BlogAI Provenance

Does Claude Watermark Its Output?

7 min read — by HALLMARK.AI

Yes. Since August 2, 2026, Claude embeds an invisible watermark in the text it generates, and attaches C2PA provenance metadata to supported files it produces. The more useful detail is the part that gets skipped in the coverage: as of writing, there is no public tool that lets you check for it.

What Claude marks

  • Generated text — an imperceptible watermark woven into the text itself. It does not change meaning or readability, and it stays in the text when you copy and paste.
  • Generated files — SVG, PNG, and JPG files receive digitally signed provenance metadata following the C2PA standard.

Models launched on or after August 2, 2026 support marking at launch, and Anthropic has said earlier models are being retrofitted. The marking applies worldwide, not only in the EU, even though the trigger was the EU AI Act's Article 50 transparency obligation — our breakdown of that law covers who it binds.

How a text watermark can even work

This is the genuinely clever part, and it is worth understanding because it explains every limitation that follows. Claude's watermark uses the SynthID-Text approach published by Google DeepMind. Nothing is added to the text and nothing is altered afterwards. Instead, when the model is choosing between words that are all equally good continuations, it derives that choice from a cryptographic key rather than from arbitrary randomness. Across a long enough passage the pattern of those choices forms a detectable statistical signature.

The watermark lives in which word was chosen among equally valid options. That single fact predicts everything: wherever Claude has no meaningful choice, there is no room to hide a signal.

Where it weakens — per Anthropic's own documentation

  • Short text. Detection works poorly on small samples — fewer word choices means less signal. Confidence rises with length.
  • Factual passages. Marking is sparser where few alternative wordings exist without making the text less accurate.
  • Code. Generally carries less watermarking than prose, because exact output is required.
  • Editing. It can survive light editing, but a thorough rewrite that replaces essentially every word removes it. Heavy paraphrasing does the same.
  • Format conversion and screenshots. Both can lose the mark.

One counterintuitive case: a translation produced by Claude does carry a watermark, because Claude chose every word in it. Someone else translating Claude's output is a different matter.

The catch: you cannot currently check

Anthropic says it is working to let users and third parties detect the marks, and that a watermark detection API is coming, with implementation details still being worked out. Until that ships, the practical situation is that Claude-generated text is marked and unverifiable by you. A teacher, editor, or platform cannot take a passage today and get an answer.

That gap matters more than it sounds. A watermark you cannot query is a compliance artifact, not a working detection system — which is exactly why absence of a detected mark should never be read as evidence of anything, here or anywhere else.

What this does not do

It is worth being precise about the boundary, because "Claude watermarks its output" gets repeated as though it solves authenticity. It answers one question: did this Claude model generate this text? It says nothing about whether a human wrote something, and nothing at all about who owns a photograph or a video.

The pattern that should interest creators

Look at the last twelve months together. Google marks its generated images and video with SynthID. OpenAI added SynthID alongside C2PA to ChatGPT images in May 2026. Anthropic now marks Claude's text and signs its generated files. Producer-side marking has gone from one vendor's feature to something close to universal among frontier labs, largely driven by regulation.

Every major AI lab now marks what its models generate. Nobody marks what you create. That asymmetry is the whole point: synthetic media is increasingly labelled at the moment of creation, while the photograph you actually shot carries no signal at all unless you put one there.

That is the gap creator-side watermarking fills, and it runs in the opposite direction to everything above — you mark your own authentic work before publishing, so that a copy can be traced back to you after it has been cropped, re-encoded, or run through a generative model. How SynthID compares and what our own watermark measurably survives go into both sides.

HALLMARK.AI watermarks your images and video free, invisibly, before you publish — with published robustness benchmarks including the failure cases, and a free checker anyone can actually run, which is more than the AI labs currently offer.