AI watermark law: what must be marked, and from when

Primary sources only Answer in the first paragraph No upload

Article 50(2) of the EU AI Act requires providers of generative AI systems to mark synthetic audio, image, video and text output in a machine-readable format. It applies from 2 August 2026; systems already on the market before that date get until 2 December 2026. Anthropic signed that article's Code of Practice, and its own published dates are those two dates.

Two different things carry a mark, and they are not equally removable. The text watermark is statistical — no cleaner, including this one, can take it out, and Anthropic's own documentation says nothing is added to the text. The file mark is a Content Credential (C2PA), which is metadata, and we measured it coming off in full.

WHAT THE LAW REQUIRES, AND WHAT COMES OFF EU AI Act, Article 50(2). The duty is on the provider, not on you. 2 Aug 2026 Article 50 applies synthetic text, image, audio, video must be marked machine-readably 2 Dec 2026 Grace period ends for systems placed on the market before 2 August 2026 TWO MARKS, TWO DIFFERENT ANSWERS Text watermark no cleaner removes it statistical, part of the wording no characters were added to the text it lives in how the tokens were chosen Content Credential (C2PA) removable metadata attached to a file APP11 segment / caBX chunk measured here: 2079 → 1327 bytes

The rule, in one table

Article 50(2) is the paragraph that matters for watermarks. Its operative sentence, quoted from the Act's official text:

“Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.”

The paragraph also sets the bar the mark has to clear — the technical solution must be “effective, interoperable, robust and reliable”, but only “as far as this is technically feasible”, taking account of the type of content, the cost, and the state of the art. That qualifier is doing a lot of work, and it is the reason the two marks below behave so differently.

QuestionAnswerSource
When does it apply?From 2 August 2026European Commission, Article 50 FAQ
Any grace period?Yes — only for systems placed on the market before 2 August 2026, and only for the marking and detection duty in Article 50(2). Those providers must comply from 2 December 2026.European Commission, Article 50 FAQ
Does old content have to be marked?No. “Content generated prior to 2 August 2026 does not need to be labelled retroactively.”European Commission, Article 50 FAQ
Who has to mark?The provider. Deployers have separate duties to inform and label.Article 50(1)–(5); Commission FAQ
What is marked?Synthetic audio, image, video and text contentArticle 50(2)

Anthropic's dates are those two dates

Anthropic's own help-centre article on how Claude marks content opens by saying it “has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content”, and then states the two dates without naming them as the Act's:

“Claude models launched in the EU on or after August 2, 2026 will support machine-readable marking at launch.”

“Consistent with our commitments under the Code, Anthropic is adding watermarks to outputs from models released before August 2, 2026, with all covered by December 2, 2026.”

That is the same pair of dates the Commission publishes for Article 50(2). Anthropic has not said in that document that the deadline is why it picked them, and we are not going to assert a motive it did not state. What is on the record is that it signed the Code, and that its own transition date is the Act's transition date.

Two further details from that document are worth keeping, because they are the parts most often mangled elsewhere. Marking “will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from” — so switching from the website to the API does not remove it. And the text mark “will travel with the text when it's copied and pasted elsewhere, and may persist through some editing.”

Measured: the file mark comes off, the text mark cannot

This is the part no guide we could find actually runs. We built a JPEG and a PNG carrying a real C2PA JUMBF box — the same container a Content Credential lives in — and then ran the site's own cleaner code over them, reporting which containers survived. Commands, then output, exactly as produced on this machine:

python dev/gen_meta_test.py     # builds a JPEG + PNG carrying a real C2PA JUMBF box
node   dev/verify_strip.js      # runs the site's cleaner.js over them

=== rich.jpg ===
ok: true reason: -
bytes: 2079 -> 1327
BEFORE: APP1 (XMP), APP11 (JUMBF/C2PA), APP13 (IPTC/IRB), APP0 (JFIF), APP1 (Exif), APP2 (ICC), COM, 0xdb, 0xdb, 0xc0, 0xc4, 0xc4, 0xc4, 0xc4, SOS
AFTER : APP0 (JFIF), APP2 (ICC), 0xdb, 0xdb, 0xc0, 0xc4, 0xc4, 0xc4, 0xc4, SOS

=== rich.png ===
ok: true reason: -
bytes: 694 -> 482
BEFORE: IHDR, iCCP, tEXt, iTXt, caBX, IDAT, IEND
AFTER : IHDR, iCCP, IDAT, IEND

Read the two lines that matter. In the JPEG, APP11 (JUMBF/C2PA) is present before and absent after. In the PNG, caBX — the chunk C2PA uses — is present before and absent after. The pixels are not touched, because nothing here re-encodes the image; only the metadata containers are dropped. APP2 (ICC) and iCCP survive deliberately, so colour does not shift. The full container list, and what each one holds →

Now the other half. A statistical watermark is not a container. It is a bias in which tokens the model chose, spread across the whole passage, and it has no byte offset you could delete. Cleaning a file cannot reach it, because there is nothing in the file to reach. That is the same reason Anthropic can say “nothing is added to the text” and still have a watermark: the mark is in the choosing, not the characters. Why those two ideas get confused →

So no tool on this site, or anywhere else, can remove a Claude text watermark. Any page that offers to is describing character cleaning. What a cleaner removes is the other class of thing: invisible characters, and file metadata including the Content Credential. Those are real and worth removing. They are not the statistical watermark.

What the law does not say

Three things get read into Article 50 that are not in it:

There are also carve-outs worth knowing before assuming a mark should be there. Outputs excluded from the marking duty include a short sequence of numbers, symbols or letters; source code; output intended only for machine-to-machine use with no human exposure; and output used only inside closed-loop industrial or product development environments, such as film production, unless it is the final output. An AI system performing an assistive function for standard editing is out of scope too.

Frequently asked questions

When does the AI watermark law start applying?

Article 50 of the EU AI Act applies from 2 August 2026. From that date, providers and deployers of AI systems must meet the transparency obligations in that article. A limited grace period applies only to systems placed on the market before 2 August 2026, and only to the marking and detection duty in Article 50(2): those providers must comply from 2 December 2026. Content generated before 2 August 2026 does not have to be labelled retroactively.

Who is allowed to detect a Claude watermark?

Anthropic says watermark detection is in private preview, available to eligible organisations as required under EU law — regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations and EU civil society groups — plus enterprises that are similarly obligated to verify watermarking for their own compliance. There is a public form to register interest. Separately, anyone can check a file's Content Credential with Anthropic's free Content Checker, because that is a signed metadata label rather than a statistical test. Why a checker cannot confirm a text watermark →

Can you remove a C2PA Content Credential from a file?

Yes, and we measured it rather than asserting it. On a JPEG carrying a real C2PA JUMBF box, the cleaner dropped the APP11 (JUMBF/C2PA) segment and the file went from 2079 to 1327 bytes; on a PNG it dropped the caBX chunk, 694 to 482 bytes. The image pixels were not re-encoded, and the ICC colour profile was kept. What that does not do is change your disclosure obligations — see below. Container by container →

Does removing the watermark remove my duty to disclose AI content?

No. They are different obligations in the same article. Article 50(2) puts the machine-readable marking duty on providers. Article 50(4) puts a labelling duty on deployers who publish deepfakes, or AI-generated text on matters of public interest without human review or editorial control. The Commission states plainly that deployers cannot simply rely on the provider's embedded mark to fulfil their own disclosure duty — which means the duty was never something the mark could satisfy, and is not something deleting the mark can dissolve.

Which content is exempt from the Article 50 marking duty?

The Commission lists output that falls outside the obligation: a short sequence of numbers, symbols or letters; source code; output intended to be communicated exclusively machine-to-machine and processed automatically without any exposure to humans; and output used only in closed-loop industrial and product development environments, for example film production, unless it is the final output. The marking duty also does not apply where the AI system performs an assistive function for standard editing.

Does the AI watermark law apply outside the EU?

Two separate things are being asked there, and it is worth keeping them apart. The obligation is framed by the Commission as something providers must meet before placing a system on the market or putting it into service — the trigger is the EU market, not where you happen to be sitting when you read the output. The marking you actually receive is wider than that, because Anthropic chose to make it wider: its own documentation says marking “will apply to output from supported models wherever Claude is offered, worldwide.” So the practical answer for a user is that Claude output is marked regardless of your location, while the legal question of exactly which providers are in scope is not something this page can settle — we have read Article 50 and the Commission's own FAQ on it, and we are not going to generalise from those to the whole Act.

Is it illegal to remove a watermark from an image?

Article 50(2) does not create a general prohibition on editing metadata in a file you hold, because the marking duty is imposed on the provider rather than on you. But that is a narrow statement and it is not legal advice: it says nothing about other rules. Removing a copyright or ownership watermark, or presenting content as something it is not, can engage separate law and the terms of whatever platform you publish on. If the question matters for your work, ask a lawyer rather than a tool page.

Does this site's cleaner make my output compliant?

No, and we would not claim it. Compliance is about what you publish and what you disclose, not about which bytes are in the file. The cleaner exists to remove invisible characters and file metadata that leak more than people expect. It cannot remove a statistical watermark, it does not rewrite your words, and it does not decide anything about your obligations. What the tool does and does not do →