Claude marks everything it writes, and almost nobody can read the mark

A sealed paper envelope beside an open one of the same size, its flap folded back

Two things shipped this summer, and only one of them shipped to everyone. Every model Anthropic has launched since 2 August 2026 marks the text it writes. The tool that reads the mark went to a list.

What the mark is

Not a phrase, not a character, not a header. At each step the model has several words that would do, and it picks with a random number; the change, set out in an explainer on 14 August 2026, is that the randomness now comes from a secret key plus the words already on the page. The output reads the same. The pattern of choices is the signal, and without the key it is indistinguishable from an ordinary run of the model.

It applies to the API and the apps alike, including through AWS, Google Cloud and Microsoft Foundry, in every country rather than only where a regulator asked for it. There is no switch.

Who gets the reader

The detection API is in private preview: regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations, EU civil society groups, and firms with their own compliance obligations. That is a considered decision, not a staged rollout — a public detector would let anyone edit a text, test it, edit again, and stop the instant it came back clean.

The asymmetry is the story

For everyone outside the list, the practical position is new and slightly strange: the text in front of you may carry a verdict about its own origin, and you have no way to ask for it. Provenance stops being something a reader can check and becomes a service an institution requests — on its own subjects, on its own timetable.

What it will not settle

A hit means the text may have passed through Claude. The signal thins where the model had few real alternatives — dense fact, figures, code — and a short passage has too little of it to read. It survives copying and light editing; translation or a genuine rewrite takes it off. Images and vector files are handled by a different mechanism entirely, C2PA provenance metadata, which a screenshot removes.

For anyone whose business rests on published text, the useful move is not to hunt for the mark but to keep your own record. Detection you cannot run is detection you cannot plan around, and reconstructing after the fact — which draft came from where, what was edited by hand, which source was checked on which day — is far harder than writing it down at the time. That record is also the thing a regulator, a client or a court actually asks for, and unlike a watermark it survives translation, paraphrase and a change of file format. Treat the watermark as somebody else's evidence and your own log as yours.

Source: Anthropic checked against the source

More Dubai news