Detection
Claude Watermark Detector: Private Preview, Not Public
A Claude watermark detector now exists, and you almost certainly cannot use it. Anthropic put its detection API into private preview on 1 September 2026, restricted to eligible organizations under EU law: regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, EU civil society groups, and enterprises with their own obligation to verify marking. Anthropic's 2026-09-04 notice to Claude for Work administrators compresses that same gate to "eligible EU organizations" and adds that it does not see or store text submitted to the API, neither of which its public help page says when re-read on 2026-09-25. Everyone else is where they were. One Anthropic checker is public and it does not check text: the free Claude Content Checker reads C2PA Content Credentials on files, across 17 listed formats, in the browser. This page said in August that an expert-access detector was the likely outcome, because the EU Code of Practice permits exactly that, and it declined to report it as Anthropic's plan without a statement. The statement arrived. What follows is who can check a passage, who still cannot, and what remains worth running if you are in the second group.
Correction,
Two answers on this page still said Anthropic's detection API did not exist. One FAQ ended "What is still missing is the API itself, its access model, and a date", and another said no date had been given for a detector at all. Both were written before 1 September 2026 and both were left standing after the API shipped, so the page contradicted its own summary. Anthropic's help centre states that watermark detection is "currently in private preview, available to eligible organizations as required under EU law", and its 14 August 2026 explainer carries the note "Updated Sep 1, 2026: Provided up to date information on the watermarking detection API". A reader could have concluded that no detector existed for anyone. Both answers now say the API shipped on 1 September 2026 into a private preview for eligible organizations under EU law, and that what is still missing is public access, published admission criteria, and a date for the expansion Anthropic says it plans.
Correction,
Among the conditions under which Claude's text watermark may be absent, this page listed files whose metadata was stripped by conversion, re-saving or a screenshot. That is a C2PA file-metadata condition, and placing it in a list about the text mark contradicted this page's own central point, quoted from Anthropic, that nothing is added to the text and there are no hidden characters. A reader could have concluded that re-saving a document strips the text watermark. The condition is now stated separately as the provenance layer it belongs to. A passage praising an unnamed free scanner for checking 34-plus invisible characters and disclaiming cryptographic watermarks also read as this site's own count and vocabulary; it now names getgpt.app and notes that Claude's mark is statistical rather than cryptographic.
Key takeaways
- A detector exists but is not public. Anthropic's detection API entered private preview on 1 September 2026. Its help centre states that detection is "currently in private preview, available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups)", plus enterprises obligated to verify marking for their own compliance, via a request form. Anthropic says it plans to expand access over time.
- For anyone outside those categories, nothing has changed in practice. You still cannot check whether a passage carries the mark, which means you still cannot check whether anything removed it. Every tool marketed to the public as a Claude watermark detector is checking something else, usually invisible Unicode characters or writing style.
- Files have a free public checker; text does not. Anthropic's help centre points readers to the free Claude Content Checker at claude.com/check-files, which needs no sign-in, reads C2PA Content Credentials across 17 listed image, video and audio formats, and says of itself "The tool does not check text." That is a provenance check on a file, not a check for the text watermark.
- Four models now carry the mark by name. Anthropic's help centre, re-read 2026-09-25, has a per-model table that ticks the text watermark for Fable 5.1 and Mythos 5.1 (released 1 September 2026), Opus 5.5 (released 22 September 2026) and Opus 5. Until 1 September no shipped Claude model met Anthropic's own 2026-08-02 threshold, which is what this page and the Claude tracker recorded through August. Until 2026-09-04 Anthropic had publicly named no retrofitted model and no date. That day's email to Claude for Work administrators scheduled Opus 5 from 2026-09-09; Anthropic's 2026-09-25 email to Claude Platform customers gives September 14 instead and schedules Fable 5, Sonnet 5 and Opus 4.8 from 2026-09-30. The help page now says every model released before August 2, 2026 will be covered by December 2, 2026.
- A third party could not build one even if it wanted to. Statistical text watermarks are keyed: detection requires the secret the provider used at generation time. Anthropic has now named the family, a SynthID-Text variant, but the key is secret and the exact scheme unpublished, and without them there is nothing to test against, which is why no independent detector has appeared.
- The gap may be a permitted posture rather than a failure. The EU Code of Practice explicitly allows signatories to restrict access to text-watermark detection where reliability is low, granting it instead to verified expert users (regulators, media, fact-checkers, researchers), with any such restriction limited in time.
- Even a working detector would not give you proof. Anthropic's own wording is that a detected mark means content may have been processed by Claude. It sets a ceiling on the strongest possible result, before anyone has built the tool.
- There is a hard interoperability date worth watching: signatories to the EU Code committed to implementing an interoperability solution for their detection mechanisms by 2 February 2027, via a public API, an embedded signpost, a shared consortium solution, or an equivalent.
- What you can check today: invisible Unicode characters (measurable, and we measured them: 96 Claude outputs contained none), C2PA metadata on generated files (checkable with public tools), and a generic AI detector's style-based guess (which is not a watermark check and fails in both directions).
Figure 1
The Claude detector gap, in order
A confirmed watermark, a rule three shipped models meet, a retrofit that marked Claude Opus 5 from 2026-09-14 and schedules three more models from 2026-09-30, a free checker for files, and a text detector almost nobody can use.
- 2026-08-02
The marking rule takes effect
ConfirmedAnthropic's policy is that Claude models launched on or after this date carry the watermark at launch.
- 2026-08-02
EU Article 50 transparency duties apply
ConfirmedThe same date the AI Act's marking and disclosure obligations begin to bite. The alignment is unlikely to be coincidental.
- Before 2026-08-02
Every generally available Claude model shipped
TensionAnthropic's own release notes date Opus 5 to 2026-07-24, Sonnet 5 to 2026-06-30, and Fable 5 to 2026-06-09, all earlier than the rule they are measured against. Launching before the threshold means launching unmarked, not staying unmarked: Anthropic dates Opus 5 output from 2026-09-14 and Fable 5 and Sonnet 5 output from 2026-09-30, and its help page says every model released before 2026-08-02 will be covered by 2026-12-02.
- 2026-08-14
Anthropic explains the mechanism
Confirmed"How Claude's text watermark works" names the family, "a version of the SynthID-Text approach published by Google DeepMind": a secret key plus a few preceding words pick among meaning-preserving candidate words, with no hidden characters. The same post announces a detection API as coming soon.
- 2026-09-01
A detector, for eligible organizations
TensionThe text detection API announced on 2026-08-14 shipped into private preview, open to regulators, law enforcement, media, fact-checkers, researchers, educational bodies, EU civil society and enterprises with their own duty to verify; the 2026-09-04 administrator notice summarises the current limit as "eligible EU organizations". No public route exists for text, so for most readers a passage still cannot be checked, and neither can any claim that something was removed from it. That notice also says Anthropic does not see or store text submitted to the API, which its public help page still did not say when re-read on 2026-09-25.
- Files, no launch date
A free public checker, for files only
ConfirmedSeparately from text, Anthropic's help page points readers to a free checker at claude.com/check-files. It needs no sign-in, reads C2PA Content Credentials on 17 listed image, video and audio formats, says uploaded files stay on the device, and states outright that it does not check text. Anthropic publishes no launch date for it; the page was read on 2026-09-05. Files have a public check. Text does not.
- 2026-09-04
The retrofit gets a model and a date
TensionUntil 2026-09-04 Anthropic had named no model and no date for marking its earlier models. An email to Claude for Work administrators then said Claude Opus 5 responses carry the watermark from 2026-09-09, with other current Claude models following "over the coming weeks". When read on 2026-09-05, the help page still named only Fable 5.1 and Mythos 5.1, and the 2026-08-14 news post said "coming months". Anthropic later gave 2026-09-14 as the Opus 5 start date.
- 2026-09-25
Three more models get a date, and the retrofit a deadline
ConfirmedAn email to Claude Platform customers schedules the text watermark for Claude Fable 5, Claude Sonnet 5 and Claude Opus 4.8 from 2026-09-30, with Amazon Bedrock, Google Cloud and Microsoft Foundry possibly a few days later, and says Opus 5 was marked from 2026-09-14. The help page, re-read the same day, now carries a per-model table marking Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5, and says every model released before 2026-08-02 will be covered by 2026-12-02.
- Stated intent
Public access to text detection
UndatedAnthropic says it plans to expand access to the detection API over time and publishes a registration-of-interest form. It has given no date and no criteria for general access, so a reader outside the eligible categories still has no route to check a passage.
Method Dates from Anthropic's help centre, its 2026-08-14 mechanism explanation, its own model release notes, its free file checker at claude.com/check-files, an email to Claude for Work administrators seen 2026-09-04, and an email to Claude Platform customers received 2026-09-25. The help centre was re-read on 2026-09-25. Items marked Stated intent have no announced date.
Checked 2026-09-25
Claude tracker- Invisible Unicode charactersAnyone, in a browser
Formatting artifacts. Not a provider watermark. Anthropic stated on 2026-08-14 that "there are no hidden characters", and 96 Claude outputs contained none.
- C2PA metadata on a generated fileAnyone, with public tools
That a manifest survived. A missing one proves nothing: ordinary uploads destroy metadata routinely.
- Generic AI detector scoreAnyone, usually paid
How the text reads to a statistical model. Not a watermark check, and documented false positives in both directions.
- Claude's statistical text watermarkEligible organizations only
Would prove content may have been processed by Claude, which is Anthropic's own ceiling. The mechanism family was published on 2026-08-14, a SynthID-Text variant; the key stays secret, and the detection API shipped on 2026-09-01 into a private preview for eligible organizations under EU law, so there is still no route for a general reader.
The three runnable checks are all real and all answer a different question than the one people ask. The fourth is the question people ask. Since 2026-09-01 it does have a runnable answer, but only inside Anthropic's private preview for eligible organizations, which is not where any tool selling removal is running it.
Is there a Claude text watermark detector available today?
ConfirmedWhat exists, what does not, and what the things calling themselves Claude detectors are actually doing.
There is still no Claude text watermark detector available to the public, but there is now one available to somebody. Rechecked 25 September 2026: Anthropic's detection API is in private preview as of 1 September, its help centre and its August explainer both updated to say so, and access runs through a request form rather than a public endpoint. No third-party tool and no research prototype anyone can run has appeared, for the structural reason in the next section.
So the honest answer splits by who is asking. A regulator, a newsroom, a fact-checking organization, an academic researcher, an educational institution, an EU civil-society group, or a company with its own Article 50 verification duty can apply and, if accepted, check a passage. A writer wondering whether their own draft is marked cannot, and neither can any product selling them that answer.
Anthropic's email to Claude for Work administrators, seen on 2026-09-04, compresses that eligibility list to "eligible EU organizations" and adds one thing no public page says: that "Anthropic does not see or store text submitted to" the detection API. Treat it as an official announcement rather than documentation, because Anthropic's public help page still does not say it when re-read on 2026-09-25, and neither it nor the 14 August 2026 news post says anything about whether submitted text is retained.
One Anthropic checker is public, and it checks files rather than text. The free Claude Content Checker at claude.com/check-files reads C2PA Content Credentials across 17 listed image, video and audio formats, runs in the browser, and states that your file "never leaves your device". Its own description of its limits is the sentence to keep: "The tool does not check text. Claude marks text with a watermark in the writing itself."
The tools that appear when you search for one fall into three groups, and none of them does what the name implies.
- Invisible-character scanners. They look for zero-width spaces, joiners, and byte-order marks. Real, useful for formatting hygiene, and unrelated to Anthropic's mark: the 14 August 2026 explainer rules the theory out directly, stating "Nothing is added to the text and there are no hidden characters."
- Generic AI detectors. They score writing style and perplexity. That is a guess about how text reads, not a decoded signal, and it is wrong in both directions on human and machine text alike.
- Removal tools claiming a before-and-after check. If nobody can detect the mark, nobody can demonstrate its removal either. The claim is unfalsifiable, which is the problem with it.
Why has no third party built a Claude watermark detector?
Research/proposalThe structural reason the gap has not been filled by the market, which is not lack of interest.
Statistical text watermarks are keyed. The scheme biases token selection during generation using a secret, and detection means running a statistical test that depends on knowing that secret and that scheme.
Google's SynthID-Text makes the shape of this concrete: it is open-sourced, ships in Hugging Face Transformers with a reference detector, and anyone can run the whole loop on their own model. That is possible precisely because the algorithm is public.
Anthropic has now described the mechanism at family level, calling it a version of the SynthID-Text approach, but it has published neither the exact scheme nor the key. Without those, an independent detector still has nothing to test against. The absence of third-party tools is therefore not a market failure or a lack of demand. It is the expected consequence of a keyed scheme whose key stays secret.
This also explains the shape of the independent research that has appeared. Analyses published on 12 August 2026 could rule out hidden characters, because characters are observable in the bytes. Neither could say anything about a token-selection watermark, and both said so. Two days later Anthropic confirmed both readings: the mark lives in keyed word selection, and nothing is added to the text.
Why is Claude's detector restricted to expert organizations?
Official announcementIn August this page argued an expert-access detector was the likely outcome, and refused to call it Anthropic's plan. On 1 September Anthropic announced almost exactly that.
Restricting text detection to verified expert users is something the EU Code of Practice Anthropic signed expressly permits. Almost every write-up treated the missing detector as a delay. The EU's Code of Practice on Transparency of AI-Generated Content, which Anthropic signed, describes something closer to a choice.
Its wording is that signatories may restrict access to detection mechanisms for free-form text where those mechanisms have lower reliability and robustness, and may produce misleading or low-confidence results, granting access instead to verified expert end-users such as regulators, law enforcement, media, fact-checkers, trusted flaggers, researchers, and civil society. Any restriction is to be limited in time, until more reliable detection emerges.
Read against that, an expert-access detector rather than a public one would be a compliant outcome, not a broken promise. That was written here in August with the caveat that Anthropic had not said it was the plan and it should not be reported as if it had.
On 1 September 2026 Anthropic said it. Line the two lists up and the resemblance is the point:
- The Code's category: "verified expert end-users such as regulators, law enforcement, media, fact-checkers, trusted flaggers, researchers, and civil society".
- Anthropic's eligibility: "regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups", plus enterprises with their own verification duty under the Act.
- How Anthropic's own notice to administrators summarises the same gate, seen 2026-09-04: detection is "limited today to eligible EU organizations", a compression its public help page still does not use when re-read on 2026-09-25.
Five of the Code's seven categories appear verbatim. That is not a coincidence and it was not a delay: the access model was available in the regulatory text weeks before the product shipped, for anyone who read the Code rather than the press release.
What do the EU's rules require of a watermark detector?
ConfirmedThe Commission's Article 50 Guidelines say marking without available detection does not satisfy the obligation. The Code of Practice separately permits an expert-only text detector for a limited time. Both bear on this preview, and they pull in different directions.
Two EU documents set the standard a detection API gets measured against, and they are not the same document. The Guidelines are the Commission's interpretation of Article 50, adopted 2026-07-20 as C(2026) 5054 final. The Code of Practice on Transparency of AI-Generated Content is voluntary, and Anthropic signed it.
The Guidelines treat marking and detection as one obligation with two halves. Paragraph 70 states that "Fulfilling only one element (e.g. for machine-readable marking of outputs without the means for their detection being available) will not suffice to comply with that provision."
Paragraph 75 says who detection has to reach. The provider "is obliged to ensure that the means of detection are available to the persons potentially exposed to the content", and under Article 50(5) the result has to be human-readable.
Paragraph 76 puts a provider's own detector second in line. Providers "must rely on publicly-available industry standard detection solutions", and only where such standards are absent, "in particular at the initial stage of the implementation of Article 50(2) AI Act for watermarking technologies", may a provider "rely on its own detection solution or on a third party or shared detection solution". That fallback "should be limited in time".
The Code of Practice pulls the other way, and only for text. Signatories "may restrict access to detection mechanisms associated to watermarking techniques for free-form text to the extent that they have a lower level of reliability and robustness", granting access instead to "verified expert end-users with a legitimate need". It adds that "Any restriction to the access will be limited in time until more reliable and robust detection mechanisms have emerged".
So a provider-run, expert-only text detector is a posture both documents anticipate at this stage of a rollout, and both describe as temporary. Neither supplies the date on which the temporary part ends.
What could a Claude watermark detector honestly tell you?
ConfirmedThe ceiling Anthropic set on the result before the tool exists, and the conditions that defeat the mark.
Anthropic's own wording caps the strongest possible outcome: a detected mark indicates content may have been processed by Claude. Not that Claude wrote it, and not that a person did not.
The 14 August 2026 explainer sharpens the same ceiling. Detection can only answer "What is the likelihood this was partly written by Claude?", it "cannot distinguish 'Claude wrote this' from 'Claude heavily edited this'", and it "doesn't confirm whether the text was human-written."
Anthropic separately lists the conditions under which the mark may be absent or unrecoverable:
- Output from models released before marking
- Heavily edited, paraphrased, or translated text
- Watermarked text mixed into a longer document
- Very short passages
Anthropic lists one more condition that belongs to a different signal: provenance metadata on generated files can be lost to conversion, re-saving, or a screenshot. That is the C2PA layer, not the text watermark, which by Anthropic's own account adds nothing to the text that could be stripped.
The first condition on that list now has dates attached to it. Anthropic's 2026-09-25 email says Claude Opus 5 responses carry the watermark from September 14 (its 2026-09-04 notice to administrators had said September 9), and that Fable 5, Sonnet 5 and Opus 4.8 follow from 2026-09-30. A detection result on text from those models turns on when the text was generated rather than on the model name alone.
That list matters more than it looks, because it means a negative result will never be evidence of anything. A clean check would be consistent with human writing, with edited Claude output, with output from an older model, and with a passage too short to score.
Anyone planning to act on a future detector (an academic-integrity process, a newsroom check, a compliance workflow) should design around a tool whose positive result is a maybe and whose negative result is silence.
What can you actually check on Claude text today?
Three real checks, in order of how much they tell you, and what each one genuinely proves.
Three checks are genuinely available to you: invisible characters, C2PA metadata on generated files, and a generic AI detector's score. You are not without options. You are without one specific option that a lot of pages pretend to sell.
- Invisible characters. Genuinely checkable, in your own browser, with an exact count per character. Just know what a hit means: nearly every invisible character has a mundane origin that predates chatbots by decades.
- C2PA metadata on files. If Claude generated an SVG, PNG, or JPG, signed provenance metadata may be attached, and public tools verify it. A missing manifest proves nothing. Ordinary uploads destroy metadata routinely.
- Detector scores, understood correctly. A generic AI detector tells you how the text reads to a statistical model. It is not a watermark check, it produces documented false positives, and it should never be the sole basis for an accusation.
On the first of those, we ran the measurement rather than repeating the theory: 96 outputs across three Claude model tiers, 19,364 words, every code point counted, against a control confirming the pipeline preserves invisible characters. Zero zero-width or bidirectional-format characters appeared.
So a Unicode scan on Claude output is worth running for formatting hygiene and will almost certainly come back clean. What it cannot be is a Claude watermark check, because the thing it looks for is not what Anthropic described.
FAQ
Is there a Claude watermark detector?
Only if you belong to one of the categories Anthropic accepts. Its detection API shipped on 1 September 2026 into a private preview for regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, EU civil society groups, and enterprises with their own duty to verify marking. No third party can build an alternative, because the key is secret and the exact scheme unpublished, though Anthropic named the mechanism family on 14 August 2026 as a SynthID-Text variant. Tools marketed as Claude watermark detectors are checking invisible Unicode characters or writing style instead.
Has Anthropic shipped the detection API it promised?
Yes. Anthropic announced the API in its 14 August 2026 explainer and shipped it on 1 September 2026, a change recorded on the explainer itself as "Updated Sep 1, 2026: Provided up to date information on the watermarking detection API". Its help centre now describes detection as "currently in private preview, available to eligible organizations as required under EU law". What is still missing is public access, published criteria for admission, and a date for the expansion Anthropic says it plans.
Why can't someone else build a Claude watermark detector?
Because statistical text watermarks are keyed. Detection is a statistical test that depends on knowing the scheme and the secret used during generation. Google's SynthID-Text has independent detectors precisely because Google open-sourced the algorithm; Anthropic now says its watermark is a version of that approach but has published neither its exact parameters nor a key.
Would a Claude detector prove text was written by Claude?
No, and Anthropic says so itself: a detected mark means content may have been processed by Claude. A negative result would prove even less, and the honest version of it keys off when the text was generated rather than which model produced it: the mark can be absent from text made before that model supported marking, from heavily edited or translated text, from short passages, and from mixed documents. Anthropic dates Claude Opus 5 output from September 14, 2026 and Fable 5, Sonnet 5 and Opus 4.8 output from September 30, 2026, which are exactly the kind of boundary a clean result cannot see.
When might a public detector appear?
The API exists; a public version of it does not, and Anthropic has given no date for one. It says it plans to expand access to the detection API over time, without naming criteria or a date. The nearest thing to a deadline is a voluntary commitment under the EU Code of Practice: signatories are to implement an interoperability solution for their detection mechanisms by 2 February 2027. The same Code permits restricting text-watermark detection to verified expert users where reliability is low and says "Any restriction to the access will be limited in time", so a public consumer tool is not the only compliant outcome in the meantime.
Who gets access to the detection API?
Anthropic's help centre names seven categories of eligible organization under EU law, "such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups", plus enterprises with their own obligation to verify marking for Act compliance, applying through a request form. Its 2026-09-04 notice to Claude for Work administrators compresses the same gate to "eligible EU organizations" and adds that "Anthropic does not see or store text submitted to" the API, a statement its public help page still does not include when re-read on 2026-09-25. Anthropic says it plans to expand access over time.
Is there any public Claude checker?
For files yes, for text no. Anthropic's help centre points to the free Claude Content Checker at claude.com/check-files, which needs no sign-in, reads C2PA Content Credentials across 17 listed image, video and audio formats, states that the file "never leaves your device", and says outright that it does not check text. Text goes through the private-preview detection API instead, so the public tool answers a question about file provenance and not about the text watermark.
Next steps
- The mechanism the missing detector would check is no longer a mystery: Anthropic explained the keyed word-selection scheme on August 14, 2026. Claude's text watermark, explained
- See the measurement behind the Unicode half of this page: 96 Claude outputs, three model tiers, data and script published. The invisible-character census
- Check which providers offer a public detector at all, per modality, with a source and verification date on every cell. AI Watermark Status Database
- Read the full sourcing on what Anthropic has confirmed, including which models actually meet its own marking threshold. Claude watermark tracker
- Understand why a watermark check and an AI-detector score are different things that fail in completely different ways. AI watermark vs AI detector
- Scan a passage for invisible characters yourself, in the browser, with a count per character. Open the checker
Sources and citation status
- OfficialAnthropic: How Claude's text watermark works
- OfficialAnthropic Help: how Claude marks AI-generated content
- OfficialAnthropic: email to Claude for Work administrators, "Text watermark extends to Claude Opus 5" (received 2026-09-04; screenshots on this site)
- OfficialAnthropic: email to Claude Platform customers, "Watermarking begins September 30, 2026" (received 2026-09-25; screenshot on this site)
- OfficialAnthropic: Claude Content Checker, free in-browser Content Credentials check for files (17 listed formats, explicitly not text)
- RegulatoryEU Code of Practice on Transparency of AI-Generated Content, full text (detector access restriction; 2 February 2027 interoperability commitment)
- RegulatoryEuropean Commission: Guidelines on the transparency obligations for certain AI systems under Article 50, C(2026) 5054 final (adopted 2026-07-20)
- OfficialGoogle: SynthID-Text safeguards documentation (open-sourced algorithm with a reference detector)
- ResearchJohn Wang: analysis of 7.2M characters of Claude prose (2026-08-12)
- ResearchSan Digital: byte-level audit of 457,045 characters across four Claude models (2026-08-12)
- ResearchAI Watermark Lab: invisible-character census, 96 Claude outputs (2026-08-12)