The invisible watermark in AI text: what it is and what it means for you
- Deborah Nas

- 4 days ago
- 5 min read
You have an AI chatbot write a piece of text, copy it into an email and send it off. What you don't see: the phrasing of that text may contain an invisible pattern that reveals AI was involved. Such a pattern is called a watermark.
A watermark in AI text is an invisible statistical pattern that the language model leaves behind in its own word choices. Since 2 August 2026, the European AI Act has required providers of generative AI to mark AI-generated content in a machine-readable way. Anthropic, the maker of Claude, is therefore introducing a text watermark. With the right key and detector, you can later estimate whether Claude probably had a hand in writing a text.
It remains a signal about origin, not hard proof: it works poorly on short texts, and anyone who heavily rewrites or translates a text can disrupt the pattern.

How can a watermark sit in the words themselves?
A language model builds text token by token. A token is usually a word or part of a word, but it can also be a space, a punctuation mark or another fragment of text. At each step the model estimates which next tokens fit best with the preceding context. Often several words all fit perfectly well. Take the sentence “Next year the economy will…”. After that, “probably”, “presumably” or “possibly” could all follow, and to the reader it barely matters which one the model picks.
With a watermark, that choice is steered very subtly. A secret key makes the model pick certain suitable words just a little more often than others. In a single sentence you notice nothing. But across hundreds of such choices, a statistical pattern emerges that a detector with the same key can recognise later.
Because the pattern lives in the phrasing, it survives when you copy the text from Word into an email. A watermark does not, by the way, prove that the model wrote the whole text. It may just as well mean that Claude heavily edited an existing text.
The technique comes from Google: SynthID
The method Anthropic uses is called SynthID-Text, and it is based on a standard developed by Google DeepMind. Google introduced SynthID in 2023, first to give AI images an invisible watermark, and later expanded it to audio, video and text. For text it works through a mechanism DeepMind calls “tournament sampling”: at each word choice, a secret key lets the suitable candidate words compete against each other, as it were, so that a pattern emerges which you can trace back later. DeepMind published the method in 2024 in the scientific journal Nature and put the code online, allowing other companies such as Anthropic to adopt it.
What exactly does the European law require?
The AI Act entered into force in August 2024, but the transparency rules in Article 50 have only applied since 2 August 2026. The core: providers of generative AI, so companies like Anthropic, Google and OpenAI, must ensure that AI-generated or AI-edited content is recognisable in a machine-readable way. Not only to a human, but also to software. That can be done through metadata, technical standards or such a statistical watermark. Anyone who breaks the rules risks a fine.
In addition, the European Commission drew up a voluntary code of practice together with the sector. Around 190 organisations have signed up, including Google, Microsoft, OpenAI and Anthropic.
The Brussels effect: European rules, worldwide consequences
Anthropic will apply the text watermark worldwide, not only in Europe. The reason is that, for now, it has no reliable way to switch the watermark on or off per region. European regulation may thus change how Claude generates text in America or Asia too. That is a textbook example of what is called the Brussels effect: European rules eventually become the global norm, because it is often easier for companies to maintain one standard than to differ per market.
Is it watertight?
Not really. A watermark works especially well on longer texts, because you need enough word choices to recognise the pattern. On a short text, a factual list or programming code it works much less well, because the model has little freedom in its phrasing there. In a sentence like “The capital of France is…” there is only one correct next word, and then the watermark has nothing to work with.
Anyone who deliberately wants to remove the watermark can also get quite far. If you rewrite the text heavily or have it rewritten by another system that adds no watermark, the pattern can become so disrupted that it is no longer reliably recognisable.
The reverse matters just as much: if you find no watermark, that does not automatically mean the text was written by a human. Not every AI model uses a text watermark, and an existing watermark may have disappeared through editing. See it as a clue about origin, not as conclusive proof.
What does this mean for businesses?
For business use, two questions matter.
1. What does the provider of your AI tool do to make the origin technically visible?
2. When do you yourself have to tell your customer or audience that you used AI?
Article 50 also places obligations on you. If you publish a deepfake, you have to indicate that. And for text, the labelling obligation applies among other things when you use AI to inform the public about matters of public interest. If such a text has been substantively reviewed and edited by a human, and someone holds editorial responsibility for it, then the label is not required. The European Commission interprets that exception strictly, though: a cursory check or a spell check does not count as editorial oversight.
If you have AI produce a product description, job posting or commercial newsletter, then Article 50 does not automatically mean it needs “this text was created by AI” underneath. That kind of text usually does not concern matters of public interest.
Frequently asked questions
Can a watermark be traced back to me or my company?
No. According to Anthropic, the watermark contains no information about the user, the organisation or the conversation with Claude. It only says something about the model's possible involvement in the text.
Does the watermark also apply to older Claude models?
For models released after 2 August 2026, the marking is there from the start. For older models there is a transition period, and Anthropic is rolling out the watermark for those over the coming months.
Does a translation get a watermark?
Yes. In a translation the model chooses every word itself, so there is plenty to hang a watermark on.
This blog is based on my conversation on BNR Nieuwsradio Zakendoen. For more on technology, AI and its societal impact, read my other blogs.

