Home AI Your AI Output Now Carries a Signature.

Your AI Output Now Carries a Signature.

Starting August 2, 2026, text generated by newer Claude models carries an invisible watermark.

Here’s What That Actually Means for Your Business.

Starting August 2, 2026, text generated by newer Claude models carries an invisible watermark. Files in certain formats carry something else entirely. Most of the coverage this week has blurred that distinction — and for executives deciding how to handle AI-assisted content in contracts, disclosures, or hiring pipelines, the distinction is the whole story.

Here’s what’s actually happening, what it isn’t, and where the real exposure sits for your organisation.

What Anthropic Announced

Anthropic has signed onto the European Union AI Act’s Article 50(2) Code of Practice on Transparency of AI-Generated Content — a voluntary framework that, once signed, creates a presumption of compliance with the Act’s transparency requirements. Roughly 200 companies had signed by late July, including Microsoft, Google, and Meta. OpenAI is a notable holdout, reportedly over concerns about false positives and competitive exposure. Elon Musk’s xAI has not signed either.

The obligation itself comes from Article 50 of the AI Act, which took effect on August 2, 2026, and requires providers of systems that generate synthetic content to mark that content as artificially generated. Non-compliance carries fines up to €15 million or 3% of global annual turnover, whichever is higher — the kind of number that gets a general counsel’s attention regardless of where your company is headquartered.

Anthropic’s rollout is not geo-fenced. Any Claude model released on or after August 2 marks its output everywhere it’s used — the consumer app, the API, Claude Code, Cowork, Claude Tag, and cloud access points through AWS, Google Cloud, and Microsoft Foundry. If your team is in Delhi, Denver, or Dubai, the marking applies to you exactly as it applies to a user in Berlin. Anthropic made a deliberate choice here: comply once, comply everywhere, rather than run two versions of the product.

Two Different Mechanisms — Don’t Conflate Them

This is where most of the week’s coverage has gotten loose, and where I’d push back if I were sitting across the table from you.

Text gets a watermark. Anthropic describes it as an imperceptible signal woven directly into the output at the model level. It doesn’t alter meaning, quality, or readability. It survives copy-paste, and Anthropic says it may survive light editing. Critically, this is not the “biased word choice” style of watermarking that some earlier academic watermarking schemes used — Anthropic has specifically avoided describing it that way, which matters if you’re wondering whether your editing process could accidentally strip it or whether the text will read differently.

Generated files get something structurally different: signed provenance metadata. For supported image formats — .svg, .png, .jpg — Anthropic attaches metadata conforming to the C2PA standard (the same provenance framework Adobe, Microsoft, and camera manufacturers have been building out for a few years now). This metadata records that Claude was involved in creating the file and flags tampering. It is not a watermark baked into the pixels. It’s a data layer sitting alongside the image, and — this is the part worth flagging to anyone on your team who handles branded assets — that layer is trivially stripped by a format conversion, a re-save, or a screenshot.

So: “watermarking image and text outputs,” as a single phrase, overstates what’s happening on the image side. One is a persistent signal in the content itself. The other is detachable metadata. If you’re briefing your board or your compliance team, keep these separate — they carry very different assurances.

The Honesty in the Fine Print

Anthropic’s own limitations section is worth reading directly, because it undercuts the “gotcha” framing some coverage has run with. The company states plainly that proofreading, translating, summarising, or converting a file can trigger a mark even when the underlying ideas and original text came from somewhere else entirely. A human-written draft that Claude cleaned up for grammar could, in principle, carry the same signal as a fully AI-generated draft.

That’s not a minor caveat. It means a detected watermark tells you Claude touched the content — not who wrote it, and not how much of it is AI-originated. Anthropic has been explicit that a detected mark indicates Claude may have processed the content, not that Claude authored it.

If your organisation is building policy around AI-disclosure — for client work, for academic integrity in a training program, for hiring evaluations — this distinction should be load-bearing. A watermark hit is evidence of contact, not proof of authorship. Treating it as the latter, before Anthropic even publishes its detection tooling, is a mistake I’d expect from someone who read the headline and not the documentation.

What I’d Actually Do With This

If you run a content, marketing, or comms function: nothing changes about your workflow, but your disclosure language should get more precise. “AI-assisted” is defensible; “written entirely without AI” is now a harder claim to stand behind if any part of your pipeline — grammar check, translation, summarisation — touched a newer Claude model.

If you’re in a regulated or litigation-sensitive industry: watch for detection tools becoming a factor in discovery, academic misconduct proceedings, or contract disputes over AI-generated work product. Anthropic has said it will publish technical detection details; until that lands, nobody outside Anthropic can independently verify a mark either way.

If you handle brand or legal assets as image files: don’t rely on C2PA metadata as your provenance record of last resort. It’s useful, but it’s also removable by routine file handling that has nothing to do with anyone trying to hide anything — a designer resaving a PNG in Photoshop can strip it inadvertently.

If you’re outside the EU and assumed this doesn’t apply to you: it does. That’s the specific choice Anthropic made, and it’s arguably the more interesting business story here — a US company extending EU-driven compliance infrastructure globally rather than segmenting by region, which tells you something about where Anthropic expects AI content regulation to head next.

None of this is cause for alarm. It’s also nothing. The gap between those two reactions is usually where good governance decisions get made — and where sloppy ones get made too, if you skip the fine print.


Exit mobile version