Provider tracker
Claude Watermark: Confirmed Facts, Reports, and Rumors
Anthropic says supported Claude models weave a watermark directly into the text they generate, in writing, in its own help center. For a month that claim outran the product: Anthropic marks models released on or after August 2, 2026, and by its own release notes no generally available Claude model was. On September 1, 2026 that gap closed. Anthropic shipped Claude Fable 5.1 and Mythos 5.1, and its help center named them as the supported models (its table now lists four models with the text watermark), so for the first time a shipped Claude model demonstrably meets Anthropic's own threshold. The same day it put the promised detection API into private preview, open to regulators, media, fact-checkers, researchers and similar bodies rather than to the public. Until September 4, 2026 Anthropic had named no further model and no date. An email shown to Claude for Work administrators that day scheduled Claude Opus 5 from September 9, 2026. By September 25, 2026 Anthropic's help page carried a per-model table that marks Opus 5 and the new Claude Opus 5.5, and a customer email received that day says Opus 5 marking began on September 14 and dates Claude Fable 5, Sonnet 5 and Opus 4.8 from September 30, 2026. Every other model released before August 2, 2026 is due by December 2, 2026, with no date of its own.
Correction,
Until September 5, 2026 an FAQ on this page said Anthropic had announced a watermark detection API "but has not released it," and that no route to check text existed "for everyone, not just consumers." Anthropic put the API into private preview on September 1, 2026 and annotated its own explainer to say so, so eligible organizations under EU law could check text while this page still said nobody could. The FAQ now says the API shipped on September 1, names who can and cannot use it, and separates text from files, which do have a free public checker.
The short answers
- Is Claude Opus 5 watermarked?
- Yes. Anthropic's help page confirms it, and a September 25 email dates it from September 14, 2026
- Is Claude Sonnet 5 watermarked?
- From September 30, 2026, per a September 25 email not yet reflected on the help page
- Can you turn it off?
- No admin or user setting
- Does it identify you?
- No information about users, organizations or conversations
- Does it cover Claude Code and the API?
- Yes, every surface, because marking sits at the model layer
The Opus 5 row rests on Anthropic's help page table, which ticked the model for text on the September 25, 2026 re-read, and on a customer email received that day. The help page confirms the model as marked; the September 14 start date comes from the email, and the help page dates only the cloud rollout from September 14. An administrator notice seen September 4, 2026 had given September 9. The Sonnet 5 date comes from the September 25 email alone, so that row is an official announcement until the help page table ticks the model. The absence of a setting comes from the September 4 administrator notice. The model-layer explanation is in that notice and on the help page. The no-identity row is confirmed by two public Anthropic posts.
Key takeaways
- Anthropic's own words, verbatim: "When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself." That covers Claude Platform, the API, Claude, Claude Code, Claude Cowork, Claude Tag, and wherever Claude is offered, worldwide. The reason the list runs that wide arrived on September 4, 2026, in an email to Claude for Work administrators: the watermark is "applied at the model layer," so it is present everywhere an organization uses Claude rather than being wired into each product separately. Anthropic's help page says the same in public: "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from."
- New on August 14, 2026: Anthropic published "How Claude's text watermark works," describing the mechanism as "a version of the SynthID-Text approach published by Google DeepMind," in "a family of approaches that go back to a proposal by Scott Aaronson in 2022." A secret key plus "a few words that come before" determine which eligible next word gets picked among meaning-preserving candidates. The exact algorithm, key handling, and detector math remain unpublished; a family was named, not a full spec.
- Confirmed passthrough: the embedded text watermark travels with supported Claude models onto AWS, Google Cloud, and Microsoft Foundry. Signed C2PA metadata is the conditional half, because Anthropic adds it when Claude creates a file, so it applies only where that platform offers Claude's file-generation features. Inside Anthropic's own apps the file side is not conditional at all: the September 4, 2026 administrator notice says files Claude creates there (.png, .jpg, .svg) have carried a C2PA Content Credential since September 1, 2026, a start date the public help page still did not give as of September 25, 2026. The text side can arrive later on a partner cloud: the help page gave Opus 5 one week from September 14, 2026 to reach them, and Anthropic says the September 30, 2026 wave there "may take a few additional days." Either way this is Anthropic's own marking riding through someone else's cloud, not a feature Microsoft or Amazon built.
- Rollout: models launched on or after August 2, 2026, the same day the EU AI Act's Article 50 transparency rules took effect, support the watermark at launch. Three have launched since then: Fable 5.1 and Mythos 5.1 on September 1, 2026 and Opus 5.5 on September 22, 2026. Earlier models sit in a transition period while marking gets retrofitted, and until September 4, 2026 that transition had no named model and no date. The administrator notice seen that day named Claude Opus 5 for September 9, 2026. On September 25, 2026 Anthropic's help page table marked Opus 5, and a customer email received that day says Opus 5 marking began on September 14 and dates Claude Fable 5, Sonnet 5 and Opus 4.8 from September 30, 2026. The help page now sets the end of the retrofit: models released before August 2, 2026 are being marked "with all covered by December 2, 2026."
- The detail almost every write-up skipped, and how it resolved: for the first thirty days of the rollout, Anthropic's own release notes dated every current Claude model before its cutoff (Opus 5 on July 24, Sonnet 5 on June 30, Fable 5 on June 9, Opus 4.8 on May 28, 2026), so no generally available model fell into the marked-at-launch category and Anthropic had named none as carrying the mark. Coverage that reported the watermark as live across Claude was, for that month, ahead of the record. Anthropic closed the gap on September 1, 2026 by shipping Fable 5.1 and Mythos 5.1 and naming them. Until September 4, 2026 the retrofit for models older than those two had no model and no date attached: Anthropic's August 14 explainer said only "over the coming months." Its administrator notice, seen that day, named Claude Opus 5 for September 9, 2026 and shortened the horizon for other current models to "over the coming weeks." On September 25, 2026 the help page table confirmed Opus 5 as marked, a customer email put its start at September 14 and dated three more models to September 30, and the help page set December 2, 2026 as the date by which all earlier models are covered.
- Detection, as of September 1, 2026: the API exists and is not public. Anthropic's help center says watermark detection is "currently in private preview, available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups)", plus enterprises with their own duty to verify marking, through a request form. Anthropic says it plans to expand access over time. The September 4, 2026 administrator notice compresses that seven-category list to "eligible EU organizations" and adds that Anthropic "does not see or store text submitted to" the API; the narrower summary and the storage claim both sat outside Anthropic's public pages as of September 25, 2026, so the help page's list is the one to rely on. For everyone outside those categories the practical position is unchanged: you cannot check a passage, so you cannot check any claim that something was removed from it.
- Anthropic signed the EU's Code of Practice on Transparency of AI-Generated Content as a Section 1 signatory, one of roughly 190 organizations that had signed by the end of July 2026, alongside Google, Meta, Microsoft, Mistral, and OpenAI.
- Rumor status, resolved by the primary source: Anthropic's August 14, 2026 explainer states "Nothing is added to the text and there are no hidden characters," which retires the em dash, phrasing-habit, and hidden-Unicode theories. Sean Goedecke's July 2, 2026 claim that Claude Code once used Unicode homoglyphs for a discontinued steganographic flag remains uncorroborated.
- Some "Claude watermark" tools are simply out of date: one detector-comparison site still says Anthropic has never deployed a checkable text watermark, and a removal tool that scans only for zero-width Unicode admits its own target is not what Anthropic's article describes.
Claude marking model
Two signals, two surfaces
Generated text
Compatible Claude model
Imperceptible embedded text watermark
Travels with copied text and may persist through some edits
Generated files
Supported file output such as SVG, PNG, or JPG
Signed provenance metadata
C2PA-style record of Claude processing where file support exists
Practical insight
Cleaning invisible Unicode can fix copy/paste artifacts, but Claude's documented text mark is embedded in the text itself: on 2026-08-14 Anthropic explained it as a keyed variant of SynthID-Text. The detection API shipped on 2026-09-01 into a private preview for eligible organizations under EU law, so before/after checking against it is not something a general reader can run today.
Which Claude models are watermarked
| Model | Released | Marked since | Watermark | Claim |
|---|---|---|---|---|
Claude Fable 5.1claude-fable-5-1 Evidence and caveatsMarked from launch, and the first Claude model Anthropic's own day-one rule reached: models launched on or after 2026-08-02 support machine-readable marking at launch. The help page table ticks its text watermark on first-party surfaces and on cloud partners, and the platform release notes entry for 2026-09-01 says text generated by Fable 5.1 and Mythos 5.1 carries Anthropic's text watermark. Confirmed rather than announced because it sits in the product documentation, not only in a post or an email.
| 2026-09-01 | 2026-09-01 | Marked | Confirmed |
Claude Mythos 5.1claude-mythos-5-1 Evidence and caveatsLaunched the same day as Claude Fable 5.1 under the same commitment, and ticked for text in the same help page table. Access is the difference: the platform release notes scope Mythos 5.1 to Project Glasswing participants rather than general availability, so almost nobody outside those programmes can produce a marked Mythos sample to test.
| 2026-09-01 | 2026-09-01 | Marked | Confirmed |
Claude Opus 5claude-opus-5 Evidence and caveatsReleased nine days before Anthropic's own 2026-08-02 threshold, so the day-one rule never covered it, and the first model Anthropic retrofitted. The help page table ticks its text watermark on first-party surfaces and on cloud partners, with a footnote that on cloud partners it rolls out gradually "starting September 14, 2026" and is fully available within one week. Anthropic's 2026-09-25 email to Claude Platform customers says "Claude Opus 5 was the first of these, on September 14". The 2026-09-04 administrator notice had announced a different date: "Starting September 9, Claude Opus 5 responses will have the same imperceptible text watermark as Fable 5.1". The site reported that notice accurately. The two Anthropic documents disagree, and this row uses September 14, the date the later email gives. The help page table confirms the model as marked but gives no first-party date; its footnote dates only the cloud rollout from September 14. Output from September 9 to 13 falls between the two dates, and neither document says whether it is marked. Confirmed from the 2026-09-25 re-read, the first on which this site found the model in the help page table.
| 2026-07-24 | 2026-09-14 | Marked | Confirmed |
Claude Opus 5.5claude-opus-5-5 Evidence and caveatsLaunched on 2026-09-22 per the platform release notes, after the 2026-08-02 threshold, so Anthropic's day-one rule applies: models launched on or after that date support marking at launch. The help page table ticks its text watermark on first-party surfaces and on cloud partners, and the 2026-09-25 email lists it among the models that "already carry" the watermark. No Anthropic document states a start date for this model separately. The marked-since date is its launch date under the day-one rule.
| 2026-09-22 | 2026-09-22 | Marked | Confirmed |
Claude Sonnet 5claude-sonnet-5 Evidence and caveatsReleased before the 2026-08-02 threshold. Anthropic's 2026-09-25 email to Claude Platform customers says that "On September 30, 2026, Anthropic will begin applying its EU AI Act text watermark" to this model, Claude Fable 5 and Claude Opus 4.8, and that rollout on Amazon Bedrock, Google Cloud and Microsoft Foundry "may take a few additional days". Output from before 2026-09-30 should not be expected to carry the mark. The help page table does not tick its text watermark as of 2026-09-25, only C2PA in files, so the row rests on an official announcement. It becomes Confirmed when the table ticks the text column.
| 2026-06-30 | From 2026-09-30 | Scheduled | Official announcement |
Claude Fable 5claude-fable-5 Evidence and caveatsReleased before the threshold and superseded by Claude Fable 5.1 on 2026-09-01. Anthropic's 2026-09-25 email dates marking for it from September 30, 2026, with cloud partners possibly a few days later. The help page table does not tick its text watermark as of 2026-09-25. Anyone comparing two Fable outputs should check the version and the date: Fable 5.1 output is marked from launch, and Fable 5 output from before 2026-09-30 should not be expected to carry the mark.
| 2026-06-09 | From 2026-09-30 | Scheduled | Official announcement |
Claude Opus 4.8claude-opus-4-8 Evidence and caveatsThe only 4.x model Anthropic has dated. Until 2026-09-25 it sat in the undated group of earlier models on this page. Anthropic's 2026-09-25 email names it with Claude Fable 5 and Claude Sonnet 5 for marking from September 30, 2026, with cloud partners possibly a few days later. The help page table does not tick its text watermark as of 2026-09-25, only C2PA in files, so the row rests on an official announcement.
| 2026-05-28 | From 2026-09-30 | Scheduled | Official announcement |
Claude Mythos 5claude-mythos-5 Evidence and caveatsReleased alongside Claude Fable 5 and superseded by Claude Mythos 5.1 on 2026-09-01. The 2026-09-25 email that dates Fable 5, Sonnet 5 and Opus 4.8 does not mention it, and the help page table ticks only C2PA in files for it as of 2026-09-25. The only commitment that covers it is the help page's general one for models released before 2026-08-02, "with all covered by December 2, 2026". Restricted access makes it the hardest row here for a reader to check independently, which is a reason to treat the absence as unverified rather than tested.
| 2026-06-09 | No date stated | Not marked | Unknown |
Earlier models (Opus 4.7, 4.6 and 4.5, Sonnet 4.6 and 4.5, Haiku 4.5)claude-opus-4-7, claude-opus-4-6, claude-opus-4-5, claude-sonnet-4-6, claude-sonnet-4-5, claude-haiku-4-5 Evidence and caveatsAnthropic has dated none of these. The help page table lists each of them with C2PA in files and no text watermark as of 2026-09-25, and the 2026-09-25 email names only Fable 5, Sonnet 5 and Opus 4.8 as next. What binds this group is a horizon rather than a per-model plan. The help page says Anthropic is adding watermarks to models released before 2026-08-02, "with all covered by December 2, 2026", which matches Article 111(4) of Regulation (EU) 2026/1744: providers of generative systems placed on the market before 2026-08-02 have until 2026-12-02 to satisfy Article 50(2) of the AI Act. The claim is Unknown because no document says when any single model in this group gets marked. Claude Opus 4.8 had its own row from 2026-09-25, when Anthropic dated it.
| Various, all before 2026-08-02 | No date stated | Not marked | Unknown |
The Claude Opus 5 row is confirmed by the per-model table on Anthropic's help page, re-read 2026-09-25, which ticks the text watermark for Opus 5. Anthropic's 2026-09-04 notice to Claude for Work administrators had said September 9; a 2026-09-25 email to Claude Platform customers says September 14, and the row uses that date. The help page gives no first-party date; its footnote dates only the cloud rollout from September 14. The three September 30 rows (Fable 5, Sonnet 5 and Opus 4.8) rest on the 2026-09-25 email alone, which is why they are labelled official announcements, and each moves to confirmed when the help page ticks its text watermark column. The email says rollout on Amazon Bedrock, Google Cloud and Microsoft Foundry may take a few additional days.
What has Anthropic confirmed about the Claude watermark?
ConfirmedAnthropic's claim is one sentence long. Read it closely and the text watermark and the file metadata turn out to be two different promises.
Anthropic's support article does not hedge: "When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself." The mark goes in during generation, not as a step bolted on afterward.
The scope is deliberately broad. Anthropic names all of these surfaces by hand:
- Claude Platform, meaning the API
- The Claude apps
- Claude Code
- Claude Cowork
- Claude Tag
- Compatible Claude models accessed through AWS, Google Cloud, or Microsoft Foundry
- In Anthropic's own phrasing, "wherever Claude is offered, worldwide"
That cloud line matters more than it looks. A Claude model running inside Amazon's or Microsoft's infrastructure carries Anthropic's own watermark, not one those platforms built, which makes the mark a property of the model rather than the host.
Generated files such as PNG and JPEG images can also carry signed C2PA provenance metadata. Anthropic is explicit that this piece is conditional: "Some platforms or features may not support certain marking types."
Inside Anthropic's own apps that piece now has a start date, and it comes from the administrator notice rather than the help page. The notice seen September 4, 2026 says files Claude creates in the apps have carried a Content Credential since September 1, 2026, and the help page still described file-level C2PA with no date as of September 25, 2026.
Why did Anthropic start watermarking on August 2, 2026?
Official announcementYou'll see why August 2, 2026 is the only date in this timeline that explains anything.
Models released on or after August 2, 2026 support machine-readable marking at launch. That is the exact day the EU AI Act's Article 50 transparency rules became applicable across the bloc.
The feature had already been live for eight days when most people heard about it. On the evening of August 10, 2026 an AI news account on X posted that new Claude models embed invisible watermarks in all generated text, a second account posted the same news about an hour and a half later, and between them the two posts pulled roughly 2.5 million views.
Models that shipped earlier sit in a transition period. Anthropic's August 14, 2026 explainer said marking would reach them "over the coming months," and until September 4, 2026 that was the whole public record: no model named, no date given.
The administrator notice seen on September 4, 2026 named one: Claude Opus 5 from September 9, 2026, with other current models "over the coming weeks." Anthropic's later documents give a different date. On September 25, 2026 the help page table marked Opus 5, and a customer email received that day says "Claude Opus 5 was the first of these, on September 14." The same email dates Claude Fable 5, Sonnet 5 and Opus 4.8 from September 30, 2026, and the help page now says all models released before August 2, 2026 will be covered by December 2, 2026.
Anthropic backed the timing with a policy commitment. It signed the EU's Code of Practice on Transparency of AI-Generated Content as a Section 1 signatory, on a list that reached roughly 190 organizations by the end of July 2026, alongside Google, Meta, Microsoft, Mistral, and OpenAI.
Across every major provider tracked on this site, Anthropic is the only one whose own documentation ties a watermarking rollout to that regulatory date this explicitly. Everyone else either ships provenance without naming the law, or names the law without shipping text marking.
Which Claude models are watermarked?
Official announcementFour models are marked by Anthropic's own documentation, three more have a September 30, 2026 date from an email, and everything older has only a December 2, 2026 horizon.
The answer is model by model, because Anthropic's rule is a launch date. Models launched on or after August 2, 2026 support marking at launch, so a model's release date decides which side of the line it starts on.
Four models carry a text tick in Anthropic's help page table as of September 25, 2026. Opus 5 is one of them, marked from September 14, 2026 per a customer email received that day, although an administrator notice seen September 4, 2026 had given September 9. The September 30, 2026 date for Fable 5, Sonnet 5 and Opus 4.8 comes from the same September 25 email and is not yet reflected in the help page table.
- Claude Fable 5.1 (claude-fable-5-1), launched September 1, 2026: marked at launch, ticked for text in the help page table. Confirmed.
- Claude Mythos 5.1 (claude-mythos-5-1), launched September 1, 2026 for Project Glasswing participants: marked at launch, ticked for text in the help page table. Confirmed.
- Claude Opus 5.5 (claude-opus-5-5), launched September 22, 2026: marked at launch under Anthropic's day-one rule, ticked for text in the help page table. Confirmed.
- Claude Opus 5 (claude-opus-5), launched July 24, 2026: confirmed by the help page table and marked from September 14, 2026 per Anthropic's September 25 email (the help page dates only the cloud rollout from September 14). The September 4 administrator notice had said September 9. Confirmed.
- Claude Sonnet 5 (claude-sonnet-5), launched June 30, 2026: scheduled from September 30, 2026 per Anthropic's September 25 email, with partner clouds possibly a few days later; not yet ticked for text in the help page table. Official announcement.
- Claude Fable 5 (claude-fable-5), launched June 9, 2026: same position as Sonnet 5, scheduled from September 30, 2026. Official announcement.
- Claude Opus 4.8 (claude-opus-4-8), launched May 28, 2026: same position, scheduled from September 30, 2026. Official announcement.
- Claude Mythos 5 (claude-mythos-5), launched June 9, 2026: not named in the September 25 email and not ticked for text in the help page table, so no date of its own. Unknown.
- Earlier models, Opus 4.7, 4.6 and 4.5, Sonnet 4.6 and 4.5, and Haiku 4.5: not marked, and no date for any of them. Anthropic's help page says all models released before August 2, 2026 will be covered by December 2, 2026, the EU transitional deadline for generative systems placed on the market before that date, under Article 111(4) of the AI Act as inserted by Regulation (EU) 2026/1744.
The table below is regenerated from this site's status database rather than typed by hand, so a row changes here only when the underlying record and its cited source change.
Who can use Anthropic's watermark detector?
ConfirmedA private preview since September 1, 2026, gated to regulators, media, fact-checkers and researchers. What detection will and will not prove, in Anthropic's own words.
Checked again on September 3, 2026. There is still no public Claude watermark detector, and there is now a private one. Anthropic put the API into private preview on September 1 and annotated its August explainer to say so. Access is by application and scoped to eligible organizations under EU law: regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, EU civil society groups, and enterprises obliged to verify marking for their own compliance. Anthropic says it plans to widen that over time.
So journalists and researchers now have a route that did not exist in August, and individuals do not. If you want to know whether your own draft carries the mark, the answer remains that you cannot find out.
The promise moved in two steps. Earlier claims of a coming detection API traced to a third-party post. On August 14 Anthropic said it itself: "We will soon be offering a watermark detection API." On September 1 it shipped that API in private preview. So "Anthropic never promised detection" was always wrong, and "anyone can check text today" is still wrong.
Anthropic's own language sets the ceiling on what detection would ever prove. The August 14 post frames the only question a detector can answer as "What is the likelihood this was partly written by Claude?" It "cannot distinguish 'Claude wrote this' from 'Claude heavily edited this'" and "doesn't confirm whether the text was human-written."
Two more limits from the same post: a detection result carries no identifying information about users, organizations, or chats, and Anthropic's detector cannot recognize other providers' watermarks, since each provider uses different keys.
The company also lists the conditions under which the mark can go missing entirely:
- Output from models released before the rollout
- Heavily edited, paraphrased, or translated text
- Watermarked text mixed into a longer document
- Very short passages
- Files whose metadata was stripped by format conversion, re-saving, or a screenshot
The August 14 explainer sharpens the editing line: "Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will." Detection is weak on short samples, and "watermarking is sparser on factual passages" where fewer word choices exist; Anthropic's own example is that only "Mathematica" can follow "Isaac Newton's most famous work was called Principia."
Translation cuts both ways in that post. Running Claude's output through another translator defeats the mark, while a translation Claude itself produces carries it, "because in this case every word is chosen by Claude."
Read Anthropic's own pages side by side and the tone does not match. The Transparency Hub, showing a last-updated date of July 23, 2026, uses soft forward-looking language about preparing for legal deadlines, while the support article makes flat present-tense claims about what ships today.
The support article is the more specific and more recent source, so it governs the text-watermarking claim itself. A mismatch between two of a company's own live pages is still worth naming plainly rather than smoothing over.
For the first twelve days that page was also as loud as Anthropic got: no announcement on X (as of August 11, 2026 no post from the company's own account had been found), which is why every early write-up traces back to the same help center article. The August 14 explainer on Anthropic's news site is the first louder statement, and the first to describe the mechanism.
What did people think the Claude watermark was?
Community discussionFive theories from one r/singularity thread, two audits aimed at them, and the August 14 explainer that finally named the family two of them pointed at.
For the first twelve days of the rollout, Anthropic never named the mechanism. In that vacuum, an r/singularity thread that opened with an accurate summary of the announcement turned into a guessing game.
- Hidden Unicode characters slipped into the output
- Overrepresented word patterns or n-grams
- First-letter and sentence-position tricks
- Token-probability nudges, sometimes described as SynthID-like
- Hybrid systems combining several signals at once
On August 14, 2026 Anthropic graded that list itself. Its explainer describes the watermark as "a version of the SynthID-Text approach published by Google DeepMind," in "a family of approaches that go back to a proposal by Scott Aaronson in 2022": a secret key plus "a few words that come before" pick which eligible next word gets chosen among meaning-preserving candidates. The same post states plainly: "Nothing is added to the text and there are no hidden characters."
So the token-selection guess was right at the family level, and the hidden-character theories were wrong. What Anthropic still has not published is the exact algorithm, the key handling, or the detector math.
Two of those theories now have data pointed at them, and it is worth being exact about what the data does. On August 12, 2026 developer John Wang published an analysis of 7.2 million characters of Claude prose: no hidden Unicode or whitespace encoding, and green/red-list permutation tests across roughly 4,800 responses returning p-values of 0.556, 0.677 and 0.886, all clear negatives. A separate byte-level audit published by San Digital found zero hidden characters across 457,045 characters and four Claude models. That repository, however, is first-party evidence for its publisher's own articles rather than third-party work.
One worry from that thread now has a first-party answer: code. Anthropic says that where a task requires an exact output "the watermark isn't applied," that code "has generally less watermarking than some other forms of text," and that comments are watermarked with "a negligible effect on the actual code produced."
Sean Goedecke went further in a July 2, 2026 post, a month before the rollout, arguing Claude's text watermarking would be "trivially removable." He also claimed Claude Code once embedded Unicode homoglyphs in date strings as a since-discontinued steganographic flag. His own post admits he does not know Anthropic's current implementation, and the article that might have corroborated it returned an access error.
On X, reaction split within hours. One paying customer wrote "If I'm paying for your plan, I don't want invisible watermarks embedded in my content," a lawyer-run account flagged court filings and privilege as the real stakes, and one reply just asked whether this was "just em dashes and calling everything load-bearing."
A separate r/ClaudeAI thread asking how to remove the mark split into two camps: one treating the question as suspicious on academic-honesty grounds, the other treating the mark as vendor tracking on output the user already paid for. The two methods floated there, hand rewriting and running text back through a second model, are commenter speculation rather than documented technique.
Are Claude watermark checker tools accurate?
Community discussionYou can tell in about ten seconds whether a watermark tool has read Anthropic's article. Two here fail; one passes by naming its own limits.
One AI-detector comparison site still states that Anthropic has not deployed a public, checkable watermark, and that Claude does not embed a token-level watermark the way OpenAI has researched for GPT. It cites no Anthropic source and does not account for the 2026 rollout at all.
A free tool marketed as a "Claude Watermark Remover and Checker" scans specifically for zero-width Unicode characters. Its own copy admits "the exact implementation and prevalence of watermarks in Claude outputs remains partially undisclosed," which quietly undercuts the product it is attached to.
FAQ
Does Claude currently watermark ordinary generated text?
Yes, according to Anthropic's own support article, for compatible models, with marking required at launch for any model released on or after August 2, 2026. Anthropic announced a watermark detection API on August 14, 2026 and shipped it on September 1 into a private preview for vetted organizations, so the watermark's presence is confirmed while the ability to check for it yourself is not.
Are em dashes a Claude watermark?
No, and Anthropic has now ruled it out at the source. Its August 14, 2026 explainer describes the mechanism as keyed word selection among meaning-preserving candidates and states, "Nothing is added to the text and there are no hidden characters," so a punctuation habit is not the watermark. The closest thing to evidence for the em dash theory never checked out anyway: a Fast Company piece citing an unnamed Economist report reportedly claims Claude uses em dashes more than human baselines, but the page returned an access error on every verification attempt, so treat it as unsourced.
Is there a way to check whether a piece of text carries Claude's watermark?
Not unless you belong to a short list of organizations. Anthropic announced the detection API on August 14, 2026 and shipped it into private preview on September 1, available to eligible organizations as required under EU law (regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups) plus enterprises with their own duty to verify marking. There is no public tool for text, so for everyone else the practical answer is still no, and any product claiming to verify or remove Claude's text watermark is claiming a result its users cannot confirm. Files are a different question: Anthropic's free Claude Content Checker reads Content Credentials on 17 listed image, video, and audio formats and states outright that it does not check text.
Which Claude models actually carry the watermark right now?
Four by Anthropic's own documentation, with three more dated. Anthropic's help page table, re-read September 25, 2026, ticks the text watermark for Fable 5.1 and Mythos 5.1 (launched September 1, 2026), Opus 5.5 (launched September 22, 2026) and Opus 5, which a customer email received the same day says has been marked since September 14, 2026. The same email dates Claude Fable 5, Sonnet 5 and Opus 4.8 from September 30, 2026. Everything else, Mythos 5 and the 4.x models back to Haiku 4.5, has no date of its own; the help page says all models released before August 2, 2026 will be covered by December 2, 2026.
Is Claude Opus 5 watermarked?
Yes, from September 14, 2026. Anthropic's help page table ticks the text watermark for Opus 5 on the September 25, 2026 re-read, and a customer email received that day says "Claude Opus 5 was the first of these, on September 14." On AWS, Google Cloud and Microsoft Foundry the help page says Opus 5 marking rolls out gradually from September 14 and is fully available within one week. An administrator notice seen September 4, 2026 had announced September 9, so Anthropic's own documents disagree by five days, and neither says whether output from September 9 to 13 is marked. Any tool page still answering a flat No is out of date.
Is Claude Sonnet 5 watermarked?
Not before September 30, 2026, per Anthropic. Sonnet 5 launched June 30, 2026, before Anthropic's August 2, 2026 marking threshold. A customer email received September 25, 2026 says Anthropic will begin applying the text watermark to Claude Sonnet 5, Fable 5 and Opus 4.8 on September 30, 2026, and that rollout on Amazon Bedrock, Google Cloud and Microsoft Foundry may take a few additional days. Anthropic's help page table did not tick Sonnet 5 for text as of September 25, 2026, so treat the date as an official announcement until it does.
How do I turn off Claude's watermark?
You cannot. The administrator notice seen September 4, 2026 states "There is no admin or user setting to turn the watermark off," which turns what used to be an absence of documented options into an explicit statement, and that sentence was still on no public Anthropic page as of September 25, 2026. Rewriting the output is not a verifiable alternative either: Anthropic says a complete rewrite where every word is replaced would defeat the mark, but with no public detector for text, nobody outside the private preview can check the result.
Does the watermark identify me or my company?
No, according to Anthropic, and this one rests on public sources rather than the administrator notice. Its August 14, 2026 explainer says a detection result carries no identifying information about users, organizations, or chats, and its September 1, 2026 launch post for Fable 5.1 and Mythos 5.1 says the watermark "contains no information about the user, their organization, or their conversations with Claude." What detection can indicate is likelihood of Claude involvement in a passage, not who prompted it. Nobody outside the preview can audit that claim, because checking requires the key Anthropic holds.
Is API or Bedrock output exempt?
No. Anthropic's help page covers the Claude Platform (the API), Claude, Claude Code, Claude Cowork, and Claude Tag, and says supported models accessed through AWS, Google Cloud, or Microsoft Foundry carry watermarks. The administrator notice seen September 4, 2026 gives the reason that list is exhaustive rather than a set of per-product integrations: the watermark is "applied at the model layer," an explanation the help page also gives, where watermarking is "applied at the model level." Timing is the one thing that can differ: Anthropic says the September 30, 2026 wave may take a few additional days on Amazon Bedrock, Google Cloud and Microsoft Foundry. The part that genuinely varies by platform is the signed C2PA metadata on generated files, which Anthropic adds when Claude creates a file, so it applies only where a platform offers Claude's file-generation features.
Did the watermark make Opus 5's writing worse?
The complaints came before any marking of Opus 5. Hacker News threads in August 2026 argued Opus 5's prose had degraded, at a point when no Anthropic source named Opus 5 as watermarked and Anthropic's own rule covered only models launched on or after August 2, 2026. Anthropic dates Opus 5 marking from September 14, 2026 (an administrator notice seen September 4 had said September 9), which is after those posts, so whatever people were reacting to in August, it was not this. Anthropic's help page says the mark does not change "the meaning, quality, or readability" of a response, which is a claim nobody outside the detection preview can test.
Does the watermark still apply through AWS, Google Cloud, or Microsoft Foundry?
Yes, for the text watermark itself. Anthropic's own article names AWS, Google Cloud, and Microsoft Foundry as the three cloud platforms where supported Claude models carry the embedded text watermark. Signed C2PA metadata on generated files is the part that varies: Anthropic adds it when Claude creates a file, so on a third-party cloud it applies only where that platform offers Claude's file-generation features. Inside Anthropic's own apps there is no such condition, and the administrator notice seen September 4, 2026 dates it: files Claude creates there have carried a Content Credential since September 1, 2026, a date the public help page still did not give as of September 25, 2026. The text mark can reach those clouds later than Anthropic's own apps: the help page gave Opus 5 one week from September 14, 2026, and Anthropic says the September 30 wave there may take a few additional days.
Next steps
- Anthropic has now explained the mechanism itself. Read the full breakdown of how the keyed word-selection watermark works, what survives editing, and what detection will and will not prove. How Claude's text watermark works
- See the hidden-character theory tested rather than argued: 96 Claude outputs across three model tiers, every code point counted, data and script published. The invisible-character census
- Looking specifically for a way to check a passage? One exists now, and you almost certainly cannot use it. Who can use the Claude detector
- Compare Claude against every other provider in one table, with a primary source and a verification date on each cell. AI Watermark Status Database
- Run copied Claude text through the site's free in-browser cleaner to see whether it actually contains invisible Unicode characters. Treat that as formatting hygiene, not watermark removal. Claude watermark checker
- Read the regulatory half of the same rollout: what Article 50 demands, what it exempts, what it fines, and why no enforcement action has landed yet. Anthropic watermark and the EU rules
- If you landed here because something you wrote got flagged, the detector question is a separate problem from the watermark question, and the two fail in completely different ways. AI watermark vs AI detector
- Read Anthropic's support article yourself. It is short, and until August 14, 2026 it was the only primary source any of this rested on. Anthropic help center
Sources and citation status
- OfficialAnthropic Help: how Claude marks AI-generated contentRe-read 2026-09-25. Now carries a per-model table, "Which Claude models support watermarking", in place of the one-sentence model list of 2026-09-05. Still stamped "Updated this week" rather than with a date.
- OfficialAnthropic: How Claude's text watermark works
- OfficialAnthropic: email to Claude for Work administrators, "Text watermark extends to Claude Opus 5" (received 2026-09-04; screenshots on this site; on the 2026-09-25 re-read the help page table confirms Opus 5 as marked; a 2026-09-25 email dates it from 2026-09-14, not the September 9 this notice gave, and the help page dates only the cloud rollout from 2026-09-14)The URL is this site's screenshot of the email as received; the notice itself directs administrators to the help page. Reopened 2026-09-04 and 2026-09-05: the help page then named only Fable 5.1 and Mythos 5.1 and mentioned neither Opus 5, September 9, nor "coming weeks", and neither did the news post, the apps release notes, or the platform release notes. On the 2026-09-25 re-read the help page table ticks Opus 5 for text and dates its cloud rollout from September 14, 2026.
- OfficialAnthropic: email to Claude Platform customers, "Watermarking begins September 30, 2026" (received 2026-09-25; screenshot on this site; the three models are not yet ticked for text in the help page's table as of 2026-09-25)The URL is this site's screenshot of the email as received; one image holds the whole text. Sent to customers whose organization uses Claude Fable 5, Claude Sonnet 5 or Claude Opus 4.8. It dates marking for those three from September 30, 2026, says rollout on Amazon Bedrock, Google Cloud and Microsoft Foundry "may take a few additional days", and says Claude Opus 5 was marked from September 14.
- OfficialAnthropic: Claude Fable 5.1 and Mythos 5.1 launch post (2026-09-01)Public source for the no-identity claim: the watermark "contains no information about the user, their organization, or their conversations with Claude" and is "invisible to anyone who does not have the detection API."
- OfficialAnthropic: Claude Content Checker (free, no sign-in, 17 listed file formats, explicitly does not check text)Read 2026-09-05. States that an uploaded file never leaves the device and is never stored.
- OfficialAnthropic: Claude Platform release notes (model release dates, verified 2026-09-03; Claude Opus 5.5, 2026-09-22, added 2026-09-25)Corroborated against the model-deprecations page, whose one-year-out retirement dates match to the day. docs.claude.com/en/release-notes/overview now redirects here.
- OfficialAnthropic Transparency Hub: voluntary commitments
- ResearchJohn Wang: analysis of 7.2M characters of Claude prose, green/red-list tests p = 0.556–0.886 (2026-08-12)Author's own conclusion is that Anthropic is probably watermarking via token selection, which his method cannot detect.
- ResearchSan Digital: byte-level audit of 457,045 characters across four Claude models (2026-08-12)First-party evidence for its publisher's own articles, not third-party work. Its own report states that ruling out hidden Unicode does not show Claude is unwatermarked.
- RegulatoryEU AI Act Service Desk: Code of Practice signatory resources
- CommunityX: @M1Astra post breaking the Claude watermark news (2026-08-10, 1.3M views)
- CommunityX: @ns123abc post amplifying the same help center article (2026-08-10, 1.2M views)
- CommunityReddit r/singularity: "Claude now embeds invisible watermarks in all text outputs + signed metadata on files"
- CommunityReddit r/ClaudeAI: "Claude will watermark generated content, thank you EU"
- CommunityReddit r/ClaudeAI: "How can I remove text watermarks in Claude output?"
- CommunitySean Goedecke: blog post arguing Claude's text watermark is "trivially removable" (2026-07-02, pre-rollout, uncorroborated claim about Claude Code Unicode homoglyphs)
- Communityaidetectors.io: blog post claiming Anthropic has not deployed a checkable Claude watermark (outdated relative to the 2026 rollout)
- Communityclaudewatermark.com: "Claude Watermark Remover and Checker" tool