Ofsted Good · Skills England Approved UK · 10,000+ learners trained · 4.9★ from 732+ reviews
AI & Governance

Claude now watermarks everything it writes. The problem was never using AI.

From this month, text generated by supported Claude models carries an invisible mark woven into the words themselves. It survives copy and paste. It is applied at model level, so it does not matter which Claude product it came from. The headlines are all about catching people out. The more useful reading is that concealment just became an expensive strategy, and declared, evidenced use just became the only sensible one.

Rod Doyle & Lisa O'Reilly · 12 August 2026 · 9 min read

Key takeaways

  • Two marks, not one. An imperceptible watermark inside generated text, and signed C2PA provenance metadata on generated files.
  • It is a model-level feature. Present whichever Claude surface the text came from, and it travels with copy and paste.
  • The nuance everyone will miss: a detected mark means content may have been processed by Claude. Processed is broader than written.
  • It is not forensic proof. Anthropic says heavy editing, paraphrasing and translation may make the mark unreadable, and detection tooling is still being built.
  • The strategic point: nothing here penalises using AI. It penalises pretending you did not.

The tabloid version of this story writes itself, and has: a warning to anyone using AI to do their work for them. That framing is not wrong, exactly, but it points at the wrong thing. Here is the sentence the whole announcement actually turns on.

The problem was never using AI. The problem is concealing it.

The spine of everything below

Nothing Anthropic has shipped penalises a person for using Claude. What it penalises is the gap between what someone did and what they said they did. That is a governance question, not a technology one, and the useful version of it for an employer is not "how do I catch people". It is "what is our actual policy, and could anyone in this building state it out loud".

Who this affects most

  • Bid and tender teams, who sign originality and authorship declarations as a matter of routine.
  • Client-facing functions billing for written deliverables: agencies, consultancies, legal, marketing.
  • Regulated sectors where advice, records or reporting carry a named accountable person.
  • Training providers, schools and universities assessing written evidence, and the learners submitting it.
  • Anyone selling into the EU, who now sits inside a regime that expects content to be marked.

What Anthropic has actually done

Anthropic has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, as a provider of both generative AI models and generative AI systems. The transparency code took effect on 2 August 2026, and it requires providers to mark AI-generated or edited content in a way other systems can identify. Anthropic set out how it is doing that in an updated support article, which TechCrunch picked up on 11 August.

There are two mechanisms and they do different jobs.

MechanismWhat it coversHow it behaves
Embedded text watermarkText generated by supported Claude modelsWoven into the text itself, imperceptible, no effect on meaning or readability. Travels with copy and paste and may survive some editing.
Signed provenance metadataGenerated files such as .svg, .png and .jpgFollows the C2PA open standard. Records provenance and lets you detect whether a file has been tampered with.

Two details matter more than they look. First, the watermark is applied at the model level, which means it is present regardless of which Claude product or surface produced the text, including the API, Claude, Claude Code, Claude Cowork and Claude Tag. Second, models released after 2 August carry it automatically, and Anthropic has said it will extend support to older models.

Anthropic is not alone. Google, Meta, Microsoft, OpenAI, Black Forest Labs and Synthesia have all committed to the same EU code. Around it, the wider market is moving in the same direction, with Suno marking AI-generated tracks and Substack partnering on detection for newsletters. This is not a one-vendor policy you can route around by switching models.

The distinction almost every write-up will miss

Read Anthropic's own careful phrasing. A detected mark indicates that content may have been processed by Claude.

Processed is a much broader word than written.

The bit that will cause the arguments

Consider the most common real-world use of AI in a professional setting. Someone writes their own report, in their own words, from their own analysis, then asks Claude to tighten the grammar, cut three hundred words or make the executive summary sharper. The text that comes back is substantially their thinking. It can also carry the mark.

Now imagine a manager, a client or an awarding body running a detection tool and treating a positive result as proof of ghostwriting. That is how good people get wrongly accused. If you are going to adopt detection, adopt the nuance with it, in writing, before the first difficult conversation rather than during it.

To be clear about what that argument is and is not. This is not a case for more AI use, and it is not a reason to ignore a detection. It is an argument against treating a mark as automatic proof of misconduct, and for having a policy that tells you what to do with one.

LO
"My worry isn't learners getting caught. It's good learners being wrongly accused, because a mark that says 'processed by Claude' will get read by somebody as 'they didn't write it'. Anyone assessing written work needs to understand that difference before they act on it, not after. The skill we are actually building is not avoiding AI. It's being able to show your judgment on top of it."

Lisa O'Reilly, Director, The TESS Group

What it cannot do

What a detected mark meansWhat it does not mean
Content may have been processed by ClaudeThat Claude wrote the whole thing
It survives copy, paste and light editingThat it survives heavy rewriting, paraphrase or translation
It is applied at model level, across every Claude surface, worldwideThat it is forensic proof of authorship
A signal worth a calm conversationGrounds for a disciplinary on its own

Three specific traps follow from that.

Trap 1 · "We can now prove someone used AI"

You have a signal, not a proof. Anthropic has said heavy editing, paraphrasing and translation may render the watermark unreadable, and has published no threshold for how much is enough. TechCrunch asked and had not been given a figure at the time of writing.

Trap 2 · "No watermark means a human wrote it"

Absence proves nothing. The text may come from another model, an older model, a heavily edited draft, or an actual person. Any policy treating a clean result as a clean bill of health will be gamed within a fortnight.

Trap 3 · "The tooling is here"

Anthropic says it is working to enable users and third parties to detect its marks, with more technical guidance to follow. Build your policy on principles you can defend today, not on a detector you have not seen yet.

What this means inside a business

Most organisations we speak to have no written position on AI-assisted writing. Not a lax one. None. Which means every individual is making a private judgment about what is acceptable, and, until now, nobody could see the result.

The places this lands first are the ones where authorship carries weight. Here is the shape of it.

A realistic Tuesday

You win a place on a framework. Six weeks later the buyer runs your submission through a detection tool and comes back with one line: parts of section 4 appear to have been AI-processed. Your bid manager wrote section 4 herself over two evenings, then asked Claude to cut it from 900 words to the 600-word limit.

Now answer their email. If you have a declared-use policy, this is a two-minute reply: our policy permits AI for editing and compression, the author is named, here is the record. If you do not, you are improvising a position on originality in front of a client, after the fact, with nothing to point at. Same facts, completely different Tuesday.

The same pattern turns up in client deliverables you invoice for, regulated advice, board papers, and recruitment in both directions, since candidates are using AI on applications and hiring managers are using it on job specs.

None of that argues for a ban. Bans move the behaviour underground and leave you with no record, which is exactly the position watermarking now makes uncomfortable. It argues for a declared-use policy people have actually been trained on. Our guide to writing an AI policy people will follow is free and takes an afternoon.

What it means for apprentices and assessment

Schools, universities and training providers get an obvious new capability here, and some will use it badly. The temptation will be to bolt on a detector and start policing.

We would argue the opposite, and we would argue it as a provider whose learners submit written evidence for a living. If an assessment collapses the moment a student uses AI, the assessment itself needs redesigning. That is not a criticism of assessors, most of whom have been asking for exactly this rethink for two years. It is a recognition that work an unsupervised model can produce in thirty seconds was never evidencing much on its own.

The alternative is to design assessment that assumes AI is in the room, then asks what the human did with it.

RD
"I've had learners tell me they were nervous about admitting they'd used AI on a piece of evidence. That always struck me as completely backwards. On our programme the assessor wants to see how you used it, and the ones who document their prompts, their dead ends and their fixes produce far better work than the ones who quietly polish something and hope. Watermarking doesn't threaten those learners. It hands them an advantage, because they can already prove what they did."

Rod Doyle, Director, The TESS Group

Why we teach Claude in the open

Watermarking only becomes a problem for organisations that still treat AI use as something to hide. The ones that treat it as a declared capability will feel almost no friction at all. That is the whole argument, and it is why we built the programme the way we did.

We run a dedicated Claude edition of the AI & Automation Practitioner Level 4: same Skills England standard as the mainstream version, ST1512, same End-Point Assessment through BCS, taught entirely through the Claude stack. On it, using Claude is not a shortcut around the assessment. It is the assessment.

The Claude Apprenticeship · Level 4 · ST1512

Declared use, evidenced work, assessed by BCS.

  • 12 months delivery plus a 3-month EPA phase. Up to £18,000, fully fundable through the Growth and Skills Levy, with up to four qualifications.
  • 11 modules covering AI fundamentals, prompt engineering, Claude and Claude Projects, no-code automation with Make, Zapier and n8n, analysis and Artifacts, ethics and responsible AI.
  • A working automation live on real company work by Month 3, and an agent built with Claude Projects and MCP connectors for a real use case by Month 4.
  • A workplace project the apprentice scopes, builds and writes up, assessed by BCS at the two-thirds point and again at the final showcase.
  • No coding background required to start.

At the ST1512 showcase the assessor wants to see how the apprentice applied AI to a real workplace problem, not whether they avoided it. An apprentice who has documented their prompting, decisions, failures and fixes has nothing to fear from a watermark, because the portfolio is itself a declaration.

See the Claude Apprenticeship →

The people exposed by watermarking are the ones hiding AI use. The people on a properly designed programme are documenting it.

If Claude is not your house standard, the same logic and the same standard apply to the mainstream AI & Automation Practitioner Level 4, with Copilot and Gemini editions too. The vendor matters far less than whether your people can show their working.

What to do this month

  1. Write down where AI is and is not allowed

    Do: name the tasks where AI is fine unremarked, where it must be disclosed, where a named human must review and sign, and where it is banned outright, such as anything holding personal or client-confidential data.
    Why: with no rule, everyone invents their own, and you find out which during an incident.

  2. Decide what a detection means before you own a detector

    Do: agree in advance what a positive result does and does not mean, and who reviews it before anyone is challenged.
    Why: get this wrong once with a good employee and the trust does not come back.

  3. Re-read your bid and contract declarations

    Do: check what you already sign about originality of work in tenders, frameworks and client contracts.
    Why: those clauses predate all of this, and you may be certifying something you cannot evidence.

  4. Ask for the working, not just the output

    Do: where authorship matters, have people keep a few lines on how they used AI.
    Why: it turns an unanswerable accusation into a boring, checkable fact.

  5. Train the policy, do not just circulate it

    Do: walk people through it using examples from their own jobs, then build the capability underneath. Start from the AI policy template and the Level 5 AI Adoption & Governance unit.
    Why: a policy nobody has practised is a document, not a control.

Get your team on the right side of this

A 25-minute call, no obligation, covering three things:

  1. Your policy position. Where AI is permitted, where it must be declared, and what your bid and client declarations already commit you to.
  2. How you will read a detection. What a mark does and does not evidence, and who decides before anyone is challenged.
  3. Which route fits. Whether a short Level 5 governance unit or the full Level 4 apprenticeship is the better use of your levy, or whether you need neither.
Book a discovery call →

The honest summary

Watermarking is not the end of AI-assisted work and it is not a reliable lie detector. It is a compliance mechanism, built to satisfy a European transparency rule, with real limits that its own maker is upfront about.

What it does change is the economics of pretending. For two years the safe move for a lot of people has been to use AI quietly and say nothing, because there was no downside. There is now a downside, it is asymmetric, and it falls hardest on exactly the people who never told anyone.

The way out is not a better hiding place. It is being the organisation where nobody needed one.

Frequently asked questions.

Does Claude watermark the text it generates?

Yes. Anthropic has confirmed that supported Claude models weave an imperceptible watermark directly into generated text. It does not change the meaning, quality or readability. Because it is part of the text it travels when the text is copied and pasted, and may persist through some editing. It is applied at the model level, so it is present whichever Claude product the text came from, including the API, Claude, Claude Code, Claude Cowork and Claude Tag. Files such as .svg, .png and .jpg also get signed provenance metadata following the C2PA standard.

Can the Claude watermark be removed?

Anthropic has said heavy editing, paraphrasing and translation may render the watermark unreadable, and it has not published a threshold for how much editing is enough. Treat it as a strong signal rather than forensic proof. Detection tooling for users and third parties is still being built, and Anthropic has said it will publish more detailed technical guidance.

Does a watermark mean the text was written by AI?

Not necessarily, and this is the most important nuance. Anthropic's own wording is that a detected mark indicates content may have been processed by Claude. Processed is broader than written. If someone drafts their own report and asks Claude to tighten the grammar, the returned text can carry the mark. Anyone treating a detected watermark as proof of ghostwriting will produce false accusations. Absence proves nothing either, since the text may come from another model, an older model, heavy editing or a human.

Why is Anthropic adding watermarks now?

To meet the EU AI Act. Anthropic has signed the Article 50(2) Code of Practice on Transparency of AI-Generated Content as a provider of both generative AI models and generative AI systems. The transparency code took effect on 2 August 2026 and requires providers to mark AI-generated or edited content in a machine-detectable way. Models released after that date carry the marking automatically, and Anthropic has said it will extend support to older models. Other signatories include Google, Meta, Microsoft, OpenAI, Black Forest Labs and Synthesia.

Does watermarking affect apprenticeship assessment?

It affects anyone submitting written evidence they claim is entirely their own. It changes very little for a well-designed AI apprenticeship, because the assessment already expects declared use. On the AI & Automation Practitioner Level 4, apprentices scope, build and write up a real workplace project, and the End-Point Assessment showcase asks them to demonstrate how they applied AI. Using Claude is the syllabus rather than a shortcut, and the evidence trail is the point.

Should we ban AI writing at work?

A ban tends to move the behaviour rather than stop it, and it leaves you with no record of what was used where. The more workable position is a declared-use policy: state clearly which tasks may use AI, which require disclosure, which require a named human to review and sign off, and which are off limits, such as anything containing personal or client-confidential data. Then train people against it, because a policy nobody has been trained on is a document rather than a control.

What is the Claude apprenticeship at TESS Group?

It is the AI & Automation Practitioner Level 4 apprenticeship, standard ST1512, delivered as a dedicated Claude edition. Twelve months of delivery plus a three-month End-Point Assessment phase, up to £18,000 and fully fundable through the Growth and Skills Levy, with up to four qualifications. Eleven modules cover AI fundamentals, prompt engineering, Claude and Claude Projects, no-code automation with Make, Zapier and n8n, analysis and Artifacts, ethics and responsible AI. No coding background is required, and apprentices build a working automation on real company work within the first few months.

Sources: Anthropic's How Claude marks AI-generated content support article; TechCrunch, 11 August 2026; JOE, 12 August 2026; and the European Commission's guidelines on AI transparency obligations. Programme details are TESS Group's own. This article describes how marking works and what it means for policy. It is not legal advice, and we are not lawyers.

Keepreading

Back to all articles