Last updated: August 13, 2026
FSR did not test Claude’s marking, run a detector, or inspect a generated file. Every statement below comes from a document FSR opened directly on 13 August 2026, listed in the methodology.
A Claude text watermark is a machine-readable signal that Anthropic says supported Claude models embed while generating text. A compatible detector can test for it. As of 13 August 2026, Anthropic has not published which models carry it, how it works, or a detector that customers can run. A detected mark would indicate that Claude may have processed the content. It would not establish who wrote it.
Verdict in one line: treat the mark as one provenance signal among several, because the public record does not yet let a buyer confirm which outputs carry it or reproduce a result.
Two dates matter, and neither of them tells you the state today.
The first marked model is whichever model Anthropic launches next. That follows from its own rule, which keys marking to models launched on or after 2 August 2026. Anthropic publishes no model roadmap, so no date attaches to it.
The date in the Regulation is 2 December 2026. That is the deadline for the Article 50(2) marking duty as it applies to generative AI systems placed on the Union market before 2 August 2026. Anthropic has not published how it maps its own products to that provision, so this briefing does not assign the date to any particular Claude system.
Neither answer can be checked from outside. The watermark is imperceptible by design, the scheme is unpublished, no public detector exists, no supported-model list exists, and the help page’s “What’s covered” section is written in the present tense. From outside Anthropic, neither the presence nor the absence of a mark in a given output can currently be demonstrated.
Anthropic updated a help center article to say it has signed the provider section of the EU’s transparency Code of Practice, and that Claude models launched in the EU on or after 2 August 2026 will carry machine-readable marking at launch. FSR located no announcement post and no release note entry for the change.
- Teams routing Claude output into products, client work, or public-facing content
- Procurement and governance leads writing vendor evidence requirements
- Anyone designing a content provenance record
- Prove that a person did or did not write a given text
- Decide a misconduct or contract dispute
- Determine whether any product or publication complies with any law
| Question | Public answer | Evidence class |
|---|---|---|
| Does Claude mark generated text? | Anthropic says supported models embed a watermark in generated text | Vendor claim |
| Which model IDs are covered? | No dated list located | Documentation gap |
| When does marking start? | Anthropic’s rule points to its next model launch, with no date published. The Regulation’s deadline for pre-existing systems is 2 December 2026. | Vendor rule and regulation |
| Which surfaces are named? | API, Claude, Claude Code, Cowork, Tag, and named partner clouds | Vendor claim |
| Do all file paths get provenance metadata? | Applies where Claude supports processing files; may vary by platform | Vendor limitation |
| Is a public detector available? | None located; Anthropic says documentation is forthcoming | Documentation gap |
| Is the scheme disclosed? | No | Documentation gap |
| Is an opt-out documented? | No public control located in the recorded search | Search-scoped finding |
| Do the terms address removing a mark? | No such term in the five documents read | Search-scoped finding |
| Who owns the marked output? | Anthropic assigns its rights in Outputs to the customer | Contract term |
| What does a positive result mean? | Content may have been processed by Claude | Vendor limitation |
| What does a negative result mean? | Claude use is not ruled out | Vendor limitation |
What Anthropic documented
Anthropic’s help center article states that the company signed the EU AI Act’s Article 50(2) Code of Practice on Transparency of AI-Generated Content as a provider of both generative AI models and generative AI systems. It commits to four things: new models mark from launch, marking applies wherever Claude is offered, the company will support detection, and existing models are in progress.

The page gives its own scope twice, in two different forms. The commitments section says Claude models launched in the EU on or after 2 August 2026 will support machine-readable marking at launch. The section headed “What’s covered” drops the EU qualifier and shifts to present tense: models launched on or after 2 August 2026 support marking at launch. FSR read the page on 12 and 13 August 2026 and both formulations were present on both dates. The page does not define what counts as a launch event. A global announcement date, first availability through Anthropic’s API, first availability in an EU region, and first availability through a cloud partner are four different dates for the same model.
The page also states that the watermark does not change the meaning, quality, or readability of Claude’s response. FSR located no public evaluation, benchmark, or sample size behind that statement. The Code does not require one to be public: Measure 4.2 provides that until recognized evaluation methods emerge, signatories test and report against internal benchmarks, subject to review by market surveillance authorities. Google’s SynthID-Text offers a disclosure benchmark rather than a competing product claim, having been published in Nature with a reported production deployment and quality evaluation in Gemini. Anthropic’s equivalent claim currently arrives without a paper attached.
Sources: Anthropic Claude Help Center, accessed 13 August 2026 · European Commission, Code of Practice, June 2026, Measure 4.2, p.21 · Nature, 23 October 2024
Which Claude models are covered
This is the question readers arrive with, and the public record does not answer it.
Anthropic has not published a dated list of models that mark output. It has not named a covered model, and it has not named a pre-August model as retrofitted. The help page says retrofit work is in progress and that the page will be updated. FSR inspected Anthropic’s release notes for 2 August to 12 August 2026 and found no model launch entry in that window.
The obvious defense is that a help center is not the place for a compliance matrix. Anthropic’s own help center answers that one.
In the same Privacy and legal collection, Anthropic maintains a page called Covered Models. It is a dated per-model, per-surface policy register. It gives each designated model a name, a designation date, a status, and an availability list spanning Claude applications, Claude Platform, Amazon Bedrock, Google Cloud Agent Platform, and Microsoft Foundry. It states that policies take effect for a model on every surface where it is offered, and that the list will be updated as designations change. Two models are currently listed, Claude Mythos 5 and Claude Fable 5, both designated 9 June 2026. The page concerns capability thresholds and data retention, not marking.
So the artifact shape exists. Anthropic builds and maintains exactly this register, in this help center, for a different policy. No equivalent page exists for marking.
The same gap governs timing. Anthropic’s rule identifies the first marked model as whichever model it launches on or after 2 August 2026, which means the answer arrives on a date Anthropic has not published. The Regulation supplies the other date: providers of generative AI systems placed on the Union market before 2 August 2026 must meet the Article 50(2) marking duty from 2 December 2026. Anthropic has not stated which of its products it treats as placed on the market before that cutoff, so the mapping is unresolved from public sources.
That leaves a state a customer cannot test in either direction. The watermark is imperceptible by Anthropic’s own description, the scheme is unpublished, no detector is available, and the “What’s covered” section is written in the present tense. A reader who wants to know whether today’s output is marked has no way to find out, and equally no way to establish that it is not.
That narrows the finding to something durable and checkable:
A customer cannot determine from Anthropic’s published sources whether a specific output carries a mark, or when a specific model will, and the absence is not explained by a lack of format or capability.
A dated document mapping model IDs, retrofit status, product surfaces, cloud partners, and file types would resolve this section entirely.
Sources: Anthropic Claude Help Center, accessed 13 August 2026 · Anthropic Claude Help Center, Covered Models, 1 July 2026 · Anthropic Claude Help Center release notes, accessed 12 August 2026
What a detected mark can show
Anthropic is direct about the limits, and those limits are the operational core of this topic.
| Result | Supported reading | Unsupported reading |
|---|---|---|
| Mark detected | Claude may have processed the content | Claude authored the work |
| No mark detected | No supported mark was found | Claude was not used |
| No detector access | The result cannot be independently reproduced | The content is unmarked |
| Provenance metadata present | A supported file was processed and the record survived | Every element was generated by Claude |
| Provenance metadata absent | No supported record is present now | Claude never touched the file |
Anthropic states that people often use Claude to proofread, translate, summarize, or convert files, and that output can carry a mark even where the underlying ideas, text, or data came from elsewhere. It also lists five reasons a mark may be absent: an older model, heavy editing or paraphrasing or translation, mixing with other writing, a passage too short to carry a reliable signal, and metadata stripped by format conversion, re-saving, or screenshots.
The Code sets the durability bar in the same territory. Measure 3.3 requires marking and detection solutions to be robust to a named list of processing operations that includes lexical substitution, homoglyphs, change of file format, screenshotting, character insertion and deletion, paraphrasing, and translation cycles.
Independent research treats that list as the hard part. “Watermark under Fire,” published in the Findings of EMNLP 2025, assembled a platform integrating ten watermarking methods and twelve removal attacks, including paraphrasing attacks driven by a language model, in order to assess robustness systematically. Its scope is published schemes. Anthropic has not disclosed its scheme, so no published attack result can be applied to Claude, and FSR cannot test Claude’s mark from current public materials.
Sources: Anthropic Claude Help Center, accessed 13 August 2026 · European Commission, Code of Practice, June 2026, Measure 3.3, p.18 · Findings of EMNLP 2025, November 2025
Detector access and the evidence chain
Without documented detector access, a customer cannot reproduce or challenge a result. No public Claude detector, API reference, or access instruction was located. Anthropic says details will come in forthcoming documentation and publishes no date.
The Code fills in what a signatory has committed to, and the detail matters more than the headline.

Detection is free, as an obligation. Sub-measure 2.1.1 states that signatories will make the detection solution available free of charge. A fee is permitted only for signatories with fewer than one million monthly users of their generative AI system whose detection solution incurs substantial operational costs, and only where a single user exceeds a reasonable request threshold. Free access without volume restriction is guaranteed to regulators, law enforcement, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions, and civil society organizations.
Text detection can be restricted. Sub-measure 2.1.2 permits signatories to restrict access to detection mechanisms associated with watermarking techniques for free-form text, on the stated grounds that those mechanisms have lower reliability and robustness and may produce misleading or low-confidence results. Where that restriction applies, access goes to verified expert end-users with a legitimate need, subject to access controls, and the restriction is to be limited in time. A person contesting an accusation about their own writing is not on that list.
Interoperability has a date, and it is not a detector launch date. Measure 3.4(c) commits signatories to implement an interoperability solution for their detection mechanisms by 2 February 2027, through a standard access method, a public signpost, a shared consortium solution, or an equivalent. That is a commitment about routing detection queries, not a promise that a consumer-facing detector will exist on that day.
One safeguard is worth requesting by name. Sub-measure 2.1.2 also commits signatories to ensuring that a detection result for submitted content can be downloaded on request in a digitally signed format, containing at least a hash of the submitted content, an identifier of the detection solution, and a timestamp. In a dispute, that record is the artifact, not a screenshot.
Sources: European Commission, Code of Practice, June 2026, Sub-measures 2.1.1 and 2.1.2, pp.12-14, and Measure 3.4, p.19 · Anthropic Claude Help Center, accessed 13 August 2026
Files, formats and provenance metadata
For files, Anthropic describes one mechanism: digitally signed provenance metadata following the C2PA standard. The page names .svg, .png, and .jpg as examples, states that provenance metadata will apply where Claude supports processing files, and adds that signed provenance metadata may not be supported on every cloud platform. No second file-level mechanism is described.
The Code separates content types in a way that changes how this reads. Measure 1.1 commits signatories to a multi-layered approach of at least two layers, signed metadata plus imperceptible watermarking, for audio, images, video, and containerised text. It then carves out two single-layer cases: generative systems embedded in physical products in a closed environment, and free-form text, on the stated ground that free-form text cannot transport metadata. The glossary defines containerised text as text inside a structured format and names PDFs, Word documents, and HTML files as examples.
Images sit in the two-layer group. So do the document formats Claude can produce.
FSR states no compliance conclusion here. The same measure allows signatories to rely on alternative techniques, or a single technique, where they can prove to market surveillance authorities that it achieves at least equivalent robustness, reliability, effectiveness, and interoperability. Whether Anthropic operates file mechanisms it has not described publicly is unknown.
What remains is a concrete procurement gap. The phrase “where Claude supports processing files” is doing a lot of work and is nowhere expanded. Anthropic names three image formats and states nothing about PDF, DOCX, PPTX, XLSX, or HTML output. The fields inside its C2PA record are not published, although the Code encourages richer provenance information while steering signatories away from including privacy-sensitive or business-sensitive material. A team relying on file provenance through an export pipeline, a content management system, or a partner cloud needs the file-type matrix, and there is no published answer.
Sources: European Commission, Code of Practice, June 2026, Measure 1.1 and Sub-measure 1.1.1, pp.8-9, glossary p.22 · Anthropic Claude Help Center, accessed 13 August 2026 · Coalition for Content Provenance and Authenticity, accessed 12 August 2026
The contract layer and what it omits
Marking commitments eventually have to land somewhere a customer signs. This is the layer nobody has checked.
Code Measure 1.2 addresses non-removal of markings. Its point (b) is written in the Code’s mandatory register: signatories will include, in the acceptable use policy, the terms and conditions, or the documentation accompanying their generative AI system, a prohibition on the intentional removal of or tampering with metadata markings by deployers or any other third party. Legitimate processing purposes are carved out. The Code defines “will” as a measure that must be met for a signatory to be compliant with Article 50(2) and (5), and which market surveillance authorities will monitor.
The Code names three possible homes for that prohibition. FSR read documents covering all three, in full, on 13 August 2026.
| Document | Route | Effective or updated | Prohibition located |
|---|---|---|---|
| Usage Policy | Acceptable use policy | 15 September 2025 | No |
| Consumer Terms of Service | Terms and conditions | 8 October 2025 | No |
| Commercial Terms of Service | Terms and conditions | 17 June 2025 | No |
| Claude Code legal and compliance docs | Accompanying documentation | Accessed 13 August 2026 | No |
| The marking help article itself | Accompanying documentation | Accessed 13 August 2026 | No |
Across all five, the words metadata, watermark, marking, provenance, and C2PA do not appear, except in the marking article itself, which describes limitations rather than imposing an obligation. The three legal documents carry effective dates that precede the Code’s publication on 10 June 2026 and Anthropic’s appearance on the signatory list.
The scope has to stay there. Anthropic publishes service-specific terms and a data processing addendum that FSR did not read for this briefing, and a customer with a negotiated enterprise agreement may hold terms that are not public. What is established is that the documents a customer actually accepts, plus the accompanying documentation for the product surface most likely to touch machine-readable artifacts, do not contain it as of the access date.
Two adjacent terms cut the other way and belong in the same reading.
The Usage Policy already restricts passing off output as human. Its Universal Usage Standards prohibit impersonating a human by presenting results as human-generated, and separately prohibit plagiarizing or submitting AI-assisted work without proper permission or attribution. Those obligations exist independently of any watermark and independently of the AI Act.
The Usage Policy also names published media as a high-risk use case. Its High-Risk Use Case list includes using Anthropic’s products to automatically generate content and publish it for external consumption, under the heading of media or professional journalistic content. The additional measures attached to high-risk use cases are a human-in-the-loop requirement, where a qualified professional reviews the content before dissemination, and a disclosure requirement where model outputs are presented directly to individuals or consumers. Each measure carries its own trigger wording, so the mapping to any specific publishing workflow is a question for the reader’s own facts. The direction is still notable: an organization publishing auto-generated content has already agreed to something adjacent to the EU disclosure debate, through the vendor rather than the regulator.
And the output is yours. The Consumer Terms assign Anthropic’s right, title, and interest in Outputs to the user, subject to compliance with the terms. The Commercial Terms state that the customer owns its Outputs and that Anthropic assigns its interest in them. So a customer owns an artifact that, by Anthropic’s own description, may carry a signal the customer cannot detect, cannot verify, and has no documented control over. Ownership and inspectability have come apart, and no published document closes the distance.
Sources: European Commission, Code of Practice, June 2026, Measure 1.2 and Commitments preamble, pp.7 and 10-11 · Anthropic Usage Policy, effective 15 September 2025, accessed 13 August 2026 · Anthropic Consumer Terms of Service, effective 8 October 2025, accessed 13 August 2026 · Anthropic Commercial Terms of Service, effective 17 June 2025, accessed 13 August 2026 · Anthropic Claude Code documentation, accessed 13 August 2026
Where the publisher duty actually sits
A Claude mark and a publisher’s disclosure decision are different controls, and one does not settle the other.
Article 50(2) concerns providers of generative AI systems and the machine-readable marking of outputs. Article 50(4) concerns deployers, and its text limb applies to text published for the purpose of informing the public on matters of public interest. Publishing AI-assisted output does not by itself trigger it. The obligation does not apply where the content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication. The Commission describes human review as deliberate examination of the substance by a person with relevant knowledge and professional judgment. A spelling or grammar pass does not qualify.
FSR’s separate briefing sets out the four duties, the two actors, the transition dates, the Code’s legal status, and a vendor evidence pack in full: EU AI Act Article 50: The Law, the Code of Practice, and What a Buyer Can Verify. Read that one for the legal architecture. This briefing stays with what Anthropic has and has not documented about Claude.
The Regulation sets the duty and the exemption. The Commission’s guidance interprets terms such as human review and public interest. The Code of Practice is a voluntary route for signatories, and its Section 2 adds commitments the statute does not impose on every publisher, including identifying the person with editorial responsibility and publishing their contact details. FSR’s suggestion below is operational governance, not a legal test. Case-specific questions belong with qualified counsel.
For internal governance, the useful record answers what a watermark cannot. Log the model identifier, the product or API surface, the cloud partner where relevant, the generation date, the source materials, who reviewed the substance, what changed, who approved publication, and what disclosure decision was made and why. Keep drafts and edit history where authorship may later be disputed. If a detector appears, record its version, timestamp, output, and retention terms.
Sources: European Commission, last updated 24 July 2026 · European Commission, last updated 6 August 2026 · European Commission, Code of Practice, June 2026, Section 2 Commitment 1, p.29
FAQ
Does Claude watermark every response?
Anthropic says supported models embed a watermark in generated text. It has not named which models are supported, so a customer cannot confirm coverage for a specific output. The Code also excepts very short text and, as of publication, treats that as text shorter than 200 tokens.
Which Claude models are marked?
No model has been named. Anthropic’s rule is keyed to models launched on or after 2 August 2026, with retrofit work described as in progress and no date given. Anthropic maintains a dated per-model register for another policy, but not for marking.
When does Claude start watermarking?
Anthropic’s rule points to its next model launch, and no roadmap is published. The Regulation sets 2 December 2026 as the Article 50(2) deadline for generative AI systems placed on the Union market before 2 August 2026. Anthropic has not mapped its products to that provision.
Is there an official Claude watermark detector?
None was located. Anthropic says detection details are forthcoming without a date. The Code’s dated item is an interoperability solution for detection mechanisms by 2 February 2027, which is not the same as a public detector launch.
Can the watermark be disabled?
No public API parameter, admin setting, plan tier, or regional control that disables marking was located in FSR’s search of Anthropic’s published sources. That is a documentation finding within a recorded search scope, not evidence that no private mechanism exists.
Do Anthropic’s terms say anything about removing a mark?
Not in the five documents FSR read on 13 August 2026. The Usage Policy, Consumer Terms, Commercial Terms, Claude Code legal documentation, and the marking article contain no prohibition on removing or tampering with markings, and no reference to metadata or provenance at all.
Does a mark prove Claude wrote the text?
No. Anthropic states a detected mark indicates content may have been processed by Claude and does not on its own confirm provenance. Human-authored work that was proofread, translated, summarized, or converted through Claude can carry the same mark.
Does Claude Code output carry a mark?
Anthropic lists Claude Code among covered surfaces, but a product surface is not an output category and neither the marking page nor the Claude Code legal documentation addresses code specifically. The Commission’s guidance places source code outside the Article 50(2) marking obligation. FSR did not establish Claude’s behavior here.
Does file metadata survive export and upload?
Anthropic says a file’s metadata can be stripped through format conversion, re-saving, screenshots, or other means. FSR has not tested survival through any specific platform pipeline, which would require controlled testing this briefing did not perform.
Sources: Anthropic Claude Help Center, accessed 13 August 2026 · Anthropic Usage Policy, accessed 13 August 2026 · European Commission, Code of Practice, June 2026, Sub-measure 1.1.2 p.9, Measure 3.4 p.19, glossary p.24
Methodology and evidence status
Evidence class. Tier C, document-first. FSR did not test Claude’s marking, run any detector, inspect a generated file, or measure anything. No observational claim appears in this briefing.
Documents opened directly. Anthropic: the marking help article, release notes, the Covered Models page, the Usage Policy, the Consumer Terms of Service, the Commercial Terms of Service, and the Claude Code legal and compliance documentation. European Commission: the full Code of Practice PDF, the Article 50 questions and answers, the Guidelines on transparency obligations, the Code of Practice policy page, and the signatory list. Coalition for Content Provenance and Authenticity: the frequently asked questions.
Lock day. The marking help article and all Anthropic legal documents were re-read on 13 August 2026. The two scope formulations described in section 01 were present on both 12 and 13 August.
Signatory status. On the Commission’s signatory page, Anthropic appears under Section 1, covering provider marking and detection, and does not appear under Section 2, covering deployer labeling. That is a page state on the access date, the Commission updates the list on an ongoing basis, and section signature determines nothing about any customer’s own obligations.
Absence statements. Where this briefing reports that something was not located, the scope is the documents listed above on the access dates given.
Not established. The identity of any marked model. The meaning of “launched in the EU.” Whether any private, partner, or regulator-facing detector exists. Anthropic’s watermarking scheme, thresholds, or error rates. Any opt-out, public or contractual. Whether a marking-removal prohibition appears in Anthropic’s service-specific terms, data processing addendum, or negotiated enterprise agreements, none of which were read here. The fields in Anthropic’s C2PA record. Whether a second file-marking layer exists. Whether source code output specifically carries a mark. Per-platform survival of provenance metadata. Pricing or plan treatment of detector access. Whether the Japanese-language version of the marking article differs in scope or tense.
Excluded on purpose. Social media posts were treated as signal and none is cited. Statements attributed to individual employees on social platforms were not used. Secondary reporting was not used as a source of fact. Third-party sites using Claude product names were not treated as Anthropic sources. Outputs from external AI research tools were treated as leads and admitted only where FSR opened the underlying document. Two research figures that appeared in an earlier draft were removed rather than published, because FSR had not read them in the source papers directly.
Disclosure. FSR uses AI systems, including Claude, in its research and drafting workflow. No vendor paid for, reviewed, or approved this briefing. FSR holds no affiliate relationship with any company named. This is an editorial process disclosure and not a compliance conclusion.
Change log
| Date | Change |
|---|---|
| 13 August 2026 | Initial evidence audit published |
Verdict
The buyer problem is the missing coverage map, not the existence of the watermark.
Anthropic’s commitment is broader than the law requires in one respect, applying worldwide rather than only in the EU, and it is unusually candid about what a mark does not prove. What has not been published is the operational layer: no model list, no surface behavior confirmation, no file-type coverage, no definition of the triggering launch event, no detector, no access terms, no opt-out or a statement that none will exist, no evaluation behind the quality claim, and, in the five documents a customer accepts or is pointed to, no term about markings at all. Anthropic maintains a dated per-model policy register for a different question, which removes the simplest explanation for the absence. Together these mean the honest answer to “is this output marked” comes from Anthropic or from nowhere.
Timing inherits the same problem. The first marked model arrives on a date Anthropic has not published, and the Regulation’s deadline for systems already on the Union market before 2 August 2026 is 2 December 2026, a provision Anthropic has not mapped to its own products in public. Between now and whichever of those comes first, a customer cannot establish that a given output is marked, and cannot establish that it is not.
Approve Claude for a provenance-sensitive workflow only as a supplementary signal, alongside your own generation logs, retained drafts, and substantive human review. Do not use the mark as the sole basis for a provenance, authorship, or disclosure decision, and do not promise a client that output is unmarked.
Put these in the vendor file: the dated model and surface matrix, the file-type coverage list, detector availability and eligibility, error-rate and inconclusive-state behavior, detection data retention, the signed-result format, any control or opt-out setting, the contractual treatment of marking removal and where it is recorded, and the change-notification process.
What would change this verdict. A dated Anthropic document mapping model IDs, retrofit status, product surfaces, cloud partners, file types, detector access, and control settings would resolve most of this briefing. FSR will update this page when one appears.
Tier B means hands-on tested. Tier C means document-first.
- TIER C EU AI Act Article 50: The Law, the Code of Practice, and What a Buyer Can VerifyThe legal architecture this briefing assumes: four duties, two actors, the transition dates, and what a Code signature does and does not establish.
Found an error, or have a document that changes this briefing? FSR corrects on the record and logs every correction. Vendor responses are published.
Future Stack Reviews publishes independent structural audits for technical buyers. This briefing is not legal advice and states no conclusion about whether any product, organization, or publication complies with any law. Readers with a specific question should consult qualified counsel in their jurisdiction.
Last updated 13 August 2026. Source pages were accessed on 12 and 13 August 2026 and are subject to change without notice. Recheck trigger: publication of an Anthropic supported-model matrix or detector documentation.