Does Claude Watermark Your Code? What Anthropic's New AI Mark Actually Proves
Does Claude watermark code? Anthropic says supported models can mark text worldwide, but detection proves processing—not authorship, privacy, or ownership.
Anthropic now confirms that text generated by Claude Fable 5.1 and Claude Mythos 5.1 carries its statistical watermark on every platform where either model is available. That includes API and Claude Code paths using those exact models. Code can carry less detectable signal than prose because exact syntax leaves fewer equally valid token choices, while comments and other flexible text can still be marked. Anthropic has not published code-specific reliability thresholds or opened its detector to the general public.
The bigger catch is what detection means. Anthropic says a detected mark can indicate that content was processed by Claude, even when Claude only proofread, translated, summarized, or converted human work. A mark is not proof that Claude authored the ideas, wrote the entire file, owns the output, or stored the source material. And no detected mark is not proof that AI was absent.
What Is Confirmed
Anthropic's official guide to marking AI-generated content describes two different mechanisms:
- Embedded text watermarks: a supported Claude model weaves an imperceptible pattern into generated text at the model level. Anthropic says the pattern travels with copied text and may survive some editing.
- Signed provenance metadata: supported generated file types, including SVG, PNG, and JPG, can receive cryptographically signed information identifying the model and generation time and indicating whether the file changed after generation.
Anthropic says the policy applies to output from supported models across Claude Platform, Claude, Claude Code, Claude Cowork, and Claude Tag, wherever Claude is offered worldwide. Models launched in the European Union on or after August 2, 2026 support machine-readable marking at launch. Anthropic says it is still working to add support to models released before that date.
Anthropic's September 1 Fable 5.1 documentation removes one earlier uncertainty: text from Fable 5.1 and Mythos 5.1 is watermarked on every platform where those models are available. Anthropic says the mark adds no tokens or hidden characters, carries no information about a person, organization, or chat, and does not require a request or response-format change.
The policy responds to the European Union's AI Act transparency requirements. The European Commission's official Code of Practice page says Article 50 obligations became applicable August 2. Providers must make generated audio, images, video, and text machine-readable and detectable as artificially generated or manipulated when technically feasible.
The Commission describes the goal as provenance and transparency. It does not say a watermark proves truth, authorship, copyright ownership, confidentiality, or the absence of human work.
Anthropic also confirms important limitations:
- A detected mark only suggests the content may have been processed by Claude.
- Claude may have edited or transformed material that originated with a person.
- The content may have been modified, excerpted, or combined with other material after Claude processed it.
- A mark may become undetectable after heavy editing, paraphrasing, translation, or mixing.
- Very short passages may not contain enough signal for reliable detection.
- File conversion, re-saving, or screenshots can strip signed metadata.
- Output from a model released before marking support may be unmarked.
Those caveats are not speculation from critics. They come from Anthropic's own documentation.
What Is Still Unclear
Anthropic has now published the design family and confirmed two supported model identifiers, but an ordinary user still cannot independently test the complete claim.
Anthropic's updated text-watermark explainer says the system uses a version of Google DeepMind's SynthID-Text approach and that a detection API is in private preview for eligible organizations. It still does not provide:
- a public detector or detection API;
- a minimum reliable text length;
- measured false-positive and false-negative rates;
- separate test results for prose, source code, structured data, or other constrained text;
- independent validation of the claim that meaning, quality, and readability are unchanged; or
- a reliable way to calculate how much of a mixed document Claude contributed.
It is therefore still too broad to say “Claude watermarks all code now.” The defensible version is narrower: Fable 5.1 and Mythos 5.1 watermark generated text across every platform where those models are available, but exact code can carry less signal and detection depends on length, flexibility, and later transformation.
The distinction matters because current selectable models may have launched before the August 2 cutoff. Anthropic says older-model support is in progress, not complete. A product name alone does not reveal whether a particular response came from a marked model.
Does Claude Watermark Code?
Potentially yes, when a supported Claude model generates the code as text.
Anthropic does not publish a carve-out saying source code from Claude Code is excluded. Instead, its guide says text marking happens at the model level and applies across Claude Code. That supports the conclusion that generated code can be marked.
But three boundaries keep that answer from becoming “every file is tagged”:
- The model must support marking. Fable 5.1 and Mythos 5.1 are confirmed; support for older models is still being added.
- The generated material must carry a detectable signal. Anthropic says exact code generally has less watermarking because correctness constrains token choice, while comments can contain more signal. It has not published code-specific thresholds.
- The artifact path matters. Text pasted into a source file is different from an image with signed provenance metadata. Anthropic names SVG, PNG, and JPG for the signed-file path, not ordinary
.py,.js,.ts,.md, or.txtfiles.
That third point prevents a common misunderstanding. A statistical or model-level text mark does not necessarily look like visible metadata attached to a code file. Conversely, ordinary HTML formatting, editor metadata, Git history, telemetry, and file provenance are separate signals. Finding one does not prove the presence of another.
What Does A Detected Claude Mark Actually Prove?
The safest answer is: it supplies evidence that a supported Claude system may have processed the detected content.
It does not, by itself, prove:
- that Claude originated the underlying idea;
- that Claude wrote every sentence or line;
- that a person did not review or substantially revise the result;
- that the result is accurate;
- that the publisher violated a school, employer, client, or platform policy;
- that Anthropic owns the work;
- that a prompt, file, or conversation was retained;
- that the content was used for model training; or
- which user or account generated it.
That is why Axios focused on proofreading and formatting: a communications team could submit human-written copy for cleanup and receive marked output. The signal “Claude processed this” is materially different from the claim “Claude authored this.”
The same logic applies in software development. A developer might ask Claude to rename variables, explain a compiler error, translate a function between languages, or format a file. A later detector cannot reconstruct the full division of labor from a binary mark.
Can Proofreading Human Work Add A Claude Mark?
Yes, according to Anthropic. Its guide explicitly says output can carry a mark when Claude proofreads, translates, summarizes, or converts material whose ideas, text, or data came from another source.
This is one reason downstream policies should not treat detection as a verdict. A useful review needs at least four separate questions:
- What did the person supply?
- What did Claude change?
- What does the relevant policy prohibit or require disclosing?
- Is there a revision history or other evidence of the actual process?
If an employer prohibits undisclosed AI assistance, a mark may be relevant evidence. If a policy prohibits only fully generated work, the same mark may be insufficient. The detector cannot replace the policy language.
This also connects to a broader issue examined in whether AI rewriting creates a recognizable model style. Stylistic resemblance, statistical detection, and a provider-embedded mark are three different signals. None should be silently substituted for the others.
Does Copying And Pasting Remove The Watermark?
Anthropic says the text mark is part of the generated text, so ordinary copying and pasting should carry it with the words. That description rules out the simplistic assumption that pasting into a plain-text editor necessarily removes the mark.
Anthropic also says a complete rewrite can remove the mark, while light editing probably will not remove it completely. Short passages, constrained factual text, proofreading, and exact code can carry too little signal for confident detection. It has not published the threshold at which that happens or a public tool that readers can use to verify the result.
For supported images and SVG files, the mechanism is different. Signed provenance metadata can be stripped by re-saving, format conversion, screenshots, or other transformations. A broken or missing signature does not prove the file was never generated or edited with AI.
This asymmetry is important:
- Text: copying may preserve the distributed signal, but larger semantic changes may weaken it.
- Supported files: copying the original file may preserve signed metadata, while rendering and re-exporting can remove or invalidate it.
Do not use “I copied it through Notepad” or “the detector found nothing” as conclusive evidence of origin.
Is A Claude Watermark A Privacy Risk?
A provenance mark and a privacy policy answer different questions.
The mark asks: Can this output be recognized as having passed through a supported Claude system?
Privacy questions ask:
- Where was the prompt processed?
- Was normal chat history stored, and where?
- Was content used for model training?
- How long can request, safety, billing, or abuse records remain?
- Which providers or tools received the data?
- What can the user delete?
Anthropic's marking guide does not say the embedded text watermark contains a person's identity, account ID, prompt, or conversation. It also does not publish the full encoding design. Claims that every mark secretly identifies the individual user are therefore unconfirmed.
At the same time, provenance can have consequences. A provider-origin signal could matter in publishing, procurement, education, software audits, or workplace disclosure. Those are governance concerns even when the mark contains no personal identifier.
The right response is to avoid collapsing provenance into privacy. Turning off model training does not necessarily stop retention, as explained in why training controls and chat retention are separate. Likewise, a detectable output mark does not tell you whether the source prompt was retained or trained on.
Use The MARK Check Before Trusting A Detection Claim
When a person, platform, or vendor says it found a Claude watermark, use this four-part check.
M — Model
Identify the exact model and generation date. Fable 5.1 and Mythos 5.1 are confirmed as marked; older models can have different rollout status.
“Created in Claude” is not enough. Claude products can expose different models, and Anthropic's transition is model-dependent.
A — Artifact
Determine what was tested: a prose passage, source code, a mixed document, an SVG, or a re-exported image.
Text watermarks and signed provenance metadata have different failure modes. A detector designed for one should not be assumed to validate the other.
R — Role
Document what Claude did. Did it originate the draft, rewrite one section, translate it, format it, or proofread human work?
A detected mark does not answer this question. Revision history, prompts, commits, tracked changes, and human testimony may be more informative.
K — Known Limits
Ask for the detector version, confidence, minimum length, model coverage, false-positive and false-negative rates, and what transformations occurred after generation.
Anthropic's detector is in private preview for eligible organizations, not generally available. A confident third-party claim should therefore identify what detector and access path it used, along with the model coverage and threshold. Generic “AI detectors” are not automatically Claude-mark detectors.
What The Policy Means For Teams Using Claude Code
Teams do not need to panic or purge every Claude-assisted commit. They do need a policy that matches the evidence.
A practical workflow is:
- Inventory which Claude models and products the team uses.
- Record whether the exact model is confirmed as marked; Fable 5.1 and Mythos 5.1 are confirmed today.
- Decide whether AI assistance, fully generated code, or only undisclosed use matters to the organization.
- Preserve ordinary development evidence such as commits, reviews, tests, issue discussions, and design decisions.
- Do not treat a provider mark as proof of ownership, security, quality, or policy violation.
- Keep confidential code and credentials out of prompts unless the chosen service, plan, contract, and workflow are appropriate for that data.
- Revisit the policy when Anthropic expands detector access or confirms additional models.
This is also a reminder that code provenance is not code security. A marked function can be safe or vulnerable. An unmarked function can be safe or vulnerable. Review, tests, dependency controls, secret scanning, and deployment boundaries remain necessary.
How This Compares With OpenVeil
OpenVeil and Claude's marking policy address different parts of the AI trust problem.
OpenVeil is a hosted, privacy-focused AI workspace for chat, files, private search, voice, images, and video. Its documented boundaries include browser-local normal chat history and no use of prompts, uploads, media, or outputs to train foundation models. Active requests still require processing by OpenVeil and necessary providers.
OpenVeil does not document a Claude-watermark detector, guarantee that every output is unmarked, prevent a model or downstream service from adding provenance information, or make active processing fully offline or anonymous. Readers should not infer those promises from this article.
The useful comparison is the set of questions each person can verify. Before trusting any AI service, separate local history, training, retention, provider processing, connected tools, and output provenance. OpenVeil's AI privacy-claim checklist provides a broader framework, while OpenVeil's file-training explainer focuses on uploads and training controls.
If browser-local normal chat history and a documented no-foundation-model-training boundary fit your needs, you can try OpenVeil. Treat output marking as its own requirement and verify it separately for the exact model and media path you use.
Frequently Asked Questions
Does Claude watermark every response today?
No. Anthropic confirms Fable 5.1 and Mythos 5.1 text is watermarked on every platform where those models are available. Support for older models is still being added, and short, constrained, lightly edited, or transformed content may not contain enough detectable signal.
Does Claude Code watermark source code?
Code generated as text by Fable 5.1 or Mythos 5.1 falls under the watermark policy. Anthropic says exact code generally has less watermarking because correctness limits alternative token choices, while comments and other flexible text may carry more. It has not published code-specific detection thresholds, so “every Claude Code file is detectably watermarked” is not confirmed.
Can a Claude mark identify the user who generated the text?
Anthropic says the text mark contains no identifying information and cannot be traced to a person, organization, or chat. The mark tests likely Claude involvement; it is not an account identifier.
Does a detected mark prove plagiarism or policy violation?
No. Anthropic says Claude may only have proofread, translated, summarized, or converted human-originated work. Whether that use violates a rule depends on the rule and the actual workflow.
Does no detected mark prove a person wrote the content?
No. Older models, short passages, heavy edits, translation, mixing, stripped file metadata, or another AI system can all produce content without a detectable Claude mark.
Is C2PA the same as the text watermark?
No. Anthropic describes embedded patterns for text and signed provenance metadata for supported files such as SVG, PNG, and JPG. They are related provenance controls with different technical behavior.
Does the watermark mean Anthropic retained my prompt?
Not by itself. Output marking and prompt retention are separate data-handling questions. Check the applicable Claude product, plan, model, account controls, and contract.
Bottom Line
Claude Fable 5.1 and Mythos 5.1 watermark generated text worldwide on every platform where those models are available, including Claude Code paths. That does not mean every source file will be detectably marked: exact code, short passages, proofreading, and later edits can leave too little signal.
Most importantly, a detected mark means less than many headlines imply. It can indicate that Claude processed the content; it does not prove that Claude authored everything, that a person did nothing, that the work is false or plagiarized, that Anthropic owns it, or that the source prompt was retained. Missing detection proves even less.
Until Anthropic opens detector access and publishes sample thresholds and reliability data, treat Claude marks as one provenance signal—not a verdict about authorship, privacy, quality, or trust.
Updated September 2, 2026 after Anthropic confirmed Fable 5.1 and Mythos 5.1 watermark coverage and described the private-preview detector.