Claude's generated text is now equipped with an "invisible watermark," and altering a few words may not necessarily remove it.
According to Dynamic Insight Beating monitoring, Anthropic has started adding a machine-readable "invisible watermark" to the text generated by Claude. Claude, Claude Code, Cowork, API, as well as models supported on AWS, Google Cloud, and Microsoft Foundry will be covered. The new models are immediately enabled, and existing models are being gradually added.
This change is primarily to comply with the transparency requirements of the EU's "AI Act," but Anthropic will enforce it globally. The watermark is directly embedded in the generated text of the model, not as additional metadata attached to the file, so it is retained even after copy and paste.
Anthropic has not yet disclosed the algorithm, but the official description is more akin to a statistical watermark like Google SynthID. It may not be a zero-width character steganography but rather a slight alteration of token selection probabilities during generation, leaving a detectable statistical signal across the entire text. The official mention that when the text is too short, there may not be sufficient signal, and significant rephrasing, translation, or mixing in of other content may also evade detection, which aligns with typical characteristics of statistical watermarks.
Therefore, simply changing a few words may not be effective; a significant rewrite is more likely to disrupt the watermark signal. Anthropic also cautions that detecting the watermark can only indicate that the text may have passed through Claude, but it cannot prove that the entire piece was written by Claude.