Tracker
AI watermark status database
Exactly one provider's own documentation currently says its text output carries a watermark: Anthropic. Every other row below is either media-only, contested, or unknown. The difference between those three is the whole point of this table.
18 product surfaces across 11 providers. Rows are split by surface rather than by company, because the same provider can watermark its consumer app and not its API. Every cell traces to a primary source with the date someone last opened it.
By Rowan Vale.
Which AI providers watermark their output?
One line per product surface, giving every output type that surface offers, its value, and the date the row was last verified. Output types the surface does not offer are left out. Each name links to the same row in the table below, which adds the public detector and mechanism columns and the source.
- Anthropic
- Claude Platform (API), Claude, Claude Code, Claude Cowork and Claude Tag, plus supported models through AWS, Google Cloud and Microsoft Foundry, where the text watermark carries through (cloud rollout can lag: the help page gives Opus 5 one week from 2026-09-14 on cloud partners, and Anthropic says the 2026-09-30 wave there "may take a few additional days") and C2PA file metadata applies only where that platform offers Claude's file generation: Text Yes, Metadata / C2PA Partial, verified 2026-09-25
- Gemini app and web experience (consumer): Text Contested, Image Yes, Audio Yes, Video Yes, Metadata / C2PA Yes, verified 2026-09-25
- Gemini API, AI Studio and Antigravity (developer): Text Contested, Image Yes, Audio Yes, Video Yes, Metadata / C2PA Yes, verified 2026-09-25
- SynthID-Text, open-sourced implementation: Text Yes, verified 2026-09-25
- OpenAI
- ChatGPT and API text output: Text No, verified 2026-09-25
- ChatGPT, API and Codex image output: Image Yes, Metadata / C2PA Yes, verified 2026-09-25
- ChatGPT and API audio output: Audio Yes, Metadata / C2PA No, verified 2026-09-25
- Sora video output: Video Contested, Metadata / C2PA Contested, verified 2026-09-25
- Meta
- Meta AI app and meta.ai image output: Image Yes, Video No, Metadata / C2PA Yes, verified 2026-09-25
- Llama Defenders audio tooling: Audio Yes, Metadata / C2PA Unknown, verified 2026-09-25
- Llama open-weight models: Text No, verified 2026-09-25
- xAI
- Grok output: Text Unknown, Image Yes, Audio Unknown, Video Yes, Metadata / C2PA Unknown, verified 2026-09-25
- DeepSeek
- chat.deepseek.com and Open Platform: Text No, Image Unknown, Metadata / C2PA Unknown, verified 2026-09-25
- Microsoft
- Microsoft 365 Copilot and Designer: Text No, Image Yes, Audio Partial, Video Partial, Metadata / C2PA Partial, verified 2026-09-25
- Amazon
- Bedrock: Titan Image, Nova Canvas, Nova Reel: Text No, Image Yes, Video Yes, Metadata / C2PA Yes, verified 2026-09-25
- Mistral AI
- Le Chat and La Plateforme: Text Unknown, Image Unknown, Metadata / C2PA Unknown, verified 2026-09-25
- Perplexity
- Answers and image generation: Text Unknown, Image Unknown, Metadata / C2PA Unknown, verified 2026-09-25
- Alibaba
- Qwen international API vs Tongyi Qianwen in China: Text Unknown, Image Unknown, Metadata / C2PA Partial, verified 2026-09-25
Status table
Showing 18 of 18 rows.
| Provider and surface | Text | Image | Audio | Video | C2PA | Public detector | Mechanism disclosed | Last verified |
|---|---|---|---|---|---|---|---|---|
Anthropic #Claude Platform (API), Claude, Claude Code, Claude Cowork and Claude Tag, plus supported models through AWS, Google Cloud and Microsoft Foundry, where the text watermark carries through (cloud rollout can lag: the help page gives Opus 5 one week from 2026-09-14 on cloud partners, and Anthropic says the 2026-09-30 wave there "may take a few additional days") and C2PA file metadata applies only where that platform offers Claude's file generationFable 5.1 and Mythos 5.1 marked at launch on 2026-09-01; Opus 5.5 marked at launch on 2026-09-22; Opus 5 confirmed by the help page table and marked from 2026-09-14 per a 2026-09-25 email (the help page dates only its cloud rollout from 2026-09-14; the 2026-09-04 notice had said 2026-09-09); Fable 5, Sonnet 5 and Opus 4.8 from 2026-09-30 per the 2026-09-25 email; the remaining models released before 2026-08-02 "all covered by December 2, 2026", with no date per modelVerified 2026-09-25Evidence and caveatsThe only provider whose own documentation states in the present tense that its text output is watermarked, and now the only one shipping any detector at all. On 2026-08-14 Anthropic published a technical explanation naming the mechanism family: "a version of the SynthID-Text approach published by Google DeepMind", in "a family of approaches that go back to a proposal by Scott Aaronson in 2022", where a secret key plus "a few words that come before" pick among meaning-preserving candidate next words. "Nothing is added to the text and there are no hidden characters." That moves the mechanism column to Yes. Two things changed on 2026-09-01. Anthropic released Claude Fable 5.1 and Mythos 5.1, the first models launched after its own 2026-08-02 threshold, and its support article named them in a sentence that read, at the time, "Models currently supported include Fable 5.1 and Mythos 5.1." Until then no shipped model had met the rule, which is what the earlier note recorded. The same day Anthropic put the promised detection API into private preview, and the platform release notes recorded the API-side half: text from both models carries Anthropic's text watermark. Development recorded 2026-09-04, not a correction. Until that day Anthropic had named no retrofit model and no date: the news post of 2026-08-14 puts the rollout for models launched before 2026-08-02 "over coming months". On 2026-09-04 an email to Claude for Work administrators, headed "Text watermark extends to Claude Opus 5", named one and dated it: "Starting September 9, Claude Opus 5 responses will have the same imperceptible text watermark as Fable 5.1", and "Other current Claude models will follow over the coming weeks." On 2026-09-05 no public Anthropic page matched that notice. Development recorded 2026-09-25, not a correction. The help page now carries a per-model table, "Which Claude models support watermarking", in place of that one-sentence list. It ticks the text watermark, on first-party surfaces and on cloud partners, for Claude Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5, and says Opus 5 text marking on cloud partners rolls out gradually "starting September 14, 2026" and is fully available within one week. Claude Opus 5.5 launched on 2026-09-22, after the threshold, so the day-one rule covers it. An email to Claude Platform customers received the same day, headed "Watermarking begins September 30, 2026", says "Claude Opus 5 was the first of these, on September 14". That is five days later than the September 9 the 2026-09-04 notice gave. The two Anthropic documents disagree, and this row records September 14, the date Anthropic put in writing after the fact. That first-party date comes from the email alone; the help page table confirms Opus 5 as marked without a first-party date, and its footnote dates only the cloud rollout from September 14. The same email says that "On September 30, 2026, Anthropic will begin applying its EU AI Act text watermark" to Claude Fable 5, Claude Sonnet 5 and Claude Opus 4.8, and that "Rollout on Amazon Bedrock, Google Cloud, and Microsoft Foundry may take a few additional days." The help page table does not tick those three for text as of 2026-09-25, so their dates rest on an official announcement. For the rest of the models released before 2026-08-02 the help page now gives a horizon, "with all covered by December 2, 2026", which matches Article 111(4) of the AI Act, but it gives no date for any single model. The per-model tracker on this page carries the rollout row by row. The notice also supplies the explanation the public pages lacked for why the mark reaches every surface: "Because the watermark is applied at the model layer, it's present everywhere your organization uses Claude". The 2026-09-25 email says the same of the September 30 models: the watermark "applies globally on every platform where these models are served". The detector column stays Partial because access is conditional rather than open: detection is "available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups)", plus enterprises with their own Act obligations, through a request form, and Anthropic says it plans to expand access over time. The admin notice summarises the same limit as "eligible EU organizations" and adds two commitments that appear on no public page: Anthropic "does not see or store text submitted to" the detection API, and "There is no admin or user setting to turn the watermark off." What is public and free covers files only. claude.com/check-files is an ungated in-browser Claude Content Checker that reads C2PA Content Credentials on 17 listed formats, keeps the upload local ("Your file never leaves your device"), and states plainly "The tool does not check text." So anyone can check a Claude image, video or audio file today, and nobody outside those eligible categories can check a Claude sentence. The metadata column stays Partial because the documented scopes still do not add up to unconditional coverage, and there are three of them. The admin notice says files Claude creates in the apps (.png, .jpg, .svg) "have carried a C2PA Content Credential since September 1". The help page describes the same behaviour for a supported file type "such as a PNG or JPEG" with no start date, scopes signed provenance metadata to "where Claude supports processing files", and on cloud partners says supported models "will carry watermarks" while metadata "applies only where a platform offers Claude's file generation features". The platform release notes' 2026-09-01 entry covers a third scope, image, video and audio files produced by the code execution tool and retrieved through the Files API. One of those three has a start date and it is the one with no public source. Anthropic is also not a C2PA member at any tier, unlike OpenAI, Google, Meta, Amazon and Microsoft. Anthropic: How Claude's text watermark works | Yes | N/A | N/A | N/A | Partial | Partial | Yes | 2026-09-25 |
Google #Gemini app and web experience (consumer)Gemini consumer surfacesVerified 2026-09-25Evidence and caveatsDeepMind's SynthID page states, verbatim, "We've expanded SynthID to watermarking and identifying text generated by the Gemini app and web experience." A Google-affiliated reply on Google's own AI developer forum, dated 2026-08-05, states that API text is not SynthID-watermarked and that native text watermarking is not planned. Nothing published reconciles the two, so the app/web text row stays Contested. Media watermarking is not in dispute. The SynthID Detector portal is access-gated rather than public, which is why the detector column is Partial. Rechecked 2026-08-17: the DeepMind sentence is unchanged, and Google's own Gemini Apps verification tool documents images, videos and audio only, with text absent from the page entirely. That is the second reason the detector column is Partial: even on the consumer surface Google says is watermarked, Google offers users no way to check text. Rechecked 2026-09-03: the sentence is unchanged, the page still scopes SynthID to "Google's generative AI consumer products" and never mentions the API, and the SynthID Detector portal is still gated behind an early-tester waitlist Google describes as a collaboration with "journalists and media professionals". The developer-surface reversal of 2026-08-19 is recorded on the Gemini API row. Reopened 2026-09-04, when one link in this row's evidence chain turned out to be broken: support.google.com/gemini/answer/16162474, the Gemini Apps help page behind the images, videos and audio only reading, now returns 404. That sentence keeps its 2026-08-17 reading date until the page is relocated. What was reread on 2026-09-04 is the DeepMind sentence and the gating on the SynthID Detector portal, and both are unchanged. Relocated 2026-09-25: the same guidance now lives at support.google.com/gemini/answer/16722517, titled "Verify AI-generated images, videos, and audio". It still covers images, videos and audio only and never mentions checking text. It now also documents Content Credentials checks alongside SynthID. Rechecked 2026-09-25: the DeepMind sentence, the "consumer products" scoping and the early-tester waitlist are unchanged. Google DeepMind: SynthID | Contested | Yes | Yes | Yes | Yes | Partial | Yes | 2026-09-25 |
Google #Gemini API, AI Studio and Antigravity (developer)Named in the original forum reply: gemini-2.5-flash-lite, gemini-3.1-flash-liteVerified 2026-09-25Evidence and caveatsSplit from the consumer row deliberately, and the most volatile row in this database. Google's position here has now reversed twice on the same forum thread, both times from the same account. On 2026-08-05 a reply carrying the Discourse user title "Google" answered an Article 50(2) question with a flat denial: "Generated text from the API is NOT SynthID-watermarked. There is no machine-readable providence [sic] signal... Native text watermarking is not planned at the moment." This row recorded that as No. On 2026-08-19 the same author retracted it: "I need to post an important correction to my previous message: After checking further with the team, it turns out that text generated via the Gemini API IS actually SynthID-watermarked! I apologize for the confusion earlier, the previous statement was incorrect. This also applies to text generated through Google AI Studio and/or antigravity!" Rechecked 2026-09-03, and again 2026-09-25, against the thread's raw post data: the 2026-08-05 post is still live and unedited, so a reader who stops at the first answer gets the withdrawn one, and the correction is a separate post rather than an edit. The row is Contested rather than Yes because the axis has flipped, not resolved. The denial no longer contradicts Google's documentation; the correction now claims more than any documentation supports. DeepMind's SynthID page still scopes text watermarking to "the Gemini app and web experience" and to "Google's generative AI consumer products", and Google's developer SynthID page, last updated 2025-04-09, still does not mention the API. Neither post is marked as the thread's accepted answer, and the account's only visible credential is a user title, not a staff or moderator badge. A follow-up asking whether API text was always watermarked or introduced at some point, posted 2026-08-19, was still unanswered on 2026-09-25, thirty-seven days later. Note also what nobody can do either way: no published route accepts text, so the Gemini app flow and the SynthID Detector portal both take image, video and audio only. Watermarked and verifiable are separate questions here, and the second answer is still no. SynthID watermarking and Article 50(2) on the Google AI Developer Forum | Contested | Yes | Yes | Yes | Yes | Partial | Yes | 2026-09-25 |
Google #SynthID-Text, open-sourced implementationShipped in Hugging Face Transformers 4.46.0+Verified 2026-09-25Evidence and caveatsThe one text watermark anyone can actually run and detect end to end: a logits processor applied after Top-K and Top-P sampling, using tournament sampling (named in the Nature paper the page links), with a reference Bayesian detector that returns watermarked / not watermarked / uncertain. Every independent robustness evaluation of "SynthID" tests this, not Google's production keys and configuration, which have never been published. Google: SynthID safeguards documentation | Yes | N/A | N/A | N/A | N/A | Yes | Yes | 2026-09-25 |
OpenAI #ChatGPT and API text outputAll current text modelsVerified 2026-09-25Evidence and caveatsOpenAI describes expanding provenance signals to all modalities including text as a goal, in the future tense. Reporting from 2024 established that OpenAI built a text watermarking system internally and held it back over circumvention risk, false positives, and disproportionate impact on non-native English writers. Nothing since supersedes that. Corroborated 2026-08-17 against OpenAI's developer content-provenance guide, which documents images (C2PA Content Credentials plus a SynthID watermark) and audio (SynthID) and does not mention text anywhere. Rechecked 2026-09-25 against the help-centre page cited here: its answer to "Do you have plans to support text outputs?" still states a goal "to expand provenance signals to all modalities including text", now tied to OpenAI's commitments under the Commission's Code of Practice on Transparency, and its modality table still lists images and audio only. OpenAI Help: Provenance signals in OpenAI-generated content | No | N/A | N/A | N/A | N/A | N/A | N/A | 2026-09-25 |
OpenAI #ChatGPT, API and Codex image outputGPT-image series and DALL·E seriesVerified 2026-09-25Evidence and caveatsSince 2026-05-19, OpenAI embeds Google DeepMind's SynthID watermark in generated images alongside C2PA Content Credentials. Corrected 2026-09-03: this row implied C2PA steering-committee membership was part of that rollout. OpenAI's own page places it in 2024, alongside adding Content Credentials to DALL-E 3, and describes only "C2PA Conforming Generator Product" status as recent. OpenAI's framing is that the two layers are complementary: C2PA carries context, SynthID survives when the metadata does not, and it states plainly that metadata "can be stripped, lost through uploads and downloads, or broken by transformations" and that "No detection method is foolproof." OpenAI's post introduced the public Verify tool as a preview. Rechecked 2026-09-25: openai.com/verify redirects to openai.com/research/verify/, the tool page itself no longer uses the word preview, and it still accepts images and audio only. OpenAI: Advancing content provenance | N/A | Yes | N/A | N/A | Yes | Yes | Yes | 2026-09-25 |
OpenAI #ChatGPT and API audio outputVerified 2026-09-25Evidence and caveatsCorrected 2026-09-03: this row previously read Yes for metadata, on the basis that audio "got the same treatment" as images. It did not. OpenAI marks audio with SynthID only and does not attach C2PA Content Credentials to it. Three of its own surfaces agree: the 2026-07-31 update says supported audio "now includes SynthID watermarking" and never mentions C2PA; the help-centre modality table reads "Audio | SynthID watermarks"; and the developer provenance guide scopes Content Credentials to "Images" while scoping SynthID to "Images and audio", stating that "images include C2PA and SynthID results, and audio includes a SynthID result." So an audio file has no manifest to strip and no issuer to read, which also means the usual C2PA caveat does not apply to it. Added 2026-07-31, two days before EU AI Act Article 50 became applicable, together with a verification API, POST /v1/content_provenance_checks, that accepts images and audio up to 50 MiB with audio capped at 60 seconds. The surface name is also narrowed this cycle: OpenAI's own page says "ChatGPT and the OpenAI API" and never names ChatGPT Voice or GPT-Live, which this row previously did. Notably, OpenAI's GPT-Live system card published three weeks earlier makes no mention of SynthID, C2PA, or watermarking. Rechecked 2026-09-25: the update, the help-centre table and the developer guide all read as quoted. OpenAI: Advancing content provenance (audio update) | N/A | N/A | Yes | N/A | No | Yes | Yes | 2026-09-25 |
OpenAI #Sora video outputVerified 2026-09-25Evidence and caveatsOpenAI states every Sora video includes both visible and invisible provenance signals. A November 2025 investigation by Ethan Le Sage found the reverse in practice: videos carrying the visible watermark had no detectable C2PA metadata via the Content Credentials Verify tool or the open-source c2pa-rs CLI, while Pro-tier videos without the visible mark did. Rechecked 2026-09-03 and 2026-09-25: the post is unedited, carries no author correction, and its three comments are all from November 2025 with none from OpenAI. Corrected 2026-09-03: this row read Yes for a public detector, which was never right. no OpenAI provenance surface accepts video at all. The Verify tool takes PNG, JPG, WEBP and a list of audio formats; the Content Provenance API takes the same. So the one modality where OpenAI's claim has been contradicted is also the one modality OpenAI gives nobody a way to check, and the November finding still rests on a single independent tester using third-party tooling. Independent investigation: Sora watermark and C2PA inconsistency | N/A | N/A | N/A | Contested | Contested | No | Yes | 2026-09-25 |
Meta #Meta AI app and meta.ai image outputMuse ImageVerified 2026-09-25Evidence and caveatsContent Seal launched 2026-07-07 for images, described as carrying "a hidden provenance signal that stays intact, even when cropped, compressed, resized, or screenshotted". Meta says it plans to extend it to video; no video launch has been announced. Detector moves from No to Partial on 2026-09-03: Meta's own announcement previews a web tool at meta.ai/identification "that lets you check whether an image carries a Content Seal watermark". Partial rather than Yes because it is explicitly a preview, recognises only images made or edited with Muse Image through Meta's own app or site, misses output from older Meta AI models, is rate-limited daily, and is not interoperable with C2PA Content Credentials or SynthID. Photorealistic Meta AI images separately carry visible markers plus invisible watermarks and metadata. Rechecked 2026-09-25: the Muse post is unchanged and still says Meta plans "to extend Content Seal to video soon", with Muse Video "coming soon". The detector page has changed. It is now headed "Identify files created or edited with AI" and its upload control accepts an image, video, or audio file. Meta has not announced Content Seal for video or said what the tool reports for a video or audio upload, so video stays No and the detector stays Partial. Meta: Introducing Muse Image and Muse Video | N/A | Yes | N/A | No | Yes | Partial | Partial | 2026-09-25 |
Meta #Llama Defenders audio toolingVerified 2026-09-25Evidence and caveatsMeta shipped an audio watermark detector on 2025-04-29, more than a year before Content Seal and under entirely different branding, aimed at voice fraud. Rechecked 2026-09-03: access is still not self-serve. Meta names ZenDesk, Bell Canada and AT&T as launch integrations and tells everyone else they "can request information by visiting the Llama Defenders Program website", which redirected to developer.meta.com/ai/llama-protections/ai-defenders/ on 2026-09-03 and to dev.meta.ai/llama/llama-protections/ai-defenders on 2026-09-25. Neither version documents a form, waitlist or download for the audio tools. Hence Partial. Meta's AI Defenders Program and Llama protection tools | N/A | N/A | Yes | N/A | Unknown | Partial | Partial | 2026-09-25 |
Meta #Llama open-weight modelsLlama 3.1, Llama 4, Muse GlimmerVerified 2026-09-25Evidence and caveatsCitation caveat recorded 2026-09-03: the Stable Signature post cited here is from October 2023 and covers images only, describing modality expansion as something Meta "hope[s] to explore" rather than ship, so it supports the images-under-another-name point but cannot itself evidence a claim about Llama model cards. Those are cited below on their own terms. The Llama 3.1 and Llama 4 model cards contain zero mentions of watermarking. There is also a structural reason to expect none: once weights ship, whoever runs the model controls decoding, so a provider cannot apply a sampling-time text watermark. Meta has open-sourced a Content Seal framework whose text component, TextSeal, is a May 2026 preprint Meta never claims to have deployed. Because it is generation-time, it could not be retrofitted to text after the fact anyway. Meta signed the EU Code of Practice on Transparency of AI-Generated Content on 2026-07-28, which covers text, while its own announcement discusses only image tooling. Muse Glimmer, released 2026-08-10 under Apache 2.0, is the clearest illustration of the structural point: it shipped after the 2026-08-02 marking threshold, runs locally on a single consumer GPU, and carries no provenance language in its model card. A signature covering text does not reach weights someone else is running. Rechecked 2026-09-25: the Stable Signature post is unchanged, and the Llama 3.1 and Llama 4 model cards and the Muse Glimmer model page still contain no mention of watermarking, provenance, C2PA or Content Seal. Meta: Stable Signature research | No | N/A | N/A | N/A | N/A | N/A | N/A | 2026-09-25 |
xAI #Grok outputVerified 2026-09-25Evidence and caveatsxAI's Grok FAQ states that "Generated images and videos include a Grok watermark to indicate that the content was created with AI" and that "There is no setting to remove the watermark." That is a visible mark on the media, which is why image and video are Yes and mechanism is Partial: the FAQ says what the mark is, not how any invisible signal would work. Text is absent from the FAQ entirely, so it stays Unknown. The FAQ also gives a rationale worth quoting, that "In some jurisdictions, labeling AI-generated content is also legally required." Separately, xAI's Acceptable Use Policy prohibits "stripping, altering or circumventing embedded provenance metadata or watermarks." That clause could not be re-read on 2026-09-03, when x.ai returned 403 to scripted fetches and the docs.x.ai copy returned 404. It was re-read in a browser on 2026-09-25 and the wording is unchanged. The FAQ now points to it directly: "Removing, altering, or obscuring the watermark or other provenance signals is prohibited under our Acceptable Use Policy." That clause is an obligation on users and does not establish that xAI embeds any such metadata, so the metadata column is Unknown rather than Partial. xAI is not a C2PA member and did not sign the EU transparency code. The Grok 4.6 model card of 2026-08-12 is the strongest evidence yet for the Text column: across the whole document there is no mention of watermarking, SynthID, C2PA, provenance, machine-readable marking, or the EU AI Act. Silence in a launch document is not a denial, so the row stays Unknown rather than No. xAI: Grok FAQ | Unknown | Yes | Unknown | Yes | Unknown | No | Partial | 2026-09-25 |
DeepSeek #chat.deepseek.com and Open PlatformVerified 2026-09-25Evidence and caveatsDeepSeek's own documentation describes visible AI-content labels required by China's labeling measures, not an invisible watermark. The widely repeated claim that DeepSeek hides a digital fingerprint in its text traces to secondary press describing the national standard's "implicit labeling" requirement, and is not corroborated by DeepSeek's own pages. DeepSeek: Model and algorithm disclosure | No | Unknown | N/A | N/A | Unknown | No | N/A | 2026-09-25 |
Microsoft #Microsoft 365 Copilot and DesignerVerified 2026-09-25Evidence and caveatsCorrected 2026-09-03: this row read Yes for a public detector. Microsoft operates none. Its page names no detection tool and routes verification through third-party C2PA readers instead, so the detector column is now No. The metadata column drops to Partial for a reason stated on Microsoft's own page: "Currently, this additional information is added only to the metadata of images. We're working on getting the information added to video and audio content, but we don't have a specific time frame for when that will happen." So Copilot video and audio carry no provenance metadata today. What Microsoft does ship is perceptible rather than hidden: audio watermarks "verbally state 'This audio is generated by AI'" at the start or end of a clip. Video and audio watermarks sit behind a tenant admin Cloud Policy that defaults to disabled, and image watermarks are a per-user setting under My Account, so all three are off unless somebody turns them on. The document contains no provision for watermarking plain-text Copilot responses. Page dated 2026-08-07, and unchanged when reopened on 2026-09-25. Microsoft Learn: Watermarks for AI-generated content | No | Yes | Partial | Partial | Partial | No | Yes | 2026-09-25 |
Amazon #Bedrock: Titan Image, Nova Canvas, Nova ReelVerified 2026-09-25Evidence and caveatsInvisible watermarks plus C2PA metadata on generated images by default, and a Bedrock Watermark Detection feature that scores whether an image carries a Titan Image Generator G1 or Nova Canvas mark. Rechecked 2026-09-03 and 2026-09-25, the access conditions are unchanged and narrow enough to matter: detection is "available in public preview release", only in the us-west-2 and us-east-1 Regions, and AWS notes the API is "not available in the latest SDKs" so callers must downgrade to reach it. AWS also warns that "images that are modified from the original image may produce less accurate detection results." Hence Partial rather than Yes. Nova Reel embeds a per-frame mark designed to survive H.264. No watermarking mechanism is documented for Amazon's text models. AWS documentation for Amazon Titan image models | No | Yes | N/A | Yes | Yes | Partial | Partial | 2026-09-25 |
Mistral AI #Le Chat and La PlateformeVerified 2026-09-25Evidence and caveatsThe gap closed on the commitment side, not the product side. Mistral's usage policy still says nothing about watermarking, which is why this row cited it and read Unknown, but its AI-governance pages now carry a dated first-party statement: "Mistral AI has signed the EU Code of Practice on Transparency of AI-generated Content, which sets out how output marking should be implemented technically", and "We are actively working on implementing our obligations and will provide output marking and a detection solution in accordance with the Code of Practice by December 2, 2026." The source URL moved there on 2026-09-03. Nothing is shipped today, and Mistral is not late: 2026-12-02 is the AI Act's transitional deadline for generative systems already on the market before 2026-08-02, per Article 111(4). So the honest reading is committed with a deadline rather than unknown. One gap remains: that statement sits on the pages for two systems named Vibe Code and Vibe Work, and no first-party page confirms the same commitment covers Le Chat or the platform models. Le Chat's images come from a Black Forest Labs partnership rather than a Mistral image model, and there is no confirmation Mistral enables that provider's optional invisible-watermark library. Rechecked 2026-09-25: both quoted sentences are unchanged, and the AI-systems index still lists only Vibe Code and Vibe Work. The page also gives its own basis for the date: the Article 50(2) obligations "come into effect on December 2, 2026, in line with the revised timeline under Article 75(d) of the AI Omnibus". That is a different citation from the Article 111(4) reading above, for the same date. Mistral: AI governance, Vibe Work (output marking commitment) | Unknown | Unknown | N/A | N/A | Unknown | No | Unknown | 2026-09-25 |
Perplexity #Answers and image generationVerified 2026-09-25Evidence and caveatsArchitecturally a router over third-party models, so any watermark present is most plausibly inherited from whichever provider served the request rather than added by Perplexity. That makes a per-provider marking field the wrong shape for this row, and it is kept only so the absence is on the record. Whether provenance metadata survives Perplexity's own pipeline is unconfirmed. Rechecked 2026-09-03: the cited community thread is from 2025-05-15 and concerns model availability, not marking, and trust.perplexity.ai renders only its title to a fetcher, so the one place a first-party statement would plausibly live could not be read. Recorded as unread rather than as an absence. Rechecked 2026-09-25 with the same result: the thread is unchanged, and trust.perplexity.ai did not finish loading in a browser either, so it is still unread. Perplexity community: image generation models | Unknown | Unknown | N/A | N/A | Unknown | N/A | N/A | 2026-09-25 |
Alibaba #Qwen international API vs Tongyi Qianwen in ChinaVerified 2026-09-25Evidence and caveatsTwo different Chinese standards are in play here and conflating them is the easy mistake. The cited page is Alibaba Cloud leading GB/T 45909-2025, a digital-watermarking standard effective January 2026, and it names deployments across Amap, Xianyu, Taobao and Tmall but not Qwen, which still held when it was reopened on 2026-09-25. Separate from that is GB 45438-2025, the mandatory AI content-labelling standard effective 2025-09-01, and on 2026-09-03 Alibaba-owned documentation was found citing it by name for a compliance route built on "the practice of Qwen and other Alibaba products". That route matters because of what it is not: for images and video it checks for an implicit label in file metadata, and for text it offers a classifier, text_aigc_detector via the TextModerationPlus API, which guesses whether text reads as AI-generated rather than reading a watermark out of it. So text stays Unknown for a watermark specifically, while metadata and detector move to Partial: Alibaba sells detection, as a paid cloud service, and its image watermarking is now first-party documented as embedding "visible or invisible" marks automatically. The 2023 tech-press report describing screenshot-resistant invisible watermarks in Tongyi Qianwen under the name Orange Shield remains unlocatable on any Alibaba domain after a domain-restricted search, so treat it as uncorroborated. Alibaba retired the Tongyi Qianwen brand for Qwen on 2026-02-03. Qwen3.8-Max, published 2026-08-12, makes no watermarking or labelling claim in its model card. Alibaba Cloud: national digital watermark standard GB/T 45909-2025 | Unknown | Unknown | N/A | N/A | Partial | Partial | Partial | 2026-09-25 |
One provider row cannot answer the question most readers arrive with, which is whether the specific Claude model in front of them is watermarked. Anthropic's answer differs by model and lives in several documents that do not agree on every date, so it gets its own table. Claude Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5 are marked and documented as marked. An email Anthropic sent customers on 25 September 2026 dates Opus 5 from 14 September 2026 (an administrator notice had said 9 September) and schedules Claude Fable 5, Sonnet 5 and Opus 4.8 from 30 September 2026, which its help page does not reflect as of 25 September 2026. Every other older model has only Anthropic's commitment to cover it by 2 December 2026.
Which Claude models are watermarked
| Model | Released | Marked since | Watermark | Claim |
|---|---|---|---|---|
Claude Fable 5.1claude-fable-5-1 Evidence and caveatsMarked from launch, and the first Claude model Anthropic's own day-one rule reached: models launched on or after 2026-08-02 support machine-readable marking at launch. The help page table ticks its text watermark on first-party surfaces and on cloud partners, and the platform release notes entry for 2026-09-01 says text generated by Fable 5.1 and Mythos 5.1 carries Anthropic's text watermark. Confirmed rather than announced because it sits in the product documentation, not only in a post or an email.
| 2026-09-01 | 2026-09-01 | Marked | Confirmed |
Claude Mythos 5.1claude-mythos-5-1 Evidence and caveatsLaunched the same day as Claude Fable 5.1 under the same commitment, and ticked for text in the same help page table. Access is the difference: the platform release notes scope Mythos 5.1 to Project Glasswing participants rather than general availability, so almost nobody outside those programmes can produce a marked Mythos sample to test.
| 2026-09-01 | 2026-09-01 | Marked | Confirmed |
Claude Opus 5claude-opus-5 Evidence and caveatsReleased nine days before Anthropic's own 2026-08-02 threshold, so the day-one rule never covered it, and the first model Anthropic retrofitted. The help page table ticks its text watermark on first-party surfaces and on cloud partners, with a footnote that on cloud partners it rolls out gradually "starting September 14, 2026" and is fully available within one week. Anthropic's 2026-09-25 email to Claude Platform customers says "Claude Opus 5 was the first of these, on September 14". The 2026-09-04 administrator notice had announced a different date: "Starting September 9, Claude Opus 5 responses will have the same imperceptible text watermark as Fable 5.1". The site reported that notice accurately. The two Anthropic documents disagree, and this row uses September 14, the date the later email gives. The help page table confirms the model as marked but gives no first-party date; its footnote dates only the cloud rollout from September 14. Output from September 9 to 13 falls between the two dates, and neither document says whether it is marked. Confirmed from the 2026-09-25 re-read, the first on which this site found the model in the help page table.
| 2026-07-24 | 2026-09-14 | Marked | Confirmed |
Claude Opus 5.5claude-opus-5-5 Evidence and caveatsLaunched on 2026-09-22 per the platform release notes, after the 2026-08-02 threshold, so Anthropic's day-one rule applies: models launched on or after that date support marking at launch. The help page table ticks its text watermark on first-party surfaces and on cloud partners, and the 2026-09-25 email lists it among the models that "already carry" the watermark. No Anthropic document states a start date for this model separately. The marked-since date is its launch date under the day-one rule.
| 2026-09-22 | 2026-09-22 | Marked | Confirmed |
Claude Sonnet 5claude-sonnet-5 Evidence and caveatsReleased before the 2026-08-02 threshold. Anthropic's 2026-09-25 email to Claude Platform customers says that "On September 30, 2026, Anthropic will begin applying its EU AI Act text watermark" to this model, Claude Fable 5 and Claude Opus 4.8, and that rollout on Amazon Bedrock, Google Cloud and Microsoft Foundry "may take a few additional days". Output from before 2026-09-30 should not be expected to carry the mark. The help page table does not tick its text watermark as of 2026-09-25, only C2PA in files, so the row rests on an official announcement. It becomes Confirmed when the table ticks the text column.
| 2026-06-30 | From 2026-09-30 | Scheduled | Official announcement |
Claude Fable 5claude-fable-5 Evidence and caveatsReleased before the threshold and superseded by Claude Fable 5.1 on 2026-09-01. Anthropic's 2026-09-25 email dates marking for it from September 30, 2026, with cloud partners possibly a few days later. The help page table does not tick its text watermark as of 2026-09-25. Anyone comparing two Fable outputs should check the version and the date: Fable 5.1 output is marked from launch, and Fable 5 output from before 2026-09-30 should not be expected to carry the mark.
| 2026-06-09 | From 2026-09-30 | Scheduled | Official announcement |
Claude Opus 4.8claude-opus-4-8 Evidence and caveatsThe only 4.x model Anthropic has dated. Until 2026-09-25 it sat in the undated group of earlier models on this page. Anthropic's 2026-09-25 email names it with Claude Fable 5 and Claude Sonnet 5 for marking from September 30, 2026, with cloud partners possibly a few days later. The help page table does not tick its text watermark as of 2026-09-25, only C2PA in files, so the row rests on an official announcement.
| 2026-05-28 | From 2026-09-30 | Scheduled | Official announcement |
Claude Mythos 5claude-mythos-5 Evidence and caveatsReleased alongside Claude Fable 5 and superseded by Claude Mythos 5.1 on 2026-09-01. The 2026-09-25 email that dates Fable 5, Sonnet 5 and Opus 4.8 does not mention it, and the help page table ticks only C2PA in files for it as of 2026-09-25. The only commitment that covers it is the help page's general one for models released before 2026-08-02, "with all covered by December 2, 2026". Restricted access makes it the hardest row here for a reader to check independently, which is a reason to treat the absence as unverified rather than tested.
| 2026-06-09 | No date stated | Not marked | Unknown |
Earlier models (Opus 4.7, 4.6 and 4.5, Sonnet 4.6 and 4.5, Haiku 4.5)claude-opus-4-7, claude-opus-4-6, claude-opus-4-5, claude-sonnet-4-6, claude-sonnet-4-5, claude-haiku-4-5 Evidence and caveatsAnthropic has dated none of these. The help page table lists each of them with C2PA in files and no text watermark as of 2026-09-25, and the 2026-09-25 email names only Fable 5, Sonnet 5 and Opus 4.8 as next. What binds this group is a horizon rather than a per-model plan. The help page says Anthropic is adding watermarks to models released before 2026-08-02, "with all covered by December 2, 2026", which matches Article 111(4) of Regulation (EU) 2026/1744: providers of generative systems placed on the market before 2026-08-02 have until 2026-12-02 to satisfy Article 50(2) of the AI Act. The claim is Unknown because no document says when any single model in this group gets marked. Claude Opus 4.8 had its own row from 2026-09-25, when Anthropic dated it.
| Various, all before 2026-08-02 | No date stated | Not marked | Unknown |
The Claude Opus 5 row is confirmed by the per-model table on Anthropic's help page, re-read 2026-09-25, which ticks the text watermark for Opus 5. Anthropic's 2026-09-04 notice to Claude for Work administrators had said September 9; a 2026-09-25 email to Claude Platform customers says September 14, and the row uses that date. The help page gives no first-party date; its footnote dates only the cloud rollout from September 14. The three September 30 rows (Fable 5, Sonnet 5 and Opus 4.8) rest on the 2026-09-25 email alone, which is why they are labelled official announcements, and each moves to confirmed when the help page ticks its text watermark column. The email says rollout on Amazon Bedrock, Google Cloud and Microsoft Foundry may take a few additional days.
What each value means
The distinction that matters most is between No and Unknown. "No" means a provider's own documentation rules it out. "Unknown" means nobody has said either way, which is a finding about that provider's transparency, not a gap for us to fill with a guess.
- Yes
- The provider's own current documentation says this output is marked.
- No
- The provider's own documentation confirms it is not marked, or explicitly describes it as a future goal.
- Partial
- Marked only under conditions: a specific product surface, an admin setting, or an opt-in.
- Contested
- Two sources of comparable authority disagree, and nothing published reconciles them.
- Unknown
- No primary source says either way. Absence of a claim is not a claim of absence.
- N/A
- The provider does not offer this output type here.
Three things the table shows that summaries miss
Text and media are on completely different timelines
Read down the image column and it is nearly solid: invisible watermarks plus C2PA metadata are settled industry practice. Read down the text column and it is one Yes, one Contested, several explicit Nos and a row of Unknowns. Anyone who says "AI content is watermarked now" is reading the image column.
A watermark without a detector is not a check you can run
The public-detector column is where the practical answer lives, and Partial is doing a lot of work in it. Image and audio provenance can be verified today by anyone with a browser, Claude's own generated files included: Anthropic runs a free, ungated checker for Content Credentials at claude.com/check-files which states plainly that it does not check text. Text is where the gate is: Anthropic's detection API shipped on 1 September 2026 but only to eligible organizations under EU law, Google's portal is waitlisted, and the one detector anyone can run belongs to an open-source implementation rather than a provider's production system. So the answer to "can I check this text" is still no for almost everyone, and now for a different reason.
The surface split is where the contradictions hide
Google appears three times because its consumer app, its developer API, and its open-sourced algorithm carry three different answers for text, and the sources for them disagree. Collapsing those into one "Google" row is how a real, unresolved contradiction gets flattened into a confident sentence.
Method, limits, and how to cite this
Each row starts from a primary source the provider controls: documentation, a support article, terms, a model card, or an official announcement. Secondary reporting is used to find those primaries, not to stand in for them. Where a provider blocks automated access and the claim was read through an archive capture, the row's note says so.
The honest limits: this table records what providers say, not what independent testing has confirmed. Nobody outside these companies can currently verify a text watermark's presence in a given passage, so a "Yes" in the text column means documented, not measured. Rows go stale. Check the last-verified date before relying on one.
Reuse is welcome. Cite it as: AI Watermark Status Database, www.aiwatermarkremoval.com, version 1.4.1, updated 2026-09-25. A link back to this page is the only thing asked. If you reproduce a row, please carry its last-verified date with it.
Found a row that is wrong or stale? That is a correction, and corrections get logged publicly. See the corrections policy.