What changed in Claude?

Anthropic's current documentation says new Claude models launched on or after 2 August 2026 support machine-readable marking, and that support is being added to older models. For generated text, Anthropic describes an invisible watermark embedded during generation using a version of SynthID-Text. For generated files, it describes signed provenance metadata. Where a model supports the mark, Anthropic says it applies globally across Claude surfaces rather than in one region only.

That scope matters. “Claude watermarks every sentence” is not an accurate summary. Coverage depends on the model and on whether marking support has reached it yet, and short output may not contain enough signal for reliable detection.

The timing sits alongside the European Union's new transparency framework. Article 50 of the AI Act applies from 2 August 2026, and the European Commission's Code of Practice describes machine-readable marking of generated audio, images, video and text where technically feasible. It does not require every provider to use the same technical method.

Why copy and paste can preserve it

A SynthID-Text style watermark lives in the pattern of generated language. A model normally chooses each next token from a distribution of plausible options, and the watermark subtly influences those low-stakes choices so that a matching detector can later look for the resulting pattern. The pattern is statistical: it encodes nothing about the person, organisation or conversation behind the request.

Copying that passage as plain text retains the words and their order, so it can also retain the pattern. This is different from file metadata, which may disappear when someone copies a paragraph out of a document, and different from a literal hidden character, which a code-point inspector can find directly.

How much signal exists depends on how much room the model had to choose. Longer passages give a detector more evidence, while short answers, tightly factual statements, exact quotations and code offer fewer equally good alternatives and therefore carry the mark more sparsely.

What editing does to the signal

Anthropic says the mark may remain detectable after light editing. The same documentation warns that heavy rewriting, paraphrasing, translation, mixing the passage with other material, unsupported models and short samples can reduce the signal or remove it altogether.

That is a limitation of the signal, not a reliable recipe or a permission to evade a disclosure rule. A substantial rewrite can change facts, caveats, tone or authorship meaning. A second model may also apply its own provenance system. Without a supported detector, a third-party rewriting tool cannot honestly certify that the result is “watermark-free.”

What a watermark can—and cannot—prove

A detected mark is a signal that some of the passage was probably processed by a supported Claude model. It does not prove who requested the text, who owns it, who edited it, whether the final author reviewed it, whether its claims are accurate, or the full provenance of the surrounding document.

The reverse is equally important. No detected mark is not proof that no AI was used. The text may be too short, heavily edited, translated, produced by an unsupported or older model, mixed with other writing, or created before marking was enabled. Anthropic says official detection mechanisms, including an API, are forthcoming, and cautions against treating any single result as conclusive evidence.

Three different things called an “invisible watermark”

MechanismWhere it livesCopy and pasteHow it is checked
SynthID-Text token watermarkWord or token-choice patternMay travel with plain textProvider-specific detector
Invisible Unicode controlsLiteral characters in the stringOften travels unless removed or normalizedCode-point inspection
File provenance metadataDocument or media containerOften lost when copied as plain textCredential or metadata verifier

This distinction is why stripping zero-width characters or copying into a plain-text editor does not establish that a Claude SynthID-Text watermark has been removed.

Is this only a Claude development?

No. Google DeepMind says SynthID already watermarks text generated in Gemini app and web experiences by adjusting token probabilities during generation. Google also documents the same broad limitation: longer, varied text offers a stronger signal, while thorough rewriting or translation can reduce detector confidence.

OpenAI has publicly described research into text watermarking, classifiers and metadata, including trade-offs around global rewriting, false positives and impacts on non-native English speakers. The first-party material reviewed for this guide does not establish that all ChatGPT text currently carries a general text watermark. Provider implementations should be checked individually instead of assumed.

The broader direction is clear—labs and regulators are investing in machine-readable provenance—but coverage remains uneven. “AI text watermark” is a category, not one universal mark shared by every model.

Can a rewriter remove Claude's watermark?

Major rewriting may lower detector confidence according to Anthropic's own limitations, but that is not the same as a verified removal. Today, Ruja cannot ask an Anthropic detector to confirm the outcome, and another generative model may produce a different provenance signal.

A careful rewrite can still be useful for legitimate editing—improving clarity, adapting tone, or making AI-assisted text genuinely reflect the user's intended meaning. The honest product promise is therefore “rewrite privately and review the changes,” not “become undetectable.”

What Ruja Guard does today

A local checkpoint before sensitive text reaches AI.

The live Ruja Guard extension reviews personal data, company secrets and private-dictionary terms locally before you paste text into an AI service. It creates stable placeholders and can restore them on your device. It does not currently detect or remove Claude or other AI text watermarks.

Add Ruja Guard to ChromeTry the local demo

Related reading

If your concern is what you send to an AI tool rather than what comes back from one, see how to protect sensitive data before using ChatGPT.

Primary sources

Sources last reviewed 26 August 2026. This guide is educational information, not legal advice. Ruja Guard is not affiliated with Anthropic. Claude is a trademark of Anthropic.