Anthropic adds an invisible SynthID-style watermark to Claude’s text
Confirmed
The takeaway
On Aug 14, 2026 Anthropic published “How Claude’s text watermark works”: future Claude models embed a statistical watermark in their word choices, adapted from Google DeepMind’s SynthID-Text, to meet the EU AI Act’s Article 50 marking rule.
Status
- Claim
Confirmed
- Our reporting
- High confidence
- Importance
- 3 of 5
- Last verified
- 9 October 2026
Your AI and this story
- GPT-6 Astra106 days after its cutoff
- Claude Opus 5.545 days after its cutoff
- Gemini 3.8 Flash136 days after its cutoff
- Grok 4.775 days after its cutoff
None of these four assistants can know about it. The closest, Claude Opus 5.5, stops 45 days before it.
Key facts
- Published Aug 14, 2026 (‘How Claude’s text watermark works’); future Claude models generate watermarked text, and models launched before Aug 2, 2026 (covered by the EU transition period) get it over the following months
- Method: among equally valid word choices Claude picks using a cryptographic key seeded by the preceding words, adapted from DeepMind’s SynthID-Text (Nature, 2024), which traces back to Scott Aaronson’s 2022 proposal. Anthropic says it does not change meaning, quality or readability
- Scope: applied globally at launch because Anthropic does not ‘yet have a durable way to scope it by region’
- Detection: Anthropic keeps the key; a detection API is in private preview for groups eligible under EU law (regulators, law enforcement, media, fact-checkers, researchers, educators, civil society) and compliant enterprises
- Files: images and other files get C2PA content credentials, ‘a cryptographically signed note in the file’s metadata’ saying they were made or processed with Claude
- Limits (Anthropic): weak on short samples, code and factual passages with few word choices; full rewrites remove it; it cannot prove that unmarked text is human-written or identify a user
- Follow-up research (Oct 2026, secondary sources): Lasso Security’s ‘The Provenance Tax’ (Andrea Siposova) ran paired tests on seven open-weight models with Hugging Face’s SynthID-Text processor. It reported lower tool-calling accuracy in six of seven and changed refusal behavior under prompt injection, with the effect depending on the watermark key. At temperature 1.0 Phi-4 changed its tool-call verdict on 16.8% of tasks. Lasso did not test Anthropic’s deployed Claude watermark
What happened
On August 14, 2026 Anthropic explained how the watermark in Claude’s text works (Anthropic1). Where several wordings are equally good, Claude chooses among them using a secret cryptographic key, which leaves a statistical pattern that the key holder can detect. The method is adapted from Google DeepMind’s SynthID-Text. Anthropic adopted it to comply with Article 50 of the EU AI Act, which from August 2, 2026 requires machine-readable marking of AI-generated content, but applies it worldwide. Files get C2PA content credentials. Detection is offered through a private-preview API to regulators, researchers, journalists and other eligible groups, not to the public.
In October 2026 Lasso Security reported that SynthID-Text watermarking can shift the behavior of open-weight agents: wrong tool calls, malformed arguments, and refusals that hold or break differently under prompt injection. This was reported by secondary outlets; Lasso’s own report was not located, and the study did not test Claude’s deployed watermark.
Why it matters
With OpenAI and Google also marking text, invisible watermarks are becoming standard for frontier chatbots, driven by EU law. The Lasso findings suggest that, for agents, watermarking may not be free: it can change what an agent does as well as how its text looks.
Sources
5 sources from 5 sites. Numbers match the chips in the text.
5 sources: 1 primary, 3 press, 1 reaction
Primary
- Anthropic: How Claude’s text watermark works (Aug 14, 2026)anthropic.com, official
Press
- Campus Technology: Anthropic adding invisible watermarks to Claude-generated textcampustechnology.com, press
- The Batch (DeepLearning.AI): How Claude’s watermarks workdeeplearning.ai, press
- shattered.io: AI watermarking weakens safety in 6 of 7 models (Lasso Security study, Oct 8)shattered.io, press
Reactions
- explainx: Lasso ‘Provenance Tax’ - watermarking and agent tool callingexplainx.ai, discussion
Changes
- Filed (the Aug 14 Anthropic post had not been covered)