Back to Articles
    AI News & Analysis

    Claude Is Watermarking AI Text

    Anthropic has committed to embedding invisible, machine-readable watermarks in text Claude produces, and to doing it worldwide rather than only where the law required it. Models launched from August 2 carry the mark at launch, older models are still being brought in, and public detection does not exist yet. That gap is the whole opportunity for nonprofits: the time to settle your disclosure position is before the mark reaches the model your team uses every day.

    Published: August 12, 202613 min readAI News & Analysis
    Claude Text Watermarking - What Nonprofits Should Do About AI Disclosure

    On August 11, Anthropic's plans to mark AI-generated content drew wide coverage in TechCrunch and Fortune, framed as part of a wider industry scramble to make machine-written text identifiable. The substance is that Claude will weave an imperceptible watermark into the text it generates. The mark is invisible to readers, does not change the meaning or quality of the output, and travels with the text when someone copies and pastes it somewhere else.

    The timing detail matters more than most coverage suggested, and getting it wrong will send you looking for a problem you do not have yet. Marking attaches to models rather than to dates on a calendar. Claude models launched on or after August 2, 2026 support marking at launch. Models released before that date do not carry it yet, and Anthropic says it is working to add marking support to those models under a transition period the law provides. If your team is working in a model that shipped before August, its output is most likely unmarked today.

    The trigger was regulatory. Transparency obligations for AI-generated content took effect abroad on that date, and a code of practice published in June set out how providers should meet them. What matters for a US nonprofit is what Anthropic chose to do with that requirement. Rather than applying the mark only in the territory that mandated it, the company committed to applying it everywhere. Its documentation states plainly that marking applies to output from supported models wherever Claude is offered, worldwide, across the API, the Claude apps, Claude Code, Claude Cowork, and Claude Tag, and when supported models are reached through AWS, Google Cloud, or Microsoft Foundry.

    That single decision is what makes this relevant to a community health center in Ohio or a food bank in New Mexico that has never given a moment's thought to overseas AI law. The mark is not confined to the jurisdiction that required it, and nobody at your organization will be asked to opt in or notified when it starts applying to their work. It simply arrives with the model, and it is not something anyone can see by looking at the document.

    That gives most nonprofits a short and genuinely useful window. Your existing documents are almost certainly unmarked. Your future ones increasingly will not be, because organizations move onto newer models by default as older ones are retired, and very few nonprofits track which model version their staff are using. The practical question is not what to do about the drafts in your files. It is what you want your position to be by the time the mark is on everything, which is a decision worth making deliberately rather than discovering later.

    This article covers what the mark actually is, the two things it specifically cannot prove, where it intersects with real nonprofit work like grant applications and funder reporting, and what a reasonable organization should do in the next month. It also covers what not to do, because the most likely harm from this change is not a nonprofit getting caught using AI. It is a nonprofit misunderstanding what a detection result means and accusing the wrong person.

    What the Mark Actually Is

    It helps to be precise here, because the word watermark carries visual baggage that does not apply. There is no logo, no footer, no tag appended to the bottom of the response, and no strange character hidden between words. Nothing has been added to the text in the way a stamp is added to a photograph.

    Instead, the mark lives in the word choices themselves. As the model generates text, it is nudged toward particular options among the many near-equivalent words and phrasings available at each step, following a pattern that a detector holding the right key can recognize statistically. The result reads normally because at any given point the model was choosing between words that were all reasonable. The signal only emerges across the passage as a whole.

    This design has a deliberate consequence. If the mark were something you could inspect by hand, it would also be something you could strip by hand, and a five-second find-and-replace would defeat the entire system. Because it is distributed across the statistical texture of the writing, it survives copying, pasting, changing the font, moving the text into a grant portal, and a fair amount of ordinary editing. It is meaningfully harder to remove than any previous approach to labeling machine-written text.

    Files are handled differently. Rather than embedding a statistical pattern, supported files including common image formats receive signed provenance metadata built on the C2PA standard, which is the same content credentials framework covered in the guide to content authenticity for libraries, archives, and museums. That approach is more fragile in one sense, since metadata can be stripped when a file is re-encoded or uploaded to a platform that discards it, but it is also more informative when it survives, because it carries a verifiable signature rather than a probability score.

    One practical detail matters for planning. Detection is not something your organization can currently perform. Anthropic has said technical guidance and detection mechanisms will follow, but at the time of writing there is no public tool that lets a program officer paste a paragraph and get an answer. The mark exists in your documents now; the ability to read it is still being built, and it will be built by others before it is built by you.

    What Survives

    Ordinary handling that keeps the mark intact

    • Copying and pasting into a document or grant portal
    • Changing formatting, fonts, or file type
    • Light copyediting and small wording fixes
    • Emailing the text or posting it to a website

    What Erases It

    Common situations that leave no detectable signal

    • Substantial rewriting or paraphrasing
    • Translation into another language
    • Short passages such as a subject line or tagline
    • Blending AI output into a longer human-written piece
    • Output from other AI tools, or from older Claude models

    The Two Things It Cannot Prove

    This is the part of the story most likely to be lost in summary, and it is the part with the most potential to cause harm inside a nonprofit. The mark supports two much narrower claims than most people will assume, and the gap between what it shows and what people will read into it is where trouble starts.

    The first limitation is that a detected mark indicates the text was processed by Claude, not that Claude authored it. Those are very different statements. A grant writer who drafts a narrative entirely herself, then pastes it into Claude and asks it to tighten the third paragraph, has produced a document that may carry the mark. So has a program director who wrote a report longhand and used the model to fix grammar, and a communications volunteer whose own writing was run through for a plain-language pass. In each case the thinking, the claims, and the substance are human. The mark does not distinguish between these people and someone who typed one sentence and published the response unread.

    The second limitation runs the other way and is at least as important. The absence of a mark proves nothing at all. Text written entirely by ChatGPT or Gemini carries no Claude mark. Neither does output from Claude models released before August 2. Neither does a Claude draft that someone rewrote substantially, translated, or chopped into short fragments. An unmarked document is not evidence of human authorship, and treating it as such would be a serious error.

    Put those together and you get a tool that is genuinely useful for provenance at scale, when a platform wants to understand what fraction of submitted content came through a particular model, and close to useless for adjudicating an individual case. That asymmetry is familiar to anyone who watched AI detection software arrive in education, where tools with respectable aggregate accuracy produced individual false accusations that damaged real people. The underlying technology here is better, but the reasoning error it invites is exactly the same one.

    The practical rule that follows is short. A detection result is a question, never a finding. If a funder, a board member, or a manager ever raises one, the correct next step is to ask the person what they did, not to decide what they did. Anthropic's own framing supports this, describing a detected mark as a signal rather than something conclusive.

    Reading a Detection Result Correctly

    What each outcome does and does not support

    Both possible results are weaker evidence than they appear, and in opposite directions.

    • Mark found: Claude touched this text at some point. It does not indicate how much, or whether a human wrote the substance.
    • No mark found: Nothing established. Another tool, an older model, heavy editing, or a short passage all produce this result.
    • Either result: Grounds for a conversation with the author, never grounds for a conclusion about them.

    Where This Lands in Actual Nonprofit Work

    Abstract provenance debates become concrete quickly when you list the documents a small nonprofit produces in a normal month. Nearly all of the writing that carries institutional weight now passes through an AI tool somewhere in most organizations, and the categories differ sharply in how much the mark matters.

    Grant applications sit at the top of the list. If your development team uses Claude anywhere in the proposal process, from researching a funder to drafting a needs statement to tightening a budget narrative, the submitted text may carry the mark. Funders are already asking about this directly. Federal agencies have moved fastest, with the National Science Foundation permitting AI use in proposal preparation while requiring applicants to disclose the extent and manner of that use, and the National Institutes of Health taking a notably harder line on applications substantially developed by AI. Private funders have been adding AI-use questions to their 2026 application cycles as well, typically clustering around three concerns: whether AI was used, what information was fed into it, and who reviewed the output before submission. Our guidance on using AI in grant writing covers the workflow side of this in more depth.

    Donor communications are the second category, and the calculus is different. Appeal letters, acknowledgments, and stewardship emails carry no formal disclosure requirement, but they carry a relationship. The research on how supporters react when AI involvement is disclosed is genuinely mixed, as covered in the analysis of donor reactions to AI-disclosed communications, and the arrival of a durable mark does not resolve that debate. What it does change is the risk calculation around silence. A practice you would be uncomfortable explaining is now a practice that could conceivably be surfaced by someone else.

    Third are the governance documents: board minutes, policies, bylaws revisions, and committee reports. These are typically drafted by one staff member, approved by a body that assumes it is reading that person's work, and retained for years. The question a board should be asking is not whether AI touched the minutes. It is whether the person who signed them read every line and stands behind it. That question was always the right one, and the mark simply makes it harder to avoid.

    Fourth, and most sensitive, is anything written about the people you serve. Case notes, referral letters, incident reports, and outcome narratives describe real individuals who did not consent to being characterized by a language model. The mark introduces no new risk here on its own, but it does create a durable record that a tool was involved, which is worth thinking about before it appears in a document that ends up in a case file or a legal proceeding.

    Finally there is inbound text, which most organizations have not considered at all. Job applications, volunteer statements of interest, scholarship essays, and community survey responses all arrive from outside. If detection becomes available to hiring platforms and application systems before it becomes available to you, your organization may find itself receiving flagged candidates without any policy for what a flag means. Deciding that in advance is considerably easier than deciding it while looking at a specific applicant.

    Where the Mark Matters Most

    Ranked by the cost of getting it wrong

    • Grant applications: Disclosure is increasingly required, and federal agencies are explicit about it
    • Client records: Durable evidence of tool involvement in documents about real people
    • Governance documents: Retained for years, signed by someone who is accountable for them
    • Donor communications: No formal requirement, but a relationship that silence can damage
    • Inbound applications: You may receive flags before you have a policy for reading them

    The Honest Reframing: Disclosure Was Always the Answer

    There is a temptation to treat this as a technical problem requiring a technical response, and to start asking which models are unmarked, whether paraphrasing tools defeat the pattern, and how to keep the organization's AI use unobservable. That instinct is understandable and it is a mistake, both ethically and practically.

    Practically, it is a losing race. Other providers are moving in the same direction under the same pressure, and an organization that reorganizes its writing workflow around avoiding detection will be doing it again in six months, and again after that. The effort is substantial, the benefit is temporary, and the posture is one nobody wants to explain to a funder.

    Ethically, the reframing is simpler than it looks. If your organization is comfortable telling a program officer exactly how AI was used in a proposal, the mark changes nothing about your situation. It is merely a durable record of something you were already willing to say. If your organization is not comfortable saying it, the problem is not the watermark. The problem is a practice you had already decided to keep quiet, and the watermark has only shortened the amount of time you can keep it quiet for.

    This maps onto guidance that predates the announcement. The case for disclosing selectively rather than universally, made in the piece on where nonprofits should label AI use and where they should not, still holds. A blanket notice on every document is not more honest than a specific one, and it tends to communicate less. What changes is the downside of getting the judgment wrong. Previously, an undisclosed use that a funder would have objected to was likely to stay invisible. Now it may not.

    The related question of labeling images and marketing assets is covered separately in the guide to AI provenance watermarks for nonprofit marketing, and the compliance framing that prompted this change is discussed in the earlier piece on disclosure rules for AI-generated content. Read together, the through line is consistent: organizations that decided their disclosure position deliberately are in good shape, and organizations that avoided the decision have now had the timeline set for them.

    What to Do in the Next Month

    None of this warrants an emergency response. It warrants an hour of deliberate attention from whoever owns AI decisions at your organization, and a short conversation at the next leadership meeting. The work divides into four pieces, and a small organization can complete all of them in an afternoon.

    Start by finding out what your team actually does. Most executive directors underestimate how much AI-assisted writing flows through their organization, because staff who use these tools for routine drafting rarely mention it. Ask directly and without any implication of wrongdoing, because the goal is an accurate picture rather than a confession. You cannot form a disclosure position without knowing what you would be disclosing.

    Second, check the funders you are actively applying to. Pull up the application guidelines for every proposal in your pipeline and find out whether an AI-use question exists and how it is worded. This takes ten minutes per funder and resolves the highest-stakes uncertainty first. Where a question exists, answer it accurately, which is far easier when you completed the first step.

    Third, write down the rule for reading a detection result before you ever encounter one. It should say that a mark is a prompt to ask a question, that an absent mark establishes nothing, and that no personnel or partnership decision will be made on a detection result alone. Committing to this in advance is what prevents a bad decision made under pressure, and it belongs alongside whatever you already have in your AI acceptable use policy.

    Fourth, decide the disclosure line for each category of document rather than for the organization as a whole. Grant narratives, client records, board minutes, and donor emails carry different obligations and different relationships, and a single blanket rule will be either too restrictive for the low-stakes categories or too permissive for the high-stakes ones. If your organization has never written this down, the one-day approach in the guide to building a nonprofit AI policy in a day is a reasonable starting structure.

    Worth Doing Now

    Four steps, roughly an afternoon

    • Ask your team where AI is genuinely being used, without blame
    • Check AI-use questions on every application in your pipeline
    • Write the rule for reading a detection result before you need it
    • Set the disclosure line per document category, not organization-wide
    • Tell the board what changed in three sentences at the next meeting

    Not Worth Doing

    Responses that cost more than they return

    • Switching tools to find an unmarked one, which is a temporary fix
    • Routing drafts through paraphrasing tools to strip the mark
    • Banning AI outright, which pushes usage out of sight
    • Buying detection software before detection is even available
    • Retroactively auditing documents your team wrote last year

    The Larger Shift Underneath

    Step back from the specifics and this announcement is a marker of something broader. For three years, the default assumption about AI-assisted writing was that it was undetectable in practice, and a great deal of organizational behavior quietly organized itself around that assumption. Policies said one thing while daily practice said another, and the gap was sustainable because nothing could close it.

    That assumption is now weakening, unevenly and imperfectly, but in one direction only. The mark is easy to defeat if you are trying, which means it will not catch anyone determined to hide. What it will do is remove the comfortable ambiguity for everyone who was not really trying to hide but had never been forced to say so out loud. That is most nonprofits, and the adjustment is more cultural than technical.

    The organizations that will handle this well are the ones that already treat AI use as normal, discussable, and bounded by written rules that staff actually know. For them, a durable mark on their text is a non-event, because there was never a gap between what they do and what they would say they do. The organizations that will struggle are the ones where usage is widespread, undiscussed, and technically prohibited by a policy nobody has read since it was adopted.

    If your organization is in the second group, the useful response to this news is not to worry about watermarks. It is to close the gap between practice and policy while you are doing it voluntarily, on your own timeline, and in a conversation you control rather than one a funder starts for you.

    Conclusion

    Text produced by Claude models launched from August 2 carries an invisible, machine-readable mark, and the decision to apply it worldwide rather than only where it was required is what makes this a US nonprofit story rather than a foreign compliance story. Older models are not marked yet and are being brought in over a transition period, so the accurate description of your situation is that this is arriving rather than that it has already happened.

    The mark supports narrower conclusions than its name suggests. It shows that Claude processed the text, not that Claude wrote it, and its absence shows nothing whatsoever. Any organization that responds by treating detection results as verdicts about individual people will do more damage than the underlying issue ever could, which is why writing the interpretation rule before the first result arrives is the single most valuable thing on the list.

    The genuinely actionable work is small and unglamorous. Find out what your team is really doing, read the AI-use question on every application in your pipeline, decide the disclosure line document category by document category, and tell your board what changed. None of it requires new software, and all of it is work you would benefit from having done regardless.

    The uncomfortable version of the takeaway is worth stating plainly. Nothing about your organization's AI use became wrong on August 2. It only became harder to leave unexamined, and a practice that only worked while it was invisible was never really working.

    Close the Gap Before Someone Else Points at It

    We help nonprofits work out where AI belongs, what to tell funders about it, and how to write a disclosure position the whole team can follow.