Treat a Claude watermark result as evidence of possible model involvement, never as proof of authorship, dishonesty or inaccurate content.
Anthropic has not released its detection API or published operating thresholds, false-positive rates or results from independent testing. Older Claude models are still being updated, so coverage will vary during the rollout.
Public detector documentation showing validated error rates across short text, factual writing, proofreading, translation and mixed human-AI drafts, plus a clear process for interpreting and challenging results.
Claude Text Watermarks: What They Can Actually Prove
Claude’s text watermark can indicate that the model selected enough words in a passage to leave a detectable statistical pattern. It cannot identify the user, prove who wrote the document, show how much work Claude did or confirm that the content is true. Those limits should govern any decision based on a detection result.
I was recently asked to inspect a CV for an Anthropic or Claude watermark.
The request sounded straightforward. It wasn’t.
Anthropic announced on 14 August 2026 that future Claude models will generate text containing an invisible watermark. The company is also working to add it to older models over the coming months.
There is currently no public Claude watermark detector. Even once Anthropic releases its planned detection API, a positive result will answer a narrow question:
How likely is it that Claude helped produce this passage?
It won’t establish who wrote the document, how much work Claude did or whether its contents are true.
Those limits matter for CVs, student work, reports and any other document where someone may be tempted to turn a probability score into a verdict.

What has Anthropic announced about Claude watermarks?
According to Anthropic’s explanation of Claude text watermarking, future Claude models will use a version of Google DeepMind’s SynthID-Text method. Older models launched before 2 August 2026 have a transition period, and Anthropic says it will add watermarking to them over the coming months.
The change is linked to Article 50 of the EU AI Act and the Code of Practice on Transparency of AI-Generated Content. Anthropic says it plans to apply the watermark globally because it currently lacks a lasting way to limit it by region.
Anthropic says the watermark:
This is different from adding metadata to a Word document or placing a visible mark over an image.
- Is invisible to readers.
- Adds no hidden characters to the text.
- Contains no personal, account or chat information.
- Requires no extra tokens.
- Has a negligible effect on speed and no practical effect on output quality.
How does Claude watermark text?
Language models generate responses by choosing one token at a time. A token can be a word, part of a word or a character.
Sometimes there is one clear choice. A factual answer, mathematical result or piece of working code may allow little variation.
Other passages give the model several reasonable options. It might choose “grey” instead of “overcast”, for example, without changing the meaning.
Claude’s watermark changes the source of randomness used to make those low-stakes choices. Across a long passage, the choices form a statistical pattern that can be checked using Anthropic’s key.
Nothing is added after the text is generated. The pattern sits within the sequence of words Claude selected. A detector can compare the passage with the expected pattern and return a probability that Claude was involved.
Google DeepMind’s technical explanation of SynthID-Text describes the same basic process: the system adjusts token probabilities during generation and later compares the resulting pattern with expected watermarked and unwatermarked text.
What can a Claude watermark prove?
A detected watermark can indicate that Claude probably selected some of the words in a passage.
That is the limit.
It cannot establish:
It also says nothing about ownership or legal responsibility. Anthropic says the watermark does not change a user’s rights under its terms.
Anthropic describes its detector as answering a question closer to “What is the likelihood this was partly written by Claude?” Authorship remains a separate judgement.
- Whether Claude wrote the first draft.
- Whether Claude edited something written by a person.
- Who used Claude or which account produced the text.
- Which organisation or conversation produced it.
- Whether the claims in the document are accurate.
- Whether another AI system was involved.
Could a Claude watermark appear in a CV?
It depends on how Claude was used.
Suppose someone writes their own career history and asks Claude to correct punctuation. Claude may change too few words for the watermark to register.
If the same person asks Claude to rewrite every role, achievement and summary, the model makes far more word choices. A detectable pattern becomes more likely.
Both documents could contain the same truthful career evidence. The difference is the amount of wording selected by Claude.
A positive result would therefore fail to tell a recruiter whether the candidate invented their experience, improved their writing or asked Claude to restructure a genuine draft. Those are different acts. The watermark cannot separate them.
Does Claude proofreading leave a watermark?
Light proofreading may leave little or no detectable watermark.
The pattern can appear only in words Claude chooses. If Claude corrects a handful of spelling mistakes and punctuation marks, there may be too little information for a reliable result.
Longer and more varied passages provide more opportunities for watermarking. Short text, factual writing and exact code provide fewer.
Detection confidence will therefore vary with the type and length of the content. Two documents processed by Claude could produce different results.
Can editing remove a Claude watermark?
Anthropic says light editing probably won’t remove the watermark completely. Google DeepMind reports that SynthID-Text can retain a signal after cropping, a few word changes and mild paraphrasing.
A full rewrite in which every word is replaced can remove it. Translation or heavy rewriting can also reduce detection confidence.
This creates an obvious limit for enforcement. Someone trying to hide AI use may be able to rewrite the text, while an honest user who lightly edited a Claude draft may retain the signal.
The watermark is better suited to supporting an investigation than deciding one.
Can you check for a Claude watermark today?
No public Claude watermark checker is available at the time of publication.
Anthropic says it plans to release a watermark detection API, but it hasn’t announced the full details or a public availability date.
Third-party AI detectors work differently. They don’t have Anthropic’s watermark key. They usually look for patterns associated with AI writing, such as predictable phrasing or sentence structures.
A result from one of those services is not a reading of Claude’s watermark. Uploading a document to several public AI checkers and comparing the scores won’t fix this. Different services can apply different methods and reach conflicting results.
What about Claude images and other files?
Anthropic plans to handle supported image and design files differently.
Files such as PNG, JPG and SVG outputs can receive a C2PA Content Credential in their metadata. This is a signed record stating that Claude created or processed the file.
The credential doesn’t contain information identifying the user or their conversation. It records Claude’s involvement with the file.
Metadata can be removed when a file is copied, converted or handled by software that strips it. The C2PA explainer confirms that provenance metadata can be removed and describes optional methods for recovering credentials. Anthropic has not said that every Claude file will use those extra recovery methods, so the absence of a credential may not settle the question.
How should employers and schools use watermark results?
A watermark result should trigger a conversation or further review. It should never make the final decision by itself.
An employer reviewing a CV should verify dates, employers, qualifications and claimed results. Those checks address whether the application is accurate.
A school assessing student work should compare the submission with earlier work, apply the assignment rules and ask the student to explain their reasoning.
A company checking an internal report should examine its sources, calculations and approval trail.
These checks test the substance of the work. A watermark tests possible model involvement.
Organisations adopting AI detection should define four things before using it:
Without those rules, a detector can create false confidence while leaving the real question unanswered.
- Which types of AI help are allowed.
- What a detection result can trigger.
- What other evidence is required.
- How someone can challenge an incorrect decision.
What should Claude users do?
There is little value in trying to beat the watermark.
Keep your original notes and drafts where authorship matters. Check every factual claim and retain links to the source material. Make the final argument and decisions yourself.
If an employer, teacher or client asks about AI use, explain what the tool did. “Claude reorganised my own employment history” is far more useful than a detector’s probability score.
The watermark records possible involvement. Your evidence shows ownership of the work.
The practical verdict
Claude’s text watermark could provide useful evidence that the model helped produce a long passage.
It cannot identify the user, recover the chat, confirm plagiarism or distinguish original generation from heavy editing. Proofreading and short factual text may leave too little signal to detect.
The risk comes from organisations demanding certainty from a tool designed to return likelihood.
Treat the watermark as a lead. Check the work itself before judging the person behind it.