Claude is Watermarking your code
Claude is Watermarking your code
Anthropic's Claude models, as of 2 August 2026, embed machine-readable marks into AI-generated content: invisible watermarks woven into generated text, and digitally signed provenance metadata (Content Credentials, via the C2PA standard) attached to generated files. The goal is to make it possible to distinguish AI-involved content from human-only work in a way that isn't trivially stripped out by casual editing. This arose from the EU AI Act's Article 50 transparency requirements, specifically the Code of Practice on Transparency of AI-Generated Content, which Anthropic signed along with roughly 190 other companies.
Because this applies to Claude output across the board, Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, it applies to code Claude Code writes, not just prose. If you're using Claude Code day to day, it's worth understanding what that actually means and doesn't mean for your commits.
How it works
Claude uses two separate mechanisms depending on what's being generated:
Embedded text watermarks. When a supported Claude model generates text, the watermark is woven directly into the token choices during generation, not appended as metadata, not inserted as hidden characters. There's nothing visually different about the output; it doesn't change meaning, quality, or readability. Because it's baked into the text itself rather than attached alongside it, the watermark travels with the text through copy-paste and can survive some editing, though a full rewrite where every token is replaced will remove it. For code specifically, this matters in a nuanced way: natural language has a lot of statistical slack in word choice (many ways to phrase the same sentence), which is what watermarking schemes like this lean on. Code has far less of that slack syntax, naming conventions, and correctness constraints narrow the space of "equally good" token choices considerably. Anthropic hasn't published model-by-model detail on how reliably the watermark survives in generated code specifically, so the honest state of the art here is: the mechanism applies to Claude Code's text output the same way it applies to prose, but its detectability in a five-line function versus a 2,000-word blog post is a different question.
Content Credentials (C2PA). For generated files images like PNGs and JPEGs being the clearest example, Claude attaches signed provenance metadata following the C2PA open standard, the same provenance format used elsewhere in the industry. This is a distinct mechanism from the text watermark: it's metadata riding alongside the file rather than something woven into the content itself, which also means it's more fragile, format conversion, re-saving, or a screenshot can strip it.
What this means for Claude Code specifically
A few things worth knowing if you're writing code with Claude Code day to day:
-
Coverage depends on the model, not just the product. Watermarking is applied at the model level, so it's present regardless of which Claude surface you're using, but only for models that support it. Models launched on or after 2 August 2026 support marking at launch (Claude Fable 5.1, Claude Mythos 5.1, and Claude Opus 5, per Anthropic's current model table). Models released earlier, including Claude Sonnet 5, the model many Claude Code users are on by default, are in a transition period; Anthropic says it's working to extend marking to those models, with full coverage targeted by 2 December 2026. Practically: as of today, whether your Claude Code output carries a text watermark depends on exactly which model generated it.
-
It's not a copyright or authorship claim. Anthropic is explicit that a detected mark only signals that Claude was likely involved in producing or processing the content at some point , it says nothing about who owns it, and doesn't change your rights under Anthropic's terms. A watermarked function in your codebase isn't "Anthropic's code" in any legal sense; the mark is a provenance signal, not a claim of ownership.
-
It can't distinguish "wrote" from "edited." If you ask Claude Code to review or lightly modify code a human wrote, the boundary between "Claude generated this" and "Claude touched this" isn't something the watermark resolves cleanly. Anthropic's own guidance is blunt about this: a mark tells you Claude was likely involved, not what it did.
-
Detection isn't self-serve, for now. You can't currently run your own codebase through a public checker to see which lines are marked. Watermark detection is in private preview, limited to organizations with a documented need under EU law, regulators, law enforcement, media, researchers, and enterprises with their own compliance obligations. There is a public checker for file-level Content Credentials (Claude's Content Checker), but that's for files like images, not for verifying text watermarks in a codebase.
-
It's global, not EU-scoped. Even though the requirement originates from EU law, Anthropic applies watermarking to output everywhere Claude is offered, worldwide, including through cloud partners like AWS, Google Cloud, and Microsoft Foundry. There's no "turn it off outside the EU" setting; Anthropic has said this is because it doesn't yet have a durable way to scope the behavior by region.
Should you care?
For most day-to-day use, probably not in any way that changes how you work, the stated design goal is that watermarking has no effect on output quality, and there's no user-facing toggle to manage. Where it's worth being aware of it:
- If your organization has its own compliance obligations around disclosing AI-generated or AI-assisted code, this is the mechanism Anthropic is offering to support that, not a replacement for your own disclosure process, but a technical signal that can back it up.
- If you're stripping or reformatting Claude Code's output in ways that touch every token, full rewrites, heavy obfuscation, minification, you shouldn't assume a watermark's presence or absence tells you anything reliable after that point.
- If you're building a product on top of Claude that redistributes generated code or content, Anthropic's guidance is that you should independently assess what Article 50 obligates you to do, since their marking is meant to support your compliance, not substitute for it.
None of this changes what Claude Code can do for you or how you should prompt it, it's a background provenance layer, not a feature you interact with directly. But given how much production code is now written with AI assistance, it's a reasonable bet that "was this AI-generated" questions are only going to come up more, not less, and it's worth knowing that Anthropic already has an answer mechanism in place, however early-stage the detection tooling still is.