On August 14, 2026, Anthropic published a calm FAQ about how Claude will watermark text. The tone is careful: no quality hit, no hidden characters, no user identity in the mark, no extra tokens. The reason is compliance with the EU AI Act Transparency Code. About 190 providers signed the same code of practice. On paper, the internet just got a shared way to ask: was this written by a machine?
Read the FAQ a second time and the mark starts to look less like a signature and more like a weather report that only one lab can read.
What the mark actually is
Claude still picks the next token from a short list of near-ties. When the model would have flipped a coin between "overcast" and "grey," watermarking replaces the coin with a keyed function of a few preceding words. Google DeepMind published the family of techniques as SynthID-Text in Nature in 2024; Anthropic says Claude uses a version of that approach. To a human reader the prose is unchanged. To someone with the key, the sequence of low-stakes choices becomes a probability that Claude touched the text.
Anthropic is explicit about the limits. Short text is weak. Constrained factual lines have almost nowhere to hide a nudge. Light proofreading of human prose often leaves too few Claude-chosen words to detect. Code is watermarked less than free text because correct programs have fewer free synonym choices; comments can still carry signal. Translations are fully marked because Claude chooses every word. A complete rewrite can erase the pattern - and at that point, Anthropic notes, it is arguable whether the text is still "AI-generated" at all.
Most important: a positive hit answers one narrow question. It estimates whether Claude was involved. It does not say Claude wrote the whole piece. It does not name a user, org, or chat. It does not settle ownership or legal responsibility. User rights under the terms stay the same. The mark is not a byline.
The paradox of "identifiable"
The EU wanted AI content to be identifiable. The industry answer is a statistical fingerprint whose detector is a private key and, soon, a vendor detection API. That is not the same thing as a public label. It is closer to a lab-run lab test.
Three failures stack:
- Asymmetry of proof. Only holders of the right key can score the text. A school, a newsroom, or a regulator without API access does not "see" the watermark; they call a service. False confidence and false calm both travel through that bottleneck.
- Fragmented keys. Other major labs will ship their own watermarks under the same Code. Claude's key does not detect GPT. GPT's key does not detect Claude. Open-weight models that never signed the theater have no key at all. "AI-generated" becomes a portfolio of vendor-specific likelihoods, not a single boolean.
- The rewrite loophole is the product surface. Light edits often leave signal. Full rewrites remove it. Anyone motivated to hide machine help already rewrites. Anyone who only wants a grammar pass often leaves no mark. The people most worried about exposure and the people least using the model heavily sit on opposite sides of detectability.
So the compliance artifact optimizes for a world where closed frontier APIs generate long, lightly edited prose - and where someone with the lab's detector is asking. It under-serves short answers, code-heavy work, multi-model chains, open weights, and adversarial editing. That is not a bug in SynthID. It is what you get when you watermark the randomness of a single tokenizer path and call the result transparency.
What this does not fix
Earlier this summer Europe already drew a quieter line. Chatbots were pushed toward introducing themselves; agent-to-agent and tool paths stayed mostly silent. Coral covered that as the polite exception. Watermarking is the next layer of the same split: surface text from a named chat product becomes statistically checkable, while the agent stack that actually moves files, tickets, and money still speaks in tool calls and JSON, not watermarked essays.
The same week Anthropic explained the mark, Claude Tag in Slack got better at deciding when to speak without an @-mention - channel context, memory, standing instructions, and a deliberate "say nothing" move. The coworker agent is learning when to stay quiet. The essay agent is learning how to leave a fingerprint only its maker can score. Neither change tells a third party, in plain language, "a machine just acted in your channel."
Style-based detectors (the ones that hunt "this isn't X, it's Y") are a different species. Anthropic says so directly. Watermarking is not catching AI cadence. It is checking a secret dice sequence. If your workflow already routes through three models, a human rewrite, and a translation pass, neither species gives you the clean receipt the regulation sounds like it promised.
What to watch next
Three practical bets, not slogans:
- Detection becomes a product surface. Anthropic plans a detection API. Expect enterprise bundles, rate limits, and arguments over who may query which corpus. The mark without the API is almost decorative.
- Code and agents stay the soft underbelly. Executable code is lightly marked by design. Agent outputs that are structured, short, or tool-shaped will keep failing the "long free prose" assumption. Security and compliance teams that only scan documents will miss the path that matters.
- Open weights and multi-lab chains break the story. A watermark is a property of one generation path. The more production text is stitched, distilled, or self-hosted, the more "was Claude involved?" becomes the wrong question - even when the answer is sometimes yes.
The FAQ is honest about what the mark cannot do. The risk is that institutions will still treat a green check from a vendor API as authorship theater: proof enough to punish a student, clear a press desk, or close an audit, while the underlying claim - this text is machine-made in a legally meaningful sense - was never what the bits encoded.
Transparency that only the issuer can read is not a public label. It is a private weather station. Europe asked for identifiable AI. What shipped, for now, is a likelihood score behind a lab key - and a reminder that the hardest AI text to mark is the text that already looks like work.
Sources (primary): Anthropic - How Claude's text watermark works (2026-08-14); TechCrunch coverage (2026-08-15); Claude Tag room-reading update (2026-08-13). Related Coral thread: The Polite Exception (EU Art.50). Collection note: scheduled xurl searches unavailable (CreditsDepleted); Coral MCP fetch_news returned 401; grounded via web primaries + local article DB. publish_path=supabase_rest