Which Claude Models Are Watermarked? The Rule, and Why Nobody Can Verify It Yet
The Rule, Stated Precisely
There is a lot of confused reporting on this, including sites that publish confident model-by-model lists which contradict each other. Here is the only claim traceable to Anthropic itself:
Models launched on or after 2 August 2026 support text watermarking at launch. Support for older models is "in progress".
That is a rule, not a list. Applying it correctly matters more than memorising which model was covered on any given day, because the "in progress" category can change without a separate announcement.
| Model launch date | Watermark status | Confidence |
|---|---|---|
| On or after 2 Aug 2026 | Enabled at launch | High — stated by Anthropic |
| Before 2 Aug 2026 | "In progress" — may be enabled during the transition | Low — can change silently |
| Any model, output generated before enablement | No mark | High — watermarks apply at generation |
Why the Model Lists You See Are Unreliable
Three problems make third-party lists untrustworthy right now.
The transition period is undated. Anthropic says older-model support is "in progress" without committing to a completion date. A list accurate on 13 August may be wrong on 20 August.
No detector exists. Anthropic has not published its technical documentation or a detection tool. Nobody outside Anthropic can test a model's output and confirm whether a mark is present. Every confident public claim about a specific model is therefore inference, not measurement.
Coverage is per-product as well as per-model. Anthropic lists Claude, the API, Claude Code, Claude Cowork and Claude Tag as covered surfaces. A model reached through a cloud partner or an unsupported file type may behave differently.
We could publish a model table here and it would get traffic. It would also be a guess presented as fact, which is the opposite of useful.
What "Retroactive" Actually Means
This comes up constantly, and the answer is reassuring and technical.
A text watermark is applied during generation. The model biases its token selection as it writes, producing a statistical pattern. There is no post-processing step, and no way to reach into text that already exists and add one.
So:
| Scenario | Carries a mark |
|---|---|
| Text generated before that model had watermarking | No |
| Text generated after enablement | Yes |
| Old text pasted into Claude and returned unchanged | Yes — the returned copy is new output |
| Old text you edited yourself in your own editor | No |
That third row is the one people miss. If you paste a 2025 document into Claude and it hands text back to you, what you copy out is freshly generated output from a covered model, regardless of when you originally wrote it.
What You Can and Cannot Verify Today
| Question | Answerable now? |
|---|---|
| Does Anthropic watermark text? | Yes — confirmed by Anthropic |
| Which products are covered? | Yes — Claude, API, Claude Code, Cowork, Tag |
| Is a specific model covered? | Only by launch date, not by testing |
| Does this specific paragraph carry a mark? | No — no public detector exists |
| What does the mark look like? | No — technical spec unpublished |
| Will a journal or university detect it? | No — they have no tool either |
That last row deserves emphasis, because it drives a lot of anxiety that is currently unfounded. Institutions cannot check for a Claude watermark today, for the same reason you cannot: Anthropic has not shipped the detector. That will change, and Anthropic has said documentation is forthcoming.
Where the Other Labs Stand
| Provider | Text watermarking | Mechanism |
|---|---|---|
| Anthropic (Claude) | Deployed from 2 Aug 2026 | Proprietary, spec unpublished |
| Google (Gemini) | Deployed in supported products | SynthID |
| OpenAI (ChatGPT) | Researched, not publicly deployed as of Aug 2026 | — |
The forcing function is Article 50 of the EU AI Act, in force since 2 August 2026, which requires providers of generative AI to mark output in a machine-readable form wherever technically feasible. Anthropic and Google have moved. Pressure on the rest is regulatory rather than voluntary, which is why this is unlikely to reverse.
What To Do With This
If you are trying to work out whether your text is marked: check when the model you used was launched. If it was before 2 August 2026, treat the answer as genuinely unknown rather than "no" — Anthropic's transition language allows enablement without notice.
If you are worried about being detected: nobody can detect it yet. When tooling ships, the same limits Anthropic already documents will apply — the mark does not survive heavy editing, paraphrasing, translation or mixing with other writing, and short passages carry too little signal.
If you are setting institutional policy: do not write a rule that depends on detecting a watermark. There is no tool to enforce it with, and when one arrives, Anthropic's own guidance is that a detected mark shows content "may have been processed by Claude" and is "not fully conclusive" about authorship.
For the full mechanism, see what the Claude watermark actually detects. If your own writing carries a mark because you used Claude as an editor, read Claude watermark false positives.
Dr. Sarah Chen
AI Content Specialist
Ph.D. in Computational Linguistics, Stanford University
10+ years in AI and NLP research