Regulation & Policy

Anthropic Is Watermarking Every Claude Output — And Users Are Canceling Over It

Starting August 2, every word Claude generates carries an invisible cryptographic signal. The move is driven by EU law — but the backlash is coming from everywhere.

ETBy Editorial Team·6d ago·6 min read·0 views
Anthropic Is Watermarking Every Claude Output — And Users Are Canceling Over It
Photo: Pexels

Every sentence Claude writes now carries a hidden mark. Not a disclaimer, not a visible label — the watermark is embedded in the words themselves, invisible to any reader but detectable by a machine with the right key. Anthropic confirmed this week that it has deployed text watermarking across all Claude models launched on or after August 2, 2026, using a technique developed by Google DeepMind called SynthID-Text. The announcement triggered one of the most vocal user revolts the company has seen.

How It Actually Works

The watermarking does not add extra characters, modify punctuation, or append anything to Claude's responses. Instead, it operates at inference time — the moment the model is choosing which word to generate next. When Claude faces a low-stakes choice between two roughly equivalent words or phrases, a secret cryptographic key quietly influences which option gets selected. Over the course of a response, enough of these subtle nudges accumulate to create a statistically detectable pattern — one that is invisible to a human reader but verifiable by software holding Anthropic's key.

The watermark carries no identifying information and cannot be traced to a specific user, organization, or chat session. What it does signal is simply: Claude was likely involved in generating this text.

The model itself is not aware it is being watermarked, and the watermarking produces no extra tokens, meaning there is no impact on speed or cost to serve. Anthropic confirmed it has a "negligible impact on the speed of models."

The system is built on the same SynthID-Text foundation that Google DeepMind published in a Nature paper in 2024 — a family of approaches that traces back to a proposal by Scott Aaronson in 2022. Anthropic describes the secret key as being similar to pi in its complexity and randomness — a near-infinite string that is effectively impossible to reverse-engineer.

The EU AI Act Is the Reason

The EU AI Act's Transparency Code, which took effect on August 2, requires AI companies to mark AI-generated or edited content in a way that other systems can identify. Anthropic joined OpenAI and Google in outlining how it plans to comply with the transparency requirements.

Anthropic, along with several other major AI model providers and around 190 total signatories, signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026. Rather than limiting the watermark to European users — which it says it does not yet have a reliable way to do — Anthropic applied it globally from day one.

Models launched before August 2, 2026 are covered by the EU's transition period, and Anthropic says it is working to add watermarking to those models over the coming months. A public watermark detection API is also coming, though it has not yet launched.

What the Watermark Can't Do

The system has real limitations that Anthropic has been upfront about.

Claude-generated text may lose the signal if it is heavily edited, paraphrased, translated, or mixed with other writing. Short passages may also not contain enough text for a reliable signal. Light editing, however, is unlikely to strip it entirely — Anthropic acknowledged that "light editing probably won't remove the watermark completely."

Code gets special treatment. Anthropic notes that watermarking can still be used in parts of code where arbitrary choices exist, such as comments, but says it should have a negligible effect on the actual code produced.

Crucially, the watermark is not a guarantee. Its absence does not confirm something is human-written, and its presence does not prove Claude wrote everything. It is, as one Anthropic engineer put it, "not perfect — you can edit it, but it's a first step."

The Backlash

The reaction online was swift and, in places, furious.

"This is bullsh*t" — X user, upon seeing Anthropic's watermark announcement post

"Why should I, being a non-EU citizen, watermark my work generated by a paid subscription of Claude?" — X user

"The only reason you wouldn't want this is to lie to people." — Reddit counter-argument, r/ClaudeAI

Math and AI influencer John Ennis posted a screenshot of his subscription cancellation on X, citing Anthropic's "ridiculous watermark idea" as the cause. Policy worker Arturo Villarroya and consultant Richard Echols both canceled their $100-a-month Claude Max subscriptions, citing concerns that invisible markers could falsely flag original work.

Santiago Alessandro Rivera Martínez, a software engineer and founder of digital agency Directa, said Anthropic's watermark reinforced his concerns about becoming too dependent on Claude.

A developer in France even released a tool on GitHub claiming to remove Claude's watermarks.

On Reddit, one poster characterized the watermarking as "a conspiracy against innocent Claude users," while another fired back that the backlash only exists because people want to deceive others with AI.

Despite the noise, Anthropic told reporters it has not seen a trend of an uptick in cancellations since it announced the watermark, and the company had 300,000 business customers as of September 2025 — a number widely expected to have grown significantly since then.

The Broader Industry Shift

Anthropic is not doing this alone. Google continues to integrate SynthID technology for text and media. OpenAI has deployed similar watermarking for supported outputs. X has implemented visible "Made with AI" tags on content it determines to be AI-generated or manipulated — a tag that notably appeared on the resignation post of outgoing White House press secretary Karoline Leavitt before disappearing.

The direction of travel is clear: AI-generated content is going to be marked, one way or another, across every major platform. The EU AI Act is the regulatory engine behind it, but the logic extends well beyond Europe.

What This Means

The watermark debate is really two separate arguments happening at the same time. One is about the EU law and compliance — largely uncontroversial, since Anthropic had little choice. The other is about what it means for users who rely on Claude professionally and now worry that their delivered work carries a permanent, invisible marker of AI involvement — one they cannot see, cannot remove with light editing, and cannot opt out of.

Anthropic's position — that the watermark is undetectable to human readers, carries no personal data, and exists only to satisfy a regulatory requirement — is technically accurate. But it does not fully address the professional anxiety driving the cancellations. For consultants, policy workers, developers, and writers whose clients or employers may eventually gain access to a detection API, the question is not whether the watermark changes the text. It is what the watermark signals about the work.

More like this