← All articles
AI Visibility 101·17 August 2026·8 min read

How AI watermarking works, and what it means if you write with AI

Since 2 August, most text Claude writes carries an invisible marker showing where it came from, and the company applied the rule everywhere, not just in the EU. Here's how AI watermarking actually works, and what changes if you draft marketing copy with it.

By The Babel42 team

How AI watermarking works, and what it means if you write with AI

If you've asked Claude to draft a social caption, an email subject line or a full blog post in the last couple of weeks, that text almost certainly carries something you can't see. As of 2 August, new EU transparency rules require AI providers to mark generated content as artificial, and Anthropic responded by embedding an invisible watermark in Claude's text output worldwide, not just for EU users (TechCrunch, "Anthropic says it will watermark text generated by its AI models"). If any part of your marketing workflow touches an AI assistant, it's worth understanding how AI watermarking works before you assume it doesn't apply to you.

What changed on 2 August

Article 50 of the EU AI Act, its transparency chapter, became fully enforceable on 2 August 2026. It requires providers of AI systems that generate synthetic content to mark that output in a machine-readable format so it can be detected as AI-generated, with an exemption for AI that only performs standard editing or doesn't substantially change the input. Non-compliance can bring fines of up to €15 million or 3% of a company's worldwide annual turnover, whichever is higher (EU AI Act Service Desk, "Article 50: Transparency obligations for providers and deployers of certain AI systems").

Anthropic's response, reported the same week, was to start embedding an imperceptible watermark in text from new Claude models, and to sign AI-generated image and file outputs with metadata that follows the C2PA open standard, an industry format for recording where a piece of content came from. Anthropic applies the marking at the model level, so it's present whichever Claude product or surface the text comes from, and critically, it isn't limiting the change to EU users: it's rolling out globally, on the logic that maintaining two different versions of Claude, one watermarked and one not, isn't worth the engineering cost of a rule the company has to meet somewhere anyway (Euronews, "EU compliance, delivered globally: Anthropic to watermark Claude's output worldwide"). Older Claude models get until 2 December 2026 before the same marking applies to them.

How does AI watermarking work?

The general technique, used across the industry and not unique to Claude, works at the point the text is generated rather than being stamped on afterwards. A model doesn't just produce one possible next word at each step, it holds a ranked list of plausible options. A generation-time watermark nudges that selection in a specific, repeatable pattern, favouring certain words or token sequences over others in a way that's statistically detectable by a matching algorithm but invisible to a human reader, because the sentence still reads as ordinary prose (TechTarget, "What is AI watermarking and how does it work?"). Detecting it means running that same text back through a checking process that looks for the pattern, not scanning for a visible tag or a change in wording.

For Claude specifically, Anthropic says the text watermark doesn't change the meaning, quality or readability of a response, that nothing is added to the text and there are no hidden characters, and that it survives being copied, pasted and lightly edited. On how much rewriting strips it out, Anthropic's own answer is direct: "Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will" (Anthropic, "How Claude's text watermark works"). Two other limits matter just as much for anyone drafting copy. Detection doesn't work well on short passages, because there are fewer word choices for the pattern to live in, and the watermark is sparser on factual writing where the wording is constrained. Anthropic has also said a watermark detection API is coming but hasn't shipped one yet, so for now nobody outside Anthropic can actually check a piece of text. Image and file outputs work differently: rather than a hidden pattern in the content itself, Anthropic attaches signed metadata using the C2PA standard, the same provenance format camera and editing software vendors have been adopting, which records that the file came from an AI system without altering the pixels themselves.

Does this only apply if you're in the EU?

No. That's the part most marketing teams outside Europe are likely to miss. Anthropic built the watermark into Claude everywhere, not behind a regional flag, which means a UK, US or Australian team using Claude to draft copy today is already producing watermarked text, regardless of whether EU transparency rules apply to that business directly. This is a familiar pattern: a company builds one product to meet its strictest regulatory market rather than maintaining separate versions, so a rule written for one region ends up shaping what everyone gets. If you use Claude and assumed this was someone else's compliance problem, it currently isn't; it's already running under your account.

What this means if you draft marketing copy with AI

None of this requires you to add a disclaimer to every AI-assisted email or blog post. The marking duty under Article 50 sits with the AI provider, and separate deployer obligations mostly apply to specific cases like deepfakes or AI-generated content on matters of public interest, not routine marketing copy. Read the source directly with your own legal counsel before you treat any of this as compliance advice for your business, because the deployer side of Article 50 has more nuance than fits in a blog post.

What's worth doing regardless of the legal question is getting ahead of the disclosure conversation rather than waiting to be asked. A watermark existing doesn't mean a reader, a journalist or a platform will ever check for one, but the direction of travel is clear: content provenance is moving from a niche technical concern to something regulators, and increasingly readers, expect a straight answer about. A brand that already has a plain internal answer to "did AI write this" looks more credible than one that has to work it out under pressure.

The other practical point is about editing habits, not policy. If your process is "have Claude draft it, then lightly polish it," that draft-plus-polish text is very likely still carrying the watermark by the time it's published, per what Anthropic has said about it surviving light edits. If your process instead has a person substantially rewriting the structure and argument rather than swapping a few words, that's a materially different editing pass, and Anthropic's own line is that only a complete rewrite, where every word is replaced, removes the watermark entirely.

The wider point: content provenance is becoming visible, one way or another

We can't tell you whether watermarking changes how an AI assistant treats a page when deciding what to cite; nobody's published anything on that we could point you to, so we're not going to guess. What we can say is that the same forces pushing AI providers toward marking their own output, regulatory pressure and a general shift toward wanting to know where content actually came from, are the same forces behind why brands are paying closer attention to what AI assistants say about them, not just what they publish themselves.

We've written before about why some brands get cited by AI assistants and others don't: that's a separate mechanism to watermarking, about retrieval and sourcing rather than provenance marking, but both point at the same shift, that what a page says and where it came from are both becoming things a machine checks, not just a person. That's the territory Babel42's AI Visibility product sits in: not the mechanism behind AI outputs, but a weekly read on how AI assistants like Claude, ChatGPT and Perplexity are actually describing your brand when someone asks a buying question. Below is a real result from a demo workspace tracking an email marketing brand, Brevo, across two AI models.

Babel42's AI Visibility overview dashboard for a demo workspace, showing the brand Brevo appearing in 100% of buyer journeys with a 25% win rate, a 24% share of AI voice, and a "Value pick" perception summary, alongside its top-recommended competitor Omnisend

Two things worth doing this week

  • Write down your own answer to "did AI draft this." You don't need to publish it anywhere yet, but if a client, a journalist or a regulator asked tomorrow, know whether your team's policy is disclosure, heavy editing, human-only for certain formats, or something else, before you're asked under pressure.
  • If your team uses Claude for anything client-facing, check whether that matters for your contracts. Some client agreements already require disclosure of AI-assisted work; if yours doesn't mention it either way, that's worth a five-minute read rather than an assumption.

The short version

From 2 August 2026, EU rules require AI providers to mark generated content as artificial, and Anthropic responded by watermarking Claude's text output everywhere, not just for EU accounts. The watermark works by nudging word choice during generation in a pattern a detector can find but a reader can't, Anthropic says it survives copying and light editing, and only a complete rewrite where every word is replaced removes it. None of this obliges most marketing teams to add a disclaimer to routine AI-assisted copy, but it's a clear signal that content provenance is becoming something regulators and readers expect a straight answer about, which is worth getting ahead of before someone asks.

Enjoyed this?

Get the next dispatch in your inbox. No spam, unsubscribe anytime.

Occasional dispatches on listening, trends and the Babel42 roadmap. No spam, unsubscribe anytime.

Start listening free