Find an image Claude made for you last week. Drag it onto claude.com/check-content. The tool is free and needs no login. There is a fair chance nothing comes back.
And here is the awkward part: you cannot tell from an empty answer whether the file never carried a mark, or whether somebody saved it once along the way. The two look identical.
Since 1 September, Claude has been marking the words
Claude Fable 5.1 and Claude Mythos 5.1 arrived on 1 September, and both put a watermark into the text they write. Anthropic is explicit about it: marking requires no changes to your requests or to how you handle the response.
Read that again. There was no setting for anyone to switch on. There was no note to the administrator. If your company uses either model, your text started carrying a mark without anyone at your end deciding anything.
This covers models released on 2 August or later. For the older ones Anthropic says support is being rolled out over the coming months, and gives no date. So if you are running on something older than August, the answer for now is that you do not know.
The marking runs across Claude, Claude Code, Claude Cowork, Claude Tag and the API, and it follows you whether you call the model directly or through AWS, Google Cloud or Microsoft Foundry.
Alongside it sits a completely separate mechanism. A Claude watermark in text is one thing. Files Claude produces get something else entirely: a Content Credential under the C2PA standard, a small cryptographically signed note in the file's metadata. That is what the checker in the opening reads. The two systems share a name in everyday speech and have very little else in common, and the difference between them is the whole reason this article exists.
Where the watermark settles
When I wrote about the marking in August, I had to note that Anthropic had not said precisely how a Claude watermark is made. Two days later they did.
The mechanism is simpler than you might expect. As a language model writes, it picks word by word, and along the way there are constant moments where several words would do equally well. Should it say "submitted" or "delivered"? "Asked for" or "requested"? Normally a source of randomness settles that. Anthropic has replaced that source with a key, combined with the words immediately preceding. The upshot is that the choices are no longer random but follow a pattern Anthropic can recognise afterwards.
The method builds on a version of SynthID-Text, published by Google DeepMind in Nature in 2024 and tracing back to a 2022 proposal from Scott Aaronson. So it is not something Anthropic invented in-house, and it is published research rather than a closed vendor scheme.
Two things follow from the mechanism.
The first is reassuring. The mark only lands in the choices where several words were equally good. Your text has not been made worse to make room for a mark. Nobody swapped a precise word for a vague one.
The second is the one that matters. Anthropic describes what the mark is for, and they are careful about it: a way of determining the likelihood that Claude was involved in writing the text. Likelihood. Not proof, and not a name on an author.

A translation from Claude carries a mark in every word
Here it gets concrete for a Danish company, and here is where most people guess wrong.
Anthropic writes that a translation produced by Claude carries a watermark, because in that case every word is chosen by Claude. And they write that when Claude proofreads text a person wrote, there is very little for the watermark to attach to, because nearly all the words are still the person's.
Put those two sentences side by side and the result turns the intuition upside down.
The document your people worked hardest on, the Danish one a person thought through and wrote and Claude afterwards fixed the commas in, barely carries a mark at all. The English version Claude translated carries a mark in every single word. Same thinking, same author, same afternoon. Opposite readings.
And it is usually the English version that leaves the building. It goes on the website, it is attached to the proposal, it is sent to the customer abroad. The Danish draft that shows a person thought of it sits in a folder with a name nobody remembers.
Marking also varies with what the text is. Anthropic describes it as sparser in fact-dense passages, where fewer words can be swapped without making the content wrong. In code there is less still, for the same reason: when the output has to be exact, there are fewer free choices to lay a pattern into. And on short pieces of text detection works poorly, simply because there are fewer choices to go on.
At the other end the mark is stubborn. Anthropic describes only the two endpoints: light editing probably will not remove it completely, and only a full rewrite, where every word is replaced, takes it away.

Try it yourself: the checker is free
This is the new part, and it is the one you can act on today.
Anthropic has opened a tool at claude.com/check-content that checks whether a file carries a Content Credential from Claude. It is free, it needs neither account nor login, and the file stays on your own machine. It takes image, video and audio formats up to 100 MB.
Note what the page itself says: the tool does not check text. Claude marks text with a watermark in the writing itself, and that is a different matter.
So far, so good. Now the caveat, and it is what makes the tool hard to use for anything.
The checker reads the note attached to the file. It does not read the file. And a Content Credential lives in metadata, which is exactly the part of a file that falls away under ordinary handling. I tested that myself in August. I saved the file, rescaled it and converted it to JPEG, and every time the Content Credential was gone. The test is in the article from 12 August, and it still holds.
Which means an empty answer from the checker is the ordinary answer. A file Claude genuinely made, then scaled for the website or run through a design program, comes back with no Content Credential. It looks like a file Claude never touched.
In August I wrote that no public tool existed, for you or for me. That is no longer true for the files. It is still true for the words, and that is the half that matters.

The list of people who can read the watermark
Take Anthropic's own reasoning first, because it is neither hidden nor unreasonable.
They write that they are implementing watermarking to comply with the AI Act, and they signed the EU code of practice on transparency of AI-generated content in July. The requirements took effect on 2 August. This is a provider doing something the law asks of it, and putting the underlying research on the table.
Then there is the other end. Detection of the text watermark is in private preview, and Anthropic names who it is open to: regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations and civil society groups in the EU. On top of that, enterprises with their own duty to verify under the Act. Access is requested through a form.
Read the list again with your own company in mind. It is a list of parties who might one day ask a question about something you published. If you do carry a verification duty under the Act, there is a door, and it is worth looking into. If you do not, there is not.
And then there is the part nobody can do anything about: Anthropic publishes no error rate, no word threshold and no accuracy figure for the detection. There are no numbers. I have looked for them. Nobody outside the access list can produce them, because nobody outside the list can run the test.
My own position, and this is where I land: the mark that can be read is the one that proves least. The Content Credential on the file disappears the first time somebody saves it, and it says nothing about who wrote anything. The watermark in the words holds through editing and translation, and that is the one you cannot get to.

A proposal, a translation and an image
Try the distinction on three things sitting on your own desk right now.
The proposal Claude drafted. It is text, so there is no Content Credential to check. If a person at your end wrote most of it and Claude tidied it, there is almost no mark. If Claude wrote it and a person edited lightly, it carries a mark, and a light pass probably will not remove it completely. Nobody at your end can verify which of the two applies.
The English translation of it. That is the most heavily marked text you produce, because every word is Claude's choice. It is also the version the customer reads, and the one that stays in their inbox.
The image at the top of the proposal. It is the only one of the three you can check yourself, and the answer is probably that there is nothing there. Not because Claude did not make it, but because it has been saved since. A negative check does not tell you what you were hoping it would.
Three items from one document. One you can verify, and that answer is weak. Two you cannot, and those are the durable ones.
Who at your end answers when somebody has read the mark
Here is what is left once you strip out everything the technology cannot do.
A regulator, a journalist or a fact-checker can read a mark that nobody at your end can read, on a text you published yourself. Nobody has forbidden you anything, and nobody has you in their sights. That is simply how the access is distributed right now.
The question it leaves is practical and has nothing to do with technology: who at your end can say whether a particular text came from you, and how it came about, if the question arrives from outside six months from now? Not who clicked approve. Who read it, and who can account for it.
In most smaller companies the answer is nobody, because nobody was given the job. The problem is organisational, and no tool is coming that solves it. Somebody has to own it.
That is exactly the job a retainer covers on the Claude side: somebody who knows what is set up, what it writes, and what you say when somebody asks.
The document you send out on Friday
On Friday a document leaves the building. Maybe a proposal, maybe a report, maybe a page for the website.
The English version of it carries a mark in every single word, if Claude translated it. The image at the top probably lost its Content Credential the first time somebody saved it. And the Danish draft, where a person at your end actually did the thinking, is sitting somewhere nobody is looking.
You cannot read any of it. You may as well know that before you hit send.
FAQ
Frequently asked questions
No. The checker at claude.com/check-content takes files only, and the page says so itself: it does not check text. Detection of a Claude watermark in text is in private preview and requires you to be in one of the categories Anthropic has named.
Nobody outside Anthropic knows yet. Anthropic says models released on 2 August or later apply it, and names Fable 5.1 and Mythos 5.1. For the older models they say support is being rolled out over the coming months, without giving a date. I asked that question in August and it is still open.
The sources do not describe a way to turn it off. They also do not say it is impossible. I am not going to claim either when Anthropic has not written it.
It is the other way round. If Claude does the translating, the English version carries a mark in every single word, because every word is Claude's choice. A translation is the most heavily marked text most companies produce.
There is no figure. Anthropic describes only the two endpoints: light editing probably will not remove it completely, and a full rewrite, where every word is replaced, does. Everything in between is undescribed, and the absence of a threshold is itself the answer.
Less than ordinary text. The mark lands in choices between words that are equally good, and in code the output has to be exact, so there are fewer free choices to lay a pattern into.
Possibly. Alongside regulators, law enforcement, media, fact-checkers, researchers, educational organisations and EU civil society, Anthropic names enterprises with their own duty to verify marking under the Act. If you carry that duty, you can request access through the form on Anthropic's page.
No. The signature covers your supplier's own obligations as provider of the model. Whoever puts the model to work and publishes the text is a deployer under the Act and carries their own obligations. I have written about that split in [the article on the transparency requirements](https://brinvik.com/en/journal/eu-ai-act-transparency-rules-august-2026).
Sources
Anthropic, How Claude's text watermark works, 14 August 2026 →
Anthropic Help Center, How Claude marks AI-generated content →
Anthropic, Claude Content Checker →
Claude Platform, release notes, 1 September 2026 →
Dathathri et al., Scalable watermarking for identifying large language model outputs, Nature, 2024 →













