• Latest
  • Trending
  • All
Anthropic announcement illustration for the Claude text watermarking post: an ornate quill pen resting across a detailed engraved hand, on a muted heather background.

Every Claude output is watermarked, with no opt-out

3 September 2026
The official xAI announcement card for Grok 4.7, white type on a dark grey and navy gradient.

Grok 4.7 keeps $2 and $6, and its gains over 4.6 are xhigh versus high

22 September 2026
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Tuesday, September 22, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Dev

Every Claude output is watermarked, with no opt-out

by stephane
3 September 2026
in Dev
0
Anthropic announcement illustration for the Claude text watermarking post: an ornate quill pen resting across a detailed engraved hand, on a muted heather background.
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Paste a Claude answer into a doc and something invisible travels with it. Since 2 August, every new model Anthropic ships marks its own prose, and on 15 August the company explained how: a version of SynthID-Text, the Google DeepMind method that nudges word choice rather than hiding characters in the string. It covers the API, claude.ai, Claude Code, Cowork and Tag. Worldwide, not only the EU, with no flag to turn it off. We read the official pages instead of the reaction, because the reaction got the mechanism wrong in both directions, and the part that matters for work is duller than the outrage: the mark is weakest exactly where developers spend their day.

The short answer

Anthropic published the mechanics on 15 August. Claude’s text watermark is a SynthID-Text style statistical mark that biases word choice where several words fit, survives copy and paste, and covers every Claude surface worldwide. There is no opt-out. The catch for anyone hoping to use this: the mark thins out on short answers and on code, and the public detector Anthropic promised is not callable yet. Marked output, and nobody outside Anthropic can check it.

2 Augfrom when new Claude models mark their own text
0documented ways to request unmarked output
12,700+GitHub stars on a mark stripping tool in six days
Answer card: Anthropic marks the text output of Claude models launched on or after 2 August 2026 with a SynthID-Text style watermark that biases word choice instead of inserting hidden characters, applied worldwide across every Claude surface, with zero API flags available to request unmarked output.
Marked by default, everywhere, on models launched from 2 August.

It isn’t hidden characters, and that matters

Half the internet spent last week hunting for zero width spaces in Claude output. Wrong tree. Nothing is inserted into the string, so stripping invisible Unicode does nothing to this mark, and neither does retyping the text by hand into a fresh file.

What Anthropic uses is SynthID-Text, published by Google DeepMind in Nature in 2024, itself descended from a 2022 proposal by Scott Aaronson. The idea is small and quite elegant. When a model generates, it picks the next token from a distribution, and at plenty of points several words are equally fine. Grey or overcast. The watermark doesn’t override that choice. It changes the source of the randomness used to make it, seeded so that the resulting sequence carries a faint statistical bias only a detector holding the key can measure.

Anthropic announcement illustration for the Claude text watermarking post: an ornate quill pen resting across a detailed engraved hand, on a muted heather background.

Image: Anthropic, announcement illustration from its How Claude’s text watermarking works post, 15 August 2026.

One word proves nothing, which is the whole point. The signal only exists in aggregate, and Anthropic says it costs nothing. No extra tokens. Nothing in it identifies you or your account, and DeepMind’s own human rater tests found no quality difference in the output. I’m inclined to believe that part, since the sampling change is genuinely tiny, though “no practical impact” is the sort of claim that only gets tested properly once thousands of people go looking.

Diagram of how a SynthID-Text style watermark is placed: the model reaches a point where grey, overcast or dull would all fit, the randomness used to choose between them is seeded rather than the words being changed, and the resulting pattern only becomes measurable across a long passage.
The words stay the same. The dice behind them do not.

Where the mark holds, and where it thins out

Now the part that decides whether any of this touches your work. The signal comes from free choices, so it fades wherever the model has none.

Short answers carry little. A tight factual paragraph carries less than an essay, because facts pin the wording down. And code carries, in Anthropic’s own words, generally less watermarking than other forms of text, with what little there is landing in arbitrary places like comments. A function is not marked in any useful sense.

Copy and paste keeps it. Light editing “probably won’t remove the watermark completely”, per Anthropic, while a full rewrite does, and the company concedes the obvious follow up: at that point it’s arguable whether the text is still AI generated at all. Translation and format conversion break it too.

So the honest reading is a mark built for volume. It can tell a platform that a flood of submissions looks generated. It cannot tell a lecturer that one paragraph of a student essay was, and treating it that way would be a mistake with real consequences for the person on the wrong end.

Checklist of what Anthropic confirmed about Claude text watermarking: global coverage of the API, claude.ai, Claude Code, Cowork and Tag on models from 2 August 2026, survival through copy and paste, signed C2PA manifests on generated png, jpg and svg files, against no opt-out, weak marking on short samples and code, and a public text detector that has not shipped.
Confirmed by Anthropic on the left of the ledger. Everything it declines to claim on the right.

No opt-out, and no detector

Two things sit awkwardly together right now.

There’s no way to ask for unmarked text. Not on the consumer plans, and not through any parameter on the Claude Platform API. If you build a product on Claude and pass its output to your users, that output is marked. Anthropic points at Article 50 of the EU AI Act as the reason, which does require machine-readable marking of generative output. We went through what Article 50 actually binds you to when it applied on 2 August. Worth noting that the obligation is European and the global rollout is a company decision, not a legal one.

And the detector isn’t there. Anthropic says one is coming, “soon”, with no date and no pricing. Until it lands, the mark is readable by exactly one party. Files are the exception: generated .png, .jpg and .svg carry a signed C2PA manifest you can verify yourself today with c2patool, which is a genuinely useful provenance signal for images if nobody screenshots them.

The reaction was quick. A multi-vendor tool for stripping provenance marks appeared on GitHub on 11 August, the day the news broke, and passed 12,700 stars inside six days. Some of that is principle and some is people who dislike being measured, and the number says more about the mood than about the technology. This is roughly the same argument that followed Twitch turning AI training on by default: the thing people object to is the absence of a switch, more than the feature behind it.

What we’d actually do about it. Nothing, for code. For prose you publish under a client’s name, read your contracts, because “AI generated” is now a property somebody else can test for later, and an agency that promised human writing has a new kind of exposure. If provenance genuinely matters to your pipeline, C2PA on files is the piece you can verify today. For text, wait for the detector, then test it on your own material before trusting a score. Honestly, the most likely outcome is that this changes very little for engineers and quite a lot for whoever runs your content review.

Sources

Anthropic’s How Claude’s text watermarking works, 15 August 2026, and the support article on how Claude marks AI-generated content for the surface list and the transition period. Coverage and dates from TechCrunch and The Decoder. Star count and creation date read from the GitHub API on 17 August 2026.

Frequently asked questions

How does Claude's text watermark actually work?

It is a version of SynthID-Text, the approach Google DeepMind published in Nature in 2024. When the model reaches a point where several words would do equally well, the watermark changes the source of the randomness used to pick between them rather than changing the words themselves. One word tells you nothing. Across a long enough passage the choices form a statistical pattern a detector can score. Anthropic says the mark adds no tokens, carries no identifying information about who prompted it, and does not change cost or speed.

Can I turn the watermark off on the API?

No. Anthropic's documentation describes no API parameter, consumer setting or enterprise tier that returns unmarked output. The marking applies to Claude Platform (API), claude.ai, Claude Code, Claude Cowork and Claude Tag, and Anthropic chose to apply it worldwide rather than only to European traffic. If you resell Claude output inside your own product, that output carries the mark whether or not you disclose it.

Does it watermark code?

Barely. Anthropic states that code carries generally less watermarking than other kinds of text, because the model rarely gets a free choice between equally valid options. Where a mark does land in code it tends to be in the arbitrary parts, comments for instance. Treat a clean detector result on a function as meaning nothing at all.

Can I check a piece of text myself?

Not yet for text. Anthropic says a detection API is coming and has published no date, no pricing and no access tier for it. Files are different: .png, .jpg and .svg generated by Claude carry a signed C2PA manifest, and you can inspect that today with c2patool or any Content Credentials viewer. Format conversion or a screenshot strips it.

Which models are covered?

Models launched on or after 2 August 2026 mark text from launch. Anthropic says it is still adding marking support to models released before that date, under the transition period in the law, and has given no completion date. So an absent mark can simply mean an older model answered.

Tags: aianthropiccomplianceeullmnews
Share197Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
The official xAI announcement card for Grok 4.7, white type on a dark grey and navy gradient.

Grok 4.7 keeps $2 and $6, and its gains over 4.6 are xhigh versus high

22 September 2026
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.