News — On 14 August 2026, Anthropic published how the invisible watermark applied to Claude's text actually works: when the model picks between several words of equivalent meaning, the choice is no longer random but settled by a key, which makes the response identifiable after the fact without changing anything about how it reads (Anthropic, "How Claude's text watermarking works", 14 August 2026).

Close-up of a screen showing a block of text with certain words faintly highlighted

Until now, "was this written by an AI?" had no reliable answer. Commercial detectors get it wrong in both directions, accusing humans and clearing machines. Anthropic has changed that for its own model: from here on, what Claude writes carries a signature, and that signature travels with the text when it is copied elsewhere.

What Anthropic published

The principle is simpler than it sounds. A language model produces text one word at a time, and at each step it settles between several acceptable candidates. The watermark acts precisely there: instead of drawing randomly between equivalent candidates, Anthropic uses a key and the preceding words to decide which one comes out. The text stays natural, but it carries a recognisable statistical pattern. The company says it builds on the SynthID-Text approach published by Google DeepMind in Nature in 2024, and states that "watermarking does not impact the quality of Claude's output".

14 Aug Anthropic publishes the technical detail
2 Aug earlier models fall under an EU transition period
Global rolled out with no regional scoping at launch
API a detection tool is announced, not yet available

The timing is not accidental: Anthropic frames the move within its commitments under the EU AI Act, whose transparency obligations have applied since early August. We covered that text in the spring, when Article 50 imposed labelling of AI-generated content. The watermark is the engineering answer to that legal obligation. Anthropic also notes it is shipping the measure everywhere, for lack of a durable way to scope it to Europe.

On the file side, the logic mirrors what its competitor did: generated images and documents receive signed metadata, in line with what we saw when OpenAI adopted SynthID and the C2PA standard for its images. What is new here is the text.

What erases the watermark, and what leaves it intact

This is the part most write-ups skimmed, and the only part that matters to anyone producing content. Anthropic is explicit about where its watermark holds and where it gives way.

What you do with the textDoes the watermark survive?
Copy and paste it as isYes, it travels with the text
Light proofread, a few words changedYes, in most cases
Translation done by ClaudeYes, the model chooses every word
Heavily factual passage, constrained wordingWeakened: few choices available
Short textWeakened: too few decisions to carry a pattern
Source codeClose to none, sometimes in the comments
Full rewrite, every word replacedNo

That boundary is accidentally revealing: the watermark survives the token proofread and dies on the real rewrite. Put differently, it separates fairly precisely the content an AI produced and someone skimmed from the content an AI produced and a human genuinely rewrote. Anthropic was not trying to build a measure of editorial effort. That is nonetheless what it built.

No, Google is not going to penalise you for this

The panicked reading already circulating needs cutting short. Nothing in this announcement concerns Google rankings. The search engine's public position has not moved: Google does not penalise AI-generated content, it penalises bad content. An Anthropic watermark is not a ranking signal, and no statement suggests it will become one.

The real shift sits elsewhere, and it is contractual. Until now, the clause "original content written by a human" in an agency quote was unverifiable. It becomes verifiable: by your client, by a competitor, by a journalist, by a marketplace screening its sellers. This is not an SEO risk, it is a reputational and contractual one. It joins what was already visible in the study of 220 sites publishing AI content at scale: the problem was never the tool, it was always the absence of editorial work behind it.

What to do this week

First, reread your written commitments. If a client contract, an about page or a legal notice promises "100% human" content while your production chain uses a model, fix the wording now. A vague promise costs more than an admission of AI assistance.

Second, stop paying for cosmetic editing. The table above states exactly what a light correction pass is worth: it transforms nothing, and now it hides nothing either. If you buy writing, the unit of value is not the correction, it is the rewrite with something of your own added: data, field experience, a point of view.

Third, lean on what no model can produce alone. It is the same lever that keeps a site present in AI answers: lived experience, numbers only you hold, a position you are willing to defend. We developed this around the E-E-A-T trust score applied to AI content.

Does your content hold up against AI?

We analyse for free how visible you actually are in ChatGPT, Perplexity and Google answers, and how editorially solid your pages are.

The limits of this reading

The detection tool does not exist publicly yet. Anthropic announces a detection API whose terms are not settled. Until it opens, nobody on the outside can verify anything. We are describing an announced capability, not an available one.

The watermark only covers Claude. Text produced by ChatGPT, Gemini or an open model run locally carries no such signature. The absence of a watermark therefore proves nothing at all. The mechanism can incriminate; it cannot exonerate. That asymmetry is worth repeating every time someone waves a detection result around.

No reliability rate is public. Anthropic describes situations where the signal weakens, without publishing a minimum length threshold or a false-positive rate. Any numerical claim about the accuracy of this detection is, at this stage, an invention.

This article does not cover circumvention. That a full rewrite removes the pattern is a technical fact documented by Anthropic, not a method we recommend or detail.

Frequently asked questions

How does Claude's text watermark work?

When Claude picks between several words of equivalent meaning, the choice is no longer random: it is settled by a key and the words that come before. The resulting pattern stays invisible to a reader but can be recovered afterwards. Anthropic says it builds on the SynthID-Text approach published by Google DeepMind in Nature in 2024.

Does the watermark survive editing?

Anthropic states that light editing generally preserves the watermark, and that a complete rewrite in which every word is replaced removes it. The signal is also weaker in short texts, in heavily factual passages where word choice is constrained, and close to absent in code.

Will Google penalise content carrying an AI watermark?

Nothing suggests it will. Google's public position remains that AI-generated content is not penalised as such, only bad content is. Anthropic's watermark is a transparency measure tied to the EU AI Act, not a ranking signal announced by Google.

The Cicéro take

This watermark will be sold as a threat to anyone producing content with AI. It is the opposite. It does not separate AI from human: it separates the text someone let through untouched from the text someone actually reworked. That is the line we have defended from the start.

The only content that gets uncomfortable this week is the content nobody ever rewrote. It was already bad before it became detectable; it will simply be harder to defend.

Sources

  • Anthropic (official announcement): "How Claude's text watermarking works": key-based selection mechanism, rollout scope, documented limitations and the announcement of a detection API, 14 August 2026.
  • TechCrunch: detailed coverage of the announcement, the conditions under which the watermark survives editing, and the absence of meaningful watermarking in code, 15 August 2026.
  • TechCrunch: initial announcement of the measure and its link to the transparency obligations of the EU AI Act, 11 August 2026.
Alexis Dollé, founder of Cicéro
Alexis Dollé
CEO & Founder

Growth and SEO & GEO content strategist, I founded Cicéro to help businesses build lasting organic visibility — on Google and in AI-generated answers alike. Every piece of content we produce is designed to convert, not just to exist.

LinkedIn