Skip to main content
AI Watermark Removal

Primary source, decoded

Claude Text Watermark Explained: How It Works (Sept 2026)

On August 14, 2026, Anthropic published the first real explanation of how Claude's text watermark works. It ended the speculation that followed Anthropic's early-August watermarking announcement: the mark is a keyed statistical pattern woven into which words Claude picks, a version of Google DeepMind's SynthID-Text approach, with no hidden characters involved. September then supplied the rollout: two named models on September 1, a detection API in private preview, a notice to administrators dating Claude Opus 5 to September 9, and on September 25 a help centre table that confirms Opus 5 as marked and a customer email that dates it from September 14 and Claude Fable 5, Sonnet 5 and Opus 4.8 from September 30. This page walks through the mechanism in plain English, what Anthropic says survives editing, why code is different, and exactly what can and cannot be checked as of September 25, 2026.

By Rowan ValePublished Revised Sources verified Official announcement

Correction,

This page said in two places that Anthropic's detection API had not shipped. The detection section called it "a first-party commitment with no date, no interface, and no stated access rules", and the lab section listed the official detector as "announced August 14, 2026, not released". Both were wrong from September 1, 2026, when Anthropic put watermark detection into private preview and updated its August 14 post to say so: its help centre states detection is "currently in private preview, available to eligible organizations as required under EU law". A reader would have concluded that no Claude watermark detection existed anywhere, when regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, EU civil society groups and enterprises with their own verification duty could already apply for access. Both passages now say the API is in private preview, that access is limited today to eligible organizations under EU law, and that no route exists for the general public. Anthropic naming Claude Opus 5 and September 9, 2026 in a notice to administrators on September 4, 2026 is a later development and not part of this correction.

All corrections

The short version

Does Claude watermark text?
Yes. Models launched on or after 2026-08-02 mark at launch, and Anthropic's help centre table marks four models.
Which models carry it?
Fable 5.1, Mythos 5.1 and Opus 5.5 from launch; Opus 5 from 2026-09-14. Fable 5, Sonnet 5 and Opus 4.8 from 2026-09-30, per a customer email.
Is it a hidden character?
No. Anthropic: nothing is added to the text and there are no hidden characters.
Does copy/paste remove it?
No. The signal is the word sequence itself, so it travels with the text.
Does editing remove it?
Anthropic: light editing probably won't remove it completely; a complete rewrite will.
Can you check for it today?
Private preview since 2026-09-01, for eligible organizations under EU law only. Nothing the public can run.
Does detection prove authorship?
No. It gives a likelihood Claude was involved, and cannot separate wrote from edited.
Does Claude Code watermark output?
Covered by policy, but constrained code gets little to none. Free-choice comments do.
Can you turn it off?
No admin or user setting, per an admin notice. Anthropic's public help page says nothing either way.
Does it identify you?
No. Anthropic: it contains no information about the user, their organization, or their conversations.

Rows verified 2026-09-25 against Anthropic's help centre article and its per-model table, its 2026-08-14 news post as updated 2026-09-01, the Fable 5.1 and Mythos 5.1 launch post of 2026-09-01, and the Claude Platform release notes. The 2026-09-30 date rests on an email Anthropic sent Claude Platform customers, received 2026-09-25, which the help centre table did not yet reflect that day. The absence of a setting rests on an email Anthropic showed Claude for Work administrators on 2026-09-04; that wording was still on no public Anthropic page as of 2026-09-25.

After Anthropic announced its watermarking plans, the mechanism remained unexplained until August 14. The support article that broke the news in early August said only that supported models weave an imperceptible watermark directly into the text itself. Reddit threads guessed zero-width characters. Trade press guessed token biasing. Removal tools sold fixes for a mechanism nobody had seen.

On August 14, 2026, Anthropic published "How Claude's text watermark works" and settled it. The statistical guess was right, the hidden-character guess was wrong, and several specifics nobody had predicted, about code, proofreading, and translation, turn out to matter more than the headline.

This guide goes through what Anthropic actually said, sentence by sentence where it counts, and is explicit about the line between what Anthropic confirmed and what remains unpublished.

Key takeaways

  • The watermark is created during generation, not attached afterward. A secret key plus a few preceding words steer which of several equally good next words Claude picks, and the pattern of those picks is the mark.
  • Anthropic names the family: a version of Google DeepMind's SynthID-Text approach, descended from Scott Aaronson's 2022 proposal. The exact algorithm, parameters, and key remain unpublished.
  • Which models carry it is now a table, not a policy. Anthropic's help centre ticks the text watermark for Fable 5.1 and Mythos 5.1 (released September 1, 2026), Opus 5.5 (released September 22, 2026) and Opus 5. Its email to Claude Platform customers, received September 25, 2026, says Opus 5 has been marked since September 14 (a September 4 notice to administrators had said September 9) and dates Claude Fable 5, Sonnet 5 and Opus 4.8 from September 30, 2026. The help centre says every model released before August 2, 2026 will be covered by December 2, 2026.
  • There are no hidden characters to delete. Unicode cleaners, metadata strippers, and formatting changes do not touch this signal, because it lives in the words themselves.
  • Anthropic's own robustness summary is one sentence: light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will. Everything between those poles is unmeasured.
  • Code carries less watermark than prose by design: where only one output is correct, no watermark is applied. Comments, with free word choice, do get marked.
  • Anthropic put its detection API into private preview on September 1, 2026, limited today to eligible organizations under EU law rather than the public, and we found no independently validated third-party option. Its notice to administrators adds that Anthropic does not see or store text submitted to the API, a commitment that appears on no public Anthropic page as of September 25, 2026. Until access widens, treat any product claiming to check text for the mark as unverified.
  • Files are a separate story with a public answer. Anthropic runs a free browser-based checker at claude.com/check-files for C2PA Content Credentials on 17 listed image, video and audio formats, and it states plainly: "The tool does not check text."
  • A positive detection will mean Claude was likely involved, not that Claude wrote the document. Anthropic is explicit that it cannot distinguish wrote from heavily edited.
  • No independent test of Grammarly, QuillBot, ChatGPT rewriting, Gemini rewriting, or any other editing tool against a real Claude watermark detector has been published by anyone, including this site. Reasoning from Anthropic's own stated poles produces informed expectations, not measurements.

Figure 1

Verified record

Claude watermark status, at a glance

Seven questions people arrive with, answered as of the last verification date. Built to be updated independently of the article text, because these rows will change.

Text watermarkRolling out
Anthropic marks text from Claude models launched on or after August 2, 2026. Its help centre, re-read September 25, 2026, ticks the text watermark for Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5, and says every earlier model will be covered by December 2, 2026. Anthropic's September 25, 2026 email to Claude Platform customers dates Opus 5 from September 14 (its September 4 notice to administrators had said September 9) and schedules Fable 5, Sonnet 5 and Opus 4.8 from September 30, 2026.
How it worksExplained
Published August 14, 2026: a keyed variant of Google DeepMind's SynthID-Text approach, in the family descending from Scott Aaronson's 2022 proposal. Explicitly not hidden characters.
Detection documentationStill promised
The technical post explains marking, not checking. Anthropic's support article still lists detection details as forthcoming technical documentation.
Official detectorGated, not public
No public tool, from Anthropic or any third party, can check a passage of text for the Claude watermark. Detection does exist, as the private-preview API in the next row. Files are the exception: Anthropic's free Claude Content Checker reads Content Credentials on 17 listed formats and states that it does not check text.
Public detection APIPrivate preview
Shipped September 1, 2026, but not to the public: access is limited today to eligible organizations under EU law, such as regulators, media, fact-checkers and researchers, plus enterprises with their own verification duty. Anthropic says it plans to widen access, without naming a date. Its September 4, 2026 notice to administrators adds that it does not see or store text submitted to the API, which its public help page still does not say when re-read on September 25, 2026.
Independent verificationText no, files yes
Anthropic says checking the text watermark relies on its key, so there is no public way to reproduce that check. C2PA credentials on generated files are an open standard and can be inspected today with existing tools.
Claude CodeCovered, weaker
Claude Code is named in Anthropic's marking policy. Where an exact output is required the watermark is not applied, so code carries less signal than prose. Comments do carry it.

Method Each row verified on September 25, 2026 against Anthropic's own documentation: the August 14, 2026 technical explanation as updated September 1, the support article on how Claude marks AI-generated content and its new per-model table, the Fable 5.1 and Mythos 5.1 launch post, the Claude Platform release notes, and Anthropic's September 25, 2026 email to Claude Platform customers. Rows that also cite Anthropic's September 4, 2026 notice to Claude for Work administrators say so.

Checked 2026-09-25

Anthropic: how Claude's text watermark works

Figure 2

Conceptual explanation

Three unrelated things people call an AI watermark

Almost every confident wrong claim about Claude comes from swapping one of these for another. They are stored differently, found differently, and removed differently.

Hidden characters

Not Claude's mechanism

Example
Zero-width Unicode
Lives in
Characters and text encoding
Detected by
Character inspection

Statistical text watermark

Claude text watermark

Example
Claude's newly described approach
Lives in
Patterns across generated token choices
Detected by
Statistical watermark detector

Content provenance

Separate system for files

Example
C2PA / Content Credentials
Lives in
Signed provenance manifest and content binding
Detected by
Credential and provenance verification

These are different technologies.

Method Mechanism descriptions from each system's primary documentation: Anthropic for the text watermark and file credentials, the C2PA specification for provenance.

Checked 2026-08-15

What actually happened on August 14, 2026?

Confirmed

Three separate events keep getting collapsed into one headline. Separating them explains why so much coverage contradicts itself.

The rollout, the news cycle, and the explanation happened on three different dates. Anthropic's marking policy took effect quietly: models launched on or after August 2, 2026, the day EU AI Act Article 50 transparency duties became applicable, support machine-readable marking at launch, per Anthropic's support documentation.

The support article was live by the evening of August 10, and press coverage followed within hours and through August 11: Interesting Engineering, then TechCrunch, Tech Times, Fortune, and others. Those stories, and everything written before August 14, could only describe what the watermark was, not how it worked: the support documentation was all Anthropic had published.

The technical explanation arrived on August 14: a post titled "How Claude's text watermark works" that names the mechanism family, walks through what survives editing, and announces a detection API. That post is the primary source for this page, and it makes much of what currently ranks for these queries outdated.

One more distinction worth keeping straight: the technical explanation is not the detection documentation. Anthropic's support article still promises details on detection mechanisms in forthcoming technical documentation, and as of August 15 it does not even link the August 14 post. What was published explains how marking works, not how checking will.

Figure 3

Verified record

How Claude's text watermark arrived

Eight dated events and two scheduled items. The September 30 item rests on Anthropic's September 25, 2026 email alone; the help page did not yet tick those three models when re-read that day. The gap between August 10 and August 14 is why so much of what ranks for these queries describes a mechanism nobody had seen.

  1. 2026-06-10

    EU publishes the Transparency Code of Practice

    The Code of Practice on Transparency of AI-Generated Content is published, committing signatories to marking AI-generated output.

    Primary source
  2. July 2026

    Anthropic signs it

    Anthropic signs the Code of Practice, one of roughly 190 signatories. Anthropic gives the month rather than a day, and the Commission announced the signatory list on July 31, 2026.

    Primary source
  3. 2026-08-02

    EU AI Act Article 50 becomes applicable

    Transparency obligations take effect. This is the date Anthropic uses as its threshold: Claude models launched on or after it support machine-readable marking at launch.

    Primary source
  4. 2026-08-10

    Anthropic's support article goes live

    The first public documentation that Claude marks its text. Press coverage follows within hours and through August 11. It describes what the mark is, not how it works.

    Primary source
  5. 2026-08-14

    Anthropic explains the mechanism

    How Claude's text watermark works is published: a keyed variant of SynthID-Text, explicitly not hidden characters, with a detection API announced as coming soon.

    Primary source
  6. 2026-09-01

    Detection API ships in private preview

    Anthropic's detection API enters private preview, limited to eligible organizations under EU law, with Anthropic saying it plans to expand access over time.

    Primary source
  7. 2026-09-14

    Claude Opus 5 watermark begins

    Anthropic's help page lists Claude Opus 5 as marked, and its September 25, 2026 email says the mark began on September 14. Its September 4, 2026 notice to Claude for Work administrators had announced September 9.

    Primary source
  8. 2026-09-25

    Anthropic dates Fable 5, Sonnet 5 and Opus 4.8

    An email to Claude Platform customers schedules the text watermark for Claude Fable 5, Claude Sonnet 5 and Claude Opus 4.8. The same day, the help page carries a per-model table and says every model released before August 2, 2026 will be covered by December 2, 2026.

    Primary source
  9. 2026-09-30

    Fable 5, Sonnet 5, Opus 4.8 watermark begins, per email

    Not yet

    Anthropic's September 25, 2026 email says these three models carry the text watermark from this date. Rollout on Amazon Bedrock, Google Cloud and Microsoft Foundry may take a few additional days.

    Primary source
  10. 2026-12-02

    Transitional deadline for older systems

    Not yet

    Generative systems placed on the EU market before August 2, 2026 must comply with Article 50(2) by this date, under Article 111(4) as amended by Regulation (EU) 2026/1744.

    Primary source

Method Each date checked against a primary source: EUR-Lex for the regulation, European Commission pages for the Code of Practice, Anthropic's own pages for its documentation, and Wayback Machine captures to establish when pages went live. The September 14, 2026 entry rests on Anthropic's help page table, which confirms Opus 5 as marked, and on its September 25, 2026 email, which gives the date; the help page dates only the cloud rollout from September 14; its September 4, 2026 notice to Claude for Work administrators had given September 9. The September 25 and September 30 entries rest on that email.

Checked 2026-09-25

What did Anthropic add on September 1 and September 4?

Official announcement

Two named models and a working detector on September 1. A date for Claude Opus 5 on September 4, in a notice to administrators. On September 25, a per-model table on the help centre and a customer email that moves Opus 5 to September 14 and dates three more models.

September 1, 2026 turned the marking policy into a list of models. Anthropic launched Claude Fable 5.1 and Claude Mythos 5.1, the first Claude models to ship on the far side of its own August 2, 2026 threshold, and its help centre then stated "Models currently supported include Fable 5.1 and Mythos 5.1." (By September 25, 2026 that sentence had been replaced by a per-model table.) The Claude Platform release notes for the same day say it in engineering terms: "Text generated by Claude Fable 5.1 and Claude Mythos 5.1 carries Anthropic's text watermark."

The launch post is also the cleanest public source for what the watermark does not contain. On the mark itself it says: "This watermark is invisible to anyone who does not have the detection API. It has no practical impact on the quality or content of Claude's outputs and contains no information about the user, their organization, or their conversations with Claude."

Detection shipped the same day, into a private preview. Anthropic's help centre and its August 14 post, updated September 1, both say detection is available to eligible organizations as required under EU law, and both give the same list: regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups. Enterprises with their own EU AI Act verification duty may also apply. Anthropic says it plans to expand access over time and names no date.

Updated September 25, 2026. Anthropic's help centre now carries a per-model table, "Which Claude models support watermarking", with separate columns for text on Anthropic's own surfaces, text on AWS, Google Cloud and Microsoft Foundry, and C2PA in files. It ticks the text watermark for Claude Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5, and says that on cloud partners Opus 5 marking is "gradually available" from September 14, 2026 and fully available within one week. Opus 5.5 launched on September 22, 2026, after the threshold, so it is marked from launch. The same day Anthropic emailed Claude Platform customers under the subject "Watermarking begins September 30, 2026". The email says "Claude Opus 5 was the first of these, on September 14", five days after the September 9 the administrator notice gave; this page uses September 14, the date the email gives. The help centre table confirms Opus 5 as marked but gives no first-party date; its footnote dates only the cloud rollout from September 14. It says Anthropic "will begin applying its EU AI Act text watermark" to Claude Fable 5, Claude Sonnet 5 and Claude Opus 4.8 on September 30, 2026, and that "Rollout on Amazon Bedrock, Google Cloud, and Microsoft Foundry may take a few additional days." As of September 25, 2026 the help centre table does not tick those three models for text, so their date is an official announcement. The help centre also now sets an end date for the retrofit: "Anthropic is adding watermarks to outputs from models released before August 2, 2026, with all covered by December 2, 2026." Claude Mythos 5 and the 4.x models other than Opus 4.8 have no date of their own.

The horizon shortened twice, and every version is Anthropic's. The August 14 post says of models launched before August 2, 2026: "The EU law includes a transition period for Anthropic models launched before August 2, 2026, and we're working to add watermarking for those models as well. This will be rolled out over the coming months." The September 4 notice said "the coming weeks". The New Stack reported the "coming months" version as current on September 1, 2026. The help centre now gives a date, December 2, 2026, which matches the EU deadline in Article 111(4) of the AI Act. The August 14 post, reopened September 25, 2026, still says months.

Two more claims sit only in that notice, and both answer questions readers ask constantly. Anthropic tells administrators there is no public tool for checking text and that it "does not see or store text submitted to" the detection API. That second commitment is the obvious privacy objection to a detection API, and as of September 25, 2026 it has no public source: neither the help centre nor the news post says anything about whether Anthropic sees or stores submitted text.

The reason the mark turns up everywhere is a design decision Anthropic states publicly. Its help centre: "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from." The September 4 notice repeats that for administrators as applied at the model layer, and lists chat, Cowork, Claude Code, and the API. The help centre's own list is longer and is the one to use: Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag.

Cloud access carries the text mark and only sometimes the file metadata. The help centre: "When supported Claude models are accessed through AWS, Google Cloud, or Microsoft Foundry they will carry watermarks. Content Credentials (C2PA) are added when Claude creates a file, so it applies only where a platform offers Claude's file generation features", which it lists as the Claude apps and the Claude Platform (API), including Claude Platform on AWS and Claude in Microsoft Foundry. The text mark can reach a partner cloud later than Anthropic's own surfaces: a week for Opus 5, and "a few additional days" for the September 30 wave, per Anthropic. So an AWS or Foundry deployment of a supported model produces watermarked text; whether it produces credentialed files depends on whether that platform offers Claude's file generation at all.

  • C2PA scope one, the apps. The help centre says Claude attaches signed provenance metadata when it generates a supported file type such as a PNG or JPEG, and gives no start date. The September 4 notice dates it: files Claude creates in the apps "have carried a C2PA Content Credential since September 1". That date is notice-only as of September 25, 2026.
  • C2PA scope two, the API. The platform release notes for September 1, 2026 describe something different: "supported image, video, and audio files that Claude produces through the code execution tool carry C2PA Content Credentials when you retrieve them through the Files API on the Claude API." Different surface, different file types, same standard. Do not merge the two scopes.
  • Files have a free public checker; text does not. Anthropic's help centre points to the Claude Content Checker at claude.com/check-files, which needs no sign-in, reads Content Credentials on 17 listed formats (JPG, PNG, GIF, WEBP, TIFF, HEIC, AVIF, SVG, DNG, JXL, MP4, MOV, AVI, WAV, MP3, M4A, FLAC), and states "Your file stays on your device." It also states "The tool does not check text."

Everything in this section that came only from one of the two emails is graded Official announcement rather than Confirmed, which is the site's label for something stated in an official communication but not yet reflected in product documentation. Claude Opus 5 moved to Confirmed on September 25, 2026, when this site found it ticked in the help centre table. Claude Fable 5, Sonnet 5 and Opus 4.8 move to Confirmed when the table ticks their text column.

How Claude marks AI-generated content

Confirmed

Anthropic's own help centre article, summarised. It is the document every other source on this page points back to, and it is short enough to read in full.

The article's title is the heading above, it lives at support.claude.com, and it is the canonical statement of Anthropic's marking commitments. It opens by recording that Anthropic signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content as a provider of both generative models and generative systems, and says Anthropic will update the article and publish more detailed technical guidance as it becomes available.

Four commitments carry the content. New models mark from day one, meaning Claude models launched in the EU on or after August 2, 2026 support machine-readable marking at launch, with embedded watermarks in text and signed provenance metadata on files where supported. Marking works everywhere Claude does, across Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, worldwide. Existing models are in progress under the law's transition period. And watermark detection is in private preview for the eligible organizations listed above.

Two techniques, described separately, are the part most coverage blurs. Embedded watermarks are woven into generated text and do not change its meaning, quality, or readability. Signed provenance metadata follows the C2PA standard and is attached when Claude generates a supported file type such as a .svg, .png, or .jpg. The article's limitations section is the sentence to remember in both directions: a detected mark indicates content may have been processed by Claude and is not conclusive, and lack of a detected mark does not mean the content was not AI-generated or processed.

Read it at the source rather than through us. The full article is linked in the sources at the foot of this page, and it is the document Anthropic itself tells administrators to send to users who ask questions.

How does Claude's watermark actually work?

Official announcement

Claude replaces coin-flip word choices with keyed ones. The text reads the same; the pattern of choices becomes checkable.

Claude generates text one token at a time. At each step there is a set of candidate next words, and many of the choices among them are low-stakes: important, useful, and valuable can all continue the same sentence without changing what it says.

Without watermarking, the model settles those close calls with randomness. With watermarking, Anthropic says the choice is settled by a secret key together with a few of the preceding words. The output is still natural text, and the words still look randomly chosen. But someone holding the key can recompute what the keyed process would have preferred at each step and check whether a passage's choices are consistent with it far more often than chance.

Anthropic's own analogy: play a board game, but replace the dice with successive digits of pi. The game plays out normally, and anyone who has the digits of pi can verify afterward that pi was steering the moves.

One property matters more than it sounds: the watermark changes the source of the randomness, not the shortlist. Anthropic is explicit that it does not push Claude toward words it would not otherwise have considered, giving the example that it would not make Claude reach for an obscure synonym like "nubilous" instead of overcast or grey. The candidates stay the candidates. Only the tiebreak changes.

Anthropic names its lineage directly: the method is a version of the SynthID-Text approach that Google DeepMind published in Nature in 2024, part of a family of keyed sampling watermarks going back to a 2022 proposal by Scott Aaronson.

  • Confirmed by Anthropic: the mechanism family, the role of a key plus preceding words, that only the randomness source changes, no hidden characters, no extra tokens, no added cost, and internal testing showing no impact on content, creativity, or readability.
  • Not published by Anthropic: the exact algorithm, how many preceding words seed the key, which SynthID-Text configuration it runs, how keys are managed, and the detector's math. The family is named; the specification is not.
  • Our interpretation, labeled as such: naming SynthID-Text tells you the kind of detection to expect, a statistical score over many tokens rather than a lookup. It does not license copying DeepMind's published parameters or numbers onto Claude, and the Nature paper describes more than one configuration without Anthropic saying which it uses.

That last distinction runs through the rest of this page. Where a sentence below is Anthropic's, it is quoted or attributed. Everything else is context from the published research literature on this family of watermarks.

Figure 4

Conceptual explanation

How Claude's text watermark is created and checked

The watermark is made during generation by correlating many token choices with a keyed signal. Detection separately scores whether that pattern accumulates in the finished text.

The signal is created while Claude chooses tokens

The previous text and a secret key help produce a pseudorandom signal. Claude still samples from plausible next-token candidates, but the keyed process helps decide which valid candidate wins.

Keyed signal

Previous text + secret key
Pseudorandom seed / watermark signal

Sampling loop

Claude's next-token distribution
Watermarked sampling / selection process
Chosen next token
Repeat across the response

Conceptual illustration based on the published SynthID-Text architecture and Anthropic's description of a keyed text watermark. Anthropic has not published its exact production configuration.

Unlike hidden-character watermarks, Claude's text watermark is created during generation. There is no invisible character attached to the finished text that can be deleted.

Method Structure follows the published SynthID-Text architecture of seed generation, sampling, and scoring, plus Anthropic's description of keyed Claude text watermarking. It is not Anthropic's exact production configuration.

Checked 2026-08-15

Source: Anthropic

Does Claude add hidden characters to its text?

Official announcement

Every popular theory that involved deleting something from the text was wrong, on Anthropic's own account.

Anthropic's post is unusually blunt on this point: nothing is added to the text and there are no hidden characters. That single sentence retires most of what circulated before it.

  • Zero-width characters: no. Not the mechanism, per Anthropic directly.
  • Invisible Unicode spaces or variation selectors: no. Same sentence.
  • Metadata attached to copied text: no. File metadata does not travel with ordinary plain-text copy/paste. A statistical watermark avoids that dependency because its signal is carried by the generated text itself.
  • Em dashes or punctuation habits: no. Style tells are real observations about model writing, but no provider has publicly named punctuation as a watermark, and Anthropic did not.
  • Hidden HTML or formatting tricks: no. The signal survives paste-as-plain-text because it is the words, not the wrapper.

Claude output may still contain some of those things in the ordinary course of writing. They are just not the watermark, and removing them does not touch it.

Figure 5

Verified record

What Claude's text watermark is, and what it is not

Nearly every item in the left column has been claimed as the watermark by a popular article or a removal tool. Anthropic's own explanation rules them out.

Not

  • Zero-width characters
  • Invisible Unicode
  • Hidden whitespace
  • Em dashes
  • HTML metadata
  • Formatting

Is

A statistical signal produced through patterns in token selection during generation.

Anthropic says nothing is added to the finished text. The mark is created while Claude chooses among eligible next-token alternatives, then read statistically across a passage by a detector with the required keyed information.

Confirmed by Anthropic

Claude may still produce em dashes, and any text can pick up stray Unicode in transit. Those things are real. They are simply not what Anthropic describes as its watermark, so removing them does not remove it.

Method Verdicts taken from Anthropic's August 14, 2026 statement that nothing is added to the text and there are no hidden characters, plus its description of the mechanism.

Checked 2026-08-15

Source: Anthropic

Why does copying and pasting not remove the watermark?

Official announcement

Copying moves the word sequence intact, and the word sequence is the watermark.

Paste Claude's output into Google Docs, Word, an email, or a CMS and the thing the detector would score, the sequence of chosen words, arrives unchanged. Anthropic's support documentation says the mark travels with copied text for exactly this reason.

What copy and paste does lose is formatting and any file-level metadata. Neither carries the watermark, so losing them changes nothing. This is the practical difference between a statistical text watermark and every attachment-based scheme: there is nothing bolted on that a destination app could strip.

Copying is not transforming. The signal only starts to move when the words themselves change, which is the next section.

Figure 6

Conceptual explanation

Why copy and paste does not inherently remove the signal

Changing the container is not the same thing as changing the word sequence.

Claude

The new system provides useful information for researchers.

Copy

Word / Google Docs / website

Thenewsystemprovidesusefulinformationforresearchers.

Words changed
0
Text sequence
Unchanged
Application
Changed

The watermark is associated with patterns in the generated text, not the app containing it.

Conceptual demonstration, not a live watermark detector.

Method Conceptual demonstration only. It does not detect, estimate, or remove Anthropic's watermark.

Checked 2026-08-15

How much editing does it take to break the watermark?

Official announcement

Anthropic's one-sentence robustness summary, and the two other factors it says matter: length and how constrained the text is.

Anthropic's own summary: "Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will." It adds, of the full-rewrite case, that it is arguable whether such text can still be described as AI-generated at all.

Between those poles, expect the signal to weaken as more of Claude's word choices are replaced. Anthropic publishes no thresholds, and any page telling you that changing some percentage of words removes the watermark is inventing a number that no publicly available detector can currently verify.

  • Length matters. Short passages contain few choices and therefore little signal. Anthropic: as a passage increases in length, confidence about Claude's involvement increases too.
  • Constraint matters. Factual passages watermark sparsely because there is often only one correct continuation. Anthropic's example: after "Isaac Newton's most famous work was called Principia", only "Mathematica" is right, so there is no choice to encode.
  • Transformation type matters. A translation produced by Claude is watermarked, because every output word is Claude's choice. Heavy third-party rewriting sits at the other end of the spectrum.

Figure 7

Conceptual explanation

Why rewriting affects the signal

The useful visual question is not how much strength remains. It is how much of Claude's original sequence still exists for a detector to score.

  1. Original

    Strongest expected signal

    Themodelprovidesvaluableinformationforresearchers.

    Claude's original word choices remain.

  2. Light edit

    Most choices remain

    Themodelprovidesuseful (changed)informationforresearchers.

    A few choices changed.

  3. Substantial rewrite

    Many choices replaced

    Researchers (changed)can (changed)obtain (changed)usefulinsights (changed)from (changed)the (changed)system. (changed)

    The sequence is now substantially different.

  4. New text

    Original sequence no longer retained

    A (changed)separate (changed)passage (changed)starts (changed)from (changed)independently (changed)chosen (changed)wording. (changed)

    There is no continuity with the original token sequence.

Statistical watermarking relies on patterns across many choices rather than one secret word.

Two other factors matter as much as edit depth: length, because short passages contain few choices to measure, and constraint, because factual sentences with one correct continuation carry little signal in the first place.

Method Conceptual illustration based on Anthropic's published robustness discussion and SynthID-Text's dependence on accumulated sequence evidence. It does not show measured detection probabilities.

Checked 2026-08-15

Source: Anthropic

A practical transformation reference

Official announcement

Every version of "does X remove it" people actually ask, graded by what Anthropic has said rather than a guess dressed up as a number.

Anthropic gives exactly two fixed points, the light-editing and complete-rewrite poles quoted above. Everything below places specific, commonly asked actions against those poles plus the length and constraint factors Anthropic names. None of the middle is publicly measured, by us or anyone else, until the detection API ships.

  • Copy/paste into any editor, email, CMS, or website: expected to survive. Evidence: Anthropic direct, the signal is the word sequence and copying preserves it exactly.
  • Formatting changes (bold, headers, markdown, plain-text reflow, pasting into Notepad): expected to survive. Evidence: Anthropic direct, the mark lives in word choice, not in formatting or file structure.
  • Typo and grammar correction on human-written text: little to nothing to detect in the first place. Evidence: Anthropic direct, addressing the proofreading case specifically.
  • Light manual editing of Claude's own output, a handful of words changed: probably not removed. Evidence: Anthropic direct, this is the light-editing pole.
  • Moderate rewriting, a meaningful minority of words replaced: may weaken. Evidence: our inference, interpolating between Anthropic's two stated poles. No published threshold exists.
  • Heavy rewriting or thorough paraphrasing, most words replaced: substantially weakened, trending toward removed. Evidence: our inference from Anthropic's poles, consistent with independent robustness research on this watermark family, which tested open reimplementations, not Claude itself.
  • Complete rewrite, every word replaced: removed, on Anthropic's own account, with the caveat that Anthropic itself calls it arguable whether such text still counts as AI-generated at all.
  • Summarizing Claude's output in your own words: functionally a heavy-to-complete rewrite. Evidence: our inference, since a summary by definition replaces most of the original wording.
  • Expanding Claude's output with substantial human-written additions: the Claude-written stretches keep whatever signal they had; the added text carries none. Evidence: our inference from the mixed-document case Anthropic describes.
  • Translation produced by Claude itself: watermarked. Evidence: Anthropic direct, every output word is Claude's choice.
  • Translating Claude's output afterward with a person or a different tool: word choices are replaced, placing it at the rewrite end of the spectrum. Evidence: Anthropic's support article lists translation among the changes that can leave content without a detectable mark; the degree is our inference.
  • Functional code where only one output compiles or is correct: little to no watermark applied by design. Evidence: Anthropic direct.
  • Code comments and documentation, where wording is free: watermarked like ordinary prose. Evidence: Anthropic direct.
  • Removing zero-width characters, invisible Unicode, or other hidden formatting: no effect on this watermark. Evidence: Anthropic direct, there are no hidden characters, so there is nothing in that category to remove.
  • Very short passages of any kind, edited or not: weak signal regardless of transformation, simply because there are too few word choices to accumulate a detectable pattern. Evidence: Anthropic direct.

No row above can currently be verified by running a detector, because the only detector is Anthropic's and its private preview is limited today to eligible organizations under EU law rather than to this site. Treat every "our inference" row as reasoning from Anthropic's own stated poles, not a measurement, and be skeptical of any source that states a specific percentage here.

Do Grammarly, QuillBot, or AI rewriting tools remove the watermark?

Research/proposal

The honest answer for every specific tool people ask about is the same: not independently tested. Here is what reasoning from Anthropic's own poles suggests, and why that is not evidence.

People ask this question tool by tool, and the answer does not change by name: no third party, including this site, has run any of these tools' output against a real Claude watermark detector, because the only one is in a private preview we do not hold access to as of September 25, 2026, and no public detector for text exists at all. What follows is reasoning from Anthropic's published statements, not experimental results, and it is labeled that way in every row.

  • Grammarly and Word's built-in editor, used for spelling, grammar, and style suggestions: these change relatively few words, which resembles Anthropic's light-editing case. Not independently tested. Our reasoning: probably does not fully remove the mark, by analogy to light editing, not by measurement.
  • Google Docs' built-in suggestions and spelling/grammar check: same category and same caveat as Grammarly and Word.
  • QuillBot and other dedicated paraphrasing tools: these replace substantially more wording than a grammar check, closer to the heavy-rewriting end of the spectrum. Not independently tested. Our reasoning: likely weakens the signal more than light editing does, with no published threshold for how much.
  • Asking ChatGPT or Gemini to rewrite Claude's output: if the other model regenerates the passage rather than lightly editing it, that approaches Anthropic's complete-rewrite pole, word by word. Not independently tested. Worth separating from the removal question: the output would be that other model's generation, carrying whatever watermark policy that model uses, if any, rather than a cleaned version of Claude's text.
  • Dedicated translation tools applied after Claude has already produced text: covered in the transformation reference above as a rewrite-class case. Not independently tested.

Treat any site claiming a tested, verified percentage for how well Grammarly, QuillBot, ChatGPT, or Gemini defeats Claude's watermark as making a claim it cannot currently back up. That evidence does not exist publicly yet, for anyone.

Which Claude watermark myths are still circulating?

Confirmed

Six specific claims that keep coming up in search results and social threads, checked directly against what Anthropic actually said.

Most of what is wrong about Claude's watermark online is not dishonest, it predates August 14 and never got corrected. These six keep resurfacing anyway.

  • "Claude's watermark is a zero-width character." No. Anthropic states directly that nothing is added to the text and there are no hidden characters. A zero-width character is something a scanner can find and delete; this mark is a pattern across many word choices with nothing to point to in any single character.
  • "Removing invisible Unicode removes Claude's watermark." No, for the same reason. A hidden-character cleaner, including this site's own, operates on a different layer entirely and cannot touch a signal that was never stored in a character.
  • "Removing em dashes removes Claude's watermark." No. Punctuation preference is a real, separately documented stylistic tell in AI writing, but no provider, including Anthropic, has publicly named punctuation as part of a watermarking mechanism. Deleting em dashes changes style, not the token sequence a detector would score.
  • "Pasting into Notepad removes it." No. Notepad strips all formatting and any file metadata by design, which is exactly why it is a clean test of the underlying claim: the words that come out are identical to the words that went in, and the watermark lives entirely in which words those are.
  • "An AI detector can tell you whether the watermark is gone." No. A generic AI-writing detector like the stylometric tools covered elsewhere on this site scores writing style without a key and without knowledge of Claude's watermark at all. It can return a confident-sounding verdict that has nothing to do with whether Anthropic's specific signal is present.
  • "If a watermark is detected, Claude wrote the whole document." No. Anthropic is explicit that detection indicates likely Claude involvement and cannot distinguish text Claude wrote from text Claude heavily edited. A positive result is consistent with a thousand human words and one Claude sentence, not just with fully AI-authored text.

Can Claude's watermark be removed?

Research/proposal

Not by cleaning characters, and nobody can currently verify any other method either. What our own tool does and does not do.

Character cleaning does nothing here. Removing zero-width characters, hidden Unicode, metadata, or unusual punctuation cannot address this watermark, because the signal is not stored in any of those. This site's own cleaner inspects and strips hidden Unicode, which remains useful against character-level marking that does exist in the wild, and for text hygiene. It does not, and cannot, remove Anthropic's statistical text watermark. Any tool that says otherwise is describing a different technology.

Transformation is the only category that plausibly affects a statistical signal, and the verified evidence base is one sentence long: light editing probably insufficient, complete rewrite sufficient. The middle is unmeasured, and it stays that way without detection access, because you cannot verify removal of a signal you cannot check for, and checking requires Anthropic's key.

So the honest answer to "can I remove it" is: partially, probably, at rewrite depths nobody can currently quantify, with success nobody can currently confirm. Distrust confident removal guarantees for as long as no independently runnable detector exists to hold them to.

Figure 8

Conceptual explanation

What are you actually trying to remove?

Three different questions get asked with the same words. Only one of them is about Anthropic's watermark, and it is the one nobody can currently verify an answer to.

Hidden Unicode characters?

Removable

A character cleaner can inspect and remove them, in the browser, in a second.

But these are not Anthropic's watermark. Anthropic says there are no hidden characters in Claude's text.

Open the checker

File metadata or provenance?

Separate system

C2PA credentials live in a file and can be inspected, stripped, or lost by ordinary uploads.

A separate system from the text watermark. Removing metadata leaves every watermarked word in place.

How C2PA works

Anthropic's statistical text watermark?

Not verifiable today

There is no character to delete. Only changing the words themselves affects it, and Anthropic says light editing probably will not be enough while a complete rewrite will.

No publicly available detector can currently verify whether a given attempt worked. Treat any guarantee as unverifiable.

Method Removal claims limited to what Anthropic has published plus what our own tool demonstrably does. No claim is made that any transformation defeats Anthropic detection.

Checked 2026-08-15

Can you detect Claude's watermark today?

Confirmed

Not with any publicly available detector, including the ones currently sold as Claude watermark checks. Here is what is actually announced.

Anthropic's detection API entered private preview on September 1, 2026, limited today to eligible organizations under EU law, and we found no independently validated public third-party detector. Its help centre states detection is "currently in private preview, available to eligible organizations as required under EU law" and lists the categories: regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups, plus enterprises with their own verification duty. Access is requested through a form, Anthropic says it plans to expand over time, and it names no date. Its developer documentation still publishes no detection endpoint, so even an accepted applicant is working from something the rest of us cannot read.

One privacy commitment is worth naming and one caveat comes with it. Anthropic's September 4, 2026 notice to administrators says it "does not see or store text submitted to" the detection API, which is the obvious objection to sending a passage to the company that made the model. As of September 25, 2026 that commitment appears on no public Anthropic page, so it is an official statement rather than documentation a reader can check.

Anthropic says detection relies on its watermark key. Without access to the necessary key or detection mechanism, a third party cannot directly reproduce Anthropic's official check from the public documentation alone. The sites offering a Claude watermark checker today appear to be doing one of two other things: scanning for hidden characters, which Anthropic says are not the mechanism, or running a generic AI-writing classifier, which is a different technology entirely.

Anthropic is also specific about what its detector reports: the likelihood that text was partly written by Claude. It will not recognize other providers' watermarks, because even providers using the same family of schemes hold different keys.

Figure 9

Conceptual explanation

Detection is accumulated evidence, not authorship proof

A detector scores whether the finished text lines up with the keyed pattern across many choices. It should not be visualized as a scanner that returns Claude wrote this.

Statistical scoring

Finished text + required keyed information

Scoring function

Evidence accumulates across token choices

Watermark signal / uncertain / no sufficient signal

No detector you can run. Anthropic's API entered private preview for eligible organizations under EU law on September 1, 2026.

What it can indicate

  • Evidence of the expected watermark signal.
  • Claude involvement in text, when enough evidence exists.

What it does not automatically prove

  • Claude authored every word.
  • The user cheated.
  • No human editing occurred.
  • Absence means the text was definitely human-written.

Involvement vs authorship

Human-written content

Claude-edited portion

Possible watermark evidence

Watermark evidence can indicate Claude involvement. It does not allocate intellectual authorship.

Generated

Human prompt → Claude text

Claude involvement

Edited

Human text → Claude edits

Involvement may be limited

Mixed

Human + Claude + human edits

Authorship remains contextual

Method Conceptual explanation based on Anthropic's August 14, 2026 description and the SynthID-Text scoring model. Limits reflect Anthropic's stated distinction between Claude involvement and authorship.

Checked 2026-08-15

Source: Anthropic

Is code from Claude Code watermarked too?

Official announcement

Covered by the policy, but structurally lighter than prose, because correct code leaves no room for word choice.

Anthropic's marking policy covers Claude Code by name, alongside the apps and the API. The technical post explains the limit that comes with that: where an exact output is required, where a different token would break the code or state a falsehood, the watermark is not applied.

Anthropic's summary is that code generally carries less watermarking than other kinds of text. Where code does have genuine freedom, Anthropic points to comments: word choice there is arbitrary, so comments are watermarked, with a negligible effect on the code itself.

The New Stack reported the same rule from the other direction on September 1, 2026: if choosing a different token could make an answer incorrect or break the code, Anthropic does not apply the watermark. That is press rather than a primary source, and the article does not attribute the sentence to a named Anthropic document, but it matches what the August 14 post says about constrained output.

The practical reading for developers: a short, tightly constrained snippet may carry little or no signal, while a longer generated file with comments and documentation carries more. Anthropic publishes no per-language or per-length figures, and this page will not invent any.

Figure 10

Conceptual explanation

Why prose gives the watermark more room than constrained code

The watermark can only use choices that are still valid. Natural language often has many acceptable continuations; exact code often has very few.

Natural-language sentence

The system provides...

usefulvaluablehelpfulimportant

More valid alternatives means more room to encode a statistical pattern.

Constrained code

if (user === null) {
return

Few valid alternatives means less room for the keyed process to choose.

Method Conceptual illustration of the entropy constraint described in SynthID-Text research and Anthropic's explanation that exact required outputs may not carry the mark.

Checked 2026-08-15

Source: Anthropic

What if Claude only proofread or translated my writing?

Official announcement

The scenarios people actually worry about, and the distinction that matters more than any of them: involvement is not authorship.

The proofreading case gets its own answer in Anthropic's post. If you write 1,000 words and Claude fixes the grammar, nearly all the words are yours, and in Anthropic's phrasing there is very little, if anything, for the watermark to attach to. Depending on length and edit depth, Claude's involvement might not be detectable at all.

Translation splits in two. A translation produced by Claude is watermarked, because every word of the output is Claude's choice. Text that started as Claude output and was then translated by a human or another tool has had its word choices replaced, which is the rewrite end of the editing spectrum; Anthropic's support documentation lists translation among the changes that can leave content without a detectable mark, and publishes nothing more specific.

Mixed documents follow from the same logic: the signal lives in the stretches Claude wrote, diluted by everything humans wrote around them, with detectability depending on how much Claude text survives and how long it is.

How is a watermark detector different from an AI detector?

Confirmed

One checks for a known signal with a key. The other guesses from style. They fail differently and prove different things.

Claude watermark detection, once it exists, will ask: is the specific keyed signal Anthropic embeds present in this text? A known signal, intentionally placed, statistically scored. Generic AI detectors ask a different question: does this text read like model output? No key, no embedded signal, just stylistic inference. Anthropic's own post draws this line, pointing to detection software like Pangram as the key-less alternative that looks for tells in phrasing.

The failure modes differ accordingly. Stylometric detectors have documented false positives against human writing, especially writing by non-native English speakers. A keyed watermark test only fires on text consistent with the keyed process, which over sufficient length is hard to produce by accident. Both approaches share the same blind spots at the margins: short text, heavy edits, and content from systems that never carried the signal.

And a Claude watermark check says nothing about ChatGPT or Gemini output by design. Keys are per-provider. Detection of everything is not what is being built; detection of Claude is.

How does the text watermark differ from a C2PA credential?

Official announcement

Anthropic runs two provenance systems. One is a property of the words; the other is an attachment to a file.

For text, the watermark is in the content itself: copy the words and the signal comes along. For generated files of supported types, .png, .jpg, and .svg, Anthropic attaches a content credential instead, in its words a small, cryptographically signed note in the file's metadata, using the C2PA standard that camera makers and photo software use to record where an image came from. Anthropic draws the contrast itself: that metadata label is very different from a watermark, and the underlying image or content is not altered to encode it.

Two different scopes now exist and they are easy to merge by accident. Files Claude creates in the apps have carried a Content Credential since September 1, 2026, a date that comes from Anthropic's September 4 notice to administrators and appears on no public Anthropic page as of September 25, 2026; the help centre describes the same coverage for a supported file type "such as a PNG or JPEG" with no start date. Separately, the Claude Platform release notes for September 1, 2026 say supported image, video, and audio files produced through the code execution tool carry C2PA Content Credentials when retrieved through the Files API. Different surfaces, different file types, one standard.

They fail in opposite ways. C2PA metadata is robust evidence while it is present, and trivially lost: screenshots, re-encoding, and many upload pipelines strip it. App-created files are covered as described above; other platforms are a separate question, and Anthropic notes its file credentials may not be supported everywhere, adding that signed provenance metadata reaches a cloud platform only where that platform offers Claude's file generation features. The text watermark cannot be stripped in that sense at all, but it fades under exactly the thing metadata ignores, rewriting the content.

There is also a practical asymmetry worth knowing today, and it is the sharpest single contrast on this page. Because C2PA is an open standard, anyone can inspect a Claude-generated file with existing C2PA-aware tools, and Anthropic now runs its own free checker at claude.com/check-files: no sign-in, 17 listed image, video and audio formats, and in its own words "Your file stays on your device." The same page says "The tool does not check text." Files have a public checker; text has an application form.

Conflating the two produces confident nonsense in both directions: tools that promise to remove the text watermark by cleaning metadata, and verdicts that treat a missing manifest as proof of anything. A missing manifest proves nothing, and a cleaned file still contains every watermarked word.

Figure 11

Conceptual explanation

Statistical text watermark vs C2PA provenance

These systems live at different layers. One emerges from generated word choices; the other attaches signed provenance information to an asset.

Text watermark

Generation

Token choices

Statistical signal in the text sequence

Copying the words preserves the sequence. Rewriting changes the evidence being scored.

C2PA / Content Credentials

Asset

Signed provenance manifest

Cryptographic content binding

The credential can be verified while present, but ordinary file processing may strip it.

Method Mechanism comparison based on Anthropic's distinction between its text watermark and file credentials, plus the C2PA model of signed manifests and content binding.

Checked 2026-08-15

What did early coverage of the Claude watermark get wrong?

Confirmed

Most of what ranks for these queries was written before Anthropic explained anything. Here is where the early accounts diverge from the primary source.

This is not a complaint about reporters working from the only document that existed. It is a warning about what happens when those articles keep ranking after the primary source arrives.

  • Translation is the biggest one. Early coverage suggested translation may knock the watermark out. Anthropic says the opposite for the case it addresses: a translation produced by Claude carries the watermark, because every word of it is Claude's choice.
  • The hidden-character theory, still the most common claim on tool sites selling Claude watermark removal, is contradicted outright: nothing is added to the text and there are no hidden characters.
  • The mechanism was described as token biasing by some outlets before Anthropic confirmed anything, and cited to the wrong research lineage. Anthropic's stated lineage is SynthID-Text from 2024 and Aaronson's 2022 proposal, and its watermark changes the randomness source rather than biasing Claude toward words it would not otherwise pick.
  • At least one outlet named a specific current model as covered by the on-or-after August 2, 2026 threshold, and named the wrong one: the model in that report launched in 2025. The first two models Anthropic named, Fable 5.1 and Mythos 5.1, did not exist until September 1, 2026, three weeks after that coverage ran.
  • The scope qualifier went missing almost everywhere. Anthropic's support article frames the threshold around models launched in the EU on or after August 2, 2026, while its technical post says watermarking is applied globally at launch because there is not yet a durable way to scope it by region. Both statements are Anthropic's; reporting that quotes only one of them reads as more absolute than the source.

A separate category of wrongness is still live in search results: pages claiming Claude does not watermark text at all, some of which sell stylometric AI detection as the alternative. That was defensible before August 2026 and is not now.

The Claude Watermark Lab

Research/proposal

The honest version of a testing section: the matrix is ready, and every result cell says the same thing until Anthropic's API exists.

We cannot test Claude's watermark yet. Independent verification requires the detection API, which shipped on September 1, 2026 into a private preview this site does not have access to, and we found no independently validated public third-party detector to use instead. Publishing invented robustness percentages would be worse than publishing nothing, so this section is a commitment rather than a result.

  • Official Anthropic detector: announced August 14, 2026, released September 1, 2026 as an API in private preview limited today to eligible organizations under EU law. No public interface, no pricing, and no date for wider access.
  • Our access: none. We do not fall into any category Anthropic lists, so every robustness question on this page stays unmeasured by us until that changes.
  • Independent experiments completed: one. The invisible-character census (96 Claude outputs, three model tiers, zero hidden characters found), published with data and scripts.
  • Transformations tracked in our methodology, awaiting detection access: 20, the sixteen in the matrix below plus expansion and three tool-specific runs.
  • Public dataset: not yet published. A results table only becomes real research once it holds real detector output; publishing empty rows as results would be exactly the SEO padding this page argues against elsewhere.
  • Last updated: 2026-09-25.

The test matrix is built and waiting in our lab: original output, copy and paste, formatting changes, grammar correction, light manual editing, moderate rewriting, heavy rewriting, complete rewrite, summarization, expansion, Claude-produced translation, third-party translation of Claude's output, human and Claude mixtures, functional code, code comments, short answers, long-form prose, Grammarly, QuillBot, and LLM-based rewriting. Every result cell currently reads awaiting detection access, and they will be populated the day access exists, at a dedicated results page rather than folded into this one.

What we could measure without a detector, we already have: the character layer. The invisible-character census is published in the lab, and Anthropic's August 14 statement independently confirmed its conclusion.

Figure 12

Not yet tested

Our test matrix, published empty on purpose

Sixteen transformations we will measure the day Anthropic's detection API exists. Until then every result cell says the same thing, because inventing numbers would be worse than having none.

TransformationExampleExpected effectIndependently tested?Result
Original Claude outputUnmodified responseStrongest expected signalNoAwaiting detection access
Copy and pasteInto Word, Docs, or a CMSUnchanged: identical wordsNoAwaiting detection access
Formatting onlyFonts, spacing, headingsUnchanged: identical wordsNoAwaiting detection access
Grammar correctionLight proofreading passLikely preservedNoAwaiting detection access
Light rewritingOccasional word swapsLikely preservedNoAwaiting detection access
Moderate rewritingSentence-level reworkPotentially weakenedNoAwaiting detection access
Heavy rewritingMost sentences rebuiltSubstantially alteredNoAwaiting detection access
Complete rewriteEvery word replacedRemoved, per AnthropicNoAwaiting detection access
SummarizationCondensed to a fractionUnpublishedNoAwaiting detection access
Translation by ClaudeClaude translates its own outputWatermarked, per AnthropicNoAwaiting detection access
Translation by another toolThird-party machine translationMay be undetectable, per AnthropicNoAwaiting detection access
Mixed human and Claude textInterleaved paragraphsDepends on how much Claude text survivesNoAwaiting detection access
Code, no commentsFunction bodies onlyLittle to none, per AnthropicNoAwaiting detection access
Code with commentsCommented source fileComments carry the signalNoAwaiting detection access
Short responsesUnder a paragraphToo little material, per AnthropicNoAwaiting detection access
Long-form proseMulti-page outputBest case for detectionNoAwaiting detection access

The one thing we could measure without a detector, we already did: a census of 96 Claude outputs found zero hidden characters, which Anthropic's explanation later confirmed. Read the census.

Method Cells marked per Anthropic restate Anthropic's published statements; Unpublished means Anthropic has said nothing; the remaining cells are our inference between Anthropic's two stated poles. No result has been measured, by us or by any published third-party test we could find.

Checked 2026-08-15

Source ledger

7 claims tracked

  1. 01

    Claude's text watermark is a keyed statistical pattern in word choice, with no hidden characters involved

    Official announcement
    Proves
    Anthropic's own description of its mechanism, and its explicit rejection of hidden-character marking.
    Does not prove
    The exact algorithm, parameters, or key handling, none of which are published.
    Would change this
    Anthropic publishing detector documentation or a full technical specification.
    Primary source
    Anthropic, "How Claude's text watermark works"Checked 2026-09-25
  2. 02

    The mechanism is a version of Google DeepMind's SynthID-Text, in the family started by Scott Aaronson's 2022 proposal

    Official announcement
    Proves
    The stated lineage and therefore the kind of detection to expect: statistical scoring over many tokens.
    Does not prove
    That Anthropic's parameters match DeepMind's published configuration, or that published SynthID-Text robustness numbers transfer to Claude.
    Would change this
    A technical paper, detector spec, or measurable public API from Anthropic.
    Primary source
    Anthropic, "How Claude's text watermark works"Checked 2026-09-25
  3. 03

    Light editing probably does not remove the watermark completely; a complete rewrite replacing every word does

    Official announcement
    Proves
    Anthropic's own stated robustness bounds, including the caveats for short and heavily constrained text.
    Does not prove
    Any threshold between those poles. No publicly available detector can currently measure the middle.
    Would change this
    Public detection access enabling reproducible measurement, including ours.
    Primary source
    Anthropic, "How Claude's text watermark works"Checked 2026-09-25
  4. 04

    The watermark detection API shipped in private preview on 2026-09-01

    Official announcement
    Proves
    That a detector exists, and that access is limited today to eligible organizations under EU law: regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, EU civil society groups, and enterprises with their own verification duty.
    Does not prove
    Public availability, pricing, acceptance criteria, or a date for wider access. Anthropic says only that it plans to expand over time. Its September 4, 2026 notice to administrators adds that it does not see or store text submitted to the API, a commitment that appears on no public Anthropic page as of 2026-09-25.
    Would change this
    Access opening beyond the listed categories, or Anthropic publishing the API documentation.
  5. 05

    No detector for text that any member of the public can run exists as of 2026-09-25

    Confirmed
    Proves
    That the only text detector is Anthropic's, behind an application, and that no validated third-party option exists.
    Does not prove
    That nothing can be checked. Eligible organizations can check text, which is why a newsroom and a writer get different answers to the same question, and anyone can check a file's Content Credential free at claude.com/check-files, which states "The tool does not check text."
    Would change this
    Anthropic opening text access, or a third party publishing a validated detector.
  6. 06

    Anthropic's help centre marks four models, and Anthropic has dated three more from 2026-09-30

    Official announcement
    Proves
    That the rollout has reached older models in fact and not only in policy. The help centre table ticks the text watermark for Fable 5.1 and Mythos 5.1 (released 2026-09-01), Opus 5.5 (released 2026-09-22) and Opus 5 (released 2026-07-24), the first retrofitted model. The 2026-09-25 email dates Opus 5 marking from 2026-09-14 and dates Claude Fable 5, Sonnet 5 and Opus 4.8 from 2026-09-30. The trigger this row watched for on 2026-09-05, the help centre naming Claude Opus 5, fired by 2026-09-25.
    Does not prove
    That older Claude output is marked. Text generated before a given model's own marking date carries nothing. Anthropic's own dates for Opus 5 disagree: the 2026-09-04 notice said 2026-09-09 and the 2026-09-25 email says 2026-09-14. The help centre table confirms Opus 5 as marked but gives no first-party date; its footnote dates only the cloud rollout from 2026-09-14. The 2026-09-30 date for Fable 5, Sonnet 5 and Opus 4.8 rests on the email alone as of 2026-09-25, and cloud partners may lag it by a few days. Mythos 5 and the other 4.x models have only the help centre's "all covered by December 2, 2026". Through August the marked-model list was empty, which this row previously recorded.
    Would change this
    The help centre table ticking the text column for Claude Fable 5, Sonnet 5 or Opus 4.8, or any Anthropic document giving a date for Claude Mythos 5 or the other 4.x models.
  7. 07

    There is no admin or user setting to turn the text watermark off

    Official announcement
    Proves
    That Anthropic has told paying administrators, in writing, that no setting exists, and that it describes the watermark as applied at the model layer so chat, Cowork, Claude Code and the API are all covered.
    Does not prove
    Anything a reader can verify. The sentence was on no public Anthropic page as of 2026-09-25, and neither the help centre nor the August 14 post says anything about a setting either way. The help centre does state publicly that "Watermarking will be applied at the model level".
    Would change this
    Anthropic publishing the same wording publicly, or a product setting appearing.

FAQ

Does Claude watermark its text?

Yes, and Anthropic names which models. Anthropic marks text from Claude models launched on or after August 2, 2026, and its help centre table, re-read September 25, 2026, ticks the text watermark for Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5. Older models are being retrofitted. Anthropic's email to Claude Platform customers, received September 25, 2026, says Opus 5 has been marked since September 14 and dates Claude Fable 5, Sonnet 5 and Opus 4.8 from September 30, 2026, and the help centre says all models released before August 2, 2026 will be covered by December 2, 2026. For anything generated before a given model's own marking date, treat the rollout as in progress rather than complete.

Is Claude Opus 5 watermarked?

Yes, from September 14, 2026, by Anthropic's own account. Claude Opus 5 launched on July 24, 2026, nine days before Anthropic's own August 2, 2026 threshold, so it was outside the marking policy at launch. Anthropic's help centre table, re-read September 25, 2026, ticks its text watermark on Anthropic's surfaces and on AWS, Google Cloud and Microsoft Foundry, where it notes the rollout was gradual from September 14 and complete within one week. Anthropic's email to Claude Platform customers, received the same day, says "Claude Opus 5 was the first of these, on September 14." An earlier email to Claude for Work administrators, seen on September 4, 2026, had announced September 9. Anthropic's two dates differ by five days, and neither document says whether output from September 9 to 13 is marked.

Is Claude Sonnet 5 watermarked?

From September 30, 2026, according to an Anthropic email, and not yet according to its help centre. Claude Sonnet 5 launched on June 30, 2026, before Anthropic's August 2, 2026 threshold. Anthropic's email to Claude Platform customers, received September 25, 2026, says "On September 30, 2026, Anthropic will begin applying its EU AI Act text watermark" to Claude Fable 5, Claude Sonnet 5 and Claude Opus 4.8, and that rollout on Amazon Bedrock, Google Cloud and Microsoft Foundry may take a few additional days. As of September 25, 2026 the help centre table ticks C2PA for Sonnet 5 but not the text watermark, so the date is an official announcement. Claude Mythos 5, launched June 9, 2026, is not in the email and has no date of its own; the help centre says all models released before August 2, 2026 will be covered by December 2, 2026.

Can I disable the Claude watermark?

No. Anthropic's September 4, 2026 notice to Claude for Work administrators states: "There is no admin or user setting to turn the watermark off." That is the clearest answer available, and it comes with a caveat: as of September 25, 2026 that sentence was on no public Anthropic page, and neither the help centre nor the August 14 post addresses a setting either way. Nothing in Anthropic's public documentation describes an opt-out, and because marking is applied at the model level it is not a per-product or per-account toggle in the first place.

Is API or cloud output exempt from the watermark?

No. Anthropic's help centre says markings cover output from supported models "everywhere you use Claude, including Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag", and that "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from". It adds that supported models accessed through AWS, Google Cloud, or Microsoft Foundry carry watermarks too, though the text mark can reach those platforms a little later: a week for Opus 5 from September 14, 2026, and "a few additional days" for the models Anthropic dates to September 30, 2026. The one thing that does vary by platform is the C2PA metadata on generated files, which applies only where a platform offers Claude's file generation features.

Is Claude's watermark invisible?

Yes, by design. Anthropic says readers cannot distinguish watermarked from unwatermarked text and that its testing found no impact on quality, creativity, or readability. The mark is only visible statistically, to a detector holding Anthropic's key.

Is the Claude watermark a hidden character?

No. Anthropic states directly that nothing is added to the text and there are no hidden characters. The watermark is a pattern in which words Claude picks, not a character you can find and delete.

Does copying Claude text remove the watermark?

No. The signal is carried by the sequence of words itself, so it survives copy and paste into any editor, document, or website. Only changing the words themselves affects it.

Does pasting Claude text into Word remove it?

No. Pasting into Word, Google Docs, or email moves the word sequence intact, and formatting or metadata changes on the way do not touch the signal.

Can editing remove Claude's watermark?

Partially to fully, depending on depth. Anthropic's own summary is that light editing probably won't remove it completely and a complete rewrite replacing every word will. No thresholds in between are published, and no publicly available detector can currently measure them.

Can Grammarly remove Claude's watermark?

Not verified, and unverifiable for almost everyone, because the only detector is in a private preview. Reasoning from Anthropic's published statements, grammar-level fixes change few words, which resembles the light-editing case Anthropic says probably does not remove the mark. Treat confident claims in either direction as unsupported.

Does QuillBot remove Claude's watermark?

Not independently tested, for the same reason as Grammarly: no detector we can run exists to check against. QuillBot replaces more wording than a grammar pass, which places it closer to the heavier end of Anthropic's rewriting spectrum, but that is reasoning by analogy, not a measured result.

Does rewriting Claude's text with ChatGPT or Gemini remove the watermark?

Not independently tested. If the other model fully regenerates the passage rather than lightly editing it, that resembles Anthropic's complete-rewrite case, which it says does remove the mark. The output would then carry whatever watermark policy that second model applies, if any, rather than a cleaned copy of Claude's original text.

Does pasting Claude's text into Google Docs or Notepad remove the watermark?

No. Both destinations change formatting or strip it entirely, and Notepad strips file metadata too, but neither touches the sequence of words themselves, which is where the signal lives. Anthropic's statement that the watermark travels with copied text applies regardless of destination.

Does Claude Code output carry the watermark?

Yes in policy, and less in practice than prose does. Anthropic's help centre names Claude Code among the covered products and says marking is applied at the model level, so it is present whichever surface the text comes from. But where an exact output is required no watermark is applied, because a different token would break the code, so Anthropic says code generally carries less watermarking than other text. Comments and documentation, where word choice is free, are watermarked like ordinary prose.

Can I check whether text has a Claude watermark?

Only if you belong to one of the categories Anthropic accepts. Checking requires Anthropic's key, and since September 1, 2026 its detection API is in private preview, limited today to eligible organizations under EU law: regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, EU civil society groups, and enterprises with their own verification duty. There is no public route for text. Anthropic's September 4, 2026 administrator notice adds that it does not see or store text submitted to the API, a commitment that Anthropic's public help page, re-read September 25, 2026, still does not make. Tools claiming to check for the Claude watermark today appear to be scanning hidden characters or running generic AI detection, which are different things.

Is there an official Claude watermark detector?

Yes, in private preview since September 1, 2026, and not for general use. Anthropic announced the API on August 14, 2026 and shipped it two and a half weeks later, limited today to eligible organizations under EU law, through an application form. It says it plans to expand access over time, and its notice to administrators states that it does not see or store submitted text, which Anthropic's public help page still does not say when re-read on September 25, 2026. Pricing, acceptance criteria and a date for wider availability have not been published. Files are different: the free Claude Content Checker at claude.com/check-files reads Content Credentials with no sign-in, and says outright that it does not check text.

Can Claude's watermark prove text was written by AI?

Not in the way people usually mean. Detection will indicate a likelihood that Claude was involved, and Anthropic is explicit that it cannot distinguish text Claude wrote from text Claude heavily edited, and that absence of a mark does not confirm text was human-written.

Does proofreading with Claude watermark my text?

Light proofreading may not produce enough watermark signal to be detectable. Anthropic says lightly edited human text leaves very little, if anything, for the watermark to attach to, and that this depends on the length of the text and how heavily Claude edited it. Heavier rewriting shifts the balance toward detectability.

Does translating Claude text remove the watermark?

Two directions. A translation produced by Claude is watermarked, because every output word is Claude's choice. Anthropic has not published results for translating Claude output with another tool or by hand. Such translation replaces Claude's original word choices, so it should be treated as a substantial transformation, but its effect on detection has not been independently measured.

Is Claude's watermark the same as C2PA?

No, and the two now have different start dates and different scopes. C2PA is signed metadata Anthropic attaches to supported generated files such as PNG and JPEG images; its September 4, 2026 administrator notice says files Claude creates in the apps have carried a Content Credential since September 1, 2026, a date that appears on no public Anthropic page as of September 25, 2026, while the help centre describes the same coverage without a date. Separately, the Claude Platform release notes for September 1, 2026 say files produced through the code execution tool carry Content Credentials when retrieved through the Files API. The text watermark is statistical and lives in the words. C2PA metadata can be stripped by screenshots, re-encoding, or platforms that do not preserve it, and anyone can check a file for it free at claude.com/check-files; the text signal fades only under rewriting, and has no public checker.

Does ChatGPT use the same watermark?

No. OpenAI's current provenance documentation lists deployed signals for images and audio, but not ordinary ChatGPT text. OpenAI has previously said it developed and researched text-watermarking methods. Keys are also per-provider, so even same-family watermarks are separate systems: a Claude detector cannot see other providers' marks.

Does the watermark identify me or my company?

No. Anthropic's August 14, 2026 post says the watermark carries no identifying information and cannot be traced to a specific person, organization, or chat, and that no information about users can be recovered from the watermark or its key. Its Fable 5.1 and Mythos 5.1 launch post of September 1, 2026 says the same in one sentence: the watermark "contains no information about the user, their organization, or their conversations with Claude". Its notice to administrators repeats it as containing no information about your organization or any user, and adds that no characters are added to the text. A detection result speaks to Claude involvement in general and nothing about whose Claude.

Next steps

  • If you arrived here to clean text, know exactly what a cleaner can do: inspect and strip hidden Unicode, which is real but is not this watermark. Claude watermark checker
  • The provider tracker follows which models carry the mark, what the support documentation says, and what changes as the rollout progresses. Claude watermark tracker
  • The detection question has its own page, covering why no third-party detector can exist without the key and what the announced API changes. Claude watermark detector status
  • For the statistics underneath the family Anthropic named, the detection math has a dedicated explainer. How statistical text watermark detection works
  • Our census of 96 Claude outputs, the measurement that ruled out hidden characters before Anthropic confirmed it, is published with data and scripts. The Claude invisible-character census
  • If the em dash myth is what brought you here, the punctuation-tell question has its own dedicated, sourced answer. Do em dashes mean AI wrote it?

Sources and citation status