Model outputs now carry a mark the buyer never chose. The mark signals the likelihood that AI was involved in producing a text, not who wrote it, and what happens to that mark inside your products and processes is your decision, not the vendor's.

The Deadline Most Buyers Have Wrong

Two regimes inside the EU AI Act run on different timelines, and conflating them distorts procurement planning.

The high-risk workplace rules were pushed back from August 2, 2026, to December 2, 2027 , after EU countries and European Parliament lawmakers struck a provisional deal in May to delay and dilute the Act's provisions. [2] [3] The European Commission published draft guidelines on classifying high-risk systems in late May, the clearest signal yet of what that deferred regime will actually demand. [2]

What did take effect in early August is narrower: a transparency requirement aimed at providers. Anthropic states that as of August 2, the EU requires AI providers serving its market to mark content produced by AI . [1] The company also confirmed the vintage split that matters for your records. The law includes a transition period for Anthropic models launched before August 2, 2026 , with watermarking for those older models rolling out over the coming months. [1] A product built on a model launched after the requirement already emits marked text. One built on an older model will start to. Your approval record should know which is which.

How the Mechanism Actually Works

The watermark adds nothing to the text. No hidden characters, no extra tokens, no added cost. A reader cannot tell a watermarked response from an unwatermarked one, and Anthropic reports a negligible impact on model speed.

The mechanism operates on word choices. Where several candidate words would do roughly the same job in a sentence, a cryptographic key settles the low-stakes choice instead of arbitrary randomness. The meaning is largely the same either way; what shifts is the pattern of those small decisions, which forms a statistical signature detectable only with the key.

Anthropic describes the method as a version of the SynthID-Text approach published by Google DeepMind in a Nature paper in 2024, in a line of research tracing back to a proposal by Scott Aaronson in 2022 . [1] The quality evidence is vendor-reported. Anthropic's internal testing found no impact on content, creativity, or readability. According to Anthropic's summary of the published paper, Google DeepMind served a watermarked model to a portion of Gemini traffic and saw no statistically significant difference in user ratings, and a controlled side-by-side human study saw no quality difference. These are vendor findings, not independent audits, and they are the most specific evidence that exists.

The mark itself carries no identifying information. It cannot be traced to a person, an organization, or a chat, and it does not change ownership, rights over the output, or legal responsibility. [1]

What Detection Can and Cannot Conclude

Detection answers one question: was Claude likely involved in producing this text? It cannot confirm that a text is human-written. It cannot identify a different AI's output. It attributes nothing to a user, a company, or a session.

Confidence grows with length, and short passages produce weak signals. Factual passages carry sparser marking, because accuracy leaves fewer free choices. Code carries less marking overall, though arbitrary decisions like comment phrasing can still carry it. Proofreading leaves very little to detect, because nearly all the words belong to the human author. Translations carry the mark, because the model chooses every word.

Light editing probably preserves the mark; a complete rewrite removes it. Detection cannot distinguish "Claude wrote this" from "Claude heavily edited this." And the absence of a mark proves nothing: an unmarked text may be human-written, produced by a different model, or produced by a Claude model whose marking is still rolling out. [1]

Anthropic says a watermark detection API is coming soon, with implementation details still being worked out. [1] It does not exist as a product today. Until it ships and its error profile is documented, watermark detection cannot serve as a reliable automated signal in any workflow.

What the Deployer Needs to Decide

Anthropic applies the watermark globally at launch, because it says it has no durable way to scope marking by region yet, and it will keep evaluating approaches. [1] Companies outside the EU therefore inherit marked outputs regardless of where they operate or who their customers are.

The formal obligation runs to providers, not to you. Anthropic signed the EU's transparency Code of Practice in July, along with several other major model providers and around 190 total signatories — a vendor-reported count — and that Code requires providers to mark text produced by AI. [1] But marked outputs enter your products, and what your product does about that is your call.

A model-approval record that takes marking seriously needs three entries per model: whether its outputs are marked, whether it launched before or after the requirement took effect, and whether the vendor offers detection and on what terms. That is a small addition to an existing checklist, and it is the difference between knowing which customer-facing surfaces emit marked text and finding out later.

Disclosure posture is now a design decision. If your product generates text that customers read, you need a position on whether and how to convey that AI was likely involved. The watermark does not make that decision for you; vendor transparency infrastructure and your disclosure policy are separate commitments.

Image outputs use a different mechanism: C2PA content credentials, a small cryptographically signed note attached in a file's metadata saying Claude was involved. That is distinct from the text watermark and belongs separately in any audit trail. [1]

What to Do Before the Detection API Arrives

  • Inventory every workflow that emits or consumes model-generated text, starting with customer-facing surfaces.
  • Record each approved model's marking status and launch vintage in the model-approval record.
  • Ask each vendor for their marking and detection support: which models, what timeline, what terms.
  • Leave watermark detection out of fraud, dispute, and integrity processes until the API exists and its error rate is documented.

A mark tells you a model was probably involved in producing a text. It says nothing about who is responsible for what the text says, and that decision stays with you.