• Latest
  • Trending
  • All
Anthropic announcement illustration for the Claude text watermarking post: an ornate quill pen resting across a detailed engraved hand, on a muted heather background.

Every Claude output is watermarked, with no opt-out

3 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
Answer card stating that OpenAI published its research acceleration measurements on 6 September 2026, that as of mid August 2026 its research organisation logged 3.1 agent workdays of coding agent runtime for every workday of human labour normalised to a standard eight hour day, and that OpenAI states this should not be read as a 3.1 times productivity gain because it measures runtime rather than delivered output.

OpenAI’s 3.1 agent-workdays per human day is not a 3.1x gain

7 September 2026
Answer card stating that Mullvad announced on 3 September 2026 that it is shutting down its public encrypted domain name system servers on 2 November 2026 and sponsoring the Quad9 Foundation instead, with 194.242.2.2 and its five sibling addresses all going away, and virtual private network customers unaffected.

Mullvad’s DNS servers go dark on 2 November, and Quad9 blocks no ads

5 September 2026
OpenAI announcement image for GPT-6 Astra, a spiral galaxy of white, blue and amber points of light curling around a bright core on a near black star field.

GPT-6 Astra lists at $10 and $50, 2.5x what GPT-5.6 Sol costs

6 September 2026
Google's official announcement image for the release, reading Introducing Gemini 3.8 Flash and 3.8 Flash Cyber in black type over a pale blue background with a blurred white chevron and the four colour Gemini spark below.

Gemini 3.8 Flash keeps the price and the 1 January cliff

3 September 2026
Answer card stating that Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, that activity data used for misuse monitoring moves into cloud storage the customer controls under the customer own encryption keys, that Anthropic charges nothing for the feature while the cloud provider bills storage and egress, and that the phased rollout starts later in autumn 2026 with interim zero data retention on Fable 5 and Fable 5.1 for eligible customers.

Anthropic moves retention into your own cloud, for 30 days

3 September 2026
Official Google diagram of a client connection in three numbered steps: a DNS lookup with a query and an address, a TLS ClientHello and ServerHello, then a content exchange with a website. A callout on the DNS step reads 25% of global web traffic is now protected by encrypted DNS, and a callout beside an Android phone on the ClientHello step reads Android 17 supports ECH GREASE by default.

Android 17 hides the SNI, not your DNS or destination

3 September 2026
Still frame from the Claude Fable 5.1 launch video showing model-designed protein binders in orange docked against twelve grey target proteins, rendered as ESMFold2 structure predictions.

Claude Fable 5.1 breaks forced tool use, cuts cache 75%

1 September 2026
Answer card stating that on 31 August 2026 the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, the first conversational AI service classified that way, because it answers user prompts and queries including by searching the web, with OpenAI having declared roughly 159.1 million average monthly users in the European Union for ChatGPT search.

The EU now calls ChatGPT a very large search engine

3 September 2026
Answer card stating that on 31 August 2026 the Department of War added OpenAI ChatGPT Mil and Starshield AI Grok for Government to the GenAI.mil portal alongside Google Gemini, all three accredited at Impact Level 5 for Controlled Unclassified Information, with 1.7 million unique users onboarded out of roughly 3 million eligible personnel, and ChatGPT Mil currently serving GPT-5.4 Terra with GPT-5.6 Terra said to be rolling out.

ChatGPT Mil and Grok reached IL5 on GenAI.mil

3 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Friday, September 11, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Dev

Every Claude output is watermarked, with no opt-out

by stephane
3 September 2026
in Dev
0
Anthropic announcement illustration for the Claude text watermarking post: an ornate quill pen resting across a detailed engraved hand, on a muted heather background.
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Paste a Claude answer into a doc and something invisible travels with it. Since 2 August, every new model Anthropic ships marks its own prose, and on 15 August the company explained how: a version of SynthID-Text, the Google DeepMind method that nudges word choice rather than hiding characters in the string. It covers the API, claude.ai, Claude Code, Cowork and Tag. Worldwide, not only the EU, with no flag to turn it off. We read the official pages instead of the reaction, because the reaction got the mechanism wrong in both directions, and the part that matters for work is duller than the outrage: the mark is weakest exactly where developers spend their day.

The short answer

Anthropic published the mechanics on 15 August. Claude’s text watermark is a SynthID-Text style statistical mark that biases word choice where several words fit, survives copy and paste, and covers every Claude surface worldwide. There is no opt-out. The catch for anyone hoping to use this: the mark thins out on short answers and on code, and the public detector Anthropic promised is not callable yet. Marked output, and nobody outside Anthropic can check it.

2 Augfrom when new Claude models mark their own text
0documented ways to request unmarked output
12,700+GitHub stars on a mark stripping tool in six days
Answer card: Anthropic marks the text output of Claude models launched on or after 2 August 2026 with a SynthID-Text style watermark that biases word choice instead of inserting hidden characters, applied worldwide across every Claude surface, with zero API flags available to request unmarked output.
Marked by default, everywhere, on models launched from 2 August.

It isn’t hidden characters, and that matters

Half the internet spent last week hunting for zero width spaces in Claude output. Wrong tree. Nothing is inserted into the string, so stripping invisible Unicode does nothing to this mark, and neither does retyping the text by hand into a fresh file.

What Anthropic uses is SynthID-Text, published by Google DeepMind in Nature in 2024, itself descended from a 2022 proposal by Scott Aaronson. The idea is small and quite elegant. When a model generates, it picks the next token from a distribution, and at plenty of points several words are equally fine. Grey or overcast. The watermark doesn’t override that choice. It changes the source of the randomness used to make it, seeded so that the resulting sequence carries a faint statistical bias only a detector holding the key can measure.

Anthropic announcement illustration for the Claude text watermarking post: an ornate quill pen resting across a detailed engraved hand, on a muted heather background.

Image: Anthropic, announcement illustration from its How Claude’s text watermarking works post, 15 August 2026.

One word proves nothing, which is the whole point. The signal only exists in aggregate, and Anthropic says it costs nothing. No extra tokens. Nothing in it identifies you or your account, and DeepMind’s own human rater tests found no quality difference in the output. I’m inclined to believe that part, since the sampling change is genuinely tiny, though “no practical impact” is the sort of claim that only gets tested properly once thousands of people go looking.

Diagram of how a SynthID-Text style watermark is placed: the model reaches a point where grey, overcast or dull would all fit, the randomness used to choose between them is seeded rather than the words being changed, and the resulting pattern only becomes measurable across a long passage.
The words stay the same. The dice behind them do not.

Where the mark holds, and where it thins out

Now the part that decides whether any of this touches your work. The signal comes from free choices, so it fades wherever the model has none.

Short answers carry little. A tight factual paragraph carries less than an essay, because facts pin the wording down. And code carries, in Anthropic’s own words, generally less watermarking than other forms of text, with what little there is landing in arbitrary places like comments. A function is not marked in any useful sense.

Copy and paste keeps it. Light editing “probably won’t remove the watermark completely”, per Anthropic, while a full rewrite does, and the company concedes the obvious follow up: at that point it’s arguable whether the text is still AI generated at all. Translation and format conversion break it too.

So the honest reading is a mark built for volume. It can tell a platform that a flood of submissions looks generated. It cannot tell a lecturer that one paragraph of a student essay was, and treating it that way would be a mistake with real consequences for the person on the wrong end.

Checklist of what Anthropic confirmed about Claude text watermarking: global coverage of the API, claude.ai, Claude Code, Cowork and Tag on models from 2 August 2026, survival through copy and paste, signed C2PA manifests on generated png, jpg and svg files, against no opt-out, weak marking on short samples and code, and a public text detector that has not shipped.
Confirmed by Anthropic on the left of the ledger. Everything it declines to claim on the right.

No opt-out, and no detector

Two things sit awkwardly together right now.

There’s no way to ask for unmarked text. Not on the consumer plans, and not through any parameter on the Claude Platform API. If you build a product on Claude and pass its output to your users, that output is marked. Anthropic points at Article 50 of the EU AI Act as the reason, which does require machine-readable marking of generative output. We went through what Article 50 actually binds you to when it applied on 2 August. Worth noting that the obligation is European and the global rollout is a company decision, not a legal one.

And the detector isn’t there. Anthropic says one is coming, “soon”, with no date and no pricing. Until it lands, the mark is readable by exactly one party. Files are the exception: generated .png, .jpg and .svg carry a signed C2PA manifest you can verify yourself today with c2patool, which is a genuinely useful provenance signal for images if nobody screenshots them.

The reaction was quick. A multi-vendor tool for stripping provenance marks appeared on GitHub on 11 August, the day the news broke, and passed 12,700 stars inside six days. Some of that is principle and some is people who dislike being measured, and the number says more about the mood than about the technology. This is roughly the same argument that followed Twitch turning AI training on by default: the thing people object to is the absence of a switch, more than the feature behind it.

What we’d actually do about it. Nothing, for code. For prose you publish under a client’s name, read your contracts, because “AI generated” is now a property somebody else can test for later, and an agency that promised human writing has a new kind of exposure. If provenance genuinely matters to your pipeline, C2PA on files is the piece you can verify today. For text, wait for the detector, then test it on your own material before trusting a score. Honestly, the most likely outcome is that this changes very little for engineers and quite a lot for whoever runs your content review.

Sources

Anthropic’s How Claude’s text watermarking works, 15 August 2026, and the support article on how Claude marks AI-generated content for the surface list and the transition period. Coverage and dates from TechCrunch and The Decoder. Star count and creation date read from the GitHub API on 17 August 2026.

Frequently asked questions

How does Claude's text watermark actually work?

It is a version of SynthID-Text, the approach Google DeepMind published in Nature in 2024. When the model reaches a point where several words would do equally well, the watermark changes the source of the randomness used to pick between them rather than changing the words themselves. One word tells you nothing. Across a long enough passage the choices form a statistical pattern a detector can score. Anthropic says the mark adds no tokens, carries no identifying information about who prompted it, and does not change cost or speed.

Can I turn the watermark off on the API?

No. Anthropic's documentation describes no API parameter, consumer setting or enterprise tier that returns unmarked output. The marking applies to Claude Platform (API), claude.ai, Claude Code, Claude Cowork and Claude Tag, and Anthropic chose to apply it worldwide rather than only to European traffic. If you resell Claude output inside your own product, that output carries the mark whether or not you disclose it.

Does it watermark code?

Barely. Anthropic states that code carries generally less watermarking than other kinds of text, because the model rarely gets a free choice between equally valid options. Where a mark does land in code it tends to be in the arbitrary parts, comments for instance. Treat a clean detector result on a function as meaning nothing at all.

Can I check a piece of text myself?

Not yet for text. Anthropic says a detection API is coming and has published no date, no pricing and no access tier for it. Files are different: .png, .jpg and .svg generated by Claude carry a signed C2PA manifest, and you can inspect that today with c2patool or any Content Credentials viewer. Format conversion or a screenshot strips it.

Which models are covered?

Models launched on or after 2 August 2026 mark text from launch. Anthropic says it is still adding marking support to models released before that date, under the transition period in the law, and has given no completion date. So an absent mark can simply mean an older model answered.

Tags: aianthropiccomplianceeullmnews
Share196Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
Answer card: Apple released iOS 26.6 and iPadOS 26.6 on 27 July 2026 with a release note covering bug fixes, security updates and an optimized Spotlight index to prepare for iOS 27, the index the rebuilt Siri reads for personal context.

iOS 26.6 is out: the Spotlight index it quietly builds

27 July 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.