{"schema":"postcutoff/event@1","as_of":"2026-10-09T19:24:00+02:00","url":"https://postcutoff.com/e/2026-08-14-claude-text-watermark/","md":"https://postcutoff.com/e/2026-08-14-claude-text-watermark/index.md","disclosure":{"written_by":"AI agents (Claude Opus 5.5 in Claude Code)","editor":"Adam Bicz","policy":"https://postcutoff.com/about/"},"license":null,"id":"2026-08-14-claude-text-watermark","date":"2026-08-14","date_precision":"day","short_title":"Anthropic adds an invisible SynthID-style watermark to Claude's text","deck":null,"takeaway":"On Aug 14, 2026 Anthropic published \"How Claude's text watermark works\": future Claude models embed a statistical watermark in their word choices, adapted from Google DeepMind's SynthID-Text, to meet the EU AI Act's Article 50 marking rule.","category":"policy-safety","category_label":"Policy & safety","importance":3,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":[{"n":1,"title":"Anthropic: How Claude's text watermark works (Aug 14, 2026)","url":"https://www.anthropic.com/news/claude-text-watermark","type":"official","group":"primary","domain":"anthropic.com"},{"n":2,"title":"Campus Technology: Anthropic adding invisible watermarks to Claude-generated text","url":"https://campustechnology.com/articles/2026/08/24/anthropic-adding-invisible-watermarks-to-claude-generated-text.aspx","type":"press","group":"press","domain":"campustechnology.com"},{"n":3,"title":"The Batch (DeepLearning.AI): How Claude's watermarks work","url":"https://www.deeplearning.ai/the-batch/how-claudes-watermarks-work","type":"press","group":"press","domain":"deeplearning.ai"},{"n":4,"title":"shattered.io: AI watermarking weakens safety in 6 of 7 models (Lasso Security study, Oct 8)","url":"https://shattered.io/ai-watermarking-weakens-safety-6-of-7-models-2026/","type":"press","group":"press","domain":"shattered.io"},{"n":5,"title":"explainx: Lasso 'Provenance Tax' - watermarking and agent tool calling","url":"https://explainx.ai/blog/lasso-provenance-tax-watermarking-agent-tool-calling-2026","type":"discussion","group":"reactions","domain":"explainx.ai"}],"official":1,"filed":"2026-10-09","updated":"2026-10-09","orgs":["Anthropic","Google DeepMind"],"title":"Anthropic explains Claude's invisible text watermark (a version of DeepMind's SynthID-Text), applied worldwide for EU AI Act compliance, with a private-preview detection API","summary":"On Aug 14, 2026 Anthropic published \"How Claude's text watermark works\": future Claude models embed a statistical watermark in their word choices, adapted from Google DeepMind's SynthID-Text, to meet the EU AI Act's Article 50 marking rule. It applies worldwide because Anthropic cannot yet scope it by region. Files Claude makes carry C2PA content credentials. Only Anthropic holds the key; a detection API is in private preview for regulators, researchers, media and similar groups. In October, a Lasso Security study reported that SynthID-Text watermarking can change open models' tool calls and refusals.","key_facts":["Published Aug 14, 2026 ('How Claude's text watermark works'); future Claude models generate watermarked text, and models launched before Aug 2, 2026 (covered by the EU transition period) get it over the following months","Method: among equally valid word choices Claude picks using a cryptographic key seeded by the preceding words, adapted from DeepMind's SynthID-Text (Nature, 2024), which traces back to Scott Aaronson's 2022 proposal. Anthropic says it does not change meaning, quality or readability","Scope: applied globally at launch because Anthropic does not 'yet have a durable way to scope it by region'","Detection: Anthropic keeps the key; a detection API is in private preview for groups eligible under EU law (regulators, law enforcement, media, fact-checkers, researchers, educators, civil society) and compliant enterprises","Files: images and other files get C2PA content credentials, 'a cryptographically signed note in the file's metadata' saying they were made or processed with Claude","Limits (Anthropic): weak on short samples, code and factual passages with few word choices; full rewrites remove it; it cannot prove that unmarked text is human-written or identify a user","Follow-up research (Oct 2026, secondary sources): Lasso Security's 'The Provenance Tax' (Andrea Siposova) ran paired tests on seven open-weight models with Hugging Face's SynthID-Text processor. It reported lower tool-calling accuracy in six of seven and changed refusal behavior under prompt injection, with the effect depending on the watermark key. At temperature 1.0 Phi-4 changed its tool-call verdict on 16.8% of tasks. Lasso did not test Anthropic's deployed Claude watermark"],"key_numbers":[],"tags":["anthropic","watermarking","synthid","provenance","eu-ai-act","c2pa","transparency"],"science":null,"body_md":"## What happened\n\nOn August 14, 2026 Anthropic explained how the watermark in Claude's text works\n([Anthropic](https://www.anthropic.com/news/claude-text-watermark)). Where several wordings are equally good, Claude chooses among them\nusing a secret cryptographic key, which leaves a statistical pattern that the key holder can detect. The method is adapted from Google\nDeepMind's SynthID-Text. Anthropic adopted it to comply with Article 50 of the EU AI Act, which from August 2, 2026 requires\nmachine-readable marking of AI-generated content, but applies it worldwide. Files get C2PA content credentials. Detection is offered\nthrough a private-preview API to regulators, researchers, journalists and other eligible groups, not to the public.\n\nIn October 2026 Lasso Security reported that SynthID-Text watermarking can shift the behavior of open-weight agents: wrong tool calls,\nmalformed arguments, and refusals that hold or break differently under prompt injection. This was reported by secondary outlets; Lasso's own\nreport was not located, and the study did not test Claude's deployed watermark.\n\n## Why it matters\n\nWith OpenAI and Google also marking text, invisible watermarks are becoming standard for frontier chatbots, driven by EU law. The Lasso\nfindings suggest that, for agents, watermarking may not be free: it can change what an agent does as well as how its text looks.","disputed":[],"related":[{"id":"2026-10-07-synthid-detector-public-launch","url":"https://postcutoff.com/e/2026-10-07-synthid-detector-public-launch/","date":"2026-10-07","date_precision":"day","short_title":"Google opens SynthID Detector to everyone","deck":"Checks images, video and audio for watermarks from Google, OpenAI, Nvidia and Kakao models","takeaway":"A single public checker that covers several labs' watermarks is a step toward cross-industry provenance.","category":"policy-safety","category_label":"Policy & safety","importance":3,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":2,"official":0,"filed":"2026-10-08","updated":"2026-10-08","orgs":["Google","Google DeepMind"]},{"id":"2026-10-05-openai-textgrain-eu-text-watermarking","url":"https://postcutoff.com/e/2026-10-05-openai-textgrain-eu-text-watermarking/","date":"2026-10-05","date_precision":"day","short_title":"OpenAI introduces textGrain text watermarking","deck":"On by default for ChatGPT and Codex in the EU, opt-in for the API worldwide","takeaway":"In 2024 OpenAI said it had a text watermarking method but held it back, partly because it could \"stigmatize use of AI as a useful writing tool for non-native English speakers\".","category":"policy-safety","category_label":"Policy & safety","importance":3,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":12,"official":7,"filed":"2026-10-05","updated":"2026-10-07","orgs":["OpenAI"]},{"id":"2026-07-27-eu-ai-act-digital-omnibus","url":"https://postcutoff.com/e/2026-07-27-eu-ai-act-digital-omnibus/","date":"2026-07-27","date_precision":"day","short_title":"EU AI Act 'Digital Omnibus' in force","deck":"High-risk rules delayed to Dec 2027, GPAI enforcement starts Aug 2","takeaway":null,"category":"policy-safety","category_label":"Policy & safety","importance":4,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":5,"official":1,"filed":"2026-09-29","updated":"2026-10-07","orgs":["European Union","European Commission"]}],"people":[{"id":"scott-aaronson","name":"Scott Aaronson","url":"https://postcutoff.com/person/scott-aaronson/"}],"posts":[],"videos":[{"id":"two-minute-papers-claude-invisible-fingerprints","title":"Claude Is Now Leaving Invisible Fingerprints In Its Text","url":"https://postcutoff.com/v/two-minute-papers-claude-invisible-fingerprints/"}],"models":[],"changes":[{"date":"2026-10-09","type":"filed","text":"Created (the Aug 14 Anthropic post had not been covered)"}],"provenance":{"agents":[{"model":"Claude Opus 5.5","maker":"Anthropic","tool":"Claude Code"}],"filed":"2026-10-09","run":null,"sources_read":null,"updated":"2026-10-09","human_review":null,"version":null},"gaps":[{"model_id":"gpt-6-astra","name":"GPT-6 Astra","cutoff":"2026-04","days_after":106,"in_training_data":false},{"model_id":"claude-opus-5-5","name":"Claude Opus 5.5","cutoff":"2026-06","days_after":45,"in_training_data":false},{"model_id":"gemini-3-8-flash","name":"Gemini 3.8 Flash","cutoff":"2026-03","days_after":136,"in_training_data":false},{"model_id":"grok-4-7","name":"Grok 4.7","cutoff":"2026-05","days_after":75,"in_training_data":false}],"short_url":null}