Claude watermark explained: what it does and whether it can be removed

From 2 August 2026, new Claude models embed an invisible, machine readable mark in every piece of text they generate.
Supported files carry a second layer, signed provenance data.
The change comes from the EU AI Act’s transparency rules. It lands almost exactly where AI 2036, sizrok’s own ten year forecast, said it would.
Three different audiences are reading this news for three different reasons. Teams using Claude who want to know if anything breaks. Platforms and publishers wanting to know if a mark can actually be trusted. And a smaller crowd already searching for ways around it.
This piece speaks to all three, plainly, because that’s the only version of this worth writing.
What we actually said in July
The two dates we named
AI 2036’s regulation section made a specific, dated claim.
Transparency obligations apply from 2 August 2026. Watermarking requirements for AI generated content follow on 2 December 2026. That was the law’s own staggered timetable, and we named it rather than hedge it.
What happened next is the more interesting part.
Rather than wait for December, the labs that signed the EU’s voluntary Code of Practice on Transparency, Anthropic included, pulled watermarking forward to the same August date as the general transparency duty. We named the right law and the right two dates. Industry just moved faster than the strict deadline required.
Our own copy isn’t exempt
Worth being straight about our own copy here too, since honesty is the whole point of this piece.
Parts of sizrok’s content library have run through a model at some point in the drafting process. This piece included. Edited, checked and owned by us the same way we’d expect from any client’s build.
That’s not a confession. It’s the same standard the industry is about to be held to by law.
What the watermark actually does
How it’s embedded

The mark sits inside the text itself, not in a separate file or header.
Anthropic says it leaves the response untouched, same meaning, same quality, same readability. It survives copying and pasting into another document.
Supported file types carry a second layer too, signed provenance metadata built on the C2PA standard. Several other providers are converging on the same approach.
What it doesn’t do

Anthropic is candid about the limits.
Short passages
Short passages may not carry enough signal to detect reliably. There isn’t enough text for the pattern to sit inside.
Heavy editing
Heavy editing can weaken a text watermark. The more a person rewrites, the less of the original signal survives.
Neither of these is a loophole Anthropic is hiding. Unmarked content doesn’t prove a human wrote it, and a marked passage doesn’t prove a machine wrote all of it. Someone can run their own writing through Claude for a light edit and the output still carries a mark.
More labs are converging on the same approach
Who’s signed
Anthropic isn’t moving alone.
Google has expanded its own SynthID watermarking beyond Gemini, opening it to Apple, ElevenLabs, Kakao, NVIDIA and OpenAI as partners.
Meta signed the EU’s Transparency Code too, notable given it stayed out of the broader GPAI code covering training data and copyright.
Suno started marking AI generated tracks after legal pressure. Substack partnered with Pangram to flag AI generated newsletters.
By the end of July 2026, close to 190 companies had signed the Code of Practice.
What this becomes
This isn’t one company’s decision anymore.
It’s becoming the default shape of a generated file, the same way a phone camera has always stamped a photo with when and where it was taken.
The legislation still has two more steps

Two dates sit ahead on the same calendar AI 2036 flagged.
2 December 2026
The AI Act’s own broader watermarking duty for AI generated content lands here. It catches providers who didn’t sign the voluntary code and didn’t move early.
Under the code most major labs already signed, free form text over 200 tokens carries an imperceptible watermark from 2 August 2026, the date that had already passed by the time this piece went up.
2 February 2027
Signatories need a working watermark detection system in place by here. One that lets a platform actually check a piece of content against the mark, rather than trust it’s there.
That’s the part with real teeth. A watermark nobody can verify is a promise. A watermark with a published detection method is closer to an audit trail.
The UK question
The UK angle from AI 2036 is still unresolved on its own terms.
Burnham’s government has signalled interest in mandatory human in the loop rules and audit trail requirements of its own. None of that is law yet.
But EU rules already reach any UK business serving EU clients regardless of what Westminster decides, exactly as the forecast argued.
Where Kimi and Qwen sit outside this
Who’s missing
Not every model provider is part of this.
Alibaba’s Qwen and Moonshot’s Kimi are notably absent from the Code of Practice signatory list, in the same way Alibaba sat outside the EU’s earlier general purpose AI code alongside DeepSeek.
The AI Act’s transparency duties technically reach any provider whose output lands with EU users, open weight or not.
But a legal duty on paper and a shipped watermark with a published detection method by a fixed date are different things. Holding a fellow code signatory to a shared commitment and pursuing enforcement against a lab with no EU office and no EU revenue are different exercises entirely.
What “unmarked” will start to mean
The practical result matters more than the politics of it.
As Western frontier labs start marking their output by default, an unmarked piece of text stops being reliable evidence that a person wrote it.
It increasingly means the opposite is just as likely, that it came from a model that never joined the scheme in the first place.
Provenance is about to get more visible for some models and stay exactly as invisible as it always was for others. Anyone using content authenticity as a filter, in hiring, in publishing, in procurement, needs to know which half of that picture they’re actually looking at.
What about watermark removers
This is the search a smaller, quieter audience is already running. Worth answering directly rather than pretending nobody’s asking.
Can it actually be removed
Not cleanly, and not by design.
Anthropic built the mark to survive copying, pasting and normal editing. Independent researchers have shown that other providers’ watermarking schemes can be weakened with enough rewriting, and Anthropic itself says heavy editing can degrade the signal.
That’s different from a working removal tool. A search for a watermark remover mostly turns up services promising to strip a mark, not proof that they reliably do.
What a stripped watermark doesn’t fix
Detection moves to a second layer
Even a successfully weakened watermark doesn’t make content untraceable on its own.
The interoperability requirement landing 2 February 2027 lets a platform check content against a provider’s own detection system, not just look for a visible mark sitting in the text.
Style and metadata still point back
Structure, phrasing patterns and file metadata can all still point back to how something was produced, watermark aside.
Stripping one signal doesn’t remove the others.
The more durable answer isn’t a better removal tool. It’s not needing one. Be straight about where a draft started, and the watermark stops being a threat and starts being irrelevant.
What this actually changes for your workflow
For most people, nothing changes
The mark is invisible. It doesn’t change what Claude writes or how it reads.
It applies automatically across every surface, Claude Platform, Claude, Claude Code, Claude Cowork and Claude Tag.
Drafting an email, a report, a piece of code, a first pass at a page of copy, none of that changes. Nobody needs to opt in, configure anything or tell a client which parts a model touched first.
Where it’s worth pausing
Anywhere content authenticity already mattered before this news is worth a second look now.
Publishers. Agencies producing content for clients. Anyone marking written work. Anyone running SEO or AEO content at volume.
If a platform starts checking submissions against Claude’s mark, the honest answer to give a client or a reader is the same one this piece already gave about itself. A model touching a draft at some point isn’t the problem. Passing it off as untouched when someone asks is.
None of this changes sizrok’s actual forecast.
Regulation was always the more likely brake on the industry’s wilder claims, not compute alone, and the last few weeks made that case for us rather than the other way round. The watermark didn’t need us to be right about it. It just happened on schedule.
If any of this touches how your team produces or relies on AI generated content, an audit is the place to start, not a guess. Sixty minutes, a written recommendation either way, whether or not we build anything after it. Run the audit
Frequently asked questions
What is the Claude watermark?
It’s an invisible, machine readable signal Anthropic embeds directly inside text generated by Claude models launched on or after 2 August 2026. It survives copying and pasting, doesn’t change the meaning or quality of the response, and applies across every Claude surface, including the API, the Claude app, Claude Code and Claude Cowork.
Does the watermark change what Claude writes?
No. Anthropic says the mark leaves meaning, quality and readability untouched. It sits underneath the text as a detection signal, not as a visible or functional change to the output itself.
Will other AI companies add watermarks too?
Most already have or are committed to it. Google, OpenAI, Microsoft, Mistral and Meta all signed the EU’s Code of Practice on Transparency, and close to 190 companies had signed by the end of July 2026. Google has also opened its SynthID watermarking to partners including Apple and ElevenLabs.
Do Chinese AI labs like Qwen and Kimi watermark their output?
Not as part of this scheme. Alibaba’s Qwen and Moonshot’s Kimi are absent from the Code of Practice signatory list, so their output is unlikely to carry the same machine readable mark, even though EU transparency rules technically apply to any provider whose content reaches EU users.
What legislation is still coming?
The EU AI Act’s own watermarking duty for AI generated content applies from 2 December 2026, catching providers who didn’t move early under the voluntary code. A watermark detection interoperability requirement follows on 2 February 2027, meaning platforms will be able to check content against a provider’s mark rather than take it on trust.
Does this affect businesses using Claude for content or automation?
Not in how Claude works day to day. The change is invisible and automatic. It matters more for businesses where content authenticity is already scrutinised, publishers, agencies, education, and high volume SEO content, where being straightforward about where a draft started matters more than the watermark itself.
Can you remove the Claude watermark?
Not reliably. Heavy editing can weaken the signal, and short passages may not carry enough of it to detect in the first place, but that’s different from a tool guaranteeing removal. Most services claiming to strip AI watermarks don’t publish evidence they actually work.
Is there a way to check if text has a Claude watermark?
Anthropic has said it will publish technical detection guidance, aimed at platforms and third parties rather than individual searches. A public, one click checker isn’t confirmed yet. Treat any third party tool claiming to detect it with caution until Anthropic’s own guidance lands.
Does paraphrasing remove the watermark?
It can weaken it, according to Anthropic’s own description of the system’s limits, but weakening a signal isn’t the same as removing it reliably. The safer assumption for any business is that heavily edited AI drafted content may still be detectable, not that it definitely isn’t.
Do image watermarks work the same way as text ones?
No. Claude’s text watermark is woven into the words themselves. Supported image and file formats instead carry C2PA metadata, a signed record attached to the file rather than hidden inside pixels. Metadata is easier to strip through a screenshot or format conversion than a text watermark is to remove through editing.

