The Claude Watermark: Where the Mark Lives and What It Proves
Anthropic began marking Claude's text output on 11 August 2026. Almost every explanation of it since has described the wrong mechanism. The mark is not a character hidden in the page, it is a statistical bias in which words the model picked, and that distinction decides everything: what carries it, what clears it, and how little a positive result actually settles about who wrote a document.
Most of what has been written about Claude's watermark since August describes a mechanism that is not the one Anthropic shipped. The common account has an invisible character tucked between the words, a zero-width space or a lookalike Unicode glyph, waiting for a detector to find it. That would be a reasonable guess. It is also wrong, and the error is not academic: it is the reason a whole category of free tools marketed as watermark removers has no effect whatsoever on this particular mark.
Anthropic's mark lives in the choice of words themselves. Nothing is inserted into the text. Once that is clear, the practical questions answer themselves in a way they cannot while the hidden-character picture is still in play, including which operations carry the mark forward, which ones clear it, and what a detector is really telling you when it reports a hit.
What follows is drawn from Anthropic's own documentation rather than from the coverage around it, and it is deliberately specific about the limits the company itself states.

What Anthropic switched on, and when
Anthropic began marking Claude's output on 11 August 2026. Its help centre article on the subject describes the text mark as "an imperceptible watermark directly into the text itself", and says a reader "won't see it, and it doesn't change the meaning, quality, or readability".
Coverage is broad. Models launched on or after 2 August 2026 carry marking from release, and Anthropic lists the surfaces as the Claude Platform API, Claude, Claude Code, Claude Cowork and Claude Tag, including Claude reached through AWS, Google Cloud and Microsoft Foundry. It applies globally. Treating anything drafted before August as automatically exempt is unwise, since the company has described bringing earlier models in over a transition period.
The regulatory push behind it is Article 50 of the EU AI Act, whose transparency obligations require providers of generative systems to mark machine-readable output. Anthropic signed the Article 50(2) Code of Practice. Worth noticing is that the regulation governs systems used within the European Union and contains nothing that would force worldwide application. Anthropic applied the mark everywhere regardless, which is a policy choice rather than a legal requirement, and it is why a researcher in Kuala Lumpur or Chicago is covered by a European rule.
The mark is a pattern of word choices, not a hidden character
At every step of generating text, a language model is choosing among several continuations that are close to equivalent on its own statistics. Where one word is as good as another, something has to break the tie. A sampling watermark breaks those ties according to a key held by the provider, so that across a reasonable run of text the accumulated choices form a pattern that a detector holding the same key can measure.
Nothing is added to the page. There is no character to find, no metadata field in the text, no formatting artefact. The words you are reading are the watermark, in the specific sense that the mark is the record of which words were selected from among the alternatives. That is why Anthropic can say the mark costs nothing in meaning or readability: it never had to distort the prose, only to prefer one acceptable phrasing over another acceptable phrasing, repeatedly.
It also explains the durability. Anthropic says the mark "will travel with the text when it's copied and pasted elsewhere", and the reason is structural rather than clever. Copying preserves your words. Reformatting preserves your words. Changing the font, exporting to PDF, pasting into a different editor, converting to plain text: all of them preserve the sequence of words, and the sequence of words is the thing being measured.
Why invisible-character cleaners have no effect on it
A large number of free tools now advertise themselves as AI watermark removers. Nearly all of them do one job: scan for zero-width Unicode, invisible spacing and lookalike glyphs, then delete what they find. That was a sensible answer to a real problem, since some systems genuinely have embedded provenance in characters, and it is the correct tool for stripping stray formatting artefacts out of pasted text.
Against a sampling watermark it accomplishes nothing at all. Run a Claude passage through a character cleaner and every invisible character in it disappears, while the passage measures exactly as it did before, because not one word changed. The tool is looking in a place where the mark has never been. This is the most consequential misunderstanding in circulation, and anyone relying on a character stripper for this purpose is getting a result that feels like an action and is not one.
The general point sits alongside the broader question of how AI detectors actually work, though a keyed watermark is a different animal from a statistical classifier. A classifier guesses from the shape of the writing. A watermark reads a signal that was deliberately planted, which makes it far more precise about what it detects and no better at all at telling you who wrote the document.
The second mechanism, which applies to files rather than text
Anthropic runs two systems, and the coverage has largely collapsed them into one. Alongside the text watermark, files produced by Claude can carry "signed provenance metadata" following the Coalition for Content Provenance and Authenticity (C2PA) open standard.
This half behaves in the opposite way to the first. C2PA metadata is attached to the file rather than woven through the prose, so it is comparatively easy to lose: copy the text out of the file and the metadata stays behind, since it was never in the words. The two systems have inverted strengths. The text mark survives being moved around and resists casual editing. The file signature is precise and verifiable but does not survive the ordinary act of selecting a passage and pasting it into a document of your own.
Humanize your own paper
Transform your AI-assisted text and make it sound human, without touching important words or citations.
What a positive detection actually establishes
Considerably less than the word "detection" implies, and Anthropic is unusually direct about this. Its documentation states that "detecting a Claude mark tells you that the content may have been processed by Claude" and that it "does not, on its own, confirm the full provenance".
Read that carefully, because it is doing precise work. Processed, not written. A positive result is consistent with a document Claude drafted from nothing. It is equally consistent with a document you wrote yourself and asked Claude to tighten. The signal has no way to separate those cases, because in both of them Claude generated the tokens that ended up on the page.
The limits run in the other direction too. Anthropic notes that marks may not survive heavy editing, format conversion or very short passages, and that an absent mark does not indicate content was not AI-generated. So a negative establishes almost nothing: the text may have come from a different model, from an earlier Claude, or from Claude by way of enough revision to wash the signal out. Detection is planned through Anthropic's own interface rather than exposed to third parties, which is why general-purpose AI detectors do not read this signal and cannot be expected to.
| Operation | Effect on the text watermark | Why |
|---|---|---|
| Copy and paste | Carries through | Your words are preserved exactly |
| Reformatting, font changes, PDF export | Carries through | Presentation changes, word sequence does not |
| Deleting invisible characters | No effect | The mark was never stored in a character |
| Light copy-editing | Usually carries through | Most words survive, so most of the pattern survives |
| Substantial rewriting | Breaks down | New words mean new choices, unkeyed to the original |
| Translation into another language | Breaks down | The token sequence is rebuilt from scratch |
| Very short extracts | Unreliable either way | A statistical measurement needs a run of text to conclude anything |
The attribution problem this creates for people who wrote their own work
The sharpest response to the announcement did not come from anyone trying to disguise machine-written work. It came from lawyers, researchers, academics and editors who use the model the way they would use a copy-editor, and who noticed what the mark records.
Consider the ordinary case. You write a paragraph. The argument is yours, the evidence is yours, the structure is yours. You ask Claude to fix the rhythm and cut two hundred words. What returns is your paragraph, marked, and the mark cannot say that almost all of the thinking and most of the phrasing were already there before the model saw it. If an institution, publisher or employer treats a positive as settled proof of AI authorship, which is a stronger reading than Anthropic's own wording supports, the writer is left arguing against a signal that was never designed to answer the question being asked of it.
That is a genuine problem about attribution rather than a problem about concealment, and it is worth stating plainly because the two get conflated constantly. Wanting your own argument attributed to you is not the same as wanting to hide how a document was produced. Whatever your institution's disclosure policy requires, it still requires it: clearing a mark changes nothing about what you owe a reader in a declaration of AI use.
What clears the mark, and what only looks like it does
One principle covers all of it. Any operation that leaves your words standing carries the mark forward. Any operation that produces the words again from scratch breaks it. Everything else follows.
Copying, reformatting, converting file types and stripping invisible characters all leave the words standing, so all of them carry the mark. Translation and substantial rewriting produce the words again, so both break it, and Anthropic has acknowledged that heavy editing can make the mark disappear. Rewriting by hand works perfectly well if you have the time for it, which for a full chapter most people do not.
This is the mechanism our free Claude watermark remover is built on. It rebuilds a passage sentence by sentence through a different model, so every token is generated afresh and a signal keyed to Claude's sampling has nothing left to attach to. Openings shift and clause order moves, while figures, dates, names, hedges and field vocabulary are held fixed, and quoted material and references are copied across exactly rather than reworded. One consequence of that last rule is worth knowing in advance: a long block quotation lifted out of Claude keeps whatever mark it arrived with, because reproducing a quotation accurately is the more important of the two obligations.
For longer documents, or for academic work where register and citation handling carry more weight than they do in general prose, the same rebuilding approach runs across a full manuscript in the TextPulse humanizer, which was built for research writing specifically and treats citations, defined terms and technical vocabulary as fixed points.
If your own writing has come back marked
Start by being accurate about what you are looking at. A mark means Claude handled the text at some point. It does not rank how much of the document is yours, and Anthropic's own wording will support you on that if the conversation becomes formal.
Keep whatever evidence of process you already have. Draft history, version files, notes and outlines all speak to authorship in a way a provenance signal cannot, and they are considerably more persuasive than an argument about statistics. If your work has to go out under your own name and the marking creates a real attribution problem, rebuilding the passage in your own wording resolves it, whether you do that by hand or with a tool, and it resolves it precisely because rebuilding is the only thing that touches this kind of mark.
Anthropic will keep changing the details. Coverage is still expanding to older models, detection is still developing, and the regulatory picture behind it is younger than the technology. The part unlikely to change is the mechanism, and knowing that the mark sits in word choice rather than in a hidden character is what separates a step that does something from a step that only feels like it does. If you want to see the same question from the classifier side rather than the watermark side, the vocabulary that gives away AI writing to a human reader is a different signal again, and one no key can measure.
Frequently Asked Questions
It is a statistical mark that Anthropic embeds in Claude's text output, applied from 11 August 2026 across every model released on or after 2 August 2026. Rather than inserting anything into the page, it biases the model's choice between near-equivalent words according to a key Anthropic holds, so that a long enough passage carries a measurable pattern. Anthropic describes it as an imperceptible watermark woven directly into the text that does not change the meaning, quality or readability.
Content strategist at TextPulse, here since the company started. Mark writes the product and technical coverage: how the humanizer works under the hood, what changes in each release, and what a specification actually means for your writing. His reviews of writing software come from using them on real documents rather than reading a feature list.