If you have used Claude for anything since Tuesday, the words it handed back are marked. Not the chat log. The text itself, carrying an invisible signature you did not agree to, cannot see, and cannot switch off.

There is no setting for this. No plan tier removes it, no API parameter disables it, and it is not limited to Europe. It is applied at the model level, so it reaches every user in every country.

Claude Fable 5.1 and Mythos 5.1 shipped on September 1 to the desktop app, the API and the cloud platforms. They are the first Claude models to embed watermarks in their output, added to satisfy Article 50 of the EU AI Act. Europe wrote the rule and Anthropic applied it worldwide.

Two different things are happening here, and the difference is where most people will get it wrong. Text gets a statistical watermark that biases word choice into a pattern a detector can read. It survives copy and paste and light editing, and heavy rewriting degrades it. Files get something else, C2PA signed provenance metadata, and by Anthropic's own help documentation that covers .svg, .png and .jpg.

Read that file list again. Word documents and PDFs are not on it. Neither is anything you re-save or screenshot, because that strips file metadata regardless of format.

Now the part that should change what you do. The tool that reads the text watermark, Anthropic's Claude Watermark Detector, is in private preview. Access is currently limited to regulators, law enforcement, media organizations, fact checkers, researchers, educational organizations and enterprises with compliance obligations. Anyone can submit the access request form, but ordinary users are not currently eligible.

Your writing carries a mark you have no way to check, and the people most likely to be checking it do.

Which of your tools does this depends entirely on which one you happened to open. Claude marks text as of September 1, with no opt-out. Gemini has carried SynthID text watermarking since 2024, and as of August 13 there was still no consumer button to paste text and get a verdict. ChatGPT does not currently watermark text, and OpenAI built a text watermarker in 2024 then shelved it, citing easy evasion and disproportionate impact on non-native English speakers. xAI never signed the EU code of practice, so Grok sits outside it.

The timing is what makes this worth your Thursday. On September 3, The Decoder reported that percentage scores from AI-detection startup Pangram are fueling a public shaming culture around writers. Pangram is a 24-person Brooklyn company that has raised $9 million and now functions as a gatekeeper for publishers and universities. Its lab numbers are strong, including a measured false positive rate of roughly 1 in 10,000 from University of Chicago and University of Maryland researchers. Its Trustpilot reviews are full of students, dissertation writers and graduate researchers who say it flagged work they wrote themselves.

Four checks. There is no panel to open this time, so these point at your own outgoing work instead.

1
Choose the tool by whether the work gets judged.

If it will be submitted, graded, peer reviewed or filed with a publisher, decide before you start which assistant leaves a mark. Claude does now. Gemini has since 2024. That is a reason to draft the first version yourself.

2
Check what your file format actually carries.

The C2PA metadata only rides on .svg, .png and .jpg. A Word file or a PDF you exported carries the text watermark in its words and nothing in the file itself. A clean file is not evidence of clean text.

3
Request detector access before you are in a dispute.

Anthropic's Watermark Detector Access Request Form is open for anyone to submit, even though approval is currently restricted. If you teach, edit, review submissions or run a compliance function, apply now. The wrong week to learn you are ineligible is the week someone gets accused.

4
Never let a detector score be treated as a watermark.

They are two different kinds of claim. A watermark is a signal the tool deliberately planted, so it can say text passed through Claude. A percentage score is a statistical guess about text nobody planted anything in, from tools with documented false positives against non-native English speakers and reported elevated false positives for neurodiverse writers. If someone shows you a number, ask which of the two they are holding.

One more thing worth knowing before you treat the mark as permanent. Within four hours of the August announcement, a developer published a working bypass. The watermark is a signal, not a lock, and anyone determined to strip it already can.

The takeaway

A simple rule: assume anything Claude writes for you is signed, assume you cannot verify it yourself, and never accept a percentage as proof.

If you have already been on the receiving end of a detector score, on your own work or on someone else's, hit reply and tell me what the number was and what happened next. I want to know how these are actually being used.