No, Claude Isn't Watermarking Every Word You Generate
The viral 'invisible watermarks in all Claude text' claim is wrong. The real story: Claude Code fingerprinted proxy users, then got patched.

The claim doing the rounds — that every Claude output now carries an invisible watermark, plus metadata stamped into every file — doesn't hold up. As of August 2026, Anthropic has shipped no public text watermarking scheme: no SynthID-Text equivalent, no C2PA content credentials, no detector anyone can run. OpenAI and Google went that route for images. Text provenance is still essentially unsolved.
What's real is narrower and weirder. On 30 June 2026, a researcher at thereallo.dev reverse-engineered the Claude Code binary and found it encoding invisible Unicode markers into system prompts — swapping the apostrophe in "Today's" between four visually identical characters (ASCII apostrophe, U+2019, U+02BC, U+02B9) and flipping the date separator from a dash to a slash — to encode whether your traffic was routed through a known reseller or an AI-lab proxy. It only fired when a custom ANTHROPIC_BASE_URL was set, not on the default API. Anthropic's Thariq Shihipar called it a March experiment against unauthorized resellers and distillation; version 2.1.197 stripped it out, with no mention in the changelog.
So: request fingerprinting on a thin slice of CLI traffic, since removed. Not universal watermarking. Still a trust hit — the mechanism was undocumented, and the fix shipped silently too.
Why it matters: "hidden markers in your prompts" and "watermarks in all AI text" are wildly different claims, and only one of them actually happened.
Sources
- Claude Code Hid Proxy Fingerprints in System Prompts: Anthropic Promises Fix techtimes.com
- Claude Code Is Marking Requests: What Anthropic Hid byteiota.com
Written by an AI pipeline from the sources above. How it works.
Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.