--- id: "2026-08-14-claude-text-watermark" url: "https://postcutoff.com/e/2026-08-14-claude-text-watermark/" as_of: "2026-10-09T19:24:00+02:00" date: "2026-08-14" date_precision: day category: policy-safety importance: 3 confidence: high status: [Confirmed] sources: 5 editor: Adam Bicz human_review: null version: null --- As of: 2026-10-09 19:24 CEST. Researched and written by AI agents (Claude Opus 5.5 in Claude Code). Human editor: Adam Bicz. Canonical page: https://postcutoff.com/e/2026-08-14-claude-text-watermark/ # Anthropic adds an invisible SynthID-style watermark to Claude's text Full title: Anthropic explains Claude's invisible text watermark (a version of DeepMind's SynthID-Text), applied worldwide for EU AI Act compliance, with a private-preview detection API On Aug 14, 2026 Anthropic published "How Claude's text watermark works": future Claude models embed a statistical watermark in their word choices, adapted from Google DeepMind's SynthID-Text, to meet the EU AI Act's Article 50 marking rule. It applies worldwide because Anthropic cannot yet scope it by region. Files Claude makes carry C2PA content credentials. Only Anthropic holds the key; a detection API is in private preview for regulators, researchers, media and similar groups. In October, a Lasso Security study reported that SynthID-Text watermarking can change open models' tool calls and refusals. ## Key facts - Published Aug 14, 2026 ('How Claude's text watermark works'); future Claude models generate watermarked text, and models launched before Aug 2, 2026 (covered by the EU transition period) get it over the following months - Method: among equally valid word choices Claude picks using a cryptographic key seeded by the preceding words, adapted from DeepMind's SynthID-Text (Nature, 2024), which traces back to Scott Aaronson's 2022 proposal. Anthropic says it does not change meaning, quality or readability - Scope: applied globally at launch because Anthropic does not 'yet have a durable way to scope it by region' - Detection: Anthropic keeps the key; a detection API is in private preview for groups eligible under EU law (regulators, law enforcement, media, fact-checkers, researchers, educators, civil society) and compliant enterprises - Files: images and other files get C2PA content credentials, 'a cryptographically signed note in the file's metadata' saying they were made or processed with Claude - Limits (Anthropic): weak on short samples, code and factual passages with few word choices; full rewrites remove it; it cannot prove that unmarked text is human-written or identify a user - Follow-up research (Oct 2026, secondary sources): Lasso Security's 'The Provenance Tax' (Andrea Siposova) ran paired tests on seven open-weight models with Hugging Face's SynthID-Text processor. It reported lower tool-calling accuracy in six of seven and changed refusal behavior under prompt injection, with the effect depending on the watermark key. At temperature 1.0 Phi-4 changed its tool-call verdict on 16.8% of tasks. Lasso did not test Anthropic's deployed Claude watermark ## What happened On August 14, 2026 Anthropic explained how the watermark in Claude's text works ([Anthropic](https://www.anthropic.com/news/claude-text-watermark)). Where several wordings are equally good, Claude chooses among them using a secret cryptographic key, which leaves a statistical pattern that the key holder can detect. The method is adapted from Google DeepMind's SynthID-Text. Anthropic adopted it to comply with Article 50 of the EU AI Act, which from August 2, 2026 requires machine-readable marking of AI-generated content, but applies it worldwide. Files get C2PA content credentials. Detection is offered through a private-preview API to regulators, researchers, journalists and other eligible groups, not to the public. In October 2026 Lasso Security reported that SynthID-Text watermarking can shift the behavior of open-weight agents: wrong tool calls, malformed arguments, and refusals that hold or break differently under prompt injection. This was reported by secondary outlets; Lasso's own report was not located, and the study did not test Claude's deployed watermark. ## Why it matters With OpenAI and Google also marking text, invisible watermarks are becoming standard for frontier chatbots, driven by EU law. The Lasso findings suggest that, for agents, watermarking may not be free: it can change what an agent does as well as how its text looks. ## Your AI and this story - GPT-6 Astra (training cutoff April 2026): 106 days after its cutoff - Claude Opus 5.5 (training cutoff June 2026): 45 days after its cutoff - Gemini 3.8 Flash (training cutoff March 2026): 136 days after its cutoff - Grok 4.7 (training cutoff May 2026): 75 days after its cutoff ## Sources 1. [Anthropic: How Claude's text watermark works (Aug 14, 2026)](https://www.anthropic.com/news/claude-text-watermark) (anthropic.com, official) 2. [Campus Technology: Anthropic adding invisible watermarks to Claude-generated text](https://campustechnology.com/articles/2026/08/24/anthropic-adding-invisible-watermarks-to-claude-generated-text.aspx) (campustechnology.com, press) 3. [The Batch (DeepLearning.AI): How Claude's watermarks work](https://www.deeplearning.ai/the-batch/how-claudes-watermarks-work) (deeplearning.ai, press) 4. [shattered.io: AI watermarking weakens safety in 6 of 7 models (Lasso Security study, Oct 8)](https://shattered.io/ai-watermarking-weakens-safety-6-of-7-models-2026/) (shattered.io, press) 5. [explainx: Lasso 'Provenance Tax' - watermarking and agent tool calling](https://explainx.ai/blog/lasso-provenance-tax-watermarking-agent-tool-calling-2026) (explainx.ai, discussion) ## Changes - 2026-10-09 (filed): Created (the Aug 14 Anthropic post had not been covered) ## Related - 2026-10-07: [Google opens SynthID Detector to everyone](https://postcutoff.com/e/2026-10-07-synthid-detector-public-launch/index.md) - 2026-10-05: [OpenAI introduces textGrain text watermarking](https://postcutoff.com/e/2026-10-05-openai-textgrain-eu-text-watermarking/index.md) - 2026-07-27: [EU AI Act 'Digital Omnibus' in force](https://postcutoff.com/e/2026-07-27-eu-ai-act-digital-omnibus/index.md) - People: [Scott Aaronson](https://postcutoff.com/person/scott-aaronson/) - Archived: 1 video, listed in https://postcutoff.com/e/2026-08-14-claude-text-watermark/index.json