Claude Now Watermarks AI Text and Images, Anthropic Says
SF-based Anthropic now embeds invisible watermarks in Claude's text and C2PA signed metadata in images. How it works, how to check content, and the limits.

San Francisco-based Anthropic has quietly changed what comes out of its Claude assistant: every response now carries an invisible, machine-readable watermark, and images leave the system with cryptographically signed provenance metadata attached. The change, described in a support article the company published this month, is automatic across all of Claude's products and cannot be switched off by users.
What Anthropic actually shipped
The system has two parts. For text, Claude embeds an imperceptible watermark directly into the writing it generates. Anthropic says readers will not see it and that it changes nothing about the meaning, quality, or readability of a response. The mark is designed to travel with the text when it is copied and pasted somewhere else, which is the scenario that matters in practice, since almost no one reads AI output where it was generated.
For images and graphics, Claude attaches signed provenance metadata to .png, .jpg, and .svg files under the C2PA standard, the Coalition for Content Provenance and Authenticity framework that Adobe, Microsoft, and most major camera manufacturers have coalesced around. The signature lets anyone verify that a file originated from Claude and that its provenance record has not been tampered with.
The rollout covers the Claude apps, the developer API, Claude Code, the Claude Cowork agent product, and Claude Tag in Slack. Models launched on or after August 2, 2026 carry the marking from day one, and Anthropic says it is working on adding it to older models retroactively.
Why this lands differently in the Bay Area
The obvious constituencies are teachers grading essays and editors screening submissions. But in a region where a large share of the workforce now drafts email, code review comments, and performance feedback with AI assistance, provenance marking cuts both ways. It gives institutions a way to check whether a document was machine-written, and it gives honest users something they have never had: a means of demonstrating that a piece of writing was not generated, because Claude's marks are absent and verifiably so once detection tooling matures.
Checking is already possible today. Anyone can run a document or image through an AI watermark detector to look for embedded marks and C2PA credentials, and Anthropic says it will document its own detection mechanisms in forthcoming technical materials.
For readers keeping score at home: the marking now spans five Anthropic product surfaces and three image file formats, and applies at launch to every Claude model released since August 2, 2026.
The fine print
Anthropic is careful not to oversell the system. In the company's own words, a detected mark provides a signal, but it is not fully conclusive. Text that gets heavily edited, paraphrased, translated, or blended with human writing may shed its watermark entirely, so the absence of a mark is not evidence that something is human-made.
That honesty matters, because the failure mode of detection tools has never been missing AI content. It has been falsely accusing people, most painfully students, of using AI when they did not. A watermark regime with clearly stated limits is a real improvement on statistical classifiers that render confident verdicts from word frequencies. Provenance marking will not end arguments about AI-generated content, but it turns an unwinnable guessing game into a checkable claim, and that is the most consequential change to AI transparency any frontier lab has shipped this year.
The competitive question now sits with Anthropic's neighbors. Google has watermarked images and audio with SynthID for two years, and OpenAI has discussed text watermarking without shipping it. As of this month, the only frontier lab watermarking text in production is the one on Howard Street.
Cover photo: the San Francisco skyline from the Embarcadero. Public domain (CC0) via Wikimedia Commons.
