Anthropic has started adding machine-readable signals to output from Claude models launched in the European Union on or after August 2, 2026. According to Anthropic, supported models apply those marks wherever Claude is offered worldwide—not only inside the EU.

The qualification matters. This is not a claim that every current Claude output is marked. Older models are still being brought into the system, and some platforms, features or file types may not support every marking method.

Which Claude outputs are covered?

In its August 11 Help Center explanation, Anthropic says newly launched models in the EU support marking from launch. The coverage spans the Claude API, the Claude app, Claude Code, Cowork and Tag. Anthropic also says embedded watermarks can travel through access provided by AWS, Google Cloud and Microsoft Foundry.

That product list does not eliminate implementation differences. A supported model may be available through several surfaces while a particular platform or feature lacks one of the marking types. Legacy-model support is also described as work in progress.

For developers and operators, the practical unit to track is therefore not simply “Claude.” Model generation, access surface, output format and subsequent processing can all affect whether a detectable signal is present. Teams that need an audit trail should continue recording those details rather than treating the vendor name as sufficient provenance.

Text and files use different marking paths

Anthropic describes two mechanisms. Generated text from supported models receives an imperceptible embedded watermark. The company has not yet published the technical detection documentation, so external users do not currently have enough public detail to evaluate the detector, thresholds or error characteristics.

Supported generated files can instead carry signed C2PA provenance metadata. That metadata provides a machine-readable record associated with the file, but it is not a visible disclosure and it does not certify that the file’s contents are accurate. It is also more fragile than an intrinsic text signal: metadata may disappear when a file is converted, re-saved, captured as a screenshot or processed by software that does not preserve it.

These mechanisms serve the same broad transparency goal, but they should not be treated as interchangeable. Text detection depends on enough of the marked output remaining available for a reliable signal; file detection depends on compatible metadata surviving the content pipeline.

A mark signals processing, not authorship

Anthropic’s most important limitation is interpretive. A detected mark means content may have been processed by Claude. It does not establish that Claude originated the ideas, wrote the entire document or was the last system to modify it.

The distinction matters for common assistive workflows. Text that began with a human author may receive a mark after Claude proofreads, translates, summarizes or converts it. Marked content may then be excerpted, edited or combined with other material. A detector result cannot reconstruct that full history on its own.

The reverse inference is equally unsafe. No detected mark does not prove human authorship. An output may come from an older or unsupported model, a platform or feature without that marking type, or a file whose metadata was stripped. Heavy rewriting, paraphrasing, translation, mixing with other text and very short passages may also make a text mark harder or impossible to detect.

That makes these marks a provenance clue, not a standalone authorship verdict. Organisations considering them for compliance, moderation, academic review or employee policy should require corroborating records and a review process before drawing consequences.

Why the rollout is happening now

Article 50(2) of the EU AI Act requires providers of systems that generate synthetic text, images, audio or video to make output machine-readable and detectable where technically feasible. The provision also includes exceptions for standard assistive editing and changes that do not substantially alter the user’s input or its meaning.

Anthropic’s product implementation may cover workflows beyond that minimum legal language. Axios reported on August 12 that the worldwide rollout could mark material that passed through Claude for tasks such as cleanup or translation. That is an operational consequence, not proof that the machine produced the underlying work.

Until Anthropic publishes its detection documentation and expands legacy coverage, teams should treat the rollout as an evolving provenance layer. The useful questions are which model and surface produced the output, which marking type applied, what transformations followed, and what additional evidence supports any authorship or compliance decision.

Cover: AI-generated conceptual illustration of text watermarking and file-provenance metadata, including ways those signals can be disrupted; not a Claude interface, detector result or implementation diagram. AI-generated conceptual illustration created with OpenAI for GeethanTech.