Anthropic watermarks every Claude output — and you can't opt out

Hidden marks ride on all Claude text since Aug 2, plus C2PA tags on files, driven by the EU AI Act. A detection API looms — but a 4-cent paraphrase strips it.

Nowline AUG 18 6:00 PM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • What's marked, and where

    Every Claude model shipped since Aug 2 weaves an invisible statistical watermark into its text and signs image files (.png/.jpg/.svg) with C2PA provenance metadata — across the app, the API, Claude Code, Cowork, and the AWS, Google Cloud and Microsoft Foundry endpoints. The text mark survives copy-paste.

  • No opt-out, not even on paid plans

    The mark is applied at the model level, so no product surface can switch it off — subscribers and API users are watermarked by default. The backlash was immediate, with some builders publicly canceling over it.

  • It only proves 'processed by Claude'

    A positive hit means text 'may have been processed by Claude,' not that Claude authored it — a probabilistic signal, not proof. Don't wire it into plagiarism gates or authorship enforcement.

  • A 4-cent paraphrase erases it

    A July forensic study (arXiv 2607.16010) stripped KGW and Unigram marks in a single paraphrase pass and removed SynthID-style marks 98.3% of the time — roughly four cents per rewrite. Heavy editing or translation kills the text mark; re-saving a file drops the C2PA tag entirely.

  • The detection API doubles as an evasion oracle

    Anthropic's promised public detector — required by the EU AI Act Article 50(2) code it signed — is also an attacker's tool: feed it paraphrases until it reports 'clean.' Transparency and evasion ship through the same endpoint.