BetaMaShop is in public beta. We improve it continuously, and your feedback shapes what comes next.
MaShop/Blog/Industry/The AI Text on Your Website Now Carries an Invisib…
IndustryAugust 12, 2026
Read · 5 min
ai text watermarking · anthropic

The AI Text on Your Website Now Carries an Invisible Mark

Claude now weaves an invisible mark into the text it writes. Here is what that mark proves about a page you publish, and what it leaves entirely to you.

Key takeaways
  • Since 2 August 2026, text generated by newer Claude models carries a statistical watermark woven into the words themselves, and it survives copy and paste.
  • The mark says the text passed through Claude. It does not say Claude wrote it, so asking the model to proofread your own paragraph marks that paragraph too.
  • Anthropic applies the marking worldwide, but the legal duty behind it is European and it lands on the person publishing, not on the model vendor.
  • Generated image files get a separate treatment, signed C2PA metadata, which a screenshot or a re-save quietly destroys.
  • For most small sellers the practical risk is not a regulator. It is a platform that decides to rank labelled content differently, which Spotify has already announced for music.

You write a product description the way you have written a hundred of them. You ask Claude for a first pass, you cut the two sentences that sound like nobody, you add the detail about the stitching that only you know, and you paste the result into your store. The page looks exactly like every page you published last year.

It is not exactly the same. Somewhere in the choice of one word over its synonym, repeated across the paragraph, sits a pattern that a detector can read and you cannot. Anthropic began adding it on 2 August 2026, and the company says it applies everywhere Claude is offered.

What actually changed on 2 August?

Two things changed at once, and it helps to keep them apart. A European law started applying, and a vendor started marking its output.

The law is Article 50 of the EU AI Act, the transparency chapter. The European Commission confirmed that the new transparency rules took effect on 2 August 2026, covering notice when a person is talking to a machine, machine readable marking of generated output, and visible labels on deepfakes and certain published text.

The vendor move followed. Anthropic signed the Article 50(2) Code of Practice on Transparency of AI-Generated Content and published a support page describing how Claude marks what it produces. Claude models launched on or after 2 August support marking from day one. Older models are in a transition period and Anthropic says it is working to bring them in.

The Code itself is voluntary. The Commission is explicit on this point: signing the Code is optional while the Article 50 requirements remain legal obligations. By the end of July 2026 roughly 190 companies and organisations had signed. Signing buys a recognised way to demonstrate compliance. Not signing means proving your own approach is adequate to whichever market surveillance authority asks.

How does an invisible mark get into ordinary words?

The mark is placed while the sentence is being written, not stamped on afterwards. A language model picks each next word from a ranked list of candidates, and at almost every position several candidates are equally good. The watermark biases that choice according to a secret key, so across a few hundred words the pattern of picks drifts away from what an unmarked model would produce. A detector that knows the key can measure the drift.

That mechanism explains the properties that matter to you. Because the signal lives in the word choices, it moves with the text. Anthropic puts it plainly on its support page: the watermark travels with the text when it is copied and pasted elsewhere, and may persist through some editing. TechCrunch asked Anthropic how much editing removes it and did not get an answer, which is the honest state of the art rather than an evasion. Nobody publishes a threshold because the threshold depends on the passage.

Files work differently. When Claude produces an .svg, a .png or a .jpg, it attaches signed provenance metadata following the C2PA standard rather than altering the pixels. The C2PA explainer describes a manifest of cryptographically bound assertions: what made the asset, when, and what happened to it since. It is a receipt travelling alongside the file, and like any receipt it can be thrown away.

Note

Watermarking and provenance metadata are not the same technique and they fail in opposite ways. A text watermark degrades gradually as you rewrite. File metadata is binary: it is intact, or a screenshot removed it completely.

Does a mark mean the page was written by AI?

No, and this is the part worth reading twice. A detected mark tells you the text was processed by Claude at some point. It does not tell you who had the idea, who wrote the first draft, or how much of the final wording is yours.

Anthropic lists the cases in its own limitations section, and they are the everyday ones. People use the model to proofread, to translate, to summarise, to convert a file from one format to another. In every one of those, the output can carry a mark while the substance came from a human. Your own paragraph, handed over for a spelling pass, comes back marked.

The failure runs the other way too. Absence of a mark proves nothing. The text may have come from a model released before marking existed, or from a different vendor, or from a passage so short there was no room for a reliable signal. Heavy paraphrasing, translation, or blending into other writing can wash the signal out. On the file side, a format conversion or a screenshot strips the metadata without leaving a trace.

Comparison figure showing what a detected Claude watermark proves about a page and what an absent mark leaves entirely unknown

So the mark is evidence of one narrow fact, and only in one direction. Anyone treating a positive detection as proof of authorship has misread the tool, and anyone treating a negative as proof of human writing has misread it worse. Our earlier piece on what AI content detectors can honestly tell a shop owner reached the same conclusion from the detection side, before vendors started marking at the source.

Where a mark can turn up in a normal shop week

The surfaces are wider than most people expect, because marking happens at the model level rather than in one product. Anthropic says the marks cover output from supported models across the Claude API, the Claude apps, Claude Code, Claude Cowork and Claude Tag, and apply when supported models are reached through AWS, Google Cloud or Microsoft Foundry. If your helpdesk tool quietly calls Claude behind the scenes, the replies it drafts are in scope.

Where it shows upWhat the model producedDoes the mark survive?What to do about it
Product descriptionsText pasted into your catalogueYes, copy and paste keeps itRecord who reviewed and approved the copy
Blog posts and buying guidesText, often heavily editedWeakens as you rewrite, no fixed thresholdName a person with editorial responsibility
Support replies drafted in a helpdeskText sent to a customerYes, if the tool routes to a supported modelTell customers when they are talking to a bot
Generated product imagery and iconsA .png, .jpg or .svg fileOnly while the C2PA metadata is intactKeep the original file, not just the export
A screenshot of that same imageA new file with no historyNo, the provenance is goneDo not rely on metadata as your own record
Newsletter copy moved into an email toolTextYes, the transfer is a pasteSame review rule as the blog

Does the watermark handle my disclosure duty?

It does not. The marking obligation and the labelling obligation are different paragraphs of the same article, and they fall on different people. Anthropic says as much: if you deploy Claude inside your own product, you should assess independently what Article 50 requires of you.

Reading the text of Article 50 as a small seller, three parts are worth your attention.

Paragraph 1 covers systems that interact with people. If a visitor is talking to your chat assistant, they have to be told, unless it is obvious to a reasonably observant person. A widget that answers in the first person and never says what it is fails that test.

Paragraph 2 is the marking duty, and it sits on the provider of the generative system rather than on you. This is the one Anthropic just took on. If you resell or wrap a model under your own brand, look harder, because you may have stepped into the provider role.

Paragraph 4 is the one that surprises people. Deployers publishing text to inform the public on matters of public interest have to disclose that it was generated or manipulated. The same paragraph carves out an exemption that most shop content will land inside: content that has gone through human review or editorial control, where a natural or legal person holds editorial responsibility for the publication. A named editor who genuinely checks the piece is the mechanism the law itself offers.

The Code of Practice is worth knowing about in outline, because it is built in two halves and only one of them is about vendors. Section 1 sets rules for providers on marking and detection. Section 2 sets rules for deployers on labelling deepfakes and certain AI generated text, which is the half a shop sits in. The Commission has also published a set of icons that deployers may use to label generated content, so the visible label does not have to be invented from scratch. Signatories join taskforces that work out the implementation details in practice, which is a reasonable signal about how unsettled the details still are.

One more asymmetry deserves stating. The marking duty applies to systems that generate content, and it explicitly does not apply where a system performs an assistive function for standard editing and does not substantially alter the input or its meaning. That exemption sits in the law rather than in the vendor policy, which is why a model can mark a light proofread that the Article would not have required anyone to mark. Vendor behaviour is broader than the obligation here, not narrower.

"the transparency requirements under article 50 of the AI Act are legal obligations"European Commission, Code of Practice on Transparency of AI-generated Content

The territorial point is easy to trip over. Anthropic marks output worldwide because that is simpler than running two pipelines. Your obligation under the AI Act is not worldwide. It follows the market you sell into. A seller in Ohio shipping only inside the United States gets marked text without inheriting the European duty. The same seller opening a store for customers in Ireland inherits it that day.

If the tiers and the dates are new to you, the EU AI Act decision tree and timeline lays out which category a given system falls into and when each set of rules starts biting.

What do the platforms do with a label?

This is where the commercial consequence lives for anybody selling online, and it moves faster than enforcement does. A regulator has to open a file. A platform changes a ranking rule on a Tuesday.

Spotify announced the clearest version of this in the same week. Profiles judged to represent AI generated identities get an AI Persona badge and are excluded from editorial and personalised recommendations by default, with badges rolling out from mid September. Spotify says it will not depend on artists labelling themselves and will review profiles directly, starting with the ones above an audience threshold. There is an appeals process for a wrong label.

Read that as a template rather than a music story. The pattern is: detect, badge, then quietly demote in the recommendation surface. TechCrunch notes the same week that the music platform Suno moved to mark tracks made on it, and that Substack has been working with a detection vendor to flag AI written posts. We covered an earlier turn of this wheel when two large social platforms cut the reach of AI generated posts, and the direction has not changed since.

Card listing three checks before publishing AI drafted copy: name the human reviewer, label the chat assistant, keep the original file

What this does not change

It does not make AI assisted writing against the rules. Nothing in the Code or the Article bans generated text. They ask that it be markable and, in narrow cases, labelled.

It does not give a customer a button that reveals how a page was written. Detection is a capability Anthropic says it will extend to users and third parties, with technical documentation still to come. Until that lands, nobody outside the vendor can check a page reliably.

It does not give you a defence either. A mark on your product copy is not a certificate that you complied with anything. The certificate, in the shape the law recognises, is a person who reviewed the text and is willing to be named for it.

What to do this week

Nothing here needs a project. It needs about an hour, once.

  1. Write down where models touch your published words. Product copy, blog, support macros, email flows, image generation. Most people find one or two surfaces they had forgotten, usually inside a tool bought for something else.
  2. Give each surface a named reviewer. A single line in a document is enough. This is the mechanism Article 50(4) points at, and it costs nothing to have in place before you need it.
  3. Check your chat widget introduces itself. One sentence, visible before the first message, saying it is an automated assistant and how to reach a person.
  4. Keep original generated image files. The provenance metadata is only in the file Claude gave you. Once it has been through an image compressor or a screenshot, that history is gone.
  5. Stop using a detector as a hiring or supplier test. Given that a proofread carries a mark and a rewrite may not, a detector result is not a fact about a person.

If you are still choosing the tools that will sit under those surfaces, our guide to what an AI ecommerce store builder generates and who owns the resulting code covers the ownership question that decides how much of this you can actually inspect.

Questions people are asking

Can I remove the watermark by rewriting?

Partly, and nobody will tell you how much. The signal weakens as more word choices become yours, so a light edit almost certainly leaves it detectable and a full rewrite in your own voice almost certainly does not. Anthropic declined to give TechCrunch a threshold. Treat any specific figure you see quoted online as invented.

Does this apply to me if I sell outside Europe?

The marking does, because Anthropic applies it worldwide. The legal duties do not follow you automatically. They attach to selling into the European market, so the question is where your customers are, not where your laptop is.

Will Google penalise marked text?

There is no announced link between C2PA marks or text watermarks and Google ranking, and it would be a fabrication to claim one. What is documented is a preference for content with real added value and demonstrable first hand substance, which is a judgement about the writing rather than about the tool that helped produce it.

What about the other model vendors?

TechCrunch reports that Black Forest Labs, Google, Meta, Microsoft, OpenAI and Synthesia have all committed to the European code, so expect similar marking to appear across the tools you already use. The mechanics will differ. The consequence for a publisher will not.

The part that will still matter in a year

Watermarks will get better and then get worked around, and detection will stay probabilistic. The durable change is smaller and more boring: a page you publish now carries a machine readable fact about how it was made, and the person who has to answer for that page is you.

Which puts the value back where it was anyway. A generated draft with your knowledge of the product cut into it reads differently from a generated draft that was pasted straight in, and now the second kind is easier for a platform to spot at scale. The mark is not the problem. Publishing something you would not put your name on is.

Comments 0

0 / 4000Your email stays private.
No comments yet. Be the first.

Keep reading picked for you.

Describe it. MaShop builds it.

Commerce apps and websites from one sentence. No card to start.

Start building