Anthropic now embeds an invisible, machine-readable watermark in Claude's text worldwide, which turns the AI detection guessing game into a lookup that can implicate content but never clear it.
Every agency contract with an "original, human-written content" clause has the same enforcement problem: nobody can prove it in either direction. So publishers and content teams buy probabilistic detection software, $179 a month for the tier Originality.ai markets to agencies and publishers, run the copy through it, get a percentage back, and then argue about the percentage. On Tuesday, Anthropic took the guessing out of one corner of that problem. Claude now embeds an invisible, machine-readable watermark in the text it produces, worldwide, and the mark travels when you copy and paste.
Per Anthropic's own documentation, Claude models launched in the EU on or after August 2, 2026 support machine-readable marking from launch, with retrofitting for existing models described as in progress. The watermark is "imperceptible" and, Anthropic says, "doesn't change the meaning, quality, or readability" of the output. It "will travel with the text when it's copied and pasted elsewhere, and may persist through some editing." Generated files get a separate mechanism: when Claude produces a supported file type such as .svg, .png, or .jpg, it attaches signed provenance metadata using C2PA, the open content credentials standard.
Two details here matter more than the cryptography. The first is where the mark lives. It is applied at the model level, which TechCrunch reports means it "will be present no matter which Claude product or surface the text comes from." The API, Claude, Claude Code, Claude Cowork, and Claude Tag all carry it. There is no door you can walk through to get unmarked output.
The second is that Anthropic shipped this everywhere, not just where it was forced to. The obligation is European. Article 50 of the EU AI Act, in force since August 2, requires providers of generative systems to ensure their outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated." A company doing the minimum would have geofenced compliance to the EU and moved on. Anthropic's documentation says marking applies "wherever Claude is offered, worldwide."
So if your team ships content, you now have a provenance trail nobody asked you about and nobody can switch off. The freelancer who drafted your launch email in Claude, the agency running your blog calendar through it, the rep who generated forty personalized openers on Monday: all of that output carries the mark, and it carries the mark into whatever CMS, deck, or inbox it lands in. Anthropic says it will publish detection details in forthcoming technical documentation, which means the check does not stay in-house. Eventually anyone who wants to run it against your published work can.
The practical consequence is contractual, not technical. Human-written guarantees, AI-disclosure clauses in RFPs, editorial policies at trade publications, procurement questionnaires that ask whether AI touched the deliverable: every one of those has been mostly theater, because neither side could substantiate anything. One direction of that just became substantiable. If you are buying content, you got a free audit tool. If you are selling it, you got a liability you are probably already carrying and have not inventoried.
Now the part that deflates it, and it is worth reading twice, because it is in Anthropic's own documentation rather than in some critic's rebuttal. The mark is evidence in exactly one direction. A detected mark means the content "may have been processed by Claude," and, in Anthropic's words, "lack of a detected mark doesn't mean the content wasn't AI-generated or processed." Heavy editing, paraphrasing, translation, or blending Claude's text into other material can all push the mark below the detection threshold. Every rival lab's output is still unmarked, because Anthropic volunteered globally for something the regulation only demands in Europe. A detector that cannot clear anyone, cannot see a different model, and cannot survive a committed rewrite is not an integrity system. It catches the honest and the lazy.
There is also a question the documentation does not answer cleanly, and it is the one your editors will hit first: what happens to text a human wrote and asked Claude to tighten. Article 50 carves out systems performing "standard editing functions" that do not substantially alter the input data. But Anthropic's detection language is about content that may have been "processed" by Claude, and processed is a much wider word than written. Nobody has published where that line sits, which means for now a grammar pass and a ghostwritten draft may look identical to whoever runs the check.
That is the strange shape of the first real content provenance system to ship at scale. It is not a detector for AI. It is a detector for one company's customers, built by that company, aimed at the work those customers already published. Anthropic did the responsible thing here, and the reward for doing it is that Claude's output is now the only output in the market anyone can prove.