Foundations
Claude now watermarks what it writes. Marked is not labelled.
By Arnav Mukherjee, founder of TofuBofu · August 12, 2026
Let me put my own position on the table before the argument starts, because it is the reason I bothered to read the source documentation carefully rather than the coverage. This blog is drafted with AI, and Claude does most of the drafting. The research, the measurements, the numbers and the editing are mine. The prose is a collaboration. If watermarking AI text is a problem for anybody, it is a problem for me first.
Anthropic now marks what Claude produces. Their support page says it "weaves an imperceptible watermark directly into the text itself", and for generated files such as .svg, .png or .jpg it attaches "signed provenance metadata". It applies to models launched on or after 2 August 2026, with older ones being retrofitted, and it covers the API, Claude, Claude Code, Claude Cowork and Claude Tag, wherever Claude is offered.
Within a day of that landing I saw people conclude that AI content was now going to be visibly flagged and demoted. Both halves of that are wrong, and the way they are wrong is instructive.
Marked, not labelled, and nobody can read it yet
Start with what a reader experiences, which is nothing. There is no badge, no banner, no line appended to the bottom of the text. Anthropic's wording is that you will not see it and that it does not change the meaning, quality or readability of the response. A watermark of this kind is a statistical fingerprint in the choice of words, not a stamp on the page.
Now the part almost every write-up skipped. Public detection does not exist. Anthropic states it is "working to enable users and other third parties to detect Claude's embedded watermarks and provenance metadata", with details in forthcoming technical documentation. Until that ships, nobody outside the vendor can read the mark, which means no search engine, no AI engine and no compliance team can currently act on it even if they wanted to.
And then the sentence that matters most, in Anthropic's own words: "Detecting a Claude mark tells you that the content may have been processed by Claude. It does not, on its own, confirm the full provenance of the content."
Processed. Not authored. If you write a paragraph yourself and ask Claude to tighten it, that paragraph can carry a mark. If you translate a human-written page, same. The mark answers "did this pass through this model" and people will read it as answering "did a machine write this", which are not the same question and never were. Anthropic also lists when the mark fails: heavily edited, paraphrased, translated or mixed-in text, and metadata stripped by format conversion, re-saving or screenshots. So the signal is directional, not forensic, in both directions.
What the mark can and cannot tell anybody
Google already told you the method is not the test
The fear underneath the watermark story is that a detectable mark gives search engines a switch to demote AI-written pages. That fear misreads the policy it is worried about.
Google's spam policies define scaled content abuse as "when many pages are generated for the primary purpose of manipulating search rankings and not helping users", and describe it as "typically focused on creating large amounts of unoriginal content that provides little or no value to users, no matter how it's created".
That final clause has been sitting there the whole time. The test is volume, originality and intent. A thin page a human typed is in scope. A specific, useful page drafted with a model and then worked into something with an actual argument is not. Adding a machine-readable authorship signal does not create a policy that was never about authorship.
Which is the position we have held on this site since we started: search engines are the floor, AI answers are a distinct layer you can win, and neither of them is checking who held the pen. This has been our line long enough that I would rather point at it than repeat it.
The real question is not who drafted your pages. It is whether any engine names you when a buyer asks for a company like yours. That is measurable in about three minutes.
Run a free AI visibility scanThe risk you actually have, which predates all of this
Here is what should worry you about AI-drafted content, and it has nothing to do with detection. An engine cites a page when that page contains something specific it can lift and attribute: a number, a defined process, a comparison it cannot get elsewhere, a claim with a source behind it. Generic drafting produces the opposite by default. It produces a page that reads competently and asserts nothing anyone could check, which is invisible to an engine for the same reason it is forgettable to a reader.
That failure is fully available to human writers, and a great deal of human-written B2B content achieves it. The reason AI drafting gets blamed is that it makes the failure cheap to reach at volume, which is precisely the behaviour the scaled content abuse policy describes.
So the practical instruction is unchanged and slightly reinforced. Draft with whatever you like. Then put something in the page that only you could have put there: your own numbers, your own customers' objections, a measurement you ran, a comparison you did at the source. That is what earns the citation. It is also, incidentally, the editing that Anthropic says degrades the mark, so the same work answers both concerns. If you publish AI-drafted content from any tool, including ours, that editing pass is the part to keep.
One thing I will not pretend. If third-party detection ships and some parties start treating a positive result as a trust signal, despite the vendor saying it does not carry that meaning, the calculus shifts. Not for rankings, where the policy is clear, but for procurement questionnaires, platform authenticity rules and review sites, where a crude yes-or-no is often exactly what gets used. Saying that will never happen is the kind of confident prediction that ages badly, so I am saying instead that the hedge is the same either way: publish work you would be happy to defend as yours, which mostly means editing it until it is.
Frequently asked questions
Does Claude watermark its output?
Yes. Anthropic's own support documentation states that Claude weaves an imperceptible watermark directly into the text itself, and that you will not see it and it does not change the meaning, quality or readability of the response. For generated files such as .svg, .png or .jpg, Claude attaches signed provenance metadata instead. Marking applies to models launched on or after 2 August 2026, with earlier models described as in progress, and it covers the API, Claude, Claude Code, Claude Cowork and Claude Tag, worldwide.
Can readers or search engines see that content was written by Claude?
Not today. The watermark is imperceptible by design, so there is no visible badge, no appended disclosure and nothing a reader would notice. Anthropic says it is working to enable users and other third parties to detect the marks, with details promised in forthcoming technical documentation, which means public detection tooling does not exist yet. No search engine can act on a signal nobody outside the vendor can currently read. Marked is not the same as labelled, and that distinction is the whole story right now.
Does Google penalise AI-generated content?
Google's spam policies target the outcome, not the method. The scaled content abuse policy defines the problem as many pages generated for the primary purpose of manipulating search rankings and not helping users, and states that the practice is typically focused on creating large amounts of unoriginal content that provides little or no value to users, no matter how it is created. That last clause is the operative one. A thin, unoriginal page written by a person is in scope. A genuinely useful page drafted with a model and then edited into something specific is not.
What does it actually mean if content is detected as AI-marked?
Less than people will assume, and Anthropic states the limit itself: detecting a Claude mark tells you that the content may have been processed by Claude, and does not, on its own, confirm the full provenance of the content. Processed covers a lot of ground, including editing, translating or restructuring text a human wrote. So a positive detection is not evidence that a machine authored a piece, and treating it as a binary human-or-machine verdict misreads what the mark is.
Does editing remove the watermark?
Heavy editing degrades it. Anthropic lists the cases where a mark may not be detectable: text that has been heavily edited, paraphrased, translated or mixed into other writing, and metadata that was stripped through format conversion, re-saving, screenshots or other means. Note that this makes the mark weakest on exactly the content most worth publishing, since substantive editing is what turns a competent draft into something with a point of view. That is a happy accident rather than a loophole to chase.
Should I stop using AI to draft content for AI search visibility?
No, and the reason has nothing to do with watermarks. The thing that stops an engine citing you is the same thing that makes a page worthless to a reader: it says what a hundred other pages say, it carries no specific claim anybody could check, and nothing outside your own domain corroborates it. That failure mode is available to human writers too, and plenty reach it. Draft however you like, then do the part that actually earns the citation, which is putting a specific, sourced, checkable claim on the page.
What would change if third-party detection ships?
The calculus changes in one specific way worth planning for. If anyone can run a detector, some parties will use a positive result as a trust signal even though the vendor has said it does not carry that meaning: procurement teams, journalists, platforms with authenticity rules, and possibly review sites. That is a reputational and policy risk rather than a ranking one, and the mitigation is the same in either world. Publish content you would be comfortable defending as yours, which in practice means editing it until it is.
Sources and further reading
- Anthropic: how Claude marks AI-generated content. Every quote about the watermark, the provenance metadata, the coverage dates, the meaning of a detection and the conditions under which marks degrade.
- Google Search Essentials: spam policies. The scaled content abuse definition, including the phrase "no matter how it's created".
- SE Ranking: structured data in AI-cited pages. Evidence that markup, not authorship, is what correlates with being cited: 71 percent for ChatGPT, 65 percent for Google AI Mode.
- G2 2026 AI Search Insight Report. The demand-side context for any of this mattering, with AI chatbots now the more common starting point than Google for B2B software vendor research.