AI watermarks and what you actually have to disclose
Tell the difference between a watermark, a content credential and a disclosure obligation, and work out which of the three your published work actually needs.
on this page · 0 / 0 checked
Text that Claude produced now carries a mark you cannot see, and image files it produced carry a signed note in their metadata saying so [1]. The first thing most people want to know is how much editing washes it out. Anthropic answers that directly: light editing probably will not remove the watermark completely, and a complete rewrite where every word is replaced will [2]. Having read that sentence, you have spent your attention on the least useful part of the problem.
The useful part is that a mark and a disclosure are different objects. The mark is evidence, produced by a vendor for somebody else’s benefit. The disclosure is a decision you make about your own published work, and it is the only one of the two that a regulator, a client or an editor can hold against you. This guide is for solo operators, freelancers and small teams who publish work a model helped produce. It is not for teams building an AI system of their own, who are a provider under the EU rules and carry the heavier duty to do the marking [4]. It is scoping, not legal advice.
Two mechanisms, two different failure modes
Claude marks two things in two ways. Generated text carries an embedded watermark. Supported files, including .svg, .png and .jpg, carry signed metadata instead [1].
The text watermark changes where the randomness in word selection comes from. When the model is choosing among words that are all about equally viable, it normally picks using random numbers; the watermarked version uses a key and the few words that came before to settle what word to pick, leaving a pattern that is readable only with the key [2]. Anthropic says watermarking does not impact the quality of Claude’s output, citing human raters who saw no difference comparing watermarked and unwatermarked text side by side, and Google DeepMind testing that found no statistically significant differences from the unwatermarked model [2].
The file side is not a watermark at all. It is a small cryptographically signed note in the file’s metadata, following the Coalition for Content Provenance and Authenticity standard used across the industry to record content provenance [1][2]. C2PA describes itself as an open technical standard for publishers, creators and consumers to establish the origin and edits of digital content, and its steering committee includes Adobe, Amazon, the BBC, Google, Meta, Microsoft, OpenAI, Sony and TikTok [5].
The distinction matters because the two break in opposite ways. Metadata is a passenger in the file. OpenAI’s own documentation says C2PA metadata can sometimes be removed by platforms, editing tools or file conversions, and names upload, download, editing, conversion and sharing as the ordinary ways provenance goes missing [6]. The text watermark lives in the word choices, so Anthropic says it travels with the text when it is copied and pasted elsewhere, and may persist through some editing [1]. One survives the clipboard and dies under a rewrite. The other survives a rewrite and dies on upload.
Coverage is uneven by design. Marking applies across Claude Platform, Claude, Claude Code, Claude Cowork and Claude Tag [1]. Models launched on or after 2 August 2026 support marking at launch, which currently means Fable 5.1 and Mythos 5.1, and Anthropic says it is working to add marking support to models released before that date [1]. Your back catalogue is therefore inconsistent, and will stay that way for a while.
A clean detection result proves nothing
Anthropic states the asymmetry in two sentences worth pinning up. A detected mark provides a signal that content was processed by Claude, but is not fully conclusive. And a lack of a detected mark does not mean the content was not AI-generated or processed [1]. The Content Checker repeats it in plainer words: a missing signal does not confirm content was not made with Claude, because the signal may have been removed, or the content may have been produced by a model, platform or feature that does not support marking [3].
The text watermark has soft spots that Anthropic lists itself. Detection does not work well on small samples, where there are fewer word choices to carry a pattern. The watermark is sparser on factual passages, for the same reason. Code is barely watermarked, because code in very many cases has to be exact [2]. Anthropic also names heavy editing, paraphrase, translation and mixing the text into other writing as things that can leave the mark undetectable [1].
Then there is the question of who is allowed to look. The file checker is public. You upload a file up to 100 MB at claude.com/check-content, across a long list of image, video and audio formats, and the check runs on your device, reading only the embedded credential rather than the file itself [3]. Text watermark detection is not public. It sits in private preview for eligible organisations, listed as regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations and EU civil society groups, and is also available to enterprises similarly obliged to verify watermarking for their own compliance with the Act [1]. Google is at a similar stage with its SynthID Detector, a verification portal being tested with journalists and media professionals behind an early tester waitlist [7].
Put those facts together and the position is strange but stable. You cannot check your own text. Most people who might accuse you cannot check it either. And the parties who can check it have been told by the vendor that the result is not conclusive in either direction.
The law asks you a much narrower question than it asks the vendor
Article 50 of the EU AI Act has applied since 2 August 2026 [4]. The date is not a coincidence: it is the same date from which new Claude models ship marked [1]. But the article splits its duties across two roles, and nearly everyone reading this is in the lighter one.
Paragraph 2 is aimed at providers. Providers of AI systems, including general-purpose ones, generating synthetic audio, image, video or text content must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, with an exemption to the extent the systems perform an assistive function for standard editing or do not substantially alter the input data [4]. That is Anthropic’s obligation rather than yours, and it is why the watermark exists at all. Anthropic says it is implementing watermarking to comply with the EU AI Act, that it signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026 alongside around 190 signatories in total, and that it is applying watermarking globally at launch because it does not yet have a durable way to scope it by region [2].
Paragraph 4 is aimed at deployers, which is you, and it has two limbs. Deployers of a system that generates or manipulates image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated; where that content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the duty narrows to disclosing that such generated or manipulated content exists [4]. The second limb is the one that catches most writing. Deployers of a system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest must disclose that the text has been artificially generated or manipulated, and that obligation does not apply where the content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication [4].
Read that exemption slowly, because it decides most cases. It is not satisfied by editing. It is satisfied by a named person or company accepting responsibility for what was published. A freelancer who reads, corrects and publishes a piece under their own name is holding editorial responsibility. An unattended pipeline that pushes model output to a live blog is not, however many automated rewrite passes sit in the middle of it. The word count of the editing has nothing to do with it. The name on the masthead does.
Removing the mark is a project with no payoff
Suppose you decide to strip the marks anyway. The file credential is the easy one, and you will very likely strip it by accident just by uploading the file somewhere [6]. The text watermark is the opposite. Only a complete rewrite where every word is replaced reliably removes it [2], and at that point you have written the piece yourself.
The deeper issue is that removal buys nothing you wanted. Because absence proves nothing [1][3], an unmarked document does not demonstrate human authorship to a client, a platform or a court. Stripping it only destroys one of the few pieces of evidence that could have supported your own account of how the work was made. If your plan was to claim the work as yours, the mark was never the thing standing in the way.
There is also a contractual layer underneath the legal one, and it points the other direction. Anthropic’s Usage Policy, effective 15 September 2025, requires that all consumer-facing chatbots, including any external-facing or interactive AI agent, disclose to users that they are interacting with AI rather than a human [8]. In its high-risk use cases, where outputs go to individuals, you must disclose that you are using AI to help produce your advice, decisions or recommendations, and a qualified professional in that field must review the content or decision before it is disseminated or finalised [8]. The high-risk list covers legal interpretation and guidance, healthcare and mental health, insurance underwriting and claims, financial decisions including creditworthiness, employment and housing decisions, academic testing, accreditation and admissions, and media or professional journalistic content generated automatically and published for external consumption [8]. Those are precisely the areas where the temptation to stay quiet is strongest, and they are the areas where staying quiet already breaks the terms you agreed to.
One check does not cover a mixed pipeline
Vendors mark differently and their detectors do not interoperate. Anthropic uses a text watermark for text and C2PA content credentials for files [1][2]. OpenAI says supported images generated with ChatGPT, Codex and the OpenAI API carry both C2PA metadata and SynthID watermarks [6]. Google embeds SynthID across its consumer generative products, including Gemini, Lyria and the podcast generation feature of NotebookLM, and has extended it to text from the Gemini app and web experience by adjusting the probability scores for each word during generation [7].
Robustness differs as well. Google says SynthID image and video watermarks are designed to stand up to modifications such as cropping, adding filters, changing frame rates and lossy compression, and that audio watermarks cannot be altered by common modifications such as adding noise, MP3 compression or changing the speed of the track [7]. Anthropic’s claim for text is deliberately weaker: copy and paste survives, and some editing may survive [1].
So if you draft in Claude, generate images in ChatGPT and summarise in Gemini, no single tool tells you what is in your output. Running a file through the Claude Content Checker and getting nothing back tells you about Claude credentials on that file, and nothing else [3].
Decide once per content stream and write it down
The durable practice here is short and dull. List the streams of work a model touches, such as client deliverables, marketing pages, the newsletter, support replies, code comments and image assets. For each one, write down which model touches it, whether it is published, whether it is text published to inform the public on matters of public interest, who holds editorial responsibility by name, and whether a disclosure line appears and where. Then date the page, because model coverage, product names and the state of the detection preview will all move under you.
Most streams will resolve the same way. Published under a named human, not a matter of public interest, no Article 50 disclosure duty [4], and possibly a disclosure duty anyway under the Usage Policy if the work touches a high-risk domain [8]. A boring answer that exists in writing beats an informal sense that this probably does not apply. The realistic objection is the time it costs, which is worth estimating rather than guessing at.
items × minutes ÷ 60. Computed in the page; nothing is sent anywhere.
What still goes wrong
You cannot verify your own text. Detection sits in private preview [1][2], so the single claim you might most want to test about your own published work is the one you have no way to test. That is a defensible place for a vendor to start, given what a public text detector would immediately be used for, but it leaves you taking a vendor’s description of its own mark on trust.
The thresholds are not numbers. “May persist through some editing” [1] and “light editing probably won’t remove the watermark completely” [2] are honest descriptions of a genuinely fuzzy property, and they are useless for planning. There is no percentage of rewriting that puts you on a known side of a line, because no line has been published. Anyone selling a service that guarantees a specific result against a watermark is selling a guess.
The marking is also incomplete on purpose. Older Claude models are still being retrofitted [1], code is barely marked [2], and a file credential can disappear during an ordinary upload [6]. Treat the whole apparatus as a source of weak positive evidence and never as a negative test. Treat the European framing the same way. Article 50 is currently the rule shaping vendor behaviour worldwide [2], but it is one jurisdiction’s answer, it is not the only disclosure regime you might sit under, and none of this is legal advice.
- 01Anthropic — How Claude marks AI-generated contentsupport.claude.com
- 02Anthropic — How Claude's text watermark worksanthropic.com
- 03Anthropic — Claude Content Checkerclaude.com
- 04EU AI Act, Article 50 (transparency obligations for providers and deployers)artificialintelligenceact.eu
- 05C2PA — Coalition for Content Provenance and Authenticityc2pa.org
- 06OpenAI — Provenance signals (Content Credentials, SynthID) in OpenAI-generated contenthelp.openai.com
- 07Google DeepMind — SynthIDdeepmind.google
- 08Anthropic — Usage Policyanthropic.com