Anthropic updated its help page, and technology media around the world have been quoting it since. The content is short. Claude models released on or after 2 August 2026 weave an invisible watermark into the text they generate. Generated files get signed provenance metadata. Marking covers every product: the API, the Claude app, Claude Code, Claude Cowork and Claude Tag. And it applies wherever Claude is available, not only in the European Union.

There is one stated reason: Article 50 of the AI Act. Anthropic signed the EU Code of Practice on transparency of AI-generated content, and has now started implementing it.

This is the first move on this scale by a major model provider since 2 August. Most of the conclusions the headlines draw from it are wrong. The real ones affect your company more than they appear to.

The short version

Anthropic is introducing two layers of marking: an invisible watermark in text, and signed C2PA metadata in files. The watermark survives copy-paste and some editing. File metadata usually does not survive format conversion or a screenshot.

Anthropic states plainly that a detected mark is not conclusive proof, and that its absence does not mean the content was produced without AI.

The most important sentence in the whole document is about companies, not the model: if you deploy Claude in your own product, you have to assess for yourself what Article 50 requires of you. The provider's watermark does not discharge your own disclosure obligation.

“A detected mark provides a signal that content was processed by Claude, but is not fully conclusive. Lack of a detected mark doesn't mean the content wasn't AI-generated or processed.”

Anthropic, How Claude marks AI-generated content

What Anthropic actually announced

Three things, all from the official Anthropic help page.

Models released on or after 2 August 2026 carry marking from day one. Older models - including the ones most companies use today - are still being retrofitted. The AI Act allows a transitional period for this, and Anthropic says it is working on it and will update the document when the work is done.

Marking operates at the model level. That matters technically, because it means you cannot bypass it by changing interface. Text comes out marked from the API just as it does from the chat window, and through AWS, Google Cloud and Microsoft Foundry.

Anthropic committed to making detection tooling available to third parties, not only to itself. The Code of Practice requires this, and it is the point that changes practice the most: detection is meant to be available to platforms, publishers, buyers and universities, rather than locked inside the provider.

How it works: two layers, two different weaknesses

The first layer is a watermark in the text. While generating, the model gently shifts the statistical distribution of its word choices in a way an algorithm can read back later. A human cannot see it. Anthropic says it does not affect the meaning or quality of the answer. Because the mark is part of the text itself, it travels with it through copy-paste and survives some editing.

The second layer is file metadata. When generating a file in .svg, .png or .jpg format, Claude attaches cryptographically signed provenance information under the C2PA standard. It is the same open standard the rest of the industry uses. The signature lets you check not only that a file passed through Claude, but also whether anyone tampered with the metadata.

The two layers break in different ways. File metadata disappears on format conversion, re-saving and screenshots. One screenshot and the signature is gone. The text watermark is more robust in transit, but weakens under heavy rewriting, translation and blending into someone else's text. In a short excerpt there is simply not enough signal to read.

The Code of Practice assumes outright that no single method is reliable enough today, which is why signatories are expected to apply at least two in parallel in most cases.

What the mark does not prove

This is where the headlines need cooling down, because "the end of anonymous AI" is already circulating. Anthropic lists the limitations itself, and does so more honestly than most commentators.

A detected mark says the content probably passed through Claude. It does not say who wrote it. People use models to proofread, translate, summarise and convert files. A human-written text pasted into a model to fix its punctuation can come out marked. "A watermark was detected" therefore does not mean "a machine wrote this".

The reverse holds too. The absence of a mark does not prove the content is human. It may have come from an older model, from a different provider, or been rewritten heavily enough for the signal to fall apart.

The practical consequence: if your organisation assesses other people's texts, coursework, bids or applications, a detector result cannot be the verdict. That principle belongs in your internal rules now, before the first dispute arrives. Because it will.

Where Article 50 came from, and why it looks the way it does

The EU separated two different problems and assigned them to two different parties. This distinction is the most commonly confused and the most expensive to get wrong.

Article 50(2) covers machine-readable marking. The obligation sits with the provider of the generative system. The mark has to be machine-readable - a watermark or metadata, not a caption under an image. The point is the hygiene of the whole information ecosystem: so that platforms, search engines and verification tools can tell synthetic content from the rest at all. For systems already on the market before 2 August 2026, this obligation starts to apply on 2 December 2026.

Article 50(4) covers disclosure visible to a human. The obligation sits with the deployer - the company publishing the material. It covers deepfakes and texts published to inform the public about matters of public interest. This obligation was not postponed. It has applied since 2 August 2026, unchanged.

The machine layer and the visible layer are two separate obligations, usually on two different parties. Anthropic does its part. Your company has its own.

The Code of Practice: why the large providers agreed

In June 2026 the European Commission published the Code of Practice on Transparency of AI-generated Content. By the end of July, around 190 organisations had signed it, roughly half of them small and young companies. The Commission and the AI Board recognised the Code as an adequate way of demonstrating compliance with Article 50.

For signatories, supervision focuses on checking adherence to the Code rather than on proving compliance from scratch. Those who did not sign have to demonstrate it by other means and expect more frequent requests for information. That is a fairly strong incentive.

The Code has two sections. The first is for providers, on marking and detection. The second is for deployers, on visible labelling of deepfakes and of texts in the public interest. Anthropic signed the Code in both roles: as a model provider and as a system provider.

An ordinary company that deploys generative AI can sign it too. It is not reserved for Silicon Valley labs.

What follows for a company in Poland

Three things, in order.

First, your obligation does not disappear because a provider did something. Anthropic states it plainly in the document: if you deploy Claude in your product, assess for yourself what Article 50 requires of you. A watermark in the text is not a label for the reader. It does not satisfy the duty to disclose a deepfake in an advertisement, nor the duty to tell a customer they are talking to a bot.

Second, the definition of a deepfake is broader than most companies assume. After the Commission's May guidance, the content does not have to depict a real existing person or object. It is enough that it resembles something realistic. Lawyers cite examples that occur in marketing every day: a generated tomato in a promotional leaflet, a flat visualisation with furniture painted in, a voice-over from a synthetic voice. A drawing of a dragon needs no label, because dragons do not exist. A realistic product photo from a generator is a different category.

Third, supervision in Poland is materialising right now. The main body of the Act on artificial intelligence systems entered into force today, 11 August 2026. The chair of KRiBSI is due to be appointed in October and the full Commission in November, while the rules on proceedings and penalties start to apply on 28 October. The obligations themselves, however, follow directly from the EU regulation and exist regardless of whether the authority is operating yet. Breaches from before November will not disappear when the Commission is appointed.

The real change is operational, not legal

A watermark is not an AI detector and will not close the subject of concealment. It changes something else, less spectacular and more inconvenient: the default assumption that nobody will check stops working.

For three years companies operated in an environment where "did AI write this" had no good answer, so practically nobody asked. Now the infrastructure for asking is being built at the model level, globally, at the largest providers, with detection tooling made available externally. It will not be perfect. It will be good enough for someone to ask.

The risk companies think about least has nothing to do with an administrative fine. Picture an agency handing a client a report described as "prepared by our analysts". Or a candidate submitting a recruitment task. Or a tender bid containing a description of methodology. All of those texts leave the organisation and may end up under a checking tool. The problem then is not the AI Act. The problem is the contract, the trust, and the fact that nobody in the company established what is allowed.

This is exactly the situation we wrote about in the context of the AI system register. The company does not know who uses what, so it does not know what leaves it.

Why the answer is competence, not prohibition

The first reflex after news like this tends to be simple: let us block AI. That is the worst available option, and we have been through it with the cloud, with messaging apps and with personal phones. A ban does not eliminate the tool, it moves it out of sight. Shadow AI appears: an employee pastes client data into a free chatbot on a personal account, because the company offers nothing they could legally use instead.

If not a ban, then what. What remains is the only thing that actually works at scale: people knowing what they are doing.

That is, incidentally, the substance of Article 4 of the AI Act, in force since 2 February 2025. Providers and deployers are to take measures supporting the development of AI literacy among their staff. The Digital Omnibus softened the wording from guaranteeing a level of knowledge to acting diligently, but it removed nothing and postponed nothing. It changed how compliance is assessed, not whether the duty exists.

The thing is, even if Article 4 did not exist, the same conclusion follows from a plain risk calculation. An employee who understands that text from a model may carry a watermark, that file metadata dies in a screenshot, and that publishing a realistic visualisation without a label is their employer's obligation, simply makes better decisions. Not because they fear a penalty. Because they know.

Rules without training are a document nobody read. Training without documentation is an event you cannot evidence. You need both.

What to do this week

You do not need an implementation project. You need a review that takes a few hours.

  1. Check which models your teams actually use, and in which versions. Marking covers models released from 2 August onward, older ones are being retrofitted, so the picture will keep changing.
  2. Review the past few months of marketing material for realistic imagery, video and voice-overs. After the Commission's May guidance the threshold is lower than you probably assumed.
  3. Establish who holds editorial responsibility for texts published on your site and social media. That is the only route to disapplying the labelling duty for informational texts.
  4. Add one line to your internal rules stating that an AI detector result is not evidence in itself. It will earn its keep at the first dispute, internal or with a counterparty.
  5. Check your contracts with AI tool vendors. Who is responsible for machine-readable marking, and what happens if it turns out the tool does not do it.
  6. Remind your teams what must not be pasted into models. Personal data, trade secrets, material under NDA. Content marking changes nothing here, but a conversation about marking is a good opening to say it.
  7. Start a training register if you do not have one. It is the cheapest evidence of due diligence there is.

Points 1, 2 and 6 usually stall in the same place: nobody in the company knows how many AI tools the teams really use. If that is your situation, start with an inventory rather than a policy.

Frequently asked questions

Does every Claude output now carry a watermark?

Not every one. Marking applies to models released on or after 2 August 2026. Anthropic is still adding support to older models under the transitional period the AI Act allows, and has not given a completion date.

Can the watermark be removed?

Anthropic has not published the technical details, so this cannot be verified independently. From the description, the watermark survives copying and some editing, but weakens under heavy rewriting, translation and blending into other text. A short excerpt may simply not carry enough signal to read. File metadata is lost on format conversion, re-saving and screenshots.

Does a detected watermark prove the text was written by AI?

No. Anthropic notes that the mark only indicates the content may have been processed by Claude. The model may only have corrected, translated or summarised it, and a human may be the author. The absence of a mark settles nothing either.

If Claude marks its content, does my company still have to label anything?

Yes. These are two different obligations. Machine-readable marking sits with the provider of the system; visible disclosure of deepfakes and of texts published to inform the public sits with the deployer, meaning the company publishing the material. Anthropic states explicitly that if you deploy Claude in your own product, you must assess the Article 50 requirements yourself.

Does this only apply in the European Union?

No. The source provision is Article 50 of the AI Act, but Anthropic chose to apply marking wherever Claude is offered, including outside the EU, and across its products: the API, the Claude app, Claude Code, Claude Cowork and Claude Tag, as well as through AWS, Google Cloud and Microsoft Foundry.

Will other providers do the same?

By the end of July, around 190 organisations had signed the Code of Practice on Transparency of AI-generated Content. Signatories committed to marking and to supporting detection. Anthropic announced its rollout among the first, but the commitment covers everyone who signed.

Did the Digital Omnibus postpone the content-marking obligation?

Partly. What moved was machine-readable marking for systems already on the market before 2 August 2026, with a deadline of 2 December 2026. The disclosure obligation on deployers - labelling deepfakes and texts published in the public interest - took effect on 2 August 2026 unchanged.

Is AI literacy training still mandatory?

Yes. Article 4 of the AI Act has applied since 2 February 2025. The Digital Omnibus softened its wording, replacing the duty to ensure an adequate level of competence with a duty to take measures supporting its development. It removed nothing and postponed nothing. Documented training remains the simplest way to show the organisation meets that duty with due diligence.

How AI TrustCERT helps

This whole matter comes down to one thing: people in your organisation make decisions about what to generate, where to publish it and whether to label it. Daily, usually in a hurry and without consulting the legal team. No provider's watermark settles that for them.

The AI TrustCERT training programme covers AI literacy, AI risk management and AI governance. Each course ends with an exam and a certificate for the participant, and the employer receives a completion record - a document that supports meeting the Article 4 duty and builds evidence of due diligence. The certificate is not a guarantee of AI Act compliance and does not replace legal analysis.

The same training licence includes a platform for documenting compliance: a register of the AI tools in use, ready-made policies to adopt, risk assessment and an incident reporting path. Going live takes 1-7 days. Courses cost 1,395 PLN net per person per year, and the package from 10 people with the platform included starts at 13,950 PLN net per year. Details are on the pricing page.

If you would rather first see where you stand, start with the free AI Ready Check. Three minutes, no commitment.

In summary

Anthropic did not build an AI detector, and says so itself. It built a signal: imperfect, partly removable, but woven into the model, operating globally, with detection tooling promised for third parties.

The conclusion for companies is not "AI will be detected". It is: the era in which you could assume nobody would check is over. Which means decisions about where and how to use AI have to be made deliberately, across the whole team, and leave a trace behind them.

A company that can say today which AI tools its people use, who is responsible for published content and when it needs labelling, is in an entirely different place from one waiting for guidance.

Sources

  1. Anthropic - How Claude marks AI-generated content, Claude Help Center: support.claude.com
  2. Regulation (EU) 2024/1689 (AI Act) - Article 3 (definitions of roles), Article 4 (AI literacy) and Article 50 (transparency)
  3. European Commission - Strong backing for the Code of Practice on Transparency of AI-generated Content, July 2026: digital-strategy.ec.europa.eu
  4. European Commission - Signing the Code of Practice on Transparency of AI-generated Content (FAQ): digital-strategy.ec.europa.eu
  5. Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003): dziennikustaw.gov.pl

This article was written with the help of artificial intelligence and reviewed before publication by the author, who takes editorial responsibility for it.