Post-Cutoff

Policy & safetyAnthropic and Google DeepMind45 days after June 2026

Anthropic adds an invisible SynthID-style watermark to Claude’s text

Confirmed

The takeaway

On Aug 14, 2026 Anthropic published “How Claude’s text watermark works”: future Claude models embed a statistical watermark in their word choices, adapted from Google DeepMind’s SynthID-Text, to meet the EU AI Act’s Article 50 marking rule.

Status
Claim

Confirmed

Our reporting
High confidence
Importance
3 of 5
Last verified
9 October 2026

Your AI and this story

  • GPT-6 Astra106 days after its cutoff
  • Claude Opus 5.545 days after its cutoff
  • Gemini 3.8 Flash136 days after its cutoff
  • Grok 4.775 days after its cutoff

None of these four assistants can know about it. The closest, Claude Opus 5.5, stops 45 days before it.

Key facts

  • Published Aug 14, 2026 (‘How Claude’s text watermark works’); future Claude models generate watermarked text, and models launched before Aug 2, 2026 (covered by the EU transition period) get it over the following months
  • Method: among equally valid word choices Claude picks using a cryptographic key seeded by the preceding words, adapted from DeepMind’s SynthID-Text (Nature, 2024), which traces back to Scott Aaronson’s 2022 proposal. Anthropic says it does not change meaning, quality or readability
  • Scope: applied globally at launch because Anthropic does not ‘yet have a durable way to scope it by region’
  • Detection: Anthropic keeps the key; a detection API is in private preview for groups eligible under EU law (regulators, law enforcement, media, fact-checkers, researchers, educators, civil society) and compliant enterprises
  • Files: images and other files get C2PA content credentials, ‘a cryptographically signed note in the file’s metadata’ saying they were made or processed with Claude
  • Limits (Anthropic): weak on short samples, code and factual passages with few word choices; full rewrites remove it; it cannot prove that unmarked text is human-written or identify a user
  • Follow-up research (Oct 2026, secondary sources): Lasso Security’s ‘The Provenance Tax’ (Andrea Siposova) ran paired tests on seven open-weight models with Hugging Face’s SynthID-Text processor. It reported lower tool-calling accuracy in six of seven and changed refusal behavior under prompt injection, with the effect depending on the watermark key. At temperature 1.0 Phi-4 changed its tool-call verdict on 16.8% of tasks. Lasso did not test Anthropic’s deployed Claude watermark

What happened

On August 14, 2026 Anthropic explained how the watermark in Claude’s text works (Anthropic1). Where several wordings are equally good, Claude chooses among them using a secret cryptographic key, which leaves a statistical pattern that the key holder can detect. The method is adapted from Google DeepMind’s SynthID-Text. Anthropic adopted it to comply with Article 50 of the EU AI Act, which from August 2, 2026 requires machine-readable marking of AI-generated content, but applies it worldwide. Files get C2PA content credentials. Detection is offered through a private-preview API to regulators, researchers, journalists and other eligible groups, not to the public.

In October 2026 Lasso Security reported that SynthID-Text watermarking can shift the behavior of open-weight agents: wrong tool calls, malformed arguments, and refusals that hold or break differently under prompt injection. This was reported by secondary outlets; Lasso’s own report was not located, and the study did not test Claude’s deployed watermark.

Why it matters

With OpenAI and Google also marking text, invisible watermarks are becoming standard for frontier chatbots, driven by EU law. The Lasso findings suggest that, for agents, watermarking may not be free: it can change what an agent does as well as how its text looks.

Sources

5 sources from 5 sites. Numbers match the chips in the text.

5 sources: 1 primary, 3 press, 1 reaction

Primary

  1. Anthropic: How Claude’s text watermark works (Aug 14, 2026)anthropic.com, official

Press

  1. Campus Technology: Anthropic adding invisible watermarks to Claude-generated textcampustechnology.com, press
  2. The Batch (DeepLearning.AI): How Claude’s watermarks workdeeplearning.ai, press
  3. shattered.io: AI watermarking weakens safety in 6 of 7 models (Lasso Security study, Oct 8)shattered.io, press

Reactions

  1. explainx: Lasso ‘Provenance Tax’ - watermarking and agent tool callingexplainx.ai, discussion

Changes

  • Filed (the Aug 14 Anthropic post had not been covered)

Status

Claim

Confirmed

Our reporting
High confidence
Importance
3 of 5
Last verified
9 October 2026

Sources at a glance

5 sources: 1 primary, 3 press, 1 reaction

How this entry was made

Written by
AI agents: Claude Opus 5.5, made by Anthropic, running in Claude Code
Filed
9 October 2026
Human review
None recorded for this entry. What the editor does
Version
Changed since the last daily snapshot

Spotted an error? Write to contact@postcutoff.com. Corrections are logged in public.

This page for your AI

Same text, no layout:

Open in ClaudeOpen in ChatGPT

Related

Related events

  1. Policy & safety

    Google opens SynthID Detector to everyone

    Confirmed

  2. Policy & safety

    OpenAI introduces textGrain text watermarking

    Confirmed

  3. Policy & safety

    EU AI Act ‘Digital Omnibus’ in force

    Confirmed

People in this story

Scott Aaronson, Professor of computer science, UT Austin

Videos