Skip to main content
All posts
7 min read

Claude watermarks its text now.
That will not clear your name.

The mark records where words have travelled, not who wrote them. For a novelist under suspicion, that difference decides everything.

On 11 August 2026 Anthropic said it will embed an invisible mark in text produced by Claude. The obvious reading is that the authorship argument is over: machines will label their own work, and honest writers can finally be told apart from the rest. The obvious reading is wrong, and Anthropic is the one saying so.

What was actually announced

Every Claude model released on or after 2 August 2026 embeds a statistical mark directly into the words it generates, with older models to be retrofitted later. The mark survives copying and pasting and, in Anthropic's phrasing, may persist through some editing. Files get separate provenance metadata using the C2PA standard. It applies across Anthropic's products, and although the trigger was European regulation, the company is applying it worldwide.

The driver is the European Union's AI Act transparency code, which came into force on 2 August 2026 and requires machine-readable marking of AI-generated content. The penalties reach fifteen million euros or three percent of global turnover, which explains the pace. Google, Meta, Microsoft, OpenAI and others have signed up to the same code, though signing a code and shipping a working text watermark are different milestones.

One detail deserves emphasis before anyone changes their process: the tool that would let you or a publisher check a document for the mark has not been released. Anthropic says detection is in development. Today the check is not available to you, your agent, or your publisher.

A mark means processed, not written

Here is where the intuitive reading breaks. The watermark does not record authorship. It records contact. Anthropic states plainly that detecting a mark will not prove Claude originally authored the content, because a mark can be introduced when Claude proofreads, translates, summarizes or reformats writing that a person produced entirely on their own.

Sit with what that means for a working novelist. Suppose you write ninety thousand words yourself over two years, then paste chapter twelve into Claude and ask it to catch your typos. That chapter may now carry a mark. The prose is yours. The plot is yours. The sentences are the ones you agonised over. And the file carries a signal that an incurious reviewer will read as a confession.

The watermark, in other words, does not distinguish between the novelist who generated a book and the novelist who ran a spellcheck. Both come back marked. Any process that treats a detected mark as proof of ghostwriting will produce false accusations against exactly the careful, thorough writers who use tools responsibly.

The asymmetry that matters most

Now turn it around, because this is the part that should shape how authors think about the announcement. If a mark cannot convict you, a missing mark cannot acquit you either.

Anthropic is explicit: the absence of a detectable mark does not prove that text was written by a human. The signal can be lost through heavy editing, paraphrasing, translation, mixing Claude output with other writing, or passages too short to carry a reliable measurement. Text from older Claude models is unmarked. Text from any other model is unmarked. Text from an open-weight model running on a laptop in someone's spare room is unmarked, and always will be.

So when an agent or a platform accuses you of using AI, and you go looking for something that proves your innocence, the watermark scheme offers you nothing. A clean result means the manuscript has no detectable Claude signal. It does not mean a human wrote it, and no reviewer who understands the system will accept it as though it did. The burden stays exactly where it has always been: on you, without a convenient certificate.

What it is genuinely good for

None of this makes watermarking pointless, and it would be dishonest to pretend otherwise. At the scale of platforms it is useful. A service filtering millions of submissions, a search engine trying not to rank generated filler, a school system with obvious volume problems — all of them benefit from a cheap signal that flags a portion of machine text they would otherwise miss entirely. Marking some of it is better than marking none.

The scheme is also honest about itself, which is more than the detection industry has generally managed. Anthropic published the limitations alongside the feature rather than letting customers discover them. Security researchers have already pointed out that image watermarks have proven removable and that open-source tools for stripping C2PA metadata are freely available, and the constraint that the mark must not alter meaning or readability puts a ceiling on how robust it can be. Anyone determined to launder a manuscript will launder it.

Useful at platform scale and useless to an individual under suspicion are compatible statements. Both are true here.

Two different instruments

It helps to stop thinking of watermarks and detectors as rivals. They measure unrelated things.

A watermark is a provenance signal. It answers a question about history: has this text passed through a particular company's model? The answer arrives as a yes or a maybe, it depends on that company's cooperation, and it covers only the systems that participate.

An audit of the prose itself answers a different question: does this writing carry the structural habits that language models produce? That question can be asked of any text, from any source, whether or not the model that touched it ever agreed to mark anything. It also produces something a provenance check never will — the specific passages that look machine-patterned, which is the only form of feedback an author can actually act on.

Slopsleuth sits firmly in the second category, and deliberately so. It runs no language model. It reads the prose, applies five audits calibrated against published novels, and returns the passages that triggered each flag with the reasoning attached. That design does not depend on any AI company choosing to cooperate, which is why the announcement changes nothing about how it works or what it can tell you.

What to do differently

Very little, and that is the honest answer. The advice that mattered last week still matters.

Keep dated evidence that the manuscript changed over time. Cloud version history, dated backups, outlines, notes, messages to beta readers and editors. Provenance you control persuades a human reviewer far more reliably than any signal generated by a third party, and it is the one thing no watermarking scheme can take away from you or hand to you.

Understand your own prose before somebody else forms an opinion about it. If your writing is spare and declarative, generic detectors have always read you as suspicious, and a watermark does not change that reading. Hemingway scores around seventy-three percent AI on a standard perplexity detector. All four of our public-domain calibration novels score zero out of one hundred on ours. Knowing which passages in your manuscript look statistically unusual, and why, is preparation you can do before an accusation rather than after.

And treat any confident claim about authorship with suspicion, including confident claims made in your favour. Nobody can prove who wrote a document by inspecting the document. Watermarks did not change that this week. They simply added a new signal that will be misinterpreted in both directions by people who have not read the caveats.

See which passages in your manuscript read as machine-patterned — and why.

Five audits calibrated on published fiction. Every flag shows the passage that produced it. No model reads your manuscript.

Run a free sample audit

Questions authors are asking

Does a Claude watermark prove a manuscript was ghostwritten by AI?

No. Anthropic says so directly. A mark indicates that text was processed by Claude at some point, which includes proofreading, translating, summarizing or reformatting work a human wrote. A manuscript can carry a mark and still be almost entirely yours.

If no watermark is found, does that prove a human wrote it?

No, and this is the limitation that matters most to authors. Anthropic states that the absence of a mark cannot guarantee AI was not involved. Heavy editing, paraphrasing, translation, mixing sources, very short passages and older models can all leave AI-assisted text with no detectable signal.

Does this cover ChatGPT, Gemini, Llama and the rest?

Not today. The announcement covers Anthropic's own models. Several other companies have committed to the European code of practice, but a commitment is not a shipped feature, and open-weight models running on someone's own hardware sit outside the scheme entirely.

Can I check my own manuscript for a watermark right now?

Not yet. Anthropic has said detection tooling for users and third parties is in development, with technical documentation to follow. Until that ships, nobody outside Anthropic can run the check.

Should I stop using Claude to proofread my novel?

That is your call, and it depends on how much you trust the people who will read the result. The practical risk is not the tool — it is a reviewer who treats a detected mark as a confession. Keeping dated drafts that show the manuscript changing over time remains the strongest answer to that misreading.

Does this make AI detectors unnecessary?

It makes provenance signals and prose analysis two different instruments. A watermark reports where text has travelled. An audit reports how the prose reads. Neither one answers the other's question, and only the second is available to an author who needs to understand why their writing looks suspicious to a stranger.

Further reading