On 2 August 2026, the same week Pangram 4 took Menlo’s check, new Claude models began embedding an invisible watermark in generated text. Anthropic applied it worldwide, not just in the EU. There is no opt-out. It rides the API, Claude.ai, Claude Code, Claude Cowork, Claude Tag, and the cloud partners. It is in the token choices, not in a header you can delete. Copy-paste carries it. Light editing may keep it. Anthropic’s own explainer: nothing is added to the text, no hidden characters, no extra tokens, no extra bill. Just a different source of randomness when the model picks among plausible next words, keyed so a detector with the secret can score how much the sequence looks like Claude.
They are using a version of Google DeepMind’s SynthID-Text. The paper is public. The key is not. The detection API is a private preview for regulators, law enforcement, media, researchers, schools, and enterprises that “need” it for compliance. You, the person who paid twenty dollars, cannot ask the machine whether the paragraph still has their brand on it.
Forbes recorded the obvious user objection: my own work, marked as AI, with no way to see the mark, and a school or a publisher who might one day buy the decoder. Anthropic’s answer is a shrug in legal prose. The watermark “doesn’t say anything about ownership or authorship, and doesn’t change a user’s rights under our terms.”
That sentence is the whole trick. If the terms already let them do this, they did not have to ask. If the terms did not describe an invisible, persistent, third-party-readable brand on every clause you take out of the box, then they changed the product and pointed at a document you cannot refuse without losing the tool. There was no checkbox. There was no regional off switch. There was a help center article after the fact.
They call it transparency. You cannot read it.
The EU AI Act’s Article 50 tells providers to mark synthetic output in a machine-readable way. Anthropic signed the Code of Practice in July 2026 with Google, Meta, Microsoft, OpenAI, and about 190 others. Fines for ignoring the Act can hit €15 million or 3% of global turnover. Compliance is real. This implementation is a choice.
Choice one: mark it in the EU, in a way a user can see or strip for their own drafts. Choice two: mark everyone on earth, hide the mark in the style, keep the detector, and tell developers that they still have to do their own Article 50 work. Anthropic picked two. They say they do not yet have a durable way to scope by region. “Not yet” is doing a lot of work for a company that can route a request to a data center.
C2PA on images is at least a standard other people can read. The text mark is a house key. Transparency that only the house can verify is a loyalty program for institutions. It is not a notice to the writer.
It brands the edit, not just the slop
Anthropic is careful, and the care is damning. The watermark fires when Claude was “involved in processing” the content. They cannot distinguish “Claude wrote this” from “Claude heavily edited this.” A translation Claude produces is fully marked because every word is its choice. A human draft you asked it to tighten can carry the signal. A student who pastes a messy paragraph in for grammar can walk out with a statistical brand a detector at the registrar may one day see, and that she cannot inspect.
Absence of a mark is not proof a human wrote it. Presence is not proof a human did not. Anthropic says this themselves. Then they hand the score to the same class of customer that already bought Pangram: schools, media, enterprises. Two black boxes, one “stylistic,” one “cryptographic-ish,” neither of them a conversation with the person who typed.
This is the watermark that was not in the deal you thought you had. You licensed a writing tool. You did not license a silent informant that follows the sentence into a magazine, a classroom, or a job application. Updating a support page is not consent. “Doesn’t change your rights under the terms” is what you say when you do not intend to offer a refund or a toggle.
Put it next to the library
The same company, in Bartz, built a central library from LibGen and PiLiMi — over seven million pirated copies, a judge said, retained even after some would never be used for training. The training on lawfully gotten books was fair use. The pirate library was not. The settlement is about a billion and a half dollars and an order to destroy the torrented files. Menlo was in that company early. Menlo led Pangram’s round nine days after the settlement’s final approval week. Then Claude started branding the output of the model that library helped make.
First the books leave the building without a license. Then the sentences leave your laptop with a license you cannot see. Then a detector, trained on books versus those sentences, sells the school a grade. That is not “transparency.” That is a closed loop around the people who still write.
I am not telling you to strip a watermark. The EU code tells deployers not to. I am telling you the mark was a change in what you bought, announced as if it were weather, and aimed at everyone who is not in Brussels because Brussels was a convenient story. Series start: the cleanup crew.
Sources: Anthropic, “How Claude’s text watermarking works”; Claude help center; TechCrunch, 11 Aug 2026; The Verge / SynthID; Forbes, 13 Aug 2026; TNW on Article 50; Bartz settlement coverage, Authors Alliance, 21 Jul 2026.