AI News

Does Claude Watermark Your Code, Essays, PDFs and Client Work?

What Anthropic has confirmed, what its future detector could show, and what nobody can responsibly infer from a mark.

Last verified: August 11, 2026. Anthropic had not published a Claude detector, detector specification, API, model-by-model support list, accuracy measurements, or institutional-use guidance when this guide was checked.

Personal disclosure: I cancelled my paid Claude subscription after Anthropic’s announcement. I am not comfortable routing professional or personal work through a provider-controlled marking system while the detector rules, model coverage and downstream treatment remain undocumented. That decision shapes the risk analysis below, not the factual findings.

Quick answer

Claude is moving to marking, but “Claude watermarks everything” is too broad. Anthropic says supported models will embed an imperceptible watermark in text across Claude, Claude Code, the API and partner clouds. Supported files may receive signed C2PA provenance metadata. Models launched in the EU on or after August 2, 2026 are covered at launch; support for earlier models remains in progress.

Anthropic has not published the method, listed supported models, released a detector or disclosed error rates. It has not shown that code, short answers, translations, Word files or PDFs can be detected reliably.

A positive result could mean Claude processed the material. It would not prove Claude authored the ideas, a student cheated, or a contractor concealed AI-written work. A negative result would not exclude Claude use. Schools, clients and employers should treat any result as one clue, require human review, and examine drafts and records before judging.

The direct answers people are searching for

  • Does Claude watermark ordinary text? Anthropic says all generated text from supported models will carry an embedded watermark. It does not say every model available today is supported.
  • Does Claude watermark code or Claude Code output? Claude Code is expressly in scope, and Anthropic says markings cover generated text. It has published no code-specific detector results or quality data.
  • Can teachers detect Claude? Not with an official public Claude detector yet. Ordinary “AI detectors” are not Claude-watermark detectors.
  • Does Claude watermark Word documents and PDFs? Anthropic has not confirmed C2PA support for DOCX or PDF. Watermarked prose placed inside those files may retain its text-level signal, but that has not been measured publicly.
  • Is proofreading or translation detectable? Anthropic says a marked result may come from proofreading or translation even when a human supplied the original work. Reliability is unknown.
  • Can a Claude detector return a false positive? Any statistical decision system can. Anthropic has not supplied a Claude-specific false-positive rate, threshold, or test corpus.
  • Can clients tell if I used Claude? A future detector may signal possible Claude processing. It cannot determine who supplied the ideas or how much Claude contributed.

What Anthropic actually announced

Anthropic’s official help article says the company signed the EU AI Act’s Article 50(2) Code of Practice as a provider of generative models and systems. Its plan has two parts.

First, supported Claude models will embed a machine-readable mark in generated text at the model level. Anthropic says the mark travels when text is copied and pasted and may survive some editing. Coverage is supposed to include Claude, Claude Code, Claude Cowork, Claude Tag, the Claude API, and supported-model access through AWS, Google Cloud and Microsoft Foundry. The policy applies worldwide wherever Claude is offered.

Second, supported files such as SVG, PNG and JPG will receive cryptographically signed provenance metadata based on C2PA. Partner platforms may not support every file-marking feature.

The rollout language matters. Anthropic says models launched in the EU on or after August 2, 2026 support marking at launch. Earlier models are “in progress.” It has not published a definitive support matrix. That leaves a basic question unanswered: which model, region, endpoint and date produced a particular marked or unmarked output?

Detection is also unfinished. Anthropic promises tools or documentation that will let users and third parties check for its marks. As of this guide’s verification date, neither the detector nor its protocol was public. There is therefore no honest controlled test to run. A third-party classifier cannot substitute for the missing Claude-specific detector.

Evidence table: what is confirmed and what remains unknown

Artifact or workflow Confirmed marking method What Anthropic has documented What detection could mean Important unknowns
Ordinary prose Embedded text watermark for supported models Generated text is marked at model level across Claude products The text may have been processed by a supported Claude model Algorithm, supported models, languages, thresholds and error rates
Source code No separate method documented; covered only by the broad “generated text” statement Claude Code and supported-model outputs are in scope A supported Claude model may have generated or processed the tested code Functional impact, low-entropy behavior, language-by-language accuracy and minimum length
Claude Code output Embedded text watermark where a supported model generates text Claude Code is named as a covered product surface Possible processing through Claude Code or another covered surface Whether comments, diffs, patches and complete files perform differently
Essays and academic writing Embedded text watermark for supported output No education-specific accuracy or enforcement guidance Possible Claude processing, which can range from generation to editing False positives, appeal rules, institutional access and mixed-authorship interpretation
Proofreading human-authored text Potential embedded mark in Claude’s returned text Anthropic warns that proofreading can produce a marked output Claude may have handled text written by a person Whether minor corrections are always marked and how detector scores track degree of change
Translation Potential embedded mark in translated output Anthropic names translation as a reason a mark may appear without Claude being the original author Claude may have translated human-authored material Cross-language reliability and treatment of translation cycles
Summarization Embedded mark for supported generated text Anthropic names summarization as processing that can yield a mark Claude may have condensed source material Whether a result can distinguish summarization from original composition
Mixed human/Claude writing Signal may remain in marked portions Anthropic says marked text may be excerpted or combined with other material Some portion may have passed through Claude Localization, dilution, score calibration and the amount of Claude contribution
Very short passages No dependable commitment Anthropic says short passages may leave too little text for a reliable signal Little or nothing conclusive Minimum token count and abstention behavior; the EU Code exempts very short text
Word documents Text watermark may exist in generated prose; no confirmed DOCX metadata support DOCX is not among Anthropic’s named C2PA examples Possible Claude processing of text inside the document Whether DOCX receives signed provenance, and what saving or collaboration does to either layer
PDFs Text watermark may exist in generated prose; no confirmed PDF metadata support PDF is not among Anthropic’s named C2PA examples Possible Claude processing of extractable text or a supported precursor file Native PDF support, OCR behavior, metadata survival and scan reliability
Images and other files Signed C2PA provenance metadata on supported types SVG, PNG and JPG are examples; support varies by product and platform A signed record can indicate Claude processing and reveal later tampering Complete file list, credential fields, trust-chain policy and soft-binding support
API output Embedded text watermark from supported models Claude Platform is explicitly covered Possible output from a supported Claude model Endpoint/model matrix, streaming behavior, version pinning and detector access
Third-party cloud access Embedded text watermark; file metadata may vary AWS, Google Cloud and Microsoft Foundry are named Possible processing by a supported Claude model through a partner Platform-specific exceptions, rollout timing and provenance-feature parity

The table is deliberately repetitive about “possible processing.” Anthropic uses that language because the mark cannot carry a biography of the work around it.

Statistical watermark or hidden Unicode? Do not guess

A hidden-character scheme inserts characters such as zero-width spaces or unusual Unicode code points. They can be invisible on screen while remaining part of the encoded string. A simple character inspector can expose them, and software may alter them during normal text handling.

A statistical text watermark changes generation itself. Research systems such as the 2023 paper “A Watermark for Large Language Models” slightly favor selected tokens as the model writes. A detector with the right key or rule tests whether those favored choices appear more often than chance would predict. The visible words carry the signal; there is no secret note tucked between the letters.

Anthropic’s description of a model-level watermark “woven” into text is consistent with a statistical approach. Consistent does not mean confirmed. The company has disclosed too little to name its method, and anybody claiming to have found Claude’s zero-width characters or reverse-engineered its detector needs evidence that Anthropic has not supplied.

Statistical marks also create a trade-off. Longer, varied prose offers many token choices and more evidence. Very short or highly constrained output offers less. The final EU Code of Practice exempts very short text and requires watermarking above 200 tokens while acknowledging lower reliability than for very long text. That 200-token line comes from the EU Code, not from a published Claude detector specification.

Does Claude watermark code and Claude Code output?

The cautious answer is intended coverage, unproven performance.

Anthropic explicitly includes Claude Code and says embedded watermarks apply to all generated text from supported models. Source code is text, so code output appears to sit inside the policy. Anthropic has not stated that every code block, patch or file receives a detectable mark, nor has it published code-specific measurements.

Code is a hard case because valid next tokens are often constrained by syntax, APIs and tests. Changing a natural-language synonym may preserve meaning; changing an operator, identifier or keyword may break a program. The ACL 2024 paper “Who Wrote This Code? Watermarking for Code Generation” introduced entropy-aware watermarking precisely because ordinary logit-bias techniques can weaken detection or damage code quality in low-choice passages. That research shows the problem is solvable in some settings. It does not validate Anthropic’s undisclosed implementation.

Developers should keep commit history, issue links, prompts where policy permits, test results and review notes. Those records answer the question a watermark cannot: who designed, checked and accepted the code?

Essays, proofreading, translation and human source material

Anthropic’s most important caveat is easy to miss. A detected mark may mean Claude proofread, translated, summarized or converted the work. Claude may not have originated the ideas or underlying text.

That makes “Can teachers detect Claude?” the wrong disciplinary question. A detector may eventually identify a supported Claude mark. It cannot decide whether the use violated an assignment policy, how much content came from the student, or whether assistance was permitted. Those are factual and procedural questions for a human investigation.

Generic AI-writing classifiers do not solve the gap. They infer authorship from learned style patterns rather than checking Anthropic’s secret mark. A peer-reviewed Patterns study found that several such detectors disproportionately misclassified writing by non-native English authors. That result does not predict the accuracy of Claude’s future watermark detector. It does show why schools should stop treating a vendor score as a verdict.

For proofreading and translation, retain the source draft, tracked changes, references and dated versions. A positive mark could then be placed beside evidence of human authorship instead of being allowed to erase it.

Word documents, PDFs, images and C2PA

Text watermarks and file credentials answer different questions.

If Claude generates prose and someone places it in a Word document or PDF, the word choices may continue to carry a statistical signal. Anthropic has not published tests showing how reliably that signal survives document editing, layout changes, collaboration, export or optical character recognition.

C2PA metadata sits at the file level. The C2PA specification defines cryptographically signed Content Credentials that can record an asset’s provenance and make later tampering evident. It does not make the picture or document true. It records claims about origin and editing in a verifiable structure.

Anthropic names SVG, PNG and JPG as supported examples. It does not name DOCX or PDF. A file without Claude C2PA metadata might use an unsupported format or platform, or it might have passed through a process that did not preserve the credential. Anthropic itself warns that conversion, re-saving and screenshots can strip metadata. Absence therefore proves little.

What a detector result would and would not prove

A positive detector result would support one narrow statement: the submitted content carries a mark associated with a supported Claude workflow. Even Anthropic softens that to content that “may have been processed by Claude.”

It would not establish:

  • who wrote the source material or supplied the ideas;
  • whether Claude generated, proofread, translated, summarized or reformatted it;
  • whether the use complied with a school, employer, publisher or client policy;
  • whether the marked passage remained unchanged; or
  • whether a named person intended to deceive anyone.

A negative result would not rule out Claude. Anthropic lists older unsupported models, heavy editing, paraphrasing, translation, mixing, very short passages, stripped file metadata and unsupported platforms or formats as reasons a mark may not be detected.

False positives remain an open issue. Watermark detection is a statistical hypothesis test in many published designs. The ICLR reliability study reports performance at chosen false-positive rates for one research family, including after paraphrasing. Anthropic has not said whether Claude uses that family, what threshold it will choose, or whether its tool will return positive, negative and inconclusive states.

No school, employer, client or publisher should act on a mark alone. A defensible review needs the original material, drafts, version history, the applicable policy, the exact detector version and threshold, an opportunity to respond, and a decision by someone who understands what the result does not say.

Practical risk guide

Group Sensible action now Bad policy
Developers Keep commits, tickets, tests and review ownership; define acceptable AI assistance in the repository or contract Treat a marked function as proof that the developer did not author or verify the system
Students and researchers Save outlines, notes, sources, drafts and tracked changes; ask what assistance the course permits Submit work to unknown detector sites or accept a score as conclusive
Writers and editors Preserve the human source, client brief and edit trail; agree whether proofreading, translation and drafting require disclosure Collapse “AI touched this” into “AI wrote this”
Agencies and freelancers Put AI-use and disclosure terms in the statement of work; document review and factual checks Promise that work is “undetectable” or infer deception from a future positive mark
Employers and clients Use results only as a trigger for human review; let the worker provide workflow evidence Automate discipline, payment holds or rejection from one detector result

Do not upload confidential client, student, legal or research material to a detector until its data-retention, access and deletion rules are clear. The EU Code calls for privacy-sensitive handling and deletion after detection, but Anthropic has not yet published the product that would implement those promises.

For the sharper policy argument, see Kingy AI’s related analysis: Claude’s Watermark Can Signal Contact. It Cannot Prove Guilt.

Why I cancelled my paid Claude subscription

I cancelled my paid Claude subscription after this announcement. I am not comfortable placing professional or personal work inside a provider-controlled marking system while the detector rules, model coverage, accuracy data and downstream treatment remain undocumented.

That is a personal risk decision, not evidence that Claude’s mark is malicious or technically unsound. Provenance tools can help investigators and platforms when they are narrowly described and carefully governed. Anthropic has announced worldwide marking first and left the detector, error rates and safeguards for later. I do not consider “trust us until the technical documentation arrives” a satisfactory contract for my work.

Other users may reasonably stay, especially if their organization already discloses AI assistance and preserves strong workflow records. They should still demand answers before a Claude mark becomes evidence in a classroom, contract dispute or workplace investigation.

Questions Anthropic still needs to answer

Open as of August 11, 2026:

  1. Which exact model IDs and versions currently embed marks, and from what activation dates?
  2. Does every region receive the same marking behavior?
  3. What algorithm or watermark family does Claude use?
  4. What are the false-positive, false-negative and inconclusive rates by language, length and content type?
  5. How does detection perform on source code, mathematics, tables, citations and highly constrained text?
  6. Are proofreading, minor edits and translation always marked, and can a detector distinguish them from original generation?
  7. Do DOCX and PDF files receive C2PA credentials, or only text-level marks?
  8. Who can use the detector, and will the public receive the same information as institutions?
  9. What data will a detection service store, for how long, and under which jurisdiction?
  10. What appeal and correction process will exist when a result is used against a person?
  11. Will Anthropic publish test corpora, thresholds, version history and independent audits?
  12. How will downstream API and cloud customers learn that a model’s marking behavior changed?

FAQ

Does Claude watermark text?

Anthropic says supported Claude models will embed an imperceptible watermark in all generated text at the model level. The policy covers Claude products, the API and named partner clouds worldwide. Anthropic has not published a complete supported-model list, so it is inaccurate to say every current Claude response is already marked.

Does Claude watermark code?

Claude Code is explicitly covered, and Anthropic says supported models mark generated text. That suggests source code is in scope. The company has not released code-specific accuracy, quality or minimum-length results. A future mark could signal Claude processing, but it could not show who designed, tested or approved the code.

Can teachers detect Claude-written essays?

There is no public official Claude watermark detector yet. When one arrives, a positive result may show that Claude processed the text, including through proofreading or translation. It will not establish authorship or misconduct. Teachers should examine policies, drafts, sources and version history and give the student a chance to respond.

Does Claude watermark Word documents or PDFs?

Anthropic has not confirmed C2PA provenance support for DOCX or PDF. Watermarked prose may retain a text-level statistical signal when placed in those files, but no Claude-specific reliability results are public. Signed file metadata and embedded text watermarks are separate layers and should not be treated as interchangeable.

Is proofreading with Claude detectable?

Potentially. Anthropic warns that Claude-processed text can carry a mark even when a human supplied the original material and used Claude only for proofreading. The detector and thresholds are not public, so nobody can promise detection. Keep the original draft and tracked edits to document authorship and the scale of assistance.

Does Claude watermark translated text?

Translated output from a supported model may carry Claude’s embedded mark. Anthropic also says translation can weaken a previously present signal and that a positive mark does not make Claude the original author. No public results show detection accuracy across languages, translation directions or short translated passages.

How does the Claude watermark detector work?

Anthropic has not said. Published text-watermark systems often bias token choices during generation and later test for the statistical pattern. Claude’s model-level description is compatible with that design, but compatibility is not confirmation. Technical documentation, detector access, thresholds and accuracy measurements are still forthcoming.

Can a Claude watermark produce a false positive?

Yes in principle; any detector needs a measured false-positive rate and a decision threshold. Anthropic has published neither for Claude. Passage length, language, constrained text and the detector’s calibration may matter. Until the evidence appears, a positive result should trigger review rather than punishment, rejection or a claim of authorship.

Can clients tell if I used Claude?

A future Claude detector may indicate that submitted content was processed by a supported Claude model. It cannot determine whether Claude drafted the work, fixed grammar, translated a human original or touched only one section. Contracts should define permitted assistance and disclosure instead of pretending a watermark resolves intent or contribution.

Does a negative result prove I did not use Claude?

No. Anthropic lists unsupported older models, heavy editing, paraphrasing, translation, mixed writing, short passages, stripped metadata and unsupported formats or platforms as possible reasons a mark may not be found. A negative result cannot certify that work is human-only, and no responsible policy should promise that it can.

Bottom line

Claude marking may become useful provenance infrastructure. Its evidentiary reach stops at possible processing; authorship, misconduct and intent require separate proof and due process. I cancelled my subscription because Anthropic is asking users to accept worldwide marking before publishing detector rules and error data. Users who stay should preserve their work history. Institutions should build human review and appeals before acting on a result.

Sources and reporting note

The core reporting is based on Anthropic’s marking announcement, the European Commission’s Article 50 transparency overview, the final EU Code of Practice, the C2PA Content Credentials specification, and original or peer-reviewed research linked above.

No Claude detector test was performed because Anthropic had not made a detector, API or implementable technical protocol available. Generic AI-writing detectors were not treated as Claude-watermark detectors. No watermark-removal or detector-evasion methods were tested or described.