Text coming out of Claude can now carry something you cannot see: a watermark embedded directly into the text.1

For supported files, Anthropic is also attaching signed provenance metadata. It names SVG, PNG and JPEG as examples and uses the open C2PA standard.1

The obvious purpose is machine-readable transparency around AI output.

The limitation is more interesting. Anthropic explicitly warns that finding a Claude mark does not mean Claude “wrote” the content in the ordinary sense.1

Claude may simply have proofread, translated, summarized or converted it.

Two different kinds of mark

Anthropic describes two mechanisms.1

The first is for text. Supported Claude models weave an imperceptible watermark into generated text. Anthropic says it does not alter meaning or readability. Because the mark is embedded in the text itself, it travels through copy and paste and may survive some editing.1

There is not yet enough public technical documentation to know what “some editing” means across realistic workflows. Fixing punctuation and rewriting every paragraph are very different tests.

The second mechanism applies to files. When Claude generates a supported type, it can attach signed provenance metadata following C2PA. That signature can indicate that Claude processed the file and help show whether the signed file was later tampered with.1

Think of it less like a visible label and more like a small passport traveling with the artifact.

The mark follows the model, not only the Claude app

Anthropic says marking applies to supported models across Claude, its API, Claude Code, Cowork and Tag, with text watermarking also covering supported cloud-partner access.1

Models launched in the EU on or after August 2, 2026 support marking at launch under Anthropic's transparency commitments. The company says it is working on support for earlier models too.1

That matters to creative-tool developers.

If Claude is embedded inside a custom editor, provenance is not supposed to disappear simply because the user never visited claude.ai. Anthropic is designing the mark at the model layer.1

The history travels closer to the output itself.

“Processed by Claude” is the more useful phrase

This is also where the system becomes less magical and more honest.

Imagine an illustrator creates an image manually, then uses Claude only to convert the file. Or a writer drafts an article and asks Claude to fix spelling before publication.

The resulting content can carry a Claude mark. That does not retroactively turn the underlying work into AI authorship.1

Anthropic states the limitation directly: detection means content may have been processed by Claude. It does not establish full provenance or original authorship.1

That immediately breaks one tempting use case: treating the mark as a perfect cheating detector.

Provenance does not answer who had the idea, how much was generated, or which sentences came from a person. It records something that happened in the artifact's history.

A manufacturing chain instead of a verdict

That may be the better mental model for C2PA-style provenance.

Knowing that a physical part passed through a CNC machine does not tell you who designed it. It tells you one stage of the process.

Digital provenance can work the same way. A file passed through a particular tool, received a signature, then may have been edited later.

This becomes much more useful when creative workflows contain several systems. One model generates an image. Another retouches it. A human adds lettering. A platform recompresses the result. The binary question “AI or human?” quickly stops describing the object very well.

A chain of transformations is less emotionally satisfying than a large TRUE/FALSE stamp. It is also much closer to reality.

Detection is still unfinished

Anthropic says it is working on mechanisms that will let users and third parties detect Claude's watermarks and provenance metadata.1

Detailed technical documentation for that detection is still forthcoming.

That is a practical limitation today. Provenance only becomes broadly useful when reading the marks is as ordinary as creating them.

It will also matter how well marks survive export, compression, copying and transformations on other platforms.

For now, Anthropic is publishing the architecture and commitment more clearly than the full detection toolchain.

Generated content is beginning to keep manufacturing traces

For years we treated a digital file mostly as a final object: an image, a paragraph, a PDF.

Generative tools make that model less adequate. The same artifact can be written by a person, revised by one model, converted by another and published through a platform.

Claude's marks do not solve that history perfectly, and Anthropic is careful not to claim they do.

They do establish a useful idea: digital output can carry verifiable traces of how it was made.

For creators, publishers and tool builders, that history may be considerably more useful than another binary label saying “human” or “AI.”