A watermark names the model. Not the author.
On 14 August 2026 Anthropic published "How Claude's text watermark works", and updated it on 1 September 2026. The page still opens with a commitment rather than a status report: "Future Claude models will generate text that contains a watermark." Most of the reaction reached for the wrong use, which was catching people out. The better question for regulated work is which documents carry a mark, and what obligation that creates.
Anthropic describes it plainly. The technique "changes the source of the randomness used to pick among words", so that one "can check the sequence of words and see if it's consistent with the choices Claude would make if it was using the key". Anthropic describes the method as "a version of the SynthID-Text approach published by Google DeepMind in a Nature paper in 2024". Nothing visible changes, and the signal lives in the pattern of word choices.
What Anthropic has committed to, and how far it reaches
It is a model-level property, not a product feature. Anthropic's help centre says marking covers supported model output across "Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag", and applies "wherever Claude is offered, worldwide", including cloud partner distribution through AWS, Google Cloud and Microsoft Foundry. Anthropic says it does not "yet have a durable way to scope it by region", so an Australian organisation that chose Bedrock or Vertex for data residency sits inside the same scope.
Support is keyed to a model's launch date, not to a customer setting. Anthropic states that "Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch", with "a transition period for Anthropic models launched before August 2, 2026". The first models on the far side of that boundary have now shipped. Claude Fable 5.1 and Claude Mythos 5.1 launched on 1 September 2026, and the help centre names them: "Models currently supported include Fable 5.1 and Mythos 5.1." Claude Opus 5 launched on 24 July 2026, before the boundary, and Anthropic does not name it. Older models sit in the transition group, where Anthropic says marking "will be rolled out over the coming months".
So the list is real but partial, and the word doing the work is "include". As at 14 September 2026 you can say that text from Fable 5.1 and Mythos 5.1 is marked. You cannot say the converse about anything else, because Anthropic publishes no exhaustive list and no per-model cut-over date. No opt-out is documented for users, administrators, enterprise or API customers, which is a narrower statement than saying none exists.
The detector moved too, and in a direction worth reading carefully. Anthropic updated the watermark page on 1 September 2026 to say it is "releasing a detection API in private preview". Access is the catch. It is "currently available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups)", and to "enterprises who are similarly obligated to verify watermarking for their own compliance with the Act". Anthropic says it plans to expand access over time and takes registrations of interest.
Read that against an Australian regulated desk. A bank, insurer or self-insured licensee with no Article 50 obligation of its own is not in the eligible class, and the gate is compliance need rather than willingness to pay. As at 14 September 2026 a detector exists that most Australian organisations cannot obtain. Neither Anthropic page publishes a false positive or false negative rate, so even inside the preview it is a check with no published error characteristics.
One boundary, because the two get conflated. This is a statistical mark inside the words themselves, not the file-bound signed assertion covered in stop detecting AI, start checking provenance, and the two behave differently under ordinary copying and editing. Anthropic does both: generated .svg, .png or .jpg files carry C2PA "signed provenance metadata", while text carries the mark. The asymmetry is the useful part. Anthropic offers a free Content Checker for files today, and gates text detection behind a preview you have to qualify for.
Why the mark is weakest on your most important documents

The finding that inverts the intuition comes from both vendors.
Anthropic states that "watermarking is sparser on factual passages where there are fewer choices that can be made without decreasing the accuracy of the text". Google DeepMind says the same of the SynthID approach the method is drawn from: text watermarking "is less effective on responses to factual prompts because there are fewer opportunities to adjust the token distribution without affecting the factual accuracy". That post dates from May 2024 and is cited only for the technical limit.
The mechanism explains it. A mark of this class nudges the choice between equally valid words, then checks whether the sequence matches the key. Constrained writing offers fewer such choices. In a liability determination, a breach assessment or a normal weekly earnings calculation, the correct word is largely dictated by the statute, the figure or the fact. In a board paper it is not.
Our reading follows, and it is analysis rather than a vendor statement. The mark will be thinnest on the documents an Australian regulated team would most want to account for, and thickest where authorship matters least. Anyone assuming high-stakes text would be the most traceable has it backwards.
Anthropic adds that detection "doesn't work well on small samples, where there are fewer word choices and thus less information to go on". A short determination paragraph is the worst case twice over.
Do not bet on it being dropped for degrading output. Anthropic reports Google DeepMind found no statistically significant difference in user ratings between watermarked and unwatermarked traffic.
The two uses people will reach for, and why both fail
Policing staff output. Anthropic's own guidance closes this off. A detected mark signals only that content "may have been processed by Claude", and Anthropic states that a watermark "cannot distinguish 'Claude wrote this' from 'Claude heavily edited this'". Content lacking detectable marks does not mean it was not AI generated, given heavy editing, format conversion, or a model predating marking support.
Behaviour under ordinary use makes it worse. Anthropic states that light proofreading of human text leaves very little for the watermark to attach to, while translation is watermarked because Claude chooses every word. The mark tracks how much of the final wording the model selected, not how much thinking a person outsourced. Someone who used Claude hard as a thinking partner and then typed the text themselves leaves almost nothing. Someone who ran a finished human paragraph through Claude to render it in another language leaves a strong signal. As a measure of effort or integrity, that is close to inverted.
Detection across staff output is therefore the wrong control, and not only on accuracy grounds. Access is restricted to organisations carrying their own Article 50 obligation, no error rate is published, and the technique is weakest exactly where certainty would matter. It is also a monitoring decision, with consultation and psychosocial consequences beyond this page.
Proving your own document was written by a person. This fails for the mirror reason. Absence is not evidence of human authorship, on Anthropic's own words, and it is most likely precisely on the constrained documents you would most want to defend. A clean result on a determination establishes nothing.

The duty that actually attaches
The marking answers a provider duty. The one that reaches a deployer is different. Regulation (EU) 2024/1689 Article 50 separates them, and that separation is the practical story.
Read the exemption slowly, because it is the design brief. The deployer duty falls away where there has been "a process of human review or editorial control" and where "a natural or legal person holds editorial responsibility for the publication of the content". That is a named accountable human attached to a document class. No detector produces it.
Article 50(2) applied from 2 August 2026. Enforcement of model provider duties is covered in the EU can enforce model duties from 2 August, and the timetable in the EU delayed the hardest part of its AI Act. What is new is that the artefact now sits inside your own output, not in a vendor's file.
Nor is this one vendor's quirk. The European Commission reported on 31 July 2026 that around 190 organisations had signed its Code of Practice on Transparency of AI-generated Content, Anthropic among the provider signatories alongside Google, Meta, Microsoft, Mistral and Open AI. The Code is voluntary.
No Australian statute requires AI-generated text to be marked. It reaches Australian desks through the model layer, because Anthropic has no durable way to scope it by region.
The Australian collision worth naming early
Two regimes now point at the same document from opposite ends.
The Supreme Court of New South Wales issued Practice Note SC Gen 23 on 28 January 2025, commencing 3 February 2025 and applying to all proceedings from that date. Paragraph 3 names the tools it covers, including Claude. Paragraph 10 says Gen AI must not be used in generating the content of affidavits, witness statements or character references, and paragraph 12 extends that to "rephrasing a witness's evidence when expressed in written form". Paragraph 13 then requires such a document to disclose that Gen AI was not used in generating its content.
Witness statements and claimant statements are core workers compensation and HR material, a point already live in the medical report now has to declare its AI. An organisation whose staff draft or tidy that material with Claude will produce a document carrying a mandatory negative disclosure that may separately carry a positive machine-readable mark.
This is a foreseeable risk, not an observed one, and there is no reported Australian case in which a watermark has been raised in a proceeding. As at 14 September 2026 the version at the current practice notes path is still the one issued 28 January 2025, with a review open: the Chief Justice invited submissions on 17 November 2025, closing 18 December 2025, and no amended version is published.
The control that answers this is a drafting rule, not a detector.
What to build instead
TheAICommand works to the Verified Draft Method: de-identify the inputs, ground the model in your own source material, keep a person at the decision point, verify against the primary source, and log what happened. The Article 50(4) exemption asks for the same shape in different words. Four moves follow.
- Name the editorial responsibility holder by document class. Not a team, a person or a legal entity, recorded against determinations, breach notifications, safety alerts, public statements and board papers. It is the artefact that survives contact with a regulator.
- Write the drafting rule for restricted material. Affidavits, witness statements and character references get a rule about what Gen AI may and may not touch, drawn from the practice note governing the forum, plus a matching template line. Preparatory work sits differently from generating the content, and the rule needs to say which is which.
- Record the model and surface at drafting time. Which model, which surface, what was pasted in, who approved the output. Which model now matters twice, because marking turns on the model rather than the setting, and that record is contemporaneous, unlike anything a later check produces. It is the discipline in your AI logs the tokens, not the decision.
- Ask the vendor three questions and file the answers. Which of the models you actually run are marked today, whether any opt-out exists, and what false positive and false negative rates the detection API reports. The first now has a partial published answer. The other two do not.
Do not commission a detector. As at 14 September 2026 the detection API is a private preview most Australian organisations cannot join, there is no published error rate to calibrate against, and the technique is thinnest where the stakes are highest.
Do this Monday
- Name who holds editorial responsibility for your three highest-risk document classes
- Add a Gen AI drafting rule and disclosure line to affidavit and witness statement templates
- Record model, surface and approver at drafting time, not afterwards
- Send the vendor the three questions above and file the dated answers
- Write the one-line rule: a mark identifies a model, its absence proves nothing
Bottom line
Anthropic's watermark is now live on named models, and its detector is a private preview most Australian organisations cannot join. It applies at the model level with no durable way to scope it by region, so it reaches Australia whatever you bought it through, and it is sparsest on the factual constrained writing that fills a regulated desk. Presence points at a model. Absence points at nothing. Accountability still needs a name, and the EU wrote that name into the exemption.
References
- Anthropic, "How Claude's text watermark works", 14 August 2026, updated 1 September 2026: https://www.anthropic.com/news/claude-text-watermark
- Anthropic Help Centre, "How Claude marks AI-generated content": https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
- Anthropic, "Introducing Claude Fable 5.1 and Claude Mythos 5.1", 1 September 2026: https://www.anthropic.com/claude-fable-and-mythos-5-1
- Regulation (EU) 2024/1689, Artificial Intelligence Act, Article 50: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689
- European Commission, "Strong backing for the Code of Practice on Transparency of AI-generated Content", 31 July 2026: https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content
- Google DeepMind, "Watermarking AI-generated text and video with SynthID", 14 May 2024: https://deepmind.google/blog/watermarking-ai-generated-text-and-video-with-synthid/
- Supreme Court of New South Wales, Practice Note SC Gen 23, issued 28 January 2025: https://supremecourt.nsw.gov.au/documents/Practice-and-Procedure/Practice-Notes/general/current/PN_SC_Gen_23.pdf
TheAICommand. Intelligence, At Your Command.



