ENDASV · soonNO · soon

JOURNAL

Claude now marks its own output. It proves less than you think.

Anthropic has signed the EU code of practice on transparency. But a detected mark proves less than the word watermark suggests, and a missing mark proves nothing at all.

12 August 2026·14 min read·eu ai act · article 50 · ai content marking · c2pa · watermark · ai transparency · ai compliance · claude · anthropic

On 3 August I wrote here about Article 50 of the EU AI Act, and about what actually happened on 2 August when the transparency obligations took effect. That piece was about the rules. This one is about what the supplier has now delivered, and it is worth reading closely, because it says something different from what most people think.

Anthropic says it themselves, on their own help page:

Detecting a Claude mark tells you that the content may have been processed by Claude. It does not, on its own, confirm the full provenance of the content.
Anthropic, How Claude marks AI-generated content

That is not a guarantee. It is a caveat, written by the supplier, in their own documentation, on the same page where they announce that they have signed the EU code of practice on transparency.

TL;DR: Anthropic has signed the EU AI Act code of practice on transparency of AI-generated content. Claude now marks its output two ways: an imperceptible watermark inside the text itself, and signed provenance metadata on image files following the C2PA standard. But a detected mark only means the content may have been processed by Claude, and a missing mark proves nothing at all. The tool for finding the marks has not been released yet. If you have a policy that depends on detecting AI content, it does not work.

Source: How Claude marks AI-generated content, Claude Help Center

What has Anthropic actually signed?

Article 50(2) of the EU AI Act has a voluntary code of practice attached to it, covering transparency of AI-generated content. The European Commission has assessed it as adequate, and according to the Commission's own page it had been signed by roughly 190 organisations by the end of July 2026. Anthropic is one of them.

The commitment is to make the model's output machine-readable as AI-processed. In other words, to put something into the content that a machine can find later.

Two things are worth keeping firmly apart here, because they get blurred in almost every conversation about this.

Anthropic's signature covers Anthropic's obligation as the provider of the model. It does not cover yours. If you run a chatbot, generate text for customers, or push content through a model, you have your own obligations under Article 50. They do not disappear because your supplier signed something. Those are two different rows in the rulebook, and your row is still open.

That is the first misunderstanding I expect to meet with clients this autumn: treating the supplier's signature as your own compliance.

How does Claude mark the content?

Two mechanisms, and they behave in fundamentally different ways.

A watermark in the text. Anthropic describes it as an imperceptible watermark placed directly into the text itself. It travels with the text when it is copied and pasted. So this is not metadata (information stored alongside the content, for example in a file's properties), it is something in the words. Exactly how, they do not say.

Signed provenance metadata on files. Here Anthropic uses C2PA (Coalition for Content Provenance and Authenticity, an open standard for documenting where a file came from). It applies to file types such as .svg, .png and .jpg, and the signature is cryptographic, so it can be verified.

Coverage is broad. It spans Claude Platform (API), Claude, Claude Code, Claude Cowork and Claude Tag, and it also applies when Claude runs on AWS, Google Cloud or Microsoft Foundry. It works worldwide, not only inside the EU.

Note the difference between the two mechanisms, because it becomes decisive further down: one sits in the content, the other sits on the file.

Sankey diagram of five tested situations. The text watermark survives copy and paste. C2PA metadata on images survives only when the metadata is carried across explicitly, and is lost in three of four situations: re-saving, resizing and conversion to JPEG.
The text watermark travels through copying. The provenance data on files falls away during entirely ordinary file handling.

So what does a mark prove?

Back to the sentence the whole story hangs on. Two words carry it.

May. A detected mark does not by itself tell you how the content came to exist.

Processed. Processed is not the same as written. A text a person wrote from scratch and then asked Claude to fix the commas and repetitions in has been processed by Claude. It may carry a mark. It was still written by a person.

That is a markedly weaker claim than the word "watermark" suggests. A watermark sounds like a stamp of ownership. This is closer to a fingerprint on a doorframe: someone passed through, and you do not know why or for how long.

And what does it prove when there is no mark?

Anthropic is equally clear in the other direction:

Lack of a detected mark doesn't mean the content wasn't AI-generated or processed.
Anthropic, How Claude marks AI-generated content

There are at least three reasons for that. The content may have been edited so heavily that the mark can no longer be found. It may come from an older model that does not mark yet. And it may come from an entirely different provider who has signed nothing at all.

Put the two sentences side by side and you get a truth table with four cells, only one of which gives you anything usable.

Two-by-two table with two rows, mark found and no mark found, and two columns, what you can conclude and what you cannot. Only the top left cell gives you anything usable: that the content may have been processed by Claude.
Only one of the four cells tells you anything. That is not a basis for making decisions about people.

How durable is the marking in practice?

This is where it gets concrete, and where it surprised me.

The text watermark survives copying, Anthropic says. I believe that, and I cannot verify it, because there is no public tool yet for finding it. More on that shortly.

The provenance data on images is different. I can test the mechanism behind it, and I did. I put metadata into an image and ran it through three entirely ordinary operations.

OperationData survives
Open the file and save it again, same formatNo
Resize the image and saveNo
Convert to JPEGNo
Save with the data explicitly carried throughYes

Note what this does not show. It is not the compression destroying anything. The point is that a tool only carries metadata forward if something explicitly tells it to. The default behaviour in many image libraries is to leave it behind. So the data does not disappear because someone removes it. It disappears because nobody actively keeps it.

Worth being precise here: I tested ordinary metadata, not a genuine Claude-signed file. The mechanism is the same, but I did not have a signed file to run through.

C2PA knows the problem well. Their own FAQ states that manifests can be separated from the asset, and that the standard therefore supports what they call durable content credentials via soft bindings: invisible watermarks or fingerprints that can rediscover the provenance data even when it has been stripped from the file itself. The Content Authenticity Initiative puts it even more plainly: metadata of any kind can be removed, deliberately or accidentally.

And here is the detail I find most interesting in the whole matter. Anthropic describes a watermark for text and C2PA metadata for files. They say nothing about soft bindings on images. If that is how it is put together, the image half is the fragile half of the scheme, and it is the half nobody is talking about.

Four identical panels, one per operation on the image file, where the first three are marked as lost and the fourth as preserved.
Three of four ordinary operations stripped the metadata. Only the explicit save kept it.

Does it apply to the models you are using right now?

This is the question I cannot answer, and it is also the one with the most practical consequence.

Anthropic writes that models launched in the EU on or after 2 August 2026 support machine-readable marking at launch. For Anthropic models launched before that date there is a transition period, which they say they are working to close.

Claude Opus 5 launched on 24 July 2026. Claude Sonnet 5 launched on 30 June 2026. Both fall before the cutoff.

On a plain reading of that wording, it means the two models most people use daily sit inside the transition period and therefore may not be marking anything yet. But it says "launched in the EU", and that is not necessarily the same date as the global launch. I have asked Anthropic and had no answer at the time of writing. So it stands here as an open question, not a conclusion. If an answer arrives, I will update the article.

There is no way around it right now either. Anthropic says details of the detection mechanisms are coming in technical documentation later. So there is no public tool yet, for you or for me, that can find the watermark in a piece of text.

That is a notable place to be: a transparency scheme where the transparency cannot yet be verified by anyone outside the supplier.

So who is going to misread this?

Here is my view. It will not be the lawyers. It will be the buyers.

The lawyers will read it correctly. They read the caveats, because caveats are their job. When it says "may", they see "may".

It is the buyers I worry about. When a supplier can say, a few months from now, "our AI is marked to the EU standard", that gets heard as a guarantee. And there is one specific mistake on the way: starting to use the marking as a control rather than as disclosure.

The difference is not academic.

Disclosure is when the mark tells the recipient something. That is what Article 50 is about, and what the scheme can actually carry.

Control is when you use a mark, or the absence of one, to make a decision about a person. Reject an application. Fail a piece of work. Open a conversation with an employee. Decisions like that do not hold up when the supplier has written in plain text that absence proves nothing.

I make my living advising on exactly this, so I am not a neutral party.

When does the first case about a mark arrive?

Within a year, I think. Someone will face an accusation of AI use because a mark was found. Or someone will get away with the opposite, because no mark was found.

Both would be a misuse of the tool. And both would be entirely natural to do, if you have read the headline and not the two sentences this whole article is about.

I may be wrong about the timeline. About the direction, I am not.

What does it mean for your role?

Owners and leaders of small and medium-sized businesses. Your supplier has taken their step. You still have yours. The yardstick is simple: have you written down where you use AI with customers, and do you tell them? The marking does not answer that question for you, and it does not release you from it. The upside is that it is a small piece of work to get straight, and far cheaper now than reconstructing it afterwards.

Operations and transformation leads. If there is a policy sitting somewhere built on being able to check whether something is AI, it does not work. There is no public detection tool yet, and when one arrives, a result will say less than the policy assumes. Build on disclosure and on process instead: who discloses what, when, to whom. That is the version still standing in two years.

Sales and RevOps leads. Anything you send out that was made with Claude may carry a mark. That is not a problem in itself. It becomes one the day a customer's tool flags your proposal and someone asks about it without warning. The best answer is the honest one, and it is considerably easier to give if you have decided in advance what you use AI for in customer contact.

Product and engineering leads. The technical consequence is yours, and it is concrete: C2PA data does not necessarily survive your own pipeline. If you compress, convert or rewrite images, you are probably stripping the provenance data without knowing it. If you want to preserve it, that has to be tested, not assumed. It takes an afternoon to test and is impossible to guess.

Try the distinction on three situations

The abstract split between disclosure and control only becomes useful when you hold it against something concrete. Three situations you will find yourself in.

An employee hands in a report and your tool finds a mark in the text. What it supports: that Claude probably touched the text at some point. What it does not support: that the employee did not write it. Language editing is also processing. If you have a rule about disclosing AI use, that rule is what the conversation should be about, not the mark.

An application arrives with no mark. What it supports: nothing. Anthropic says themselves that absence proves nothing, and most other providers do not mark at all. If you use the absence of a mark as an argument that something was written by a person, you are building on a basis the supplier has already rejected in writing.

A customer asks whether your proposal was written by a machine. Here the marking is genuinely useful, but not as proof. It is useful because it forces you to have the answer ready. The best answer is the one where you have decided for yourself what you use AI for, and say so before being asked twice.

The common thread: marking is good at disclosing and bad at judging. It can support you telling someone something. It cannot carry you deciding something about a person.

GDPR and security

There is a real technical decision here, and it is not about personal data in the classic sense.

A watermark in text is data that travels with the content out of the building. It does not reveal the content, but it ties an output to a particular supplier. For most people that is uninteresting. For organisations with strict confidentiality requirements around supplier choice, for example in tender processes or sensitive advisory work, it is worth factoring in.

C2PA signing is cryptographic and can be verified. That is a strength, not a risk. But it also means removing metadata acquires a significance it did not have before. If your systems strip it routinely, and most systems do, as the test above shows, you need to be able to explain why. Not because it is unlawful, but because a question about it deserves an answer that does not sound like an excuse.

Neither of these is an obstacle. They are things that belong in the documentation before anyone asks, not things to improvise in the meeting.

If you need this sorted

If you are writing AI policy or need to document your AI use to a customer or a regulator, that is the kind of work I do. See how I work with AI governance and rollout.

Sources

How Claude marks AI-generated content, Claude Help Center

Code of Practice on Transparency of AI-generated Content, European Commission

Transparency obligations under Article 50 of the AI Act, European Commission

C2PA FAQ

Durable Content Credentials, Content Authenticity Initiative

From Brinvik: EU AI Act Article 50 and transparency, 3 August 2026

This work was produced in collaboration with AI. Overall: AI roughly 73 percent, Kim roughly 27 percent. Looking at production alone, the figures are AI roughly 89 percent and Kim roughly 11 percent. It is a qualified estimate, not a measured log.

Table of how the work split between AI and Kim across twelve phases, from finding the news to review, with share, AI percentage, Kim percentage and a reason for each phase. In total AI 73 percent and Kim 27 percent.
The split is computed last, over the finished work. The phases where Kim caught an error are the ones that raise his share.

FAQ

Frequently asked questions

No. Anthropic says themselves that a detected mark only means the content may have been processed by Claude, and that a missing mark proves nothing. On top of that, the tool for finding the marks is not publicly available yet.

It is unresolved. Claude Opus 5 arrived on 24 July 2026 and Claude Sonnet 5 on 30 June 2026, both before the 2 August cutoff in Anthropic's own wording, and there is a transition period for older models. Anthropic had not answered the question at the time of writing.

The watermark sits inside the text itself and travels with it when the text is copied. C2PA data is signed provenance metadata on an image file and sits in the file's metadata. The first is far more durable than the second.

Probably, unless someone has configured the system to preserve it. In a test, metadata disappeared on re-saving, on resizing and on converting to JPEG. That needs testing in your own setup, not assuming.

No. The signature covers Anthropic's obligations as the provider of the model. If you use AI with customers yourself, you have your own obligations under Article 50, and the supplier's signature does not discharge them.

On 2 August 2026. The code of practice attached to Article 50(2) is voluntary, and according to the European Commission it had been signed by roughly 190 organisations by the end of July 2026.

I would warn strongly against it. The supplier states that the absence of a mark proves nothing, and most other providers do not mark at all. A decision about a person on that basis is hard to defend if it is ever challenged.

Not publicly, at the time of writing. Anthropic says details of the detection mechanisms are coming in technical documentation later.

Get new essays by email.

Roughly twice a month. Same voice. No list rental, no retargeting.

Sign up for the Brinvik journal. Unsubscribe anytime. See our privacy policy.

Protected by Cloudflare Turnstile. No challenge, no CAPTCHA. Brinvik never shares your address.