# Fact and source map

Checked 12 August 2026.

## Core correction

The feature is watermarking, not encryption.

- Encryption controls who can read data.
- A watermark adds a signal that may help identify origin or processing.
- Claude's announced text mark is embedded directly in generated text. Anthropic has not published the exact method. Supported files use signed provenance metadata.

## What is confirmed about Claude

**Confirmed by Anthropic's help page**

- Supported Claude models can embed an imperceptible mark in text.
- The text mark travels with exact copied text and may survive some editing.
- Supported files can carry signed Content Credentials.
- Models launched on or after 2 August 2026 support marking at launch.
- Anthropic is working to add marking to older models.
- Marking applies at model level across supported Claude products worldwide.
- Anthropic is working on detection access for users and third parties.
- Technical detection documentation is still forthcoming.
- A detected mark may show Claude processing. It does not establish full provenance or original authorship.
- No detected mark does not establish human authorship.

**Not confirmed**

- The exact text watermark method.
- Current false-positive and false-negative rates.
- The minimum reliable passage length.
- Which older models are marked today.
- Whether the mark can identify a user or account.
- Whether any institution has integrated the forthcoming detector.

Anthropic says users own outputs generated from their inputs, subject to its terms and restrictions. The watermark announcement did not transfer ownership to Anthropic or make Claude a co-author.

### Model date and product coverage

- The 2 August date refers to the model's launch date, not the date of a chat or API request.
- Claude Opus 4.8 launched on 28 May 2026 and Claude Fable 5 launched on 9 June 2026. Both therefore belong to the pre-2-August group.
- Pre-2-August does not mean permanently unmarked. Anthropic says it is working to add support to models released before the cut-off, but has not published a live model-by-model rollout list.
- A later update can affect future outputs from an older model. It cannot alter text already generated and saved. Previously saved text could only gain an intentional Claude mark if it is processed again by a marked model.
- Claude Opus 5 launched on 24 July 2026. It belongs to the pre-2-August transition group alongside Opus 4.8 and Fable 5.
- The same model-level rule applies across Claude, Claude Platform API, Claude Code, Claude Cowork and Claude Tag.
- Anthropic says supported models also mark through cloud partners including AWS, Google Cloud and Microsoft Foundry.
- A third-party interface is not an automatic bypass. If it returns supported Claude output without changing it, the mark can travel. Rewriting, translation, truncation, routing or other post-processing makes the final status less certain.

## EU law in plain words

- Article 50 transparency duties apply from 2 August 2026.
- Providers must add machine-readable marks to covered synthetic audio, image, video and text output where technically feasible.
- Pre-existing systems have a limited transition period until 2 December 2026 for the marking duty.
- The Commission's guidance lists source code, short strings, some machine-to-machine output and standard editing among exclusions or exceptions.
- Public-interest text with meaningful human review and editorial responsibility does not need the same visible deployer label.
- The voluntary Code of Practice is a recognised route for showing compliance. The law itself is mandatory.

### Disclosure in practical settings

- The provider's machine-marking duty is separate from the user's visible disclosure duty.
- In the EU, professional deployers of deepfake image, audio or video must disclose it clearly. AI-generated text published to inform the public on matters of public interest must also be disclosed unless it has meaningful human review or editorial control and a person or organisation accepts editorial responsibility.
- Ordinary AI help with a private email, an outline or routine editing does not by itself create the same Article 50 visible-label duty.
- No standard recipient-facing AI-writing disclosure control was found in the Gmail or Outlook drafting documentation checked. Where a workplace, client, profession or contract requires disclosure, it must be added manually.
- YouTube requires disclosure for meaningfully altered or synthetic realistic content, but expressly excludes production assistance such as AI-created scripts, outlines, titles and thumbnails. YouTube says disclosure alone does not limit audience or monetisation.
- Google Ads now offers an AI label setting for AI-generated or edited assets. It says visible overlays can appear for covered ads in the EU, India and New York.
- Meta says it labels ads created or significantly edited with its own generative tools and is extending detection to third-party origin indicators. Placement can vary by the type of edit and region.
- TikTok, YouTube and Meta have separate platform labelling systems for realistic synthetic media. These are not the same as a Claude text watermark.

## Company status

| Company | Confirmed marking now | Text status | Detection access | EU provider code |
|---|---|---|---|---|
| Anthropic | Text for supported new models; Content Credentials for supported files | New models from 2 Aug 2026; older models in progress | Public and third-party access announced, details pending | Signed |
| Google | SynthID across supported text, image, audio and video products | Gemini app and web text marked since 2024 | Current portal and Gemini checks cover media; reference text detector code is open source, but there is no public production Gemini text checker | Signed |
| OpenAI | C2PA plus SynthID on images; SynthID on supported audio; Sora origin signals on remaining API outputs during sunset | No public production ChatGPT text mark found | Public OpenAI image and audio verifier; some internal media tools | Signed |
| Meta | Visible labels, invisible marks and metadata on Meta AI images; platform reads origin data | No public Meta AI text mark found | Meta platform labels and research tools | Signed |
| Microsoft | Metadata on AI images; optional marks for some Microsoft 365 audio, video and images | No public Copilot text mark found | C2PA-compatible inspection and Microsoft controls | Signed |
| Adobe | Content Credentials on Firefly assets | Not a comparable general text model | Adobe Content Authenticity Inspect | Provider role varies by product |
| TikTok | Reads C2PA; creator labels; internal detection; invisible marks on supported content | Platform role, not a general text generator comparison | TikTok controls its platform labels | Not used here as a model-provider comparison |
| YouTube | Creator labels, C2PA and internal signals | Platform role, not a general text generator comparison | YouTube controls its platform labels | Not used here as a model-provider comparison |
| xAI / Grok | Visible Grok watermark on generated images and videos | No public Grok text mark found | Visible mark; no public invisible detector described | Not confirmed in the source checked |

Other named Section 1 signatories include Mistral, Cohere, Aleph Alpha, Black Forest Labs and Synthesia. Signing is not proof that every current product or content type is already marked.

## Media marking check

**Images**

- Google: supported generated images use invisible SynthID embedded in the pixels.
- OpenAI: images generated with ChatGPT, Codex and the API include invisible SynthID plus C2PA Content Credentials.
- Anthropic: supported generated files such as PNG, JPG and SVG can carry signed C2PA provenance metadata. Anthropic does not describe this as an invisible pixel watermark.
- xAI: its consumer FAQ says Grok Imagine images carry a visible Grok watermark. It does not describe an invisible image watermark.

**Video**

- Google: Veo outputs use SynthID embedded across video frames.
- OpenAI: its Sora documentation says generated videos carry visible and invisible provenance signals plus C2PA metadata. Sora web and app ended on 26 April 2026. The Sora API remains available only until 24 September 2026.
- Anthropic: Claude can create some animations itself through code, HTML artifacts and interactive visuals. Through providers such as HyperFrames by HeyGen and Adobe it can also assemble, render, animate or edit fuller videos. The final file's provenance marking depends on the tool that produces it. No native Claude video watermark is confirmed.
- xAI: its consumer FAQ says Grok Imagine videos carry a Grok watermark and there is no setting to remove it. It does not describe an invisible video method.

**Voice and audio**

- Google: supported generated audio, including Lyria and NotebookLM audio, uses inaudible SynthID.
- OpenAI: supported audio generated through ChatGPT and the API has used SynthID since 31 July 2026. OpenAI's verification tool checks supported audio.
- Anthropic: Claude Voice Mode provides spoken responses on the web, Claude Desktop and mobile. No watermark for that audio is publicly confirmed.
- xAI: Grok has voice products, but the public voice documentation checked does not say generated voice is watermarked.

**Practical conclusion**

It is reasonable to assume supported Google and OpenAI media outputs carry at least one origin signal. That assumption is too broad for Claude and Grok. A visible logo, C2PA file metadata and an embedded invisible watermark are different systems with different failure points.

## What the Reddit material establishes

The supplied file contains several live discussions. It establishes reaction and recurring questions, not technical truth.

Common reactions:

- fear that proofreading will be mistaken for AI authorship
- concern about quality changes, especially in code
- confusion between metadata, hidden characters and statistical text marks
- belief that another model or a local model can rewrite the signal away
- support for marks as a brake on spam and disinformation
- scepticism that bad actors will use compliant frontier models
- concern that private detectors will become tools for schools, employers and platforms
- jokes about Claude's repeated phrases already acting like a visible watermark

Claims rejected or qualified:

- “Every Claude output is marked now.” Not established.
- “Typing the same text removes it.” Incorrect for a word-choice watermark.
- “OpenAI already marks ChatGPT text.” No current primary evidence found.
- “The mark identifies the user's account.” Technically conceivable, but no evidence Anthropic does this.
- “Rewrite exactly 25 per cent and it is gone.” Method-specific research cannot be applied to Claude before technical details are published.
- “A mark proves AI authorship.” Anthropic explicitly says it does not.

## Accepted editorial view and supporting evidence

Piet's accepted view is that the central risk is not secret tracking. It is a narrow processing mark being treated as proof of authorship, with the burden shifted to the person accused. The evidence supports that concern with these boundaries:

- **Interpretation:** supported. Anthropic says a detected mark may mean Claude processed text and may appear after proofreading, translation, summarising or file conversion. It does not establish original authorship.
- **Quality:** correctly left open for Claude. Google's peer-reviewed SynthID Text research found no significant change in human quality ratings for its chosen non-distortionary configuration across approximately 20 million Gemini responses, while noting some reduction in inter-response diversity. This result cannot be transferred to Claude because Anthropic has not published its method, configuration or public independent evaluation.
- **Effectiveness:** supported with limits. Anthropic says heavy editing, paraphrasing, translation, mixing and short passages can prevent a detectable result. Research on generative text watermarks also records vulnerability to paraphrasing and scrubbing.
- **EU scope:** Article 50(2) excludes standard editing or changes that do not substantially alter the input or its meaning. Anthropic's statement that proofread or translated output may carry a mark appears broader than the legal minimum. This is an inference from the two public texts, because Anthropic has not published the exact implementation boundary.
- **Privacy:** no public evidence reviewed says the Claude mark encodes an account, identity, chat history or user-specific payload. “Model-level” describes where the mark is added and why it can appear across products. This is not proof that every conceivable identifier is technically impossible; it is a boundary on what Anthropic has disclosed.
- **Code:** Google's paper says detectability depends partly on text length and the entropy of the model's next-token distribution. Code can have fewer plausible next-token choices than prose, so different trade-offs are plausible. Anthropic has not published Claude-specific code tests.

### Embedded writing tools and the authorship problem

- Google documents that Gemini in Docs can draft, improve, edit and proofread text.
- Microsoft documents that Copilot in Word can rewrite selected human text and let the user accept a replacement.
- These facts do not establish that either product carries Claude's watermark. Google's public SynthID page names text from the Gemini app and web experience; no public Copilot text watermark was found in the Microsoft material checked.
- They do support the wider concern: AI editing is becoming an ordinary feature of the document itself. A detector that identifies model processing but cannot describe the degree of assistance should not be treated as proof of authorship.

The supplied NeurIPS paper, *Secret Collusion among AI Agents: Multi-Agent Deception via Steganography*, establishes that AI agents can use steganographic communication in designed multi-agent settings. It does not test Claude's provenance watermark and is not evidence that Anthropic's mark contains a covert message or enables agent coordination.

## Primary sources

- [Anthropic help page](https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content)
- [Anthropic release notes](https://support.claude.com/en/articles/12138966-release-notes)
- [Anthropic Claude Platform release notes](https://platform.claude.com/docs/en/release-notes/overview)
- [Anthropic: Claude Voice Mode](https://support.claude.com/en/articles/11101966-use-voice-mode)
- [Anthropic: HyperFrames by HeyGen connector](https://claude.com/connectors/hyperframes-heygen)
- [Anthropic: Adobe creativity connector](https://claude.com/connectors/adobe-creativity)
- [EU AI Act Service Desk: Article 50](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50)
- [EU Code of Practice overview](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content)
- [EU Article 50 questions and answers](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act)
- [EU Article 50 quick facts](https://digital-strategy.ec.europa.eu/en/factpages/quick-facts-transparency-rules-ai-systems)
- [EU guidelines](https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations)
- [EU signatories](https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content)
- [Google SynthID overview](https://deepmind.google/models/synthid/)
- [Google SynthID Text developer guide](https://ai.google.dev/responsible/docs/safeguards/synthid)
- [Google SynthID Text paper](https://www.nature.com/articles/s41586-024-08025-4)
- [Google: Gemini in Docs](https://support.google.com/docs/answer/15123226?hl=en)
- [Microsoft: rewrite text with Copilot in Word](https://support.microsoft.com/en-us/word/copilot/rewrite-text-with-copilot-in-word)
- [NeurIPS paper on secret collusion and AI steganography](https://proceedings.neurips.cc/paper_files/paper/2024/file/861f7dad098aec1c3560fb7add468d41-Paper-Conference.pdf)
- [OpenAI provenance announcement](https://openai.com/index/advancing-content-provenance/)
- [OpenAI image provenance help](https://help.openai.com/en/articles/8912793-c2pa-in-images)
- [OpenAI Sora origin signals](https://openai.com/index/creating-with-sora-safely/)
- [OpenAI Sora discontinuation](https://help.openai.com/en/articles/20001152-what-to-know-about-the-sora-discontinuation?is_listing=false)
- [xAI Grok consumer FAQ](https://docs.x.ai/grok/faq)
- [xAI voice overview](https://docs.x.ai/developers/model-capabilities/audio/voice)
- [Anthropic output ownership help](https://support.claude.com/en/articles/12326764-can-i-use-my-outputs-to-train-an-ai-model)
- [Meta AI image labelling](https://about.fb.com/news/2024/02/labeling-ai-generated-images-on-facebook-instagram-and-threads/)
- [Microsoft 365 AI watermarks](https://learn.microsoft.com/en-us/microsoft-365/copilot/watermarks)
- [Adobe Firefly Content Credentials](https://news.adobe.com/news/2025/02/firefly-web-app-commercially-safe)
- [TikTok AI labelling](https://newsroom.tiktok.com/more-ways-to-spot-shape-and-understand-ai-generated-content?lang=en-GB)
- [YouTube AI labels](https://blog.youtube/news-and-events/improving-ai-labels-viewers-creators/)
- [YouTube altered and synthetic content disclosure](https://support.google.com/youtube/answer/14328491)
- [Google Ads AI labels and disclosures](https://support.google.com/google-ads/answer/17140115)
- [Meta AI labels for ads](https://about.fb.com/news/2025/02/gen-ai-transparency-metas-ads-products/)
- [C2PA explainer](https://c2pa.org/specifications/specifications/2.2/explainer/Explainer.html)
- [NIST synthetic content transparency report](https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content)

## China: its national labelling system

China's system is not one provider's watermark and should not be described as a copy of Claude's approach. It is a national labelling framework for covered AI services and distribution platforms. The rules took effect on 1 September 2025 and cover text, images, audio, video and virtual scenes.

- Generating services add visible labels in the content or interface and hidden information to exported file metadata.
- Distribution platforms check metadata, accept user declarations and add visible notices for content that is confirmed, declared or suspected to be AI-generated.
- The required hidden record includes the AI-generated status, a provider name or code and a content number. Digital watermarks are encouraged, but this does not establish that every Chinese text model uses a Claude-style statistical word pattern.
- Hosted products and self-hosted open model weights are different cases. A service can add labels around a model without those labels being built into downloadable weights.

Primary product evidence checked for the streamlined summary:

- [China's official AI-generated content labelling rules](https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm)
- [Mandatory national standard GB 45438-2025](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=F32EA2A561F1886CD8D606513512D547&refer=outter)
- [DeepSeek terms](https://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html)
- [Kimi current terms](https://www.kimi.com/user/agreement/modelUse?version=v2)
- [Doubao terms](https://www.doubao.com/legal/terms)
- [Alibaba Model Studio FAQ](https://help.aliyun.com/zh/model-studio/faq-about-alibaba-cloud-model-studio)
- [Baidu Qianfan generated-content marking guide](https://cloud.baidu.com/doc/qianfan-docs/s/Xmf552dlk)
- [Zhipu platform terms](https://docs.bigmodel.cn/cn/terms/user-agreement)
- [Tencent Hunyuan image API](https://cloud.tencent.com/document/product/1668/120720)

## Research on limits and attacks

- [Revisiting the Robustness of Watermarking to Paraphrasing Attacks](https://aclanthology.org/2024.emnlp-main.1005/)
- [DualGuard: Watermark defence against paraphrasing and spoofing](https://aclanthology.org/2026.findings-acl.1169/)
- [On the Reliability of Watermarks for Large Language Models](https://arxiv.org/abs/2306.04634)
- [Discovering Clues of Spoofed LM Watermarks](https://arxiv.org/abs/2410.02693)
- [Image Watermarks are Removable using Controllable Regeneration from Clean Noise](https://proceedings.iclr.cc/paper_files/paper/2025/hash/d9750da8aec3b79cf14dd29e7ab6605a-Abstract-Conference.html)
- [Vanishing Watermarks: Diffusion-Based Image Editing Undermines Robust Invisible Watermarking](https://arxiv.org/abs/2602.20680)
- [Yours or Mine? Overwriting Attacks Against Neural Audio Watermarking](https://ojs.aaai.org/index.php/AAAI/article/view/39997)
- [Audio Pirates: Black-box Audio Watermark Removal via Diffusion Priors](https://arxiv.org/abs/2605.30614)

## Workaround conclusion

- It is already technically possible to weaken or remove some text, image and audio watermarks. This does not establish a universal removal method for Claude, SynthID or every deployed media mark.
- A public Claude detector would give removers a way to test candidate rewrites. That is likely to speed up evasion work, but access to a detector does not necessarily reveal the watermark key or guarantee success.
- C2PA file information is comparatively fragile because file conversion, re-saving or screenshots may strip it. Embedded word, pixel, frame and audio marks need different attacks.
- A future Claude-specific removal market is a prediction, not a confirmed current product capability.
