A European labelling rule now applies to Claude output everywhere, and the mark follows any document Claude touches, not only the ones it drafts.
Anthropic has signed the EU AI Act’s Article 50(2) Code of Practice and will embed an invisible watermark in text produced by Claude models launched on or after August 2, 2026. Marking happens at the model level, so it applies through the API, the consumer app, Claude Code, Claude Cowork and Claude Tag, and through AWS, Google Cloud and Microsoft Foundry. Anthropic’s own support page says a detected mark means the text was processed by Claude, a category that includes proofreading, translation and summarising. The obligation to disclose that text when you publish it stays with you.
You send a client a 40-page report. You wrote it over three weeks. On the last day you pasted it into Claude to tighten the prose and fix the passive voice. Under Anthropic’s new marking system, that report now carries a machine-readable signal, and your client can check for it.
What Happened
Anthropic confirmed the change in a support article updated this week, first reported by TechCrunch on August 11. Claude models released in the EU on or after August 2, 2026 support machine-readable marking from launch. Generated text carries an embedded watermark. Generated files such as .svg, .png and .jpg carry signed provenance metadata under the C2PA standard.
Two details go further than the headline. First, coverage is global. Anthropic’s page states that marking applies to output from supported models wherever Claude is offered, worldwide, and that the watermark travels through copy and paste. Second, coverage is retroactive in ambition: Anthropic says it is working to add marking to models released before August 2, and the law gives it until December 2 to do so.
Anthropic also commits to helping third parties detect its marks, which the Code requires, with technical documentation still to come.
The Backstory
Article 50 of the EU AI Act sets four transparency duties. Two matter here. Article 50(2) tells providers of generative systems to mark synthetic output so machines can identify it. Article 50(4) tells deployers to label deepfakes and to disclose AI-generated text published to inform the public on matters of public interest.
The European Commission published the Code of Practice on Transparency of AI-Generated Content in June 2026. The Commission judged it adequate on July 8 and the AI Board followed on July 9, which turned adherence into the only EU-wide instrument formally assessed as sufficient to demonstrate compliance with Articles 50(2), (4) and (5). Final Guidelines landed on July 20. Companies had until 18:00 CEST on July 27 to make the published list of initial signatories.
Anthropic joined a group that includes Black Forest Labs, Google, Meta, Microsoft, OpenAI and Synthesia.
| Date | What changes |
|---|---|
| 2 August 2026 | Article 50 applies. New generative systems comply from day one, and Article 50(4) labelling duties start with no transition period. |
| 2 December 2026 | Systems already on the market before 2 August must bring Article 50(2) marking and detection into conformity. Content published before 2 August needs no retroactive marking. |
| 2 February 2027 | Providers must have a watermark-detection interoperability solution in place. |
The penalty sits in Article 99(4). A breach of Article 50 by a provider or deployer draws up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher. Small and medium enterprises pay the lower of the two figures. National market surveillance authorities enforce it.
The Plan
Anthropic runs two techniques. Text gets a statistical watermark woven into the tokens the model emits, invisible to a reader and, according to Anthropic, neutral to meaning and quality. Files get C2PA metadata that also flags tampering.
The company is candid about the gaps. A mark tells you Claude may have handled the text and nothing more. Absence of a mark proves nothing, because the text may come from an older model, or may have been paraphrased, translated, mixed into other writing, or cut too short to carry a reliable signal. File metadata dies on a screenshot or a format conversion.
The last line of the support page carries the commercial weight: builders should independently assess what Article 50 requires of their own products and services.
The Business Model Angle
Three things follow, and none of them are the ones in the headlines.
The mark labels the tool, not the author, and the law never asked for that. Article 50(2) carves out systems performing an assistive function for standard editing, such as grammar correction, and systems that do not substantially alter input data or its semantics. Your copy editor is exempt. Anthropic’s watermark is not, because a sampler-level watermark cannot tell whether Claude invented a sentence or repaired one. Anthropic writes this out plainly: output can carry a mark even when the underlying ideas, text or data came from somewhere else. The disclosure unit moves from “AI wrote this” to “AI touched this,” and the second category is enormous.
Anthropic globalised a European rule because one inference path costs less than two. Geofencing marked and unmarked output would mean residency detection, routing logic, VPN leakage and a compliance argument every time a Frankfurt employee of a Texas company calls the API. Shipping one marked pipeline is cheaper. So Brussels now sets the default disclosure regime for buyers in São Paulo, Lagos and Dallas who never voted on it, the same way GDPR set the world’s cookie banners. Marking follows Claude through AWS, Google Cloud and Microsoft Foundry, which closes the reseller escape hatch too.
The provider ships the evidence and the customer carries the liability. Article 50(4) binds deployers. Anthropic tells builders to assess their own exposure. That split lands hardest on businesses whose deliverable is assumed to be human work: agencies, translators, law firms, consultancies, ghostwriters, content shops. Their pricing has always rested on an unverifiable claim about process. Anthropic has now turned that claim into something a client can test, at the exact moment platforms are building the buttons. Substack wired Pangram into its reader experience on July 21, coined “Claudefishing” for undisclosed AI authorship, and Pangram raised $9 million led by Menlo Ventures on the back of it. We covered how AI detectors actually make money and why the institutional API tier, not the consumer scan, is the business.
The asymmetry is the point. A watermark tests suppliers who chose to be testable. It says nothing about anyone running open weights on their own hardware.
The Risk
Independent researchers have hammered text watermarking for two years, and the results are ugly.
The WaterPark benchmark tested 10 watermarking methods against 12 attack types across three language models and five datasets. Google’s SynthID-Text held a 99.8% detection rate on clean output and fell to 49.8% under moderate paraphrasing. One pass through a paraphrasing model dropped every scheme tested below 30%.

A July 2026 forensic evaluation went further. Meaning-preserving paraphrase eliminated detection in 100% of previously detected texts for two schemes and 98.3% for SynthID. The same study measured a 5.4% false positive rate on clean human text and concluded that all three methods fail at least two of the five Daubert factors US courts use to admit expert evidence.
Anthropic has not published its own method, so those numbers describe the field rather than Claude. The direction of travel is hard to argue with.
Now price the escape. A 1,000-word article runs roughly 1,350 tokens in and 1,350 out. Using the frontier rates we published in our tokenomics breakdown, around $5 per million input tokens and $25 per million output, one paraphrase pass costs about four cents. It has to run through an unmarked model to work, and unmarked models are the cheap ones. A 15 million euro statutory fine, a model-level compliance system and a venture-funded detection stack all sit on the wrong side of a four-cent laundering step.
Three consequences worth watching. Demand for unmarked inference rises, which pushes work toward open weights, pre-August models and non-signatory providers, so the regime taxes exactly the vendors who complied. Honest writers absorb the false positives, and a 5.4% error rate on clean text means roughly one clean document in eighteen gets flagged. And the signal cannot clear anyone, since Anthropic itself says absence of a mark proves nothing.
The counterweight deserves space. Provenance has real buyers. Regulated procurement in government, finance and healthcare will start asking whether a supply chain marks its output, and the February 2027 interoperability deadline gives that question a standard to point at. Peter Kafka’s line about the moment is the honest bull case: if AI wins, “made by humans” becomes a good business. Somebody has to build the plumbing that proves it, and signatories are building it first.
Quick Questions
Does the watermark apply outside Europe? Yes. Anthropic says marking applies wherever Claude is offered, worldwide, including through AWS, Google Cloud and Microsoft Foundry.
Will it mark text I wrote myself? If Claude processed it, yes. Anthropic’s documentation says output can carry a mark even when the ideas and text originated elsewhere, and names proofreading, translation and summarising as examples.
Can I remove it? Anthropic says the mark may survive some editing but not heavy paraphrasing, translation or mixing into other writing. Published research on comparable schemes suggests one paraphrase pass is enough.
Who gets fined? Providers and deployers, under Article 99(4), up to 15 million euros or 3% of worldwide annual turnover, whichever is higher. SMEs pay the lower of the two.
Does an unmarked document prove a human wrote it? No. Anthropic states this directly. Older models, short passages and edited text can all come back clean.
The Business Model Analyst Take
Anthropic did the reasonable thing and it produced a lopsided outcome. The marking regime is precise about the wrong variable: it records which vendor handled a file, not who did the thinking. It reaches the compliant and misses the evasive. It prices a new laundering step at pennies. And its own author warns you that a positive result is inconclusive and a negative result is meaningless.
Treat it as a procurement signal rather than an enforcement tool. The interesting question is not whether you get caught. It is what your next client contract says about AI-processed deliverables, because that clause is being drafted right now by people who just learned the check exists. Service businesses selling human judgment should write their own disclosure line before a buyer writes one for them, and price the judgment rather than the keystrokes. Anthropic, meanwhile, has quietly made “we mark our output” part of the enterprise pitch, which fits a company that has spent the past year selling trust as hard as it sells tokens, from its implementation joint venture to the valuation that came with it.
The scarce asset in this cycle keeps turning out to be verification rather than generation, as we argued about AI’s capability frontier. Watermarking is that argument arriving in the content business, and arriving broken.
