The announcement, without the headline noise

Four facts from Anthropic's own help centre article, which is a better source than any of the coverage written about it. Everything else on this page follows from these.

Announced
11 Aug

2026, by Anthropic. Not a leak, not a rumour.

Where it applies
Worldwide

Not EU-only. No opt-out on any plan.

Which models
Aug 2 +

Marked at launch. Older models retrofitted.

What a hit means
Processed

May have been processed by Claude. Not written by it.

How a text watermark is actually planted

It is not a hidden character, a zero-width space or a Unicode trick, and anything telling you to strip invisible characters is describing a different problem. The mark lives in which words were chosen, which is why it survives copy-paste and why rewriting is the thing that ends it.

Planted by
Hashing the words so far against a secret key, then tilting the odds for the next word toward a hidden list.
Read by
Recomputing that list at every position and counting how often the text landed on it.
Survives
Copy, paste, reformatting, fonts, retyping by hand. The words are the carrier.
Broken by
Changing the words. Reordering resets everything computed after it.
Weakest on
Short and low-entropy text — a choice has to exist before it can be biased.
Files instead
Signed C2PA metadata, a separate mechanism that most re-encoding strips.
0 Public tools that can read it
0 Ways to opt out

What actually removes a Claude watermark

Anthropic says heavy editing or paraphrasing removes the signal. That is the only removal method anyone has confirmed, and it is worth understanding why the half-measures people try instead do nothing at all.

  1. 01

    Rewrite the sentences, do not polish them

    Swapping an adjective here and a connective there leaves most of the sequence intact, and the signal is spread across the whole of it. Removal is a function of how much of the text stopped being the model's choice — a light polish moves that number barely at all.

  2. 02

    Change the structure, not only the vocabulary

    The hash at each position is computed from the words before it, so splitting a sentence, merging two, or moving a clause earlier resets every position downstream. Structural edits are worth more per keystroke than synonyms are.

  3. 03

    Do not send the rewrite back through Claude

    A proofreading pass re-marks the output. Anthropic is explicit that asking Claude to improve your own writing produces marked text — the mark records that Claude touched the words, not that Claude thought of them.

  4. 04

    Stop stripping invisible characters

    Pasting through a plain-text editor, retyping the text, or running a zero-width-character remover accomplishes nothing here. Those tools address a different kind of watermark. This one is the word choice itself.

  5. 05

    Then check what can actually be checked

    Nobody outside Anthropic can read the mark today, so no tool can show you it is gone — ours included. What you can read is the statistical signature, which is a separate question with a public answer. Run the rewrite through the detector and see where it lands.

Two different kinds of evidence, often confused

A watermark and an AI detector answer different questions, and the loudest confusion of the past fortnight has been treating them as the same thing. Worth knowing which one is about to be used on your writing.

Measure Anthropic's watermark An AI detector
What it measuresWhether Claude produced the tokensWhether the text reads statistically like a model wrote it
Who can read itAnthropic, and whoever it grants accessAnyone, free, in about three seconds
Public tool todayNone releasedYes
Covers which modelsClaude only40+ models
Survives paraphrasingNo — Anthropic says editing removes itOften — 88% of paraphrased text still flagged
What a hit provesThe text may have been processed by ClaudeA statistical reading, weighed alongside everything else
Wrong about honest writingNot applicable — it is not a guess2.1% of the time, published

Watermark rows are from Anthropic's help centre article of 11 August 2026. Detector rows are from one blind 500-document run, March 2026 — the same set behind the figures on our accuracy page.

The questions people are actually asking

Rewrite the text. Anthropic's own documentation says heavy editing or paraphrasing removes the signal, and that is the only removal route anyone has confirmed. What does not work is anything that leaves the word sequence intact: retyping it, pasting it through a plain-text editor, changing the formatting, or running an invisible-character stripper. The mark is not hidden in the characters, it is in which words were chosen, so the words have to change.

It is real and it is documented by Anthropic rather than inferred by anyone else. Since 11 August 2026, models launched on or after 2 August 2026 apply the mark at launch, older models are being retrofitted, and it is applied worldwide rather than only in the EU. Files generated by Claude carry signed C2PA metadata instead, which is a separate mechanism.

No. There is no setting, on any plan, and Anthropic has not proposed one. It was rolled out globally rather than as a market-specific test.

Yes, and this is the part worth being angry about rather than the watermark itself. Anthropic states directly that a detected mark means the content may have been processed by Claude, not that Claude wrote it — proofreading, translation and cleanup all produce marked output. Whether an employer, editor or university will hold that distinction is a different question, and it is the reason people who wrote their own work are looking for this page.

Not today. Anthropic has not released a public detector, and no third party can build one without the key. If that changes, the tool will read the mark and nothing else — it will not tell you whether the ideas were yours, only whether the words passed through Claude at some point.

It can detect that text reads statistically like Claude output, which is a different claim and a much older one than the watermark. TheChecker.AI is trained on more than 40 models, Claude included. See the Claude detector page for what that report looks like. That reading is evidence, not proof, and it is wrong about honest writing 2.1% of the time.

A real rewrite changes the word sequence the mark is carried in, which is exactly what Anthropic describes as removing the signal — so in principle, yes. We will not put a number on it, because there is no public detector to measure against and anyone quoting you a removal percentage today is inventing it. What we will say is what the tool does: it rewrites, keeps your meaning, and hands the result to the detector so you can read the one signal that is publicly measurable.

No, and we would not build it that way. If you are somewhere that using a model is not permitted, rewriting the output does not change that, it only makes it harder to see. What this is for is writing you are entitled to submit that happens to have been drafted, translated or tidied with a model — which is most professional writing now, and which is the case the watermark cannot distinguish from ghostwriting.

Text watermarking has been an active research area at Google and OpenAI for years — Google's SynthID is the best-documented example. Anthropic is the one that has shipped it into general text output and said so. We have written separately about why transparency law keeps landing on text last.

Rewrite it in your own order, then read what is left.

Try it free on a paragraph. A free account adds 1,000 Humanizer words, no card, and the detector on the same account so you can check the one signal anybody can actually measure.

Rewrite a paragraph free

Credits by the word · detector included on the same account

No account for the demo. Sign up free for 1,000 Humanizer words, no card.

Rewrite a Claude paragraph free