On August 11, 2026, Anthropic published its approach to marking AI-generated content: an imperceptible watermark woven into generated text, and signed provenance metadata attached when Claude generates a supported file type.
Article 50(2) of the AI Act requires that outputs be both marked in a machine-readable format and detectable as artificially generated or manipulated. Our observation is that those are two obligations, and only the first is discharged at generation. Whether a mark is still detectable at the point an artifact is delivered, archived, or produced in evidence depends on everything that happens in between — much of which the enterprise owns.
Where each mark is applied
The two mechanisms sit at different layers, and Anthropic describes them differently.
The text watermark is applied at the model level. Anthropic states it will be present in output from Claude Platform, Claude, Claude Code, Claude Cowork, and Claude Tag, and when supported models are accessed through AWS, Google Cloud, or Microsoft Foundry. Signed provenance metadata is not described that way: it is attached when Claude generates a supported file type, which Anthropic identifies as including .svg, .png, and .jpg, and applies where Claude supports processing files.
Anthropic also states plainly that some platforms or features may not support certain marking types, and that signed provenance metadata may not be supported on every cloud platform depending on the features each offers. So the coverage question has three axes rather than one: model, surface, and file type. An architect cannot assume the presence of either mark from the presence of the other.
That layering is the pattern the EU’s Code of Practice encourages: Measure 1.1 permits marking at different stages of the value chain while leaving compliance responsibility with the signatory, and Sub-measure 1.1.2 encourages model-level watermarking so downstream providers inherit it through inference. Anthropic has signed that Code’s provider section, which the Commission and the AI Board treat as an adequate route to demonstrating compliance with obligations that are themselves binding.
Two mechanisms, two failure profiles
The two techniques degrade in different directions, and the difference is structural rather than a matter of degree.
The text watermark is intrinsic. It is embedded in the token sequence, so it travels with the text through copy and paste and may persist through some editing. Nothing needs to carry it; it is the content.
Signed provenance metadata is extrinsic. It rides in the file container, and Anthropic states it may be stripped through format conversion, re-saving, screenshots, or other means. It requires a container, and the container is what enterprise pipelines rewrite.
Stated precisely: a stage that re-encodes an image may drop the signed metadata while leaving a text watermark elsewhere in the same pipeline untouched, and a paraphrase stage may degrade the watermark while touching no file metadata at all. Whether either loss occurs depends on the tool — a conversion utility may preserve, update, or reattach a manifest; an edit may weaken a watermark without eliminating it. What holds regardless is that the two marks do not fail together, so a control that treats “the mark” as one object will be wrong about one of them.
The regulator enumerated your pipeline
The Code’s robustness requirement, Measure 3.3, is where the write-path reading becomes concrete. It requires marking and detection solutions to maintain intended performance under typical processing operations, and enumerates them in three classes:
In-place modifications, including recompression, filtering, screenshot and screencasting, lexical substitution, homoglyphs, and change of file format. Desynchronization mechanisms, including cropping, up- and downscaling, rotation, aspect-ratio change, character insertion and deletion, paraphrasing, and translation cycles. And survival of the analog hole — print-and-scan including optical character recognition, audio playback and recording, screen camcording.
Read that list against a regulated content pipeline. Format conversion for archival. Recompression for delivery. Screenshots in ticketing and evidence capture. OCR on scanned intake. Paraphrase and translation in localization. Character-level edits in redaction. The operations the Code names as the robustness threat model are the ordinary stages of enterprise document handling, not an adversary’s toolkit.
Three boundaries on that requirement are worth drawing out. Robustness is a requirement on the provider’s marking and detection solutions together, not a guarantee delivered to the deployer. It does not apply to systems exceptionally subject to only one layer of metadata marking — the category where extrinsic marking stands alone and is therefore most exposed. And the Commission’s Article 50 guidelines, adopted July 20, 2026, outline exceptions including standard editing; where the line falls between standard editing and a transform that defeats a mark is a question those guidelines address and this dispatch does not resolve.
There is also a threshold. Sub-measure 1.1.2 requires watermarking for free-form text longer than 200 tokens, and the Code’s glossary defines “very short text” as text shorter than 200 tokens. Anthropic separately notes that a very short passage may leave too little text for a reliable signal. Outside the commitment, below the reliability floor, and unmarked are three different conditions, and only the first two are established here. What follows for design is narrower and still sharp: a pipeline that emits generated text in short spans reduces the likelihood that any given span is reliably detectable. Chunk size is a provenance parameter.
Intentional and incidental are governed differently
Measure 1.2 of the Code addresses removal directly. Signatories commit to best efforts to preserve metadata markings: to retain and abstain from intentionally altering or removing existing metadata when marked content is used as input and transformed into an output; to include in the acceptable use policy, terms and conditions, or accompanying documentation a prohibition on intentional removal of or tampering with metadata markings by deployers or any other third party; and to neither place on the market nor promote tools whose purpose is circumventing the markings.
The measure carves out good-faith legitimate processing where modification, transformation, or replacement of existing metadata is necessary to maintain accurate and functional information following downstream processing, or for purposes such as security audits and research.
The carve-out turns on necessity, not on accident. So a defensible assessment of any stage that loses a mark asks more than whether the loss was intended: whether the modification was necessary to the stage’s purpose, whether the mark could reasonably have been preserved, whether replacement or updated metadata was possible, whether the behavior is documented and tested, and which contractual prohibition applies to the specific deployment. A pipeline record that captures only “metadata not present at delivery” answers none of those, and each of them can be asked of it later.
What the mark can and cannot conclude
Anthropic is explicit in both directions, and the limits are the most important thing in the document for anyone designing a control.
A detected mark indicates the content may have been processed by Claude. It does not establish authorship. Proofreading, translation, summarization, and format conversion all produce marked output from material that originated elsewhere. Absence of a detected mark establishes less still: the model may predate marking support, the text may have been heavily edited or paraphrased or blended into other writing, the passage may be too short to carry a reliable signal, a file’s metadata may have been stripped in ordinary handling, or the platform, feature, or file type may not support that marking type at all.
Marked and detectable are the obligation. Attributable is not, and no control should be built as though it were.
One sourcing point belongs here rather than in a footnote. Anthropic names the C2PA standard directly. The Code does not name C2PA anywhere; it specifies criteria — recorded metadata, digitally signed, time-stamped, tamper-evident, aligned to established standards. The alignment between the two is a Luminity derivation from the criteria, not a correspondence either document asserts.
The hard claim
Marking is discharged at generation. Detectability is not. It is decided across a path that runs from model support and surface support and file type, through every transform between generation and delivery, to the availability and performance of a detector — and the middle segment of that path belongs to the enterprise.
Marking is discharged at generation. Detectability is not. Mark survival is an end-to-end pipeline property, not a provider-side guarantee — and the transform segment of that path belongs to the enterprise.
An organization that can name the stages putting a mark at risk, and say for each whether the risk was necessary and whether preservation was possible, has a provenance posture. One that reports only what survived cannot say which it has.
Which makes mark preservation a design requirement on transform stages rather than an outcome discovered later. An organization that can name the stages putting a mark at risk, and say for each whether the risk was necessary and whether preservation was possible, has a provenance posture. One that reports only what survived cannot say which it has.
The Signature Is Not the Duty takes up the other half: what a provider’s Section 1 signature does and does not do for a deployer holding obligations of its own.
