Claude watermark · updated 20 August 2026
Claude now marks
everything it writes.
Since 11 August 2026 Anthropic has embedded an invisible, machine-readable mark in text Claude generates. It is applied worldwide, there is no opt-out, and it travels with the words into your email or your document. Anthropic also states plainly what erases it: heavy editing or paraphrasing. That is the whole story, and the rest of this page is the detail underneath it.
No account needed. Sign up free for 1,000 Humanizer words, no card.
The announcement, without the headline noise
Four facts from Anthropic's own help centre article, which is a better source than any of the coverage written about it. Everything else on this page follows from these.
- Announced
- 11 Aug
- Where it applies
- Worldwide
- Which models
- Aug 2 +
- What a hit means
- Processed
2026, by Anthropic. Not a leak, not a rumour.
Not EU-only. No opt-out on any plan.
Marked at launch. Older models retrofitted.
May have been processed by Claude. Not written by it.
How a text watermark is actually planted
It is not a hidden character, a zero-width space or a Unicode trick, and anything telling you to strip invisible characters is describing a different problem. The mark lives in which words were chosen, which is why it survives copy-paste and why rewriting is the thing that ends it.
- Planted by
- Hashing the words so far against a secret key, then tilting the odds for the next word toward a hidden list.
- Read by
- Recomputing that list at every position and counting how often the text landed on it.
- Survives
- Copy, paste, reformatting, fonts, retyping by hand. The words are the carrier.
- Broken by
- Changing the words. Reordering resets everything computed after it.
- Weakest on
- Short and low-entropy text — a choice has to exist before it can be biased.
- Files instead
- Signed C2PA metadata, a separate mechanism that most re-encoding strips.
What actually removes a Claude watermark
Anthropic says heavy editing or paraphrasing removes the signal. That is the only removal method anyone has confirmed, and it is worth understanding why the half-measures people try instead do nothing at all.
-
01
Rewrite the sentences, do not polish them
Swapping an adjective here and a connective there leaves most of the sequence intact, and the signal is spread across the whole of it. Removal is a function of how much of the text stopped being the model's choice — a light polish moves that number barely at all.
-
02
Change the structure, not only the vocabulary
The hash at each position is computed from the words before it, so splitting a sentence, merging two, or moving a clause earlier resets every position downstream. Structural edits are worth more per keystroke than synonyms are.
-
03
Do not send the rewrite back through Claude
A proofreading pass re-marks the output. Anthropic is explicit that asking Claude to improve your own writing produces marked text — the mark records that Claude touched the words, not that Claude thought of them.
-
04
Stop stripping invisible characters
Pasting through a plain-text editor, retyping the text, or running a zero-width-character remover accomplishes nothing here. Those tools address a different kind of watermark. This one is the word choice itself.
-
05
Then check what can actually be checked
Nobody outside Anthropic can read the mark today, so no tool can show you it is gone — ours included. What you can read is the statistical signature, which is a separate question with a public answer. Run the rewrite through the detector and see where it lands.
Two different kinds of evidence, often confused
A watermark and an AI detector answer different questions, and the loudest confusion of the past fortnight has been treating them as the same thing. Worth knowing which one is about to be used on your writing.
| Measure | Anthropic's watermark | An AI detector |
|---|---|---|
| What it measures | Whether Claude produced the tokens | Whether the text reads statistically like a model wrote it |
| Who can read it | Anthropic, and whoever it grants access | Anyone, free, in about three seconds |
| Public tool today | None released | Yes |
| Covers which models | Claude only | 40+ models |
| Survives paraphrasing | No — Anthropic says editing removes it | Often — 88% of paraphrased text still flagged |
| What a hit proves | The text may have been processed by Claude | A statistical reading, weighed alongside everything else |
| Wrong about honest writing | Not applicable — it is not a guess | 2.1% of the time, published |
Watermark rows are from Anthropic's help centre article of 11 August 2026. Detector rows are from one blind 500-document run, March 2026 — the same set behind the figures on our accuracy page.
The questions people are actually asking
Rewrite the text. Anthropic's own documentation says heavy editing or paraphrasing removes the signal, and that is the only removal route anyone has confirmed. What does not work is anything that leaves the word sequence intact: retyping it, pasting it through a plain-text editor, changing the formatting, or running an invisible-character stripper. The mark is not hidden in the characters, it is in which words were chosen, so the words have to change.
It is real and it is documented by Anthropic rather than inferred by anyone else. Since 11 August 2026, models launched on or after 2 August 2026 apply the mark at launch, older models are being retrofitted, and it is applied worldwide rather than only in the EU. Files generated by Claude carry signed C2PA metadata instead, which is a separate mechanism.
No. There is no setting, on any plan, and Anthropic has not proposed one. It was rolled out globally rather than as a market-specific test.
Yes, and this is the part worth being angry about rather than the watermark itself. Anthropic states directly that a detected mark means the content may have been processed by Claude, not that Claude wrote it — proofreading, translation and cleanup all produce marked output. Whether an employer, editor or university will hold that distinction is a different question, and it is the reason people who wrote their own work are looking for this page.
Not today. Anthropic has not released a public detector, and no third party can build one without the key. If that changes, the tool will read the mark and nothing else — it will not tell you whether the ideas were yours, only whether the words passed through Claude at some point.
It can detect that text reads statistically like Claude output, which is a different claim and a much older one than the watermark. TheChecker.AI is trained on more than 40 models, Claude included. See the Claude detector page for what that report looks like. That reading is evidence, not proof, and it is wrong about honest writing 2.1% of the time.
A real rewrite changes the word sequence the mark is carried in, which is exactly what Anthropic describes as removing the signal — so in principle, yes. We will not put a number on it, because there is no public detector to measure against and anyone quoting you a removal percentage today is inventing it. What we will say is what the tool does: it rewrites, keeps your meaning, and hands the result to the detector so you can read the one signal that is publicly measurable.
No, and we would not build it that way. If you are somewhere that using a model is not permitted, rewriting the output does not change that, it only makes it harder to see. What this is for is writing you are entitled to submit that happens to have been drafted, translated or tidied with a model — which is most professional writing now, and which is the case the watermark cannot distinguish from ghostwriting.
Text watermarking has been an active research area at Google and OpenAI for years — Google's SynthID is the best-documented example. Anthropic is the one that has shipped it into general text output and said so. We have written separately about why transparency law keeps landing on text last.
Rewrite it in your own order, then read what is left.
Try it free on a paragraph. A free account adds 1,000 Humanizer words, no card, and the detector on the same account so you can check the one signal anybody can actually measure.
Credits by the word · detector included on the same account
No account for the demo. Sign up free for 1,000 Humanizer words, no card.
Rewrite a Claude paragraph free