Claude Watermarks Everything It Writes Now. Does Fixing a Comma Count?

Person typing an email late at night, the everyday writing the Claude watermark now covers

ℹ️ Quick Answer: The Claude watermark is an invisible statistical pattern Anthropic now embeds in text from every Claude model released on or after August 2, 2026, worldwide, with no way to switch it off. A detected mark shows Claude may have processed the text, and that includes a light proofread, so it does not prove Claude wrote anything.

📋 WHAT’S INSIDE

  1. What Anthropic Actually Turned On
  2. Why a Grammar Fix Carries the Same Mark
  3. What a Detected Claude Watermark Proves
  4. The People It Catches Were Not the Ones Hiding
  5. Schools and Hiring Are Where This Gets Messy
  6. What to Do If You Use Claude on Your Own Writing
  7. The Honest Limitations

Last updated August 13, 2026

I type my own emails and I type them badly. I get the whole thing out, say what I actually mean, then hand it to Claude and ask it to fix the commas and break up the run-on sentences I know I just wrote. The thinking is mine. The typos were mine. Claude handled the punctuation.

As of this month, that email comes back with an invisible mark in it saying Claude was involved.

I should be straight about my own stake here. Claude helps me clean up this blog and it helps me find stories worth writing about, so I am not watching this one from the cheap seats.

What Anthropic Actually Turned On

Empty European Parliament auditorium in Brussels, where the AI Act transparency rule came from

Anthropic started putting machine-readable marks into Claude’s output on August 2, 2026. It covers every Claude model launched on or after that date, it follows you everywhere Claude works, and there is no setting to switch it off.

The rule behind it is Article 50 of the European Union’s AI Act, which took effect the same day. Providers of generative AI have to make their output detectable by machine, and missing that requirement can cost up to 15 million euros or 3% of global annual turnover. Anthropic signed the associated Code of Practice on Transparency of AI-Generated Content, alongside Google, Meta, Microsoft, OpenAI and roughly 190 other organizations by the end of July.

Nothing in that law required Anthropic to mark text outside Europe. It did it anyway. The marks apply worldwide across Claude, Claude Code, Claude Cowork, Claude Tag and the API, including when you reach Claude through AWS, Google Cloud or Microsoft Foundry.

Two different mechanisms are doing the work. Generated text gets an embedded watermark. Generated files like .png, .jpg and .svg get signed provenance metadata in the C2PA format, the same standard camera makers and publishers have been building around for years. Claude models released before August 2 carry nothing yet, and Anthropic says it is working backward to add them.

Why a Grammar Fix Carries the Same Mark

A hand marking corrections on a printed page with a red pen

When Claude proofreads something, it does not hand your sentence back with a comma slotted in. It writes the passage out fresh as its own output, so the mark goes into the whole thing no matter whose idea any of it was.

Nobody outside Anthropic knows the exact recipe. The company described what the mark does and stopped short of explaining how it makes it. The general approach has been sitting in research papers for years, though, and the most cited version is the green list method from John Kirchenbauer and his colleagues.

Here is the short version. When a model writes, it usually has several words that would work next. A secret key sorts those candidates into two groups and the model gets nudged toward one of them. Nothing is forced, the odds just tilt a little. Then the groups reshuffle for the next word. One nudged choice tells you nothing at all, but across a few hundred words that tilt piles up into a pattern a detector can measure against chance.

So it is not a hidden character or a weird invisible space, which is what a lot of people assumed on day one. Alex Cui, CTO of GPTZero, put it well: “There is no sequence to search for, no suspicious character to isolate.”

The part that matters for my email is what gets counted as Claude writing. Anthropic’s documentation says output “can carry a Claude mark even if the underlying ideas, text, or data originated from another source,” and it names proofreading, translation, summarizing and file conversion as exactly how that happens.

That is an editor lightly marking up a book and the book coming out with the editor’s name on the cover. The commas were theirs. The book was not.

What a Detected Claude Watermark Proves

A magnifying glass resting on a handwritten letter

It proves the text may have gone through Claude. Anthropic says that itself, in its own help documentation, and it is careful not to claim any more than that.

The exact wording is that a detected mark “provides a signal that content was processed by Claude, but is not fully conclusive.” Two reasons get listed underneath. Claude may not be the original author, because people use it constantly to proofread and translate and summarize. The other is that content often changes after Claude touches it, getting excerpted or mixed into other writing.

The reverse is just as soft. No mark does not mean no AI. The signal goes missing if the model predates August 2, or if the text got heavily edited or paraphrased or translated somewhere along the way. A short passage never gives the detector enough to work with. File metadata falls off completely when someone changes the format, re-saves, or simply takes a screenshot.

As of today, the detector does not exist. Anthropic says it will help users and third parties find its marks and will publish documentation, and none of that has shipped. Right now there is no tool you, your boss, or your kid’s teacher can actually run.

The People It Catches Were Not the Ones Hiding

The mark survives honest use and fades under the kind of rewriting somebody would do if they were covering their tracks.

Erick Erickson, the radio host and blogger, posted the version of this complaint that stuck. He had ditched Grammarly for Claude because Claude proofreads better, and now his own writing carries a mark saying Claude did the work. “This is ridiculous,” he wrote. He is describing my email.

Researchers have a name for the other side of it. Watermark stealing is the attack where you query a detector enough times to reconstruct the hidden rules, then use that to scrub a real mark or paste a convincing fake one onto writing that never came near the model. One report put the cost of stripping a mark at around four cents per rewriting pass, though that figure cannot be checked independently while Anthropic is still sitting on the detector and the spec. Treat it as a claim rather than a fact. The imbalance underneath it is real either way.

My honest take is that transparency around AI is fine. Most people are using it at this point, and if you are afraid of being transparent about that, AI probably is not the tool for you. People want to know, and I do not blame them one bit for wanting to know.

Where I get stuck is the granularity. If Claude wrote your essay, mark it. If Claude added a semicolon to an essay you wrote yourself, calling the result Claude-generated is a different claim, and it is not a true one. I manage engineers, and I have never cared whether someone wrote a function line by line or had AI help with it. Clean, shippable code is clean, shippable code, and how it got there is not my business. What I care about is whether the label on it is accurate, and “Claude may have processed this” covers so much ground that it barely says anything at all.

Schools and Hiring Are Where This Gets Messy

An empty classroom, where a detected mark is most likely to be misread as proof of cheating

A signal that says “maybe” is about to land inside institutions that have spent three years treating AI use as a yes-or-no question.

Dan Fitzpatrick, who works with schools and wrote about this for Forbes, laid out three students who all end up with the same mark. A multilingual kid writes an essay and uses Claude to improve the English. A student with additional learning needs asks it to make a paragraph clearer. A third follows the teacher’s own instruction to get AI feedback, accepts two suggestions, and submits. Same mark, three completely different situations, and plenty of school policies still treat AI assistance and academic misconduct as the same offense.

A 2023 study found AI text detectors were biased against writers using English as an additional language, flagging them as AI far more often than native speakers. Watermarking works differently, since the signal is deliberately planted rather than guessed at from writing style. The overconfidence problem is the same one, though.

Fitzpatrick’s suggestion is the right order of operations. Schools should write the rule before they get the detector. Is proofreading allowed? Translation? Feedback? Can a student accept a suggested sentence? Does AI use have to be declared? A found mark might justify a conversation, where a teacher asks for drafts and version history and has the student talk through their own argument. That is slower than pressing a button, and it is the only version that is fair.

What to Do If You Use Claude on Your Own Writing

Hands holding a stack of draft pages beside a typewriter

You cannot remove the mark and there is no setting for it, so the useful move is keeping evidence of how you actually work.

  • Keep version history switched on. Google Docs and Microsoft Word both save it automatically, and a draft timeline showing your sentences appear over two hours beats any detector result you will ever be handed.
  • Write your first pass somewhere that is not Claude. Get it down in your own document, then paste it in for the cleanup. That leaves a timestamped version of your own words that predates the AI entirely.
  • Say what you did when the stakes are real. One line on a cover letter or an assignment noting you used AI for grammar costs you nothing and takes the whole question off the table.
  • Know that files behave differently from text. C2PA metadata on an image falls off with a screenshot, a format conversion or a re-save, so its absence tells you very little.
  • If you are shipping code, the signal is weaker anyway. Research has found code hard to watermark, since it offers fewer harmless word choices than prose, and formatters and linters rewrite plenty of what is left.

The Honest Limitations

A lot of this is still unknown, and I would rather say so than pretend the picture is clearer than it is.

The detector is not public, so nobody knows who gets access, whether it returns a probability or a verdict, or what warnings sit beside the result. The method itself is unpublished, which means the green list explanation above is an educated guess built on the research Anthropic is most likely drawing from. The four-cent evasion figure is one report and cannot be verified yet. Older Claude models still carry nothing at all.

This stops being a Claude-only story fairly soon. Google has been running SynthID Text across nearly 20 million Gemini responses and published the results in Nature, reporting no meaningful drop in how users rated answer quality, although translation and heavy rewriting still weakened the signal. OpenAI signed the same EU code and already watermarks images, without announcing anything for text. Anthropic went first and is taking the reaction that comes with going first.

Can I turn off the Claude watermark?

No. Anthropic has not offered an opt-out, and the marking applies across Claude, Claude Code, Claude Cowork, Claude Tag and the API for every model released on or after August 2, 2026. It applies worldwide rather than only inside the EU.

Does the Claude watermark survive copy and paste?

Yes for text. Anthropic says the mark travels with the text when it is copied and pasted elsewhere. Files behave differently, because the C2PA metadata attached to an image or document can be stripped by a screenshot, a format conversion or a re-save.

Does a Claude watermark mean I cheated?

No. Anthropic’s own documentation says a detected mark shows content may have been processed by Claude, and that includes proofreading, translating or summarizing writing you did yourself. It is not evidence of who came up with the ideas, and there is no public detector for anyone to run yet.

Do ChatGPT and Gemini watermark text too?

Google runs SynthID Text on Gemini and has tested it across nearly 20 million responses. OpenAI signed the same EU transparency code and already watermarks images, though it has not announced text watermarking. Anthropic is the first major lab to apply text marks this broadly.


I will update this when Anthropic ships the detector, because that is the moment it stops being theoretical for schools and employers. For now the mark is sitting in the text and nobody outside Anthropic can read it.

Related reading: Readers rated AI stories higher than human fiction | Claude Opus 5 at half the price | Gemini in Classroom has no parent off switch | AI deception is getting harder to catch | New to AI? Start here

Want AI tips that actually work? 💡

Join readers learning to use AI in everyday life. One email when something good drops. No spam, ever.

We don’t spam! Read our privacy policy for more info.

WHO WROTE THIS

Moses Smith. I write Everyday AI for people who aren’t engineers. I go try the tools, then tell you honestly whether they were worth it. Sometimes the answer is no, and that’s kind of the point.

This blog is free and has no ads. If it saved you some time, you can buy me a coffee.

Leave a Reply

Your email address will not be published. Required fields are marked *