Analysis
Anthropic published additional technical detail this week on exactly how Claude's new text watermarking system works, according to TechCrunch -- a follow-up to the company's initial announcement four days earlier that it would begin watermarking AI-generated text globally.
The mechanism itself is straightforward to describe and hard to defeat: Anthropic embeds an imperceptible statistical pattern directly into generated text as it's produced. The pattern is invisible to a human reader, detectable by machines running Anthropic's own detection tooling, and designed to persist even after the text has been copied and pasted into a different document or platform -- addressing the most obvious way a simple watermark could otherwise be stripped. For generated files rather than raw text, Anthropic is using the C2PA open standard, the same content-provenance framework Google referenced when it separately began letting users remove visible watermarks from its own AI image generations this same week -- a genuinely different design choice from Anthropic's approach, which keeps the underlying provenance signal intact even when a user requests output without a visible mark.
The regulatory driver is specific: the EU AI Act's Transparency Code took effect August 2, requiring AI companies operating in Europe to mark AI-generated or AI-edited content in a way other systems can identify, with fines reaching up to €15 million or 3% of a company's total worldwide annual turnover, whichever is higher -- a penalty structure large enough to make compliance a board-level question for any AI company with meaningful EU revenue. Anthropic's watermarking now applies across the Claude consumer app, the Claude platform API, Claude Code, Claude Cowork and Claude Tag, and the company has said it will enable the system everywhere Claude is available, not just for EU-based users -- a global rollout that goes beyond what EU law strictly requires.
User reaction has been mixed since the initial announcement, with some Claude users objecting that watermarking will make it easier to catch AI-assisted work in academic or workplace settings where that use isn't authorized -- a genuine tension between transparency-as-compliance and transparency-as-surveillance-of-employees-and-students that Anthropic's technical detail doesn't resolve, since the same detection capability serves both purposes identically.
The test of whether this approach actually works at scale is adversarial: watermarking schemes that survive casual copy-paste don't necessarily survive deliberate paraphrasing tools built specifically to strip AI-provenance signals, and Pulse has separately tracked open-source projects on GitHub explicitly built for that purpose. Whether Anthropic's specific implementation holds up against dedicated stripping tools -- rather than just accidental removal through normal editing -- is the technical claim regulators and competitors will be testing hardest in the coming months.