end and bears on nothing here: watermark, synthid, c2pa, provenance, marking and Article 50 all return nothing in its body, and its nine occurrences of 'detect' are every one about detecting misuse and cyberattacks in enterprise traffic. Re-read end to end on 4 September 2026, together with the newsroom index, which the watcher flagged the same day. This page is unchanged in substance and today is the first digest recorded for it, 317236f0b6bda3db at 5,859 words: the 3 September run's state was never saved, so the watcher baselined it today rather than diffing it, and it was therefore checked by hand. The 'Compliance with the EU AI Act' section still states the three claims above, and its 'here' still links https://forms.gle/9tGA33hPJJwtHsMk9. On the newsroom index the change was one word. The Internet Archive's snapshots of 1 September 23:14, 2 September 17:32 and 3 September 11:45 UTC all hash to exactly 788ebca4eac83416, the watcher's old baseline, and the word-by-word diff against today shows a single insertion: the category label 'Announcements' now appears on the 30 July row, 'Investigating three real-world incidents in our cybersecurity evaluations'. The list is still ten items, still headed by 'Developing Enterprise Frontier Safeguards with our customers' of 1 September and still ending at 'Our position on open-weights models' of 27 July, and this post is still the hero card. So no new Anthropic announcement has appeared since 2 September. The 31 August post 'Improving our alignment and security efforts', which the 1 September review had already read, was opened again to confirm it: watermark, SynthID, C2PA, provenance, marking, AI Act and Article 50 return nothing in its body, and its four occurrences of 'detect' are all about detecting unsafe model actions during evaluations. Flagged again on 9 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 7 September 11:43 UTC hashes to exactly 317236f0b6bda3db, the watcher's old baseline, which is also the digest first recorded for this page on 4 September, so the before copy is demonstrably the one the 4 September review read. Diffed word by word against it, today's page differs in exactly one word out of 5,860: the site-wide footer's 'Solutions' list gained 'Commerce', the same insertion that moved anthropic-watermark-explainer and the newsroom index today. The body does not appear in the diff. All three claims above still stand word for word: the 'Compliance with the EU AI Act' section still gives the July 2026 signing with 190 other signatories, still describes the watermark as invisible to anyone without the detection API and carrying no information about the user, their organization or their conversations, and still states the private-preview detection API with the same eligibility list, with 'here' linking https://forms.gle/9tGA33hPJJwtHsMk9. This entry also resolves the anthropic-news proposal of 9 September 2026, since the newsroom index is watched but not cited and has nowhere else to be recorded. The archive's snapshot of the index from 7 September 04:54 UTC hashes to exactly 6fc1856b3887ab8b, the watcher's old baseline for it, and the word-by-word diff against today shows two single-word insertions and nothing else: the footer's 'Commerce', and the category label 'Announcements' filling in on the 31 August row 'Improving our alignment and security efforts', which had been printed without one. No new post has appeared. The list is still ten items long, still headed by 'Developing Enterprise Frontier Safeguards with our customers' of 1 September and still ending at 'Our position on open-weights models' of 27 July, and this post is still the hero card. Flagged again on 10 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 9 September 02:49 UTC hashes to exactly ad906cc11e7f66e2, the watcher's old baseline, so it is demonstrably the copy the 9 September review read. Diffed word by word against it, today's page differs in exactly one place out of 5,859 words, and it is in the site-wide footer: the 'Programs' list renamed 'Research Labs' to 'Scientists'. The article body appears nowhere in the diff. All three claims above still stand word for word, including the 'Compliance with the EU AI Act' section's statement that Anthropic is rolling out a detection API in private preview, available to eligible organisations as required under EU law and to enterprises similarly obligated, with access expanding over time. The same one-word rename is the whole of the change on anthropic-watermark-explainer and on Anthropic's newsroom index, both flagged the same day. The newsroom index was read the same way: its own archived snapshot of 9 September 05:31 UTC hashes to exactly c1bca9c734b21e80, the watcher's old baseline for it, and the diff against today shows that same footer rename and nothing else, so no new Anthropic announcement has appeared since the 9 September review. Re-read on 11 September 2026; the watcher reports this page unchanged, and its visible-text hash is identical to the copy read on 10 September. The 'Compliance with the EU AI Act' section still states the private-preview detection API in the same terms as the help centre. Re-read on 12 September 2026. The watcher could not reach this page in its run today and left its state entry at 11 September, but a hand fetch with the watcher's own user agent returned HTTP 200 and reproduced the visible-text hash e1d393708b17c181 at 5,859 words, identical to the copy read on 11 September. All three claims above were checked against the live text and stand: the 'Compliance with the EU AI Act' section still says 190 other signatories, still describes the watermark as invisible to anyone without the detection API and carrying no information about the user, and still says the detection API is in private preview for eligible organisations and similarly obligated enterprises. Flagged again on 18 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive's snapshot of 13 September 19:49 UTC hashes to exactly e1d393708b17c181, the watcher's old baseline, and its snapshot of 17 September 21:58 UTC hashes to exactly 2e683e38d9b7500c, the watcher's new digest, so both sides of the diff are the copies in question. They differ in one word out of 5,860: the site-wide footer's Solutions list gained 'Sales'. All three claims above stand word for word; the 'Compliance with the EU AI Act' section is untouched. Flagged on 20 September 2026 and re-read end to end. Noise, and shown rather than judged: the Internet Archive holds snapshots of 17 September 21:58 UTC and 20 September 05:41 UTC, and both hash to exactly 2e683e38d9b7500c, the watcher's old baseline, so the before copy is demonstrably the one the 18 September review read. A hand fetch reproduced the watcher's new digest 0f9a44408f0fda00 at 5,870 words. Diffed word by word against the baseline, today's page differs in exactly one place out of 5,870 words: the site footer's copyright line, where '© 2026 Anthropic PBC' became '© 2026 Anthropic PBC. Services in the EU are provided by Anthropic Ireland Limited.' That is shared anthropic.com chrome, and it is what flagged anthropic-watermark-explainer and the newsroom index in the same run. The 20 September 05:41 UTC snapshot still carries the old footer, so the edit landed after that and before the watcher's run. All three claims above stand word for word, including the 'Compliance with the EU AI Act' section, the description of the watermark as invisible to anyone without the detection API and carrying no information about the user, their organisation or their conversations, and the detection API in private preview with access expanding over time."
  },
  "anthropic-docs-c2pa": {
    "n": 13,
    "url": "https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool#content-credentials-on-generated-files",
    "title": "Code execution tool — Content Credentials on generated files",
    "publisher": "Anthropic",
    "date": "accessed 2026-09-18",
    "fetched": "2026-09-20",
    "primary": true,
    "claims": [
      "On the Claude API, supported image, video and audio files that Claude produces in the code execution sandbox carry C2PA Content Credentials when they are downloaded through the Files API.",
      "Supported formats listed: PNG, JPEG, GIF, WebP, TIFF, HEIC, AVIF, SVG, MP4, MOV, MP3, WAV, FLAC and M4A.",
      "The credential is a cryptographically signed manifest embedded in the file's metadata. It identifies Anthropic as the issuer, carries a timestamp, and records the action description 'Claude provided this file at the request of a user and may have created or modified the file contents.'",
      "Signing requires no changes to requests or response handling, and the manifest records nothing about the developer, their organization or their request. The file's visible content is unchanged; the manifest adds a few kilobytes, so the downloaded file's size and checksum differ from the file inside the container.",
      "Text files, PDFs and office documents are not signed, because they are not supported formats for signing. Uploaded files are stored as-is, including any Content Credentials they already carry.",
      "To verify a credential, inspect the file with any C2PA-compatible tool; the page names the open-source c2patool command-line utility.",
      "Re-encoding, format conversion, screenshots and tools that strip metadata remove the credential, so a missing credential does not mean a file was not produced with Claude. For why a credential can be missing, the page links the help centre article (anthropic-help).",
      "The Claude Platform release notes entry of 1 September 2026, read the same day, says text generated by Claude Fable 5.1 and Claude Mythos 5.1 carries Anthropic's text watermark, and that supported image, video and audio files produced through the code execution tool carry C2PA Content Credentials when retrieved through the Files API, with no changes to requests or response handling."
    ],
    "notes": "Added on 18 September 2026, found by following the 'Content Credentials on generated files' link in the help centre article, which the 16 September edit re-pointed from a 404 URL to this section. Read end to end on that date; the page returns HTTP 200 and its visible text hashes to 370e0e0f78dbae8d at 4,439 words. It is a section of the developer documentation for the code execution tool, not a standalone page, and it carries no date of its own; the release notes at https://platform.claude.com/docs/en/release-notes/overview carry the watermark sentence quoted in the last claim under the 1 September 2026 entry. Note what it is and is not. It is Anthropic's first developer-facing documentation of the file marking: it names the issuer, the timestamp, the exact action description, the fourteen signed formats, the unsigned ones (text, PDF, office documents), and a verification route through any C2PA tool. It says nothing about detecting the text watermark, whose documentation remains unpublished, and it scopes the signing it describes to files produced in the code execution sandbox and downloaded through the Files API on the Claude API; the help centre is the source for the Claude apps and cloud partner surfaces. The format list settles the .svg question the help centre's 16 September edit raised: SVG is a signed format. Newly baselined by the watcher on 20 September 2026 at digest 4cbbcd5705ae4f90. This key was added to this file on 18 September and so had no saved digest to diff against, which means the watcher wrote no proposal for it and it had to be read by hand rather than picked out of pending/. Read end to end on 20 September; a hand fetch reproduced the baseline digest 4cbbcd5705ae4f90 at 4,496 words. The seven claims above that live in the 'Content Credentials on generated files' section all stand word for word, including the fourteen supported formats, the action description 'Claude provided this file at the request of a user and may have created or modified the file contents.', the statement that text files, PDFs and office documents are not signed because they are not supported formats for signing, the pointer to the open-source c2patool utility, and the note that re-encoding, format conversion, screenshots and metadata-stripping tools remove the credential so a missing credential does not mean a file was not produced with Claude. The last claim lives on a different page and was checked separately today: the Claude Platform API release notes, under the heading 'September 1, 2026', still say that text generated by Claude Fable 5.1 and Claude Mythos 5.1 carries Anthropic's text watermark and that supported image, video and audio files Claude produces through the code execution tool carry C2PA Content Credentials when retrieved through the Files API, with no changes to requests or response handling; https://platform.claude.com/docs/en/release-notes/api and https://docs.claude.com/en/release-notes/api serve the same page. One thing recorded for the next reviewer: urllib drops the fragment, so the watcher hashes the whole code execution tool page rather than the Content Credentials section, and most of that page is API reference with nothing to do with marking. A future flag on this key will often be noise from elsewhere on the page, and the section is the part to diff."
  }
}
