Funny how the same people who spent years telling us AI would “democratize knowledge” just quietly built an invisible tracking system into every single word their machine spits out. Anthropic, the company behind Claude, announced this month that all text generated by its models now carries an imperceptible, machine-readable watermark. You can’t see it. You can’t opt out of it. And it follows your text everywhere it goes.
Two marks, both machine-readable. The first is woven into the words themselves, an invisible signature baked into the language so that it survives copying, pasting, and moving between applications. The second is signed provenance metadata attached to image files, .svg, .png, .jpg, using something called the C2PA open standard. The text watermark is applied at the model level, which means it shows up no matter how you access Claude. The API. Claude Code. Cowork. Claude Tag. Even when the model runs through AWS, Google Cloud, or Microsoft Foundry. There is no door marked “exit without surveillance.”
Nicolás Eduardo Feredjian from Parque Rivadavia – Buenos Aires, Argentina (CC BY 2.0) via Wikimedia CommonsModels launched on or after August 2, 2026 get the watermark from day one. Older models are being brought into line during a “transition period.” Ask yourself who benefits from a transition period. The answer is always the same: the people doing the transitioning, not the people being transitioned.
Anthropic says the watermark identifies that Claude “processed” the text, not that Claude wrote all of it. Read that sentence again. Someone could write an original passage themselves, run it through Claude for a proofread or a translation, and the resulting text carries a Claude fingerprint. The company is building detection tools so third parties can scan writing and check for the mark. So now some employer, some publisher, some government agency can run your words through a scanner and find out you once asked a chatbot to fix your grammar. That’s not transparency. That’s a leash.
Anthropic admits the watermark has limits. Heavy editing, substantial paraphrasing, translation, or mixing generated text with other writing can make the signal undetectable. A company called WriteHuman is already offering a service to rewrite AI drafts before publishing so the watermark disappears. So the people with money and tools can scrub the mark. The regular person who just wants help writing a cover letter or organizing their thoughts? Tagged. Tracked. Categorized.
derivative work: Unitfreak (talk) Ploughmen_Fac_simile_of_a_Miniature_in_a_very_ (Public domain) via Wikimedia CommonsHere’s what gets me. The experts will tell you this is about “provenance” and “accountability.” Nice words. They always have nice words. But provenance for whom? Nobody is watermarking the press releases from Anthropic’s PR department. Nobody is tagging the statements from the policymakers who will inevitably use this technology to decide what counts as “real” writing and what doesn’t. The watermark flows one direction. Downhill. Onto you.
The establishment wants you to think this is about stopping misinformation. But the same companies building these detection systems are the ones generating the content in the first place. They built the machine, they built the tag, and now they’re building the scanner. Three products, one pipeline, and you are the raw material flowing through it.
Every sentence Claude writes for you now carries a signature you’ll never see. And the people who can see it are not your friends.