Does Claude Watermark Its Text? What Anthropic Says, and What It Does Not Prove
Updated September 2026
Anthropic answered this one in writing. Its help center describes two mechanisms: an imperceptible watermark applied to the text itself, and C2PA Content Credentials on files Claude produces. The details matter, because they decide what a cleaning tool can honestly do.
Quick answer
What Anthropic's help center says, in short:
- 1Text watermarks are applied at the model level for Claude models launched on or after August 2, 2026. Older models are in transition. Coverage is worldwide, across the API, the Claude apps, Claude Code and related surfaces.
- 2The mark is imperceptible, survives copy and paste, and is weakened by paraphrase, translation, heavy editing and very short outputs.
- 3Supported files such as PNG, JPEG and SVG get C2PA Content Credentials.
- 4A detected mark means the content may have been processed by Claude. No mark does not mean human-only.
- 5Third-party detection was described as forthcoming.
Summarized from Anthropic's help center. Policies change; read the current article for the authoritative version.
Two mechanisms, not one
| Mechanism | Where it lives | What Anthropic says | Removable? |
|---|---|---|---|
| Embedded text watermark | In the words, chosen token by token | Model-level, imperceptible, survives copy and paste, weakened by rewriting and short length | Not by any character or metadata tool. Only rewriting changes it. |
| C2PA Content Credentials | In the file container around the content | Attached to supported outputs such as PNG, JPEG, SVG | Yes. StripShot removes C2PA from images and documents at the binary level. |
The second row is old news for StripShot users: it is the same signed manifest that Instagram and LinkedIn read to label AI images, and it comes off the same way. The first row is what changed in 2026, and it deserves a careful reading.
What a model-level mark most likely is
Anthropic has not published the algorithm, so anything more specific is inference. The public description, imperceptible and surviving copy and paste but weakened by paraphrase, matches the statistical token-sampling class: the model is nudged toward a keyed subset of word choices at each step, and a detector with the key counts how often the text landed on that subset. Google's SynthID-Text is the published example of the same idea. It is not a hidden character, not a formatting trick, and not something a reader or a code-point scanner can see.
What it does and does not prove
- A mark is not authorship. Anthropic's own caveat: the text may have been processed by Claude. Ask Claude to fix the commas in your essay and your essay can carry the mark.
- No mark is not innocence. Older models, heavy edits, short outputs and other vendors' models all produce unmarked text.
- Nobody outside Anthropic can check yet. Until a detection API ships, a service that claims to detect Claude watermarks is reading style, not the mark.
- Disclosure rules stand regardless. The EU AI Act's machine-readable disclosure obligations took effect in August 2026 and apply to providers and deployers whether or not a mark survives.
What StripShot does with Claude output
Files: C2PA, XMP and document properties are stripped and the result is re-scanned. Text: invisible characters, odd spaces and look-alike letters are removed and listed, and the writing-tells panel shows the phrases that read as generated. StripShot never rewrites text, never sends it to a model, and never tells you a statistical mark is gone, because it has no way to know and neither does anyone else without the key.
Why hidden characters still matter here
Even though Anthropic's mark is not a hidden character, text that passes through chat interfaces, web pages and word processors picks up non-breaking spaces, directional marks and the occasional zero-width character. Those break search, matching and code, and a deliberate pattern of them can fingerprint a document regardless of which model wrote it. Scanning for them is worth doing on any text you did not type yourself, and it is the part of the problem that can be solved with certainty.
Check your text
Find hidden characters and writing tells, no model involved
Runs in your browser. Nothing is uploaded.
Options
Need unlimited strips?
Scans are free. Pro is unlimited.
Images, video, audio, documents, PDF and text in one tool. Pro adds unlimited strips, whole-folder batches and zip download with a JSON report.
Frequently asked questions
Does Claude watermark text?
According to Anthropic's help center article on how Claude marks AI-generated content, yes for models launched on or after August 2, 2026, with older models described as in transition. The mark is applied at the model level, is described as imperceptible, and survives copy and paste. Anthropic has not published the algorithm.
Does Claude add C2PA to files?
Anthropic says Content Credentials are attached to supported file types such as PNG, JPEG and SVG that Claude produces. Those are file-level metadata and are removed by any competent metadata tool, including StripShot.
Can I detect a Claude watermark myself?
Not today. Anthropic described third-party detection as forthcoming. Until a detection API exists, nobody outside Anthropic can score text for the mark, and no public tool that claims to is doing anything but guessing from style.
If text has no mark, does that prove a person wrote it?
No. Anthropic's own caveats say a missing mark does not mean human-only origin, and that a detected mark means the content may have been processed by Claude, which includes proofreading or translating something a person wrote.
Can StripShot remove a Claude text watermark?
No, and it does not claim to. A model-level mark lives in word choice. StripShot removes character-level carriers and file metadata, both of which are verifiable, and shows writing tells so you can edit. It does not rewrite text.