Claude Now Marks the Copy You Only Asked It to Edit
Anthropic is embedding an invisible mark in Claude's text output worldwide. It signals that Claude touched the words, which is not the same as Claude writing them.
Anthropic said on August 11 that it will weave an invisible mark into text written by Claude, everywhere Claude runs. Not a footer, not a disclosure line. A pattern inside the words themselves.
The company’s own documentation is unusually direct about what happens next:
“When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself. You won’t see it, and it doesn’t change the meaning, quality, or readability.”
It also travels. Anthropic says the mark persists “when it’s copied and pasted elsewhere, and may persist through some editing,” which means it survives the trip from a chat window into a CMS, a deck, or an email.
Most of the coverage has framed this as a cheating story, and TechCrunch reported on the users who are angry for exactly that reason. For a marketing team the more interesting sentence is buried in Anthropic’s support page, and it undercuts the entire cheating frame.
“A detected mark provides a signal that content was processed by Claude, but is not fully conclusive.”
Processed. Not written.
The gap between touched and authored
Run your own paragraph through Claude to tighten it, and what comes back is generated text. It carries the mark. So does a headline you wrote and asked Claude to shorten, a case study you drafted and asked it to restructure, and a subject line you fed in with six alternatives requested.
The mark cannot tell those apart from a brief typed into an empty box.
May Habib, CEO of the enterprise writing platform Writer, made the point in a widely shared reaction to the announcement:
“Blanket labels at the model level flatten that critical distinction”
She has a commercial interest in that argument, and it’s still the correct one. Every serious content operation now sits somewhere on a spectrum between a human writing alone and a model writing alone, and almost nobody sits at either end. A binary signal applied at the model level reports the same result for a strategist who used Claude as a copy editor and a content farm producing 400 pages a week.
Where the mark actually came from
This is a compliance artifact, not a product decision. The EU AI Act’s transparency obligations began to apply on August 2, and they require providers to mark AI-generated or edited content so other systems can identify it. Anthropic says models launched on or after that date support marking at launch, and it’s switching the system on globally rather than fencing it to Europe.
We covered the first half of this regime when the deployer duties landed on advertisers. This is the supply-side half arriving. Coverage now spans the Claude apps, the API, Claude Code, Claude Cowork, Claude Tag, and cloud partners including AWS and Google Cloud. Files get signed with C2PA, an existing standard for recording where a piece of media came from.
Anthropic has committed to publishing documentation so third parties can build detectors. That is the part that changes the calculus, because a mark nobody can read is a policy and a mark anybody can read is infrastructure. Once the detection method is public, a procurement team, a journalist, a competitor, or a client can run the check.
Update, August 18: the mark lives in the words that don’t matter
Anthropic has since explained the mechanism, and The Register detailed it on August 15. The mark isn’t hidden characters. At moments where several words would work equally well, Claude picks among them using a special source of randomness, and the pattern of those picks is the signature. The approach builds on Google DeepMind’s SynthID-Text research. Anthropic’s claim: “In internal testing, we’ve seen no impact of watermarking on the content, level of creativity, or readability.”
Two details matter for the argument above. The company says watermarking runs sparser on factual passages, where fewer word choices are safe, so the tightest, most fact-dense copy carries the fewest marks. And while light editing won’t fully remove the signature, a rewrite that replaces most of the wording will. Which means the harder a human works the text over, the weaker the signal gets. The detector will be most confident about the copy humans touched least, and that’s the one honest thing about it.
Two failure modes, one of them expensive
The first is the false positive, and it’s the one your team will hit. A detector reports Claude on a page your senior writer produced and then polished with a model, and whoever ran the check reads that as machine-written. Anthropic has said in its own documentation that this inference is wrong. Nobody running a detector is obliged to read the documentation.
The second is the false negative. Search Engine Land noted that the absence of a mark proves nothing, since it only covers one company’s models. Content written with any other tool comes back clean. A detection regime that catches Claude users and misses everyone else does not measure AI use. It measures which vendor you picked.
Put those together and the practical result is a signal that is noisy in both directions, arriving in a market that has been waiting for something to measure. That combination has a track record. Teams chase whatever gets scored.
What to do before somebody runs the check on you
There is one move here and it takes an afternoon.
Write down, per content type, what your team is allowed to use a model for, and keep the record. Not a values statement. A specific list: research yes, restructuring yes, first drafts of gated assets no, customer quotes never. Clay published exactly this kind of internal policy and it cost the company nothing but the decision.
The reason to do it this week rather than next quarter is that the question is about to change shape. Until now, “did you use AI for this” has been answerable with whatever the person answering wanted to say. Once detectors ship, a client, a publisher, or a regulator can ask the file instead. A team with a written standard gets to say the mark is there because our editor used Claude on stage four, exactly as our policy allows. A team without one gets to say nothing, while the detector says Claude.
The mark is not the problem. Not being able to explain it is.
Related coverage: the EU rules that already put a label on your AI ads, Hank Green and the creator trust backlash, and why owned media became a trust position.
Quoted in this story
- May Habib, Chief Executive Officer, Writer (source)
Want your perspective in coverage like this? Get quoted.
Sources
- Anthropic: How Claude marks AI-generated content
- TechCrunch: Anthropic says it will watermark text generated by its AI models
- Search Engine Land: Anthropic adds AI text watermarking to Claude models worldwide
- LinkedIn News: Claude's new watermark has some users up in arms
- The Register: Anthropic says text watermarking scheme relies on inconsequential words
This story is part of our running coverage: the full picture →
Get Net Effect.
The net effect of AI on your marketing: the stories that matter, twice a week, in five minutes.


