Hard Coded

Anthropic adds AI watermarks

Aug 14, 2026Emil Protalinski
Anthropic adds AI watermarks

Anthropic this week announced that new Claude models will include watermarks in all generated text and C2PA metadata in all generated files, and that it will update its past models with watermarking too.

Anthropic claims it is doing this to comply with the EU AI Act, which mandates machine-readable marking for synthetic content (whether watermarking adheres to the spirit of the law is a whole separate topic). Coincidentally, also this week, The Financial Times reported that Anthropic's investors expect an October IPO at an over $2 trillion valuation, which would beat SpaceX’s record IPO, and Bloomberg reported that Anthropic is in talks to acquire Decart, which makes world models and GPU optimization tech, for around $6 billion.

So, yeah, watermarking is just the latest example of an Anthropic product decision as the AI startup tries to stay in regulators’ good graces while it makes money moves.

Never mind that Anthropic is, in fact, late to AI-generated content watermarking. The most successful example is easily Google’s SynthID, a tool the company unveiled in August 2023 that can embed an invisible digital watermark into AI-generated images. Google expanded SynthID to also watermark text and video in May 2024, but it’s been especially successful for images, to the point that as of May 2026, even OpenAI has pledged to use SynthID.

Watermarking makes the most intuitive sense for images, but I’d like to focus on text. Watermarks were first introduced in 1282 for paper; text is a much more fascinating use case for watermarking than photos, audio, or video; and words are also my domain.

Here’s how Anthropic describes its embedded watermarks:

“When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself. You won’t see it, and it doesn’t change the meaning, quality, or readability of Claude’s response. Because the watermark is part of the text, it will travel with the text when it’s copied and pasted elsewhere, and may persist through some editing. Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from.”

No watermark is tamperproof, but text watermarks especially feel less effective because text is so much more easily manipulable.

I’ve oddly seen some people argue that watermarking is necessary because it’s becoming harder to detect AI-generated text. “The models are getting so much better at text generation!” That's nonsense. Generative AI models by their nature generate generic garbage. Humans are instead getting better at obfuscating AI-generated text, intentionally or unintentionally:

  1. Most people who want to remove watermarks will find ways to do so. It’s trivially easy now and the ensuing game of whack-a-mole is not going to make it much harder.

  2. Most models don’t include watermarks. Until now, if you were using Claude, any output you pasted didn’t have a watermark. Plenty of models output non-watermarked content by default.

  3. Most text is a hybrid of AI-generated and human-written work. For better and for worse, people are using AI tools everywhere that they write, no different from spell check and autocorrect.

There will always be ways to AI-generate content without watermarks.

As such, you can’t rely on watermarks. Even if watermarking becomes commonplace for AI-generated content, you can’t assume that content without a watermark was created by a human. That’s not a guarantee. Watermarking simultaneously has its place and is doomed to never achieve its full potential.

It’s not that the genie is out of the bottle. It’s that the world can’t possibly design bottles for all the genies, stuff them in there, and ensure nobody rubs a single bottle.

More importantly, should we even want to? Model makers effectively scraped as much human knowledge as they could get their hands on without attribution, and now the dominant ones are including attribution for their models’ outputs by default.

“Watermarking text is like selling CDs while Spotify is out,” Dataiku CEO Florian Douetteau told me in a statement. “It reminds me of the music industry around 2004, spending fortunes on DRM while Napster had already changed how music moved through the world. The technology made sense, but the market had already moved on. We’re entering a world where the volume of generated content is effectively infinite. Provenance has a role, but the harder challenge is determining what deserves our attention and trust in the first place.”

Not many tech CEOs have commented on the news publicly and few responded to my request for comment. Nobody wants to bite the hand that feeds them, and Anthropic continues to be the AI model maker to beat, especially in B2B.

Indeed, we got the latest numbers this week: Anthropic's US business market share hit 43.5% in July, per Ramp, widening its lead over OpenAI, which dipped to 39.7%, followed by Google at 6.2%, xAI at 4%, and DeepSeek at 0.2%. These figures are based on spend data from US businesses that use Ramp, so don’t focus on the exact market share breakdown. Just consider the bigger picture: Anthropic and OpenAI still have a duopoly, at least in the B2B space, which is where the revenue is.

Anthropic can afford to add watermarking now, but it can just as easily backpedal whenever it decides the costs outweigh the benefits, pointing to any of the reasons I mentioned above: the tech is imperfect, users are just stripping watermarks out, and/or hybrid content has won anyway.

 

This week’s tech news that couldn’t resist my commentary:

  • Model mayhem: Google released Gemini 3.7 Flash, its latest closed model, and Z.ai debuted GLM-5.3, its latest open-weight model (Z.ai promises to release the weights in two weeks). Both are incremental updates so you can keep using what you’re using (embarrassingly, Google still hasn’t released Gemini 3.5 Pro).

  • Prediction markets: Flight tracking platform FlightAware sued Kalshi in New York, alleging Kalshi is using its data without permission to let users bet on flight cancellations, and then withdrew its Kalshi lawsuit the next day after Kalshi stopped naming it as a source. There wasn’t enough time to take bets on who would win the lawsuit.

  • Creator economy: Google announced that as of February 1, 2027, it will be harder for YouTube creators to make money. I naturally made a YouTube video.

  • Sovereign AI: Mistral announced it will run third-party open models on the same infrastructure, regional controls, and service commitments as its own models, starting with Z.ai's GLM-5.2. Cohere, Thinking Machines Lab, and all the Chinese labs, who’s next?

  • Surveillance tech: After a Washington Post analysis concluded that US authorities charged or accused over 50 officers of misusing license-plate reader tech, Flock said it will now require US law enforcement to label every license plate search with a criminal case number. Flock CEO Garrett Langley acknowledged the startup “got this one wrong.” Only this one, Garrett?

If you haven't told your colleagues about Hard Coded yet, I'd appreciate it if you send them the link.