AI watermarking can show that an AI model was probably involved in a piece of text.
It cannot tell anyone who wrote it, identify your account, reveal your company, or trace the text back to a specific chat.
And for most copywriters, that distinction matters far more than the watermark itself.
Anthropic announced in August 2026 that future Claude models will generate text containing an invisible watermark, with older models being updated during the transition period. Other major AI providers have signed the EU’s transparency code and are introducing their own machine-readable marking systems.
The change comes from Article 50 of the EU AI Act, which began applying on 2 August 2026.
But two very different rules are being mixed together in much of the coverage:
- AI providers have to make generated content machine-detectable.
- People publishing certain AI-generated content may have to disclose that it was AI-generated.
Those are not the same obligation.
And ordinary marketing copy will usually sit outside the second one.
The part content teams should pay closer attention to is something else: what the EU now considers genuine human review.
A quick proofread is not enough.
AI watermarking: the quick answer
Here is the practical version.
- An AI text watermark is an invisible statistical pattern in the model’s word choices.
- It is not made from hidden characters.
- It does not add metadata to the text.
- Readers cannot see it.
- It does not contain information about the user who generated the text.
- It does not prove that AI wrote every word.
- It does not tell you whether another AI model wrote the text.
- Anthropic says its watermark has no practical effect on output quality, speed or price.
- Under the EU AI Act, a machine-readable watermark and a visible AI disclosure are two separate things.
- AI-generated public-interest text may need a visible label, but there is an exemption where genuine human review or editorial control takes place and someone assumes editorial responsibility.
- Spell-checking and grammar corrections alone do not count as that review.
So if your first thought was:
“Can a client now run my landing page through something and prove I used Claude?”
That is not really what this system does.
What is AI watermarking?
Large language models generate text piece by piece.
At any given point, several possible next words or tokens may make sense.
Take:
“The weather today was cold and…”
The model probably will not choose “sugary”.
But “grey”, “wet” and “overcast” might all be reasonable.
Normally, some randomness helps settle choices like these.
Text watermarking changes where that randomness comes from.
With Claude’s system, a secret key and some of the preceding text influence those low-stakes choices. Over a long enough passage, this creates a statistical pattern. Someone with the correct key can later test whether the sequence of choices is consistent with Claude having generated or processed the text.
Nothing extra is inserted into the copy.
The pattern exists in the choices the model already had to make.
That is why searching the document for invisible characters will not find it.
AI watermarking is not:
- A hidden character. There are no zero-width spaces or invisible Unicode characters to remove.
- A visible watermark. Nothing appears on the page.
- Text metadata. Metadata and content credentials are separate mechanisms. Anthropic, for example, uses C2PA content credentials in supported image and file formats.
- A normal AI detector. An AI detector tries to infer authorship from the way something is written. A watermark detector checks for a statistical pattern created with a particular provider’s key. Those are fundamentally different methods.
Does AI watermarking make the writing worse?
The evidence so far says no.
Claude’s watermark uses a version of SynthID-Text, a technique developed by Google DeepMind and published in Nature in 2024.
DeepMind tested SynthID-Text in live Gemini traffic across roughly 20 million responses.
Its researchers found no evidence of a reduction in response quality from the non-distortionary watermarking configuration. Human side-by-side evaluations also found no meaningful quality difference.
Anthropic reports the same result from its own internal testing: no practical effect on content, creativity or readability.
There is no extra token cost either, and Anthropic describes the speed impact as negligible.
For a copywriter, that means there is no reason to change your prompting or writing process because you are worried the watermark itself will make the prose worse.
The interesting questions are about provenance, disclosure and editorial responsibility.
What can an AI watermark actually prove?
Much less than the phrase “AI watermark” makes it sound like.
A successful Claude watermark check could support the conclusion that Claude was probably involved with the text at some point.
It cannot tell you:
- who used Claude
- which Claude account generated it
- which company the user worked for
- which conversation it came from
- whether Claude wrote the entire piece
- whether Claude generated a first draft and a human rewrote half of it
- whether Claude heavily edited something written by a person
Anthropic is explicit that its watermark contains no identifying information about the user, their organisation or their chats.
It also cannot test for every AI model.
A Claude watermark detector can look for Claude’s pattern.
Another provider’s model would use a different key and may use a different marking method entirely.
Think model provenance, not writer surveillance.
That is a much better mental model.
Why is AI watermarking happening now?
The main reason is the EU AI Act.
Article 50 began applying on 2 August 2026 and created transparency duties for both AI providers and people or organisations deploying certain AI systems.
For text, two rules matter most.
| Rule | Who it applies to | What it requires |
|---|---|---|
| Article 50(2) | AI providers | AI-generated or manipulated content must be marked in a machine-readable form so its artificial origin can be detected |
| Article 50(4) | Deployers | Certain AI-generated text published to inform the public on matters of public interest must be visibly disclosed unless an exemption applies |
The Commission’s Code of Practice on Transparency of AI-generated Content gives organisations a voluntary way to demonstrate compliance.
Around 190 organisations had signed it by the end of July 2026. Section 1 signatories include Anthropic, Google, Meta, Microsoft, Mistral, OpenAI and Cohere.
Anthropic says it is applying its text watermark globally at launch because it does not yet have a durable way to limit the system geographically.
So the technical change can affect writers well outside Europe.
That does not mean every writer outside Europe suddenly has an EU disclosure duty.
Those are separate questions.
Does AI-written copy need an AI label?
Usually not simply because AI was used.
Article 50(4) does not say that every piece of AI-generated text published online must carry a label.
The European Commission says three conditions must be met.
The text must be:
- Published
- Informative to the public
- About a matter of public interest
The Commission gives examples of public-interest subject matter including:
- politics and democratic processes
- public administration
- justice and law enforcement
- fundamental rights
- public security
- public health
- environmental protection
- consumer safety
- economic and financial developments
- scientific developments
- cultural developments that may be relevant to public debate
That is much narrower than “anything on a public website”.
What that means for marketing copy
As a practical reading of those criteria, ordinary promotional copy will generally sit outside this particular labelling rule.
Think:
- product descriptions
- ecommerce category pages
- landing pages
- sales pages
- ad copy
- promotional emails
- ordinary social media captions
- internal business documents
Their purpose is generally commercial persuasion rather than informing the public about a matter of public interest.
But the dividing line becomes more interesting once marketing starts looking like publishing.
A health company might publish an article explaining the symptoms of a medical condition.
A financial business might publish an explainer on pension regulation.
A legal company might explain new employment rights.
A sustainability brand might cover a contested environmental policy.
Those pieces may be marketing assets commercially, but their content and purpose can still move them towards the public-interest category described by the Commission.
So don’t ask:
“Is this content marketing?”
Ask:
“Is this piece published to inform the public about a matter of public interest?”
That is the more useful test.
The exemption copywriters should care about: human review
Even when AI-generated text falls into that public-interest category, Article 50(4) includes an important exemption.
A visible AI label is not required where the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication.
That sounds broad.
It isn’t.
What counts as human review?
The Commission describes human review as deliberate examination of the substance of the content by people with relevant knowledge and professional judgement.
The examples it gives are closer to professional validation or academic peer review than a quick read before pressing publish.
What counts as editorial control?
Someone responsible for the content needs real authority to:
- approve it
- change it
- reject it
- check factual claims
- assess the trustworthiness of sources
What does not count?
This bit is unusually clear.
The Commission says superficial, purely formal or procedural checks do not qualify.
That includes:
- spell-checking
- grammar corrections
- other purely surface-level review
And that may be the most important sentence in Article 50 for content teams.
A workflow that looks like:
AI writes → human fixes typos → publish
is not the same thing as substantive human review.
A workflow that looks like:
AI assists → knowledgeable human checks claims and sources → human materially edits where needed → responsible editor can reject it → publication
is much closer to what the Commission describes.
That is a useful standard even when the disclosure rule does not apply.
A watermark is not an AI disclosure
This distinction is easy to miss.
The provider’s machine-readable mark exists so software can identify AI-generated or manipulated content.
A publisher’s disclosure exists so people can recognise that relevant content was AI-generated.
One does not replace the other.
Where Article 50(4) requires disclosure, the Commission says people need to be informed clearly and distinguishably. It has even produced optional EU icons to support that disclosure.
So this argument does not work:
“Claude already watermarked it, so we don’t need to say anything.”
The watermark fulfils a provider-side technical function.
The visible label fulfils a deployer-side communication function.
Different problem.
Different obligation.
Where text watermarking gets weaker
Watermarking is useful, but it is not magic.
Its limits follow directly from how it works.
Short text is harder to detect
A short paragraph gives the watermark fewer word choices to work with.
Anthropic says detection confidence increases as the passage becomes longer.
That makes a 2,000-word article very different from a four-word ad headline.
Factual text carries less signal
Watermarking works best where several word choices are equally acceptable.
If only one answer is correct, there is very little freedom to encode a pattern.
Anthropic uses factual continuations such as Newton’s Principia Mathematica to illustrate this problem.
Proofreading may leave almost nothing detectable
If you write an article yourself and ask Claude only to correct punctuation and grammar, nearly all the words remain yours.
Only the changes made by the model have room to carry the watermark.
Anthropic says those changes may be too sparse to register.
Code carries less watermarking
Code often requires an exact token or expression.
That leaves fewer arbitrary choices.
Comments and other flexible language inside code can still carry a mark, but the functional code itself often provides less room for one.
Translation is different
If Claude translates a passage, it chooses the words of the translated output.
Anthropic says those translations therefore carry the watermark.
Editing gradually weakens the signal
Anthropic says light editing probably will not remove the watermark completely.
A complete rewrite replacing essentially all of the model’s wording can remove it.
That makes intuitive sense.
The more language the model chose, the more room there is for its statistical signature.
The more language a person replaces, the less of that original sequence remains.
AI watermarking vs AI detection software
These two ideas sound similar but work in opposite ways.
| AI watermark detection | Traditional AI detector | |
|---|---|---|
| What it examines | A keyed statistical signature | Patterns in the writing |
| What it needs | The provider’s watermark information | Only the text |
| What it can identify | Possible involvement of the relevant model | Whether the text resembles machine-written text |
| Scope | Model or provider specific | Attempts to work across models |
| Main evidence | Generation pattern | Writing style |
Traditional detectors do not have Anthropic’s secret watermark key.
Instead, they infer.
They may look for phrases, sentence patterns, predictability and other tendencies associated with AI writing.
Anthropic itself contrasts those stylistic systems with watermark detection, noting that a real watermark test is checking a keyed pattern rather than guessing from prose style.
So a watermark does not suddenly make every existing “AI detector” more authoritative.
They remain different technologies.
Can someone check your copy for Claude’s watermark today?
Not through Anthropic’s announced public detection tool yet.
As of 18 August 2026, Anthropic says it plans to offer a watermark detection API and is still working through the details of its implementation.
That could change quickly.
But at the time of writing, Anthropic has announced the detector rather than released it publicly.
Who is actually responsible: writer, agency or client?
The EU uses the term deployer.
A deployer is broadly a person or organisation using an AI system under their authority for professional purposes. Purely personal, non-professional use is outside this part of the Act.
For employees, the distinction is fairly straightforward.
If a writer, designer, journalist or other employee uses AI under the authority and control of a company, the Commission says that employee is not treated as a separate deployer.
The company remains the deployer.
Contractors and freelancers are more contextual.
If a freelancer operates the AI on behalf of a company and under that company’s responsibility and control, the legal person can remain the deployer.
If someone independently uses AI as part of their own regular commercial or freelance activity, they may themselves qualify as a deployer.
For agencies and freelancers, this is worth making clear with clients instead of leaving it vague.
What copywriters and content teams should change
You probably do not need a complicated AI compliance system.
You do need a better definition of “reviewed by a human”.
Here is a sensible workflow.
1. Know where AI-generated text is being published
Map the places where AI plays a meaningful role:
- blog posts
- knowledge hubs
- client websites
- social media
- reports
- guides
- public resources
You cannot make sensible disclosure decisions if nobody knows where AI is being used.
2. Separate ordinary commercial copy from public-interest publishing
Do not apply one blanket rule to an entire website.
A product page and an article explaining cancer treatment are not the same kind of publication simply because both sit inside the same CMS.
Judge the content and its purpose.
3. Give someone real responsibility for review
For higher-risk content, name the person who checks it.
They should understand the subject well enough to challenge the piece rather than simply polish it.
4. Review claims, not commas
Ask:
- Is this accurate?
- Can we support this claim?
- Is the source trustworthy?
- Is anything missing?
- Has the AI distorted the source?
- Would I personally stand behind this statement?
That is much closer to substantive human review than fixing awkward sentences.
5. Give the reviewer authority to reject the piece
Editorial control means very little if the reviewer cannot actually say no.
6. Keep a simple review trail
For sensitive public-interest content, retaining a record of who reviewed the material, what sources were checked and when the review occurred is sensible evidence of what your process actually involved.
It does not need to become bureaucratic.
7. Have disclosure wording ready
If a piece does require an AI disclosure, decide how your organisation will word and display it before the question arises.
8. Stop treating an AI detector score as proof of authorship
A traditional detector score and a provider watermark are different types of evidence.
Do not let the arrival of watermarking blur that distinction.
The bottom line
AI watermarking sounds more invasive than it is.
Claude’s watermark is not a hidden tracking code attached to a writer.
It is a statistical pattern created by the model’s own generation choices.
It can help establish that Claude was probably involved with a piece of text.
It cannot identify the person behind it.
For copywriters, the bigger change created by the EU AI Act is not the watermark.
It is the standard being set for human review.
A human opening the document is not enough.
A human fixing grammar is not enough.
The review needs to engage with the substance of the content, and the person or organisation responsible for publication needs genuine editorial control.
If your content process already works that way, AI watermarking changes surprisingly little.
If your workflow is still generate, proofread, publish, this is a good reason to make it better.
Frequently asked questions
Can an AI watermark be traced back to me or my company?
No. Anthropic says its text watermark contains no information that can identify an individual user, organisation or Claude conversation.
Can a client prove I used Claude?
A future Claude watermark detector may provide evidence that Claude was probably involved in producing or processing a sufficiently long piece of text. It cannot establish which person used Claude or distinguish perfectly between Claude generating the original text and Claude heavily editing it.
Is every Claude response watermarked already?
No. Anthropic’s 14 August 2026 announcement says future Claude models will generate watermarked text and that it is working to bring older models into compliance during the transition period.
Does watermarking change who owns AI-assisted copy?
No. Anthropic says the watermark does not determine ownership or authorship and does not change a user’s rights under its terms.
Does proofreading my own article with AI make it fully watermarked?
Not necessarily. If nearly all the wording remains yours and the model only makes small grammatical corrections, Anthropic says there may be too little watermark signal to detect.
Does AI-translated copy carry a watermark?
Claude-generated translations do. Because the model chooses the words in the translated version, Anthropic says the output carries its watermark.
Do landing pages and product pages need an AI label?
Not simply because AI was used. Article 50(4) targets AI-generated or manipulated text published for the purpose of informing the public on matters of public interest. Ordinary promotional copy will generally not meet that test, although the purpose and subject matter of each piece still matter.
What about health, finance and legal content?
Treat it more carefully. Public health, consumer safety and economic or financial developments are among the areas the Commission identifies as potentially involving matters of public interest. A commercial blog can still publish public-interest information.
Does spell-checking count as human review?
No. The Commission expressly says superficial or purely formal checks such as spelling and grammar corrections do not amount to the human review or editorial control required for the Article 50(4) exemption.
Is a watermark the same thing as an AI disclosure?
No. The watermark is a machine-readable mechanism implemented by the AI provider. Where a publisher has a disclosure obligation, the artificial origin of the content has to be communicated clearly to the people exposed to it.
Can I test text for Claude’s watermark right now?
Anthropic has announced a watermark detection API but, as of 18 August 2026, says it is still working out the details of its implementation.
What about AI-generated images and files?
Anthropic says supported file types can receive C2PA Content Credentials: cryptographically signed provenance information stored in the file’s metadata. That is a different mechanism from Claude’s statistical text watermark.
Does content created before 2 August 2026 need to be labelled retroactively?
No. The European Commission says content generated before 2 August 2026 does not need retroactive labelling, although voluntary disclosure is encouraged where appropriate.
This is a practical explanation of the EU AI Act transparency rules, not legal advice.