TLDRocket
Sign in

Anthropic’s watermark survives copy-paste, but not the real dev workflow

The New Stack Amanda Caswell Covered by 4 sources

Anthropic is adding invisible watermarks to Claude text and code. They’ll survive copy-paste, but editing, translation and dev tools can wipe them out.

Based on reporting by The New Stack, Amanda Caswell — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Anthropic is putting invisible watermarks into text from newer Claude models, including output from its API, coding tools and cloud partners. The idea is simple: give developers another clue about where AI text or code may have come from. But Anthropic says the mark is not proof of origin, and that distinction matters more than the marketing gloss suggests.

The company says Claude models released in the EU on or after Aug. 2, 2026 will ship with machine-readable marking from day one, and it is working to backfill older models too. The marks will apply across supported Claude products worldwide, including Claude API, Claude Code, Claude Cowork and Claude Tag. Output from AWS, Google Cloud and Microsoft Foundry will also carry the watermark when those services use a supported model.

Anthropic is treating text and files differently. Text gets a hidden mark inside the words themselves. Supported images and graphics files, including SVGs, PNGs and JPGs, get a C2PA digital signature that can show Claude processed the asset and whether the metadata was altered. The company says the text mark can travel with copied and pasted content and may survive some editing. That’s useful. It’s also a fairly polite way of saying the signal is fragile.

The bigger problem is the places where Claude output actually goes. Anthropic hasn’t said how the watermark works, whether it uses KGW or a semantic approach, or whether it changes latency or inference costs. And in real workflows, text gets translated, summarized, split up, fed into other models, or mixed with database content. Code is even messier. Small edits can break it, so the room for watermark-friendly synonym swapping is limited, and Anthropic has not shown how well its mark survives a pull request, let alone an automated pipeline.

That’s the tension here: the watermark is aligned with the EU AI Act’s transparency push, but it is not provenance. Anthropic says a detected mark only means content may have been processed by Claude. A public detector could make the mark easier to integrate, and easier to defeat. For teams that actually need auditability, the sensible move is still boring old logging: model ID, prompt version, response time, hashes, and a record of edits. Fancy watermark, meet reality.

My take — AI-written commentary, not fact-checked reporting

This is the classic AI compliance move: useful on slides, brittle in the wild. Watermarks sound reassuring until someone paraphrases the text, translates it, or runs it through the same messy toolchain that made the output valuable in the first place. If provenance matters, logs beat vibes every time.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.