NewFree sixty minute diagnostic on the work you would most like off your team. Written recommendation either way, whether or not we build it. Book it

Claude watermark explained: what it does and whether it can be removed

A block of placeholder text with one word on each line marked in orange, forming a diagonal thread down the paragraph

From 2 August 2026, new Claude models embed an invisible, machine readable mark in every piece of text they generate.

Supported files carry a second layer, signed provenance data.

The change comes from the EU AI Act’s transparency rules. It lands almost exactly where AI 2036, sizrok’s own ten year forecast, said it would.

Three different audiences are reading this news for three different reasons. Teams using Claude who want to know if anything breaks. Platforms and publishers wanting to know if a mark can actually be trusted. And a smaller crowd already searching for ways around it.

This piece speaks to all three, plainly, because that’s the only version of this worth writing.

What we actually said in July

The two dates we named

AI 2036’s regulation section made a specific, dated claim.

Transparency obligations apply from 2 August 2026. Watermarking requirements for AI generated content follow on 2 December 2026. That was the law’s own staggered timetable, and we named it rather than hedge it.

What happened next is the more interesting part.

Rather than wait for December, the labs that signed the EU’s voluntary Code of Practice on Transparency, Anthropic included, pulled watermarking forward to the same August date as the general transparency duty. We named the right law and the right two dates. Industry just moved faster than the strict deadline required.

Our own copy isn’t exempt

Worth being straight about our own copy here too, since honesty is the whole point of this piece.

Parts of sizrok’s content library have run through a model at some point in the drafting process. This piece included. Edited, checked and owned by us the same way we’d expect from any client’s build.

That’s not a confession. It’s the same standard the industry is about to be held to by law.

What the watermark actually does

How it’s embedded

Timeline of three EU AI Act dates. 2 August 2026 is marked as already in force, followed by 2 December 2026 and 2 February 2027

The mark sits inside the text itself, not in a separate file or header.

Anthropic says it leaves the response untouched, same meaning, same quality, same readability. It survives copying and pasting into another document.

Supported file types carry a second layer too, signed provenance metadata built on the C2PA standard. Several other providers are converging on the same approach.

What it doesn’t do

Two panels side by side. On the left, a watermark woven into the words of a text block. On the right, C2PA signed metadata attached to a file from the outside

Anthropic is candid about the limits.

Short passages

Short passages may not carry enough signal to detect reliably. There isn’t enough text for the pattern to sit inside.

Heavy editing

Heavy editing can weaken a text watermark. The more a person rewrites, the less of the original signal survives.

Neither of these is a loophole Anthropic is hiding. Unmarked content doesn’t prove a human wrote it, and a marked passage doesn’t prove a machine wrote all of it. Someone can run their own writing through Claude for a light edit and the output still carries a mark.

More labs are converging on the same approach

Who’s signed

Anthropic isn’t moving alone.

Google has expanded its own SynthID watermarking beyond Gemini, opening it to Apple, ElevenLabs, Kakao, NVIDIA and OpenAI as partners.

Meta signed the EU’s Transparency Code too, notable given it stayed out of the broader GPAI code covering training data and copyright.

Suno started marking AI generated tracks after legal pressure. Substack partnered with Pangram to flag AI generated newsletters.

By the end of July 2026, close to 190 companies had signed the Code of Practice.

What this becomes

This isn’t one company’s decision anymore.

It’s becoming the default shape of a generated file, the same way a phone camera has always stamped a photo with when and where it was taken.

The legislation still has two more steps

Four blocks of text showing the watermark weakening. Full output and lightly edited are detectable, heavily rewritten is degraded, and a short passage carries too little to tell

Two dates sit ahead on the same calendar AI 2036 flagged.

2 December 2026

The AI Act’s own broader watermarking duty for AI generated content lands here. It catches providers who didn’t sign the voluntary code and didn’t move early.

Under the code most major labs already signed, free form text over 200 tokens carries an imperceptible watermark from 2 August 2026, the date that had already passed by the time this piece went up.

2 February 2027

Signatories need a working watermark detection system in place by here. One that lets a platform actually check a piece of content against the mark, rather than trust it’s there.

That’s the part with real teeth. A watermark nobody can verify is a promise. A watermark with a published detection method is closer to an audit trail.

The UK question

The UK angle from AI 2036 is still unresolved on its own terms.

Burnham’s government has signalled interest in mandatory human in the loop rules and audit trail requirements of its own. None of that is law yet.

But EU rules already reach any UK business serving EU clients regardless of what Westminster decides, exactly as the forecast argued.

Where Kimi and Qwen sit outside this

Who’s missing

Not every model provider is part of this.

Alibaba’s Qwen and Moonshot’s Kimi are notably absent from the Code of Practice signatory list, in the same way Alibaba sat outside the EU’s earlier general purpose AI code alongside DeepSeek.

The AI Act’s transparency duties technically reach any provider whose output lands with EU users, open weight or not.

But a legal duty on paper and a shipped watermark with a published detection method by a fixed date are different things. Holding a fellow code signatory to a shared commitment and pursuing enforcement against a lab with no EU office and no EU revenue are different exercises entirely.

What “unmarked” will start to mean

The practical result matters more than the politics of it.

As Western frontier labs start marking their output by default, an unmarked piece of text stops being reliable evidence that a person wrote it.

It increasingly means the opposite is just as likely, that it came from a model that never joined the scheme in the first place.

Provenance is about to get more visible for some models and stay exactly as invisible as it always was for others. Anyone using content authenticity as a filter, in hiring, in publishing, in procurement, needs to know which half of that picture they’re actually looking at.

What about watermark removers

This is the search a smaller, quieter audience is already running. Worth answering directly rather than pretending nobody’s asking.

Can it actually be removed

Not cleanly, and not by design.

Anthropic built the mark to survive copying, pasting and normal editing. Independent researchers have shown that other providers’ watermarking schemes can be weakened with enough rewriting, and Anthropic itself says heavy editing can degrade the signal.

That’s different from a working removal tool. A search for a watermark remover mostly turns up services promising to strip a mark, not proof that they reliably do.

What a stripped watermark doesn’t fix

Detection moves to a second layer

Even a successfully weakened watermark doesn’t make content untraceable on its own.

The interoperability requirement landing 2 February 2027 lets a platform check content against a provider’s own detection system, not just look for a visible mark sitting in the text.

Style and metadata still point back

Structure, phrasing patterns and file metadata can all still point back to how something was produced, watermark aside.

Stripping one signal doesn’t remove the others.

The more durable answer isn’t a better removal tool. It’s not needing one. Be straight about where a draft started, and the watermark stops being a threat and starts being irrelevant.

What this actually changes for your workflow

For most people, nothing changes

The mark is invisible. It doesn’t change what Claude writes or how it reads.

It applies automatically across every surface, Claude Platform, Claude, Claude Code, Claude Cowork and Claude Tag.

Drafting an email, a report, a piece of code, a first pass at a page of copy, none of that changes. Nobody needs to opt in, configure anything or tell a client which parts a model touched first.

Where it’s worth pausing

Anywhere content authenticity already mattered before this news is worth a second look now.

Publishers. Agencies producing content for clients. Anyone marking written work. Anyone running SEO or AEO content at volume.

If a platform starts checking submissions against Claude’s mark, the honest answer to give a client or a reader is the same one this piece already gave about itself. A model touching a draft at some point isn’t the problem. Passing it off as untouched when someone asks is.

None of this changes sizrok’s actual forecast.

Regulation was always the more likely brake on the industry’s wilder claims, not compute alone, and the last few weeks made that case for us rather than the other way round. The watermark didn’t need us to be right about it. It just happened on schedule.

If any of this touches how your team produces or relies on AI generated content, an audit is the place to start, not a guess. Sixty minutes, a written recommendation either way, whether or not we build anything after it. Run the audit

Frequently asked questions

What is the Claude watermark?

It’s an invisible, machine readable signal Anthropic embeds directly inside text generated by Claude models launched on or after 2 August 2026. It survives copying and pasting, doesn’t change the meaning or quality of the response, and applies across every Claude surface, including the API, the Claude app, Claude Code and Claude Cowork.

Does the watermark change what Claude writes?

No. Anthropic says the mark leaves meaning, quality and readability untouched. It sits underneath the text as a detection signal, not as a visible or functional change to the output itself.

Will other AI companies add watermarks too?

Most already have or are committed to it. Google, OpenAI, Microsoft, Mistral and Meta all signed the EU’s Code of Practice on Transparency, and close to 190 companies had signed by the end of July 2026. Google has also opened its SynthID watermarking to partners including Apple and ElevenLabs.

Do Chinese AI labs like Qwen and Kimi watermark their output?

Not as part of this scheme. Alibaba’s Qwen and Moonshot’s Kimi are absent from the Code of Practice signatory list, so their output is unlikely to carry the same machine readable mark, even though EU transparency rules technically apply to any provider whose content reaches EU users.

What legislation is still coming?

The EU AI Act’s own watermarking duty for AI generated content applies from 2 December 2026, catching providers who didn’t move early under the voluntary code. A watermark detection interoperability requirement follows on 2 February 2027, meaning platforms will be able to check content against a provider’s mark rather than take it on trust.

Does this affect businesses using Claude for content or automation?

Not in how Claude works day to day. The change is invisible and automatic. It matters more for businesses where content authenticity is already scrutinised, publishers, agencies, education, and high volume SEO content, where being straightforward about where a draft started matters more than the watermark itself.

Can you remove the Claude watermark?

Not reliably. Heavy editing can weaken the signal, and short passages may not carry enough of it to detect in the first place, but that’s different from a tool guaranteeing removal. Most services claiming to strip AI watermarks don’t publish evidence they actually work.

Is there a way to check if text has a Claude watermark?

Anthropic has said it will publish technical detection guidance, aimed at platforms and third parties rather than individual searches. A public, one click checker isn’t confirmed yet. Treat any third party tool claiming to detect it with caution until Anthropic’s own guidance lands.

Does paraphrasing remove the watermark?

It can weaken it, according to Anthropic’s own description of the system’s limits, but weakening a signal isn’t the same as removing it reliably. The safer assumption for any business is that heavily edited AI drafted content may still be detectable, not that it definitely isn’t.

Do image watermarks work the same way as text ones?

No. Claude’s text watermark is woven into the words themselves. Supported image and file formats instead carry C2PA metadata, a signed record attached to the file rather than hidden inside pixels. Metadata is easier to strip through a screenshot or format conversion than a text watermark is to remove through editing.

Regulation & Policy — min read Last updated August 2026
More from the blog All posts
Three nested frames with the actual instruction in orange at the centre
Prompt EngineeringJul 2026

Prompt design best practices

Most guides on this topic hand you a list of rules and leave it there: be specific, give context, show examples. The…

July 2026Read
Four steps arranged in a circle with arrows running clockwise, the goal step marked in orange
AI Agents & Business ApplicationsJul 2026

How businesses use AI agents

If you are reading this you are probably past the question of whether to use AI agents and onto the harder one…

July 2026Read