Which AI Models Watermark Their Output?
A vendor-neutral, factual comparison of how major AI providers mark generated text and files in 2026, where marking is confirmed, where it is image-only, and where the status still needs verifying.
Several major AI models now watermark their output, but coverage varies widely by provider and by content type. As of August 2026, Claude is the clearest confirmed example of an embedded, machine-readable text watermark applied with no opt-out. Google's SynthID also watermarks generated text inside Gemini. Most other providers mark images and audio today, and their text-watermarking status is either newer or not publicly confirmed.
This page compares Claude against the other major models on a factual basis. Layer3 Labs is an AI-automation consultancy, not a ranked vendor and not a party in this comparison. There is no winner here, and avoiding a watermark is not a goal. Provenance marking is a compliance and trust feature, so the useful question is which models mark what, and how confident you can be in each status.
Watermarking statuses change fast, and several vendors have shipped image provenance long before any text signal. Where a provider's current text-watermarking status is not clearly confirmed by a primary source, this page says so plainly and tells you to verify it directly. For the full background on how these marks work, see our guide to AI watermarking and the pillar explainer on the Claude AI watermark.
Claude (Anthropic) vs. Other major AI models: Side-by-Side
| Dimension | Claude (Anthropic) | Other major AI models |
|---|---|---|
| Invisible text watermark | Confirmed. Claude models released on or after Aug 2, 2026 embed an invisible, machine-readable text watermark by biasing token selection during sampling. | Mixed. Google's SynthID watermarks generated text in Gemini (confirmed). For most others, including ChatGPT and Copilot, shipped text watermarking is not confirmed, verify with the vendor. |
| C2PA / signed file provenance | Confirmed. Claude attaches cryptographically signed C2PA provenance metadata to supported files (.png,.jpg,.svg). | Widespread for images. OpenAI, Google, and Microsoft attach C2PA Content Credentials to generated images; Meta and others are C2PA members. Confirm current file coverage per vendor. |
| Opt-out available | No opt-out. The marking is applied at the model level, so no product surface can turn it off; free and paid users alike. | Varies. Some image and media marks are admin- or setting-gated (for example Microsoft 365 Copilot). Confirm each vendor's controls before relying on them. |
| Coverage (chat + API) | All surfaces. API, claude.ai, Claude Code, Claude Cowork, Claude Tag, plus Claude via AWS, Google Cloud, and Microsoft Foundry. | Varies by provider and content type. SynthID spans Gemini text plus Google's image, audio, and video models; other vendors' coverage differs and should be checked. |
| EU AI Act Article 50 driver | Yes. Driven by EU AI Act Article 50(2) transparency obligations, but Anthropic applies the marking globally, not only in the EU. | Same regulatory pressure applies. Article 50 has extraterritorial reach, so most providers face it; how each has responded on text specifically varies, verify. |
| Public detection tool | Forthcoming, not yet released. You cannot verify Claude's text watermark yourself today. | Mixed. Google and OpenAI offer public checkers for some image and audio content; text-detection availability differs and should be confirmed per vendor. |
Which AI models watermark their output in 2026?
In 2026, Claude and Google's Gemini are the clearest examples of major models that watermark generated text, while image and audio watermarking is far more widespread across providers. Claude embeds an invisible text watermark and signed file provenance with no opt-out. Google's SynthID watermarks generated text in Gemini as well as images, audio, and video across Google's models.
Most other major providers watermark images and audio today, not text. OpenAI adds provenance to generated images and audio through ChatGPT and its API. Microsoft marks Copilot media with C2PA metadata and watermarks. Whether any of these ship an embedded text watermark right now is either newer or not publicly confirmed, so treat text and images as two separate questions.
The broader picture is that coverage is uneven and moving quickly. A model can mark images while leaving text unmarked, or mark text in one product but not another. Because statuses change, confirm each vendor's current position from a primary source before you rely on it for compliance or verification.
- Text watermark confirmed: Claude, and Google's Gemini via SynthID
- Image and file provenance widespread: OpenAI, Google, Microsoft, plus C2PA members
- Text status not confirmed for several providers: verify directly before relying on it
- No mark proves nothing, absence can mean an older model, a human author, or edited output
Weighing watermarking and provenance while choosing or governing AI vendors under the EU AI Act? Layer3 Labs advises teams on vendor selection with compliance built in.
Book a ConsultationClaude (Anthropic): text watermark + C2PA, no opt-out
Claude is the clearest confirmed case of an embedded text watermark with no opt-out. Anthropic announced on August 11, 2026 that Claude models released on or after August 2, 2026 embed an invisible, machine-readable text watermark, produced by biasing token selection while the model generates text. The mark is designed to survive copy-paste and stay invisible to ordinary readers.
Claude also attaches cryptographically signed C2PA provenance metadata to supported files, including.png,.jpg, and.svg. The text watermark and the file metadata are two separate mechanisms: the statistical signal lives inside the text itself, while C2PA Content Credentials travel with the file as signed metadata.
The marking is applied at the model level, so no product surface can switch it off, and it covers the API, claude.ai, Claude Code, Claude Cowork, Claude Tag, and Claude accessed through AWS, Google Cloud, and Microsoft Foundry. Anthropic did this to meet EU AI Act Article 50(2), but chose to apply it globally, so every user gets marked output. One important limit: the mark shows text may have been processed by Claude, not that AI authored it, because people also use Claude to proofread, translate, and reformat human writing. Public detection tooling is forthcoming, not yet released, so you cannot verify the text watermark yourself today. Our pillar explainer covers the details.
Text watermarking vs image watermarking across providers
Text watermarking and image watermarking are different problems, and most providers solved the image side first. Marking a generated image or audio file is more mature: providers embed a signal like Google's SynthID into the pixels or waveform, and attach C2PA Content Credentials as signed metadata. Embedded text watermarking is newer and less universal, because a short block of text carries far less room to hide a durable, machine-readable signal.
On images and files, coverage is broad. OpenAI joined C2PA and adds provenance to images generated through ChatGPT and its API, having supported Content Credentials on DALL-E images since 2024. Microsoft marks Copilot images, audio, and video with C2PA-style metadata and watermarks, some of it gated behind admin or account settings. Meta and many others are C2PA members. So for pictures and media, several major models mark their output today.
On text, the confirmed set is smaller. Claude embeds a text watermark, and Google's SynthID watermarks generated text in Gemini. For providers whose text-watermarking status is not clearly confirmed, this page marks it as not confirmed rather than guessing. Two caveats apply to every provider: C2PA file metadata is trivially strippable by re-saving, screenshotting, or converting a file, and heavy editing may degrade a text watermark, though vendors generally have not published an exact threshold. Our AI watermarking guide explains the mechanics, and generic AI detectors do not read these vendor signals at all.
- Images and audio: broadly marked (SynthID, C2PA Content Credentials) across major providers
- Text: confirmed for Claude and Gemini; not confirmed for several others, verify
- C2PA metadata is strippable by re-saving, screenshotting, or format-converting a file
- Generic AI detectors do not read these provider watermarks; they only guess from style
The full comparison
Here is the full multi-vendor matrix as of August 2026, with unconfirmed statuses marked as such rather than guessed. Read text and images as separate columns, because a provider can mark one and not the other. Where a cell says "Not confirmed (verify)," treat it as a prompt to check the vendor's own documentation, not as a claim that the feature is absent.
| Provider | Text watermark? | C2PA / file provenance? | Opt-out? | Notes |
|---|---|---|---|---|
| Claude (Anthropic) | Yes: invisible text watermark, confirmed | Yes: signed C2PA on.png/.jpg/.svg | No: model-level, all surfaces | Global rollout; detection tool forthcoming; mark shows processing, not authorship |
| ChatGPT / OpenAI | Not confirmed (verify) | Yes: C2PA + SynthID on generated images and audio | Varies (verify) | Text watermarking not publicly confirmed as shipped; image and audio provenance is live |
| Google Gemini | Yes: SynthID watermarks Gemini text | Yes: SynthID across images, audio, video | Varies (verify) | SynthID spans text and media; a public checker exists for some content |
| Microsoft Copilot | Not confirmed (verify) | Yes: C2PA Content Credentials on images, plus audio/video marks | Varies: some marks admin/setting-gated | Media marking rolled out in 2026; text-watermark status not confirmed |
| Meta Llama / others | Not confirmed (verify) | Partial: C2PA member; open weights cannot guarantee marking | Not applicable / varies | Open-weight models can be run without marking; confirm per deployment |
The verification note matters. Several cells above are deliberately left as "Not confirmed (verify)" because a primary source did not clearly confirm a shipped text watermark for that provider. Statuses in this space change month to month, so before you rely on any single cell for a compliance decision, confirm it against the vendor's current documentation or announcement.
What this means when you choose an AI vendor
When you choose an AI vendor, treat provenance marking as a compliance and trust feature to plan around, not an obstacle to route past. If the EU AI Act Article 50 applies to you, marked output actually helps you meet the transparency obligation, because the machine-readable signal is part of what the rule asks for. Article 50 has extraterritorial reach, so US and UK companies serving EU users are affected.
For most businesses, the practical questions are simple. Which models mark the content types you generate, can the marking be turned off in your plan, and does any downstream partner require or forbid a given provenance signal? A model that marks its output can be an asset in regulated or reputation-sensitive work, because you can show where content came from.
Across the content-automation routines we run on our own portfolio of sites, the pattern we see is that provenance and disclosure rarely hurt real publishing workflows, and clarity about what each tool marks saves far more time than trying to detect or defeat a signal after the fact. When we advise clients on AI-vendor selection, we treat watermarking status the same way we treat data residency or security posture: a factual attribute to confirm up front, per vendor and per content type, and to re-check as it changes.
- Confirm marking status per vendor AND per content type (text vs image vs audio)
- If EU AI Act Article 50 applies, marked output supports compliance rather than blocking it
- Check whether marking is model-level (no opt-out) or setting-gated in your plan
- Re-verify periodically, statuses change and detection tooling is still maturing
The Verdict
Claude is the clearest current example of an embedded, machine-readable text watermark applied with no opt-out, and Google's SynthID also watermarks Gemini text. For text specifically, that confirmed set is small in 2026.
Image and file watermarking is far more widespread: OpenAI, Google, and Microsoft all attach provenance to generated images, and many providers are C2PA members. Read text and images as separate questions when comparing vendors.
For most businesses, provenance marking is a compliance and trust asset, not a problem, especially under EU AI Act Article 50. Because statuses change fast, confirm each vendor's current position from a primary source before you rely on it.
Researched from primary Anthropic documentation and public regulator sources. Pricing and availability are accurate as of Aug 11, 2026 and can change — confirm current terms with each vendor before you buy.
Frequently Asked Questions
- A shipped text watermark for ChatGPT is not publicly confirmed as of August 2026, verify with OpenAI directly. What is confirmed is that OpenAI joined C2PA and adds provenance to generated images and audio through ChatGPT and its API, including Content Credentials on generated images. Text watermarking research exists in the industry, but treat ChatGPT text as not confirmed until OpenAI states otherwise.
- Yes. Google's SynthID watermarks generated text in Gemini, and also marks images, audio, and video across Google's models. SynthID is an embedded signal designed to stay invisible to readers. Google offers verification for some content types, though SynthID only detects content from Google's own models, and the signal can weaken against paraphrasing, translation, and heavy edits.
- No. Watermarking coverage is uneven in 2026. Claude and Gemini are the clearest confirmed cases of text watermarking, while image and audio marking is more widespread across providers like OpenAI and Microsoft. For several models, the text-watermarking status is not publicly confirmed, so you should verify each vendor individually rather than assume all models mark their output.
- Possibly, but the status changes and this page does not frame avoiding a watermark as a goal. Some models' text-watermarking status is not confirmed, and open-weight models can be run without marking, but marking is expanding under transparency rules like EU AI Act Article 50. If your work touches the EU, marked output can help you comply, so weigh provenance as a feature rather than something to dodge, and verify each vendor's current status.
- Image and file provenance is widespread: OpenAI, Google, and Microsoft attach signals like SynthID or C2PA Content Credentials to generated images, and many providers are C2PA members. Confirmed text watermarking is narrower, Claude and Gemini are the clear cases. Read the two separately, because a provider can mark images while leaving text unmarked, or vice versa.
- Detection depends on the provider. Google and OpenAI offer public checkers for some image and audio content, while Claude's text-watermark detection tool is forthcoming and not yet released. On removal, C2PA file metadata is trivially strippable by re-saving, screenshotting, or converting a file, and heavy editing may degrade a text watermark, though vendors generally have not published an exact threshold. This page does not provide removal instructions.
- No. A watermark like Claude's shows the text may have been processed by the model, not that AI authored it, because people use these tools to proofread, translate, summarize, and reformat human writing, all of which gets marked too. Likewise, the absence of a mark proves nothing, since content could come from an older model, another AI, or a human. See our guide on AI content and provenance for more.
- EU AI Act Article 50(2) sets transparency obligations that require providers of generative AI to mark synthetic output as machine-generated in a machine-readable way. It has extraterritorial reach, so US and UK companies serving EU users are affected. That rule is the main driver behind moves like Claude's global watermarking. Verify the current text of Article 50 before relying on specifics.
Choosing or governing AI vendors with provenance in mind?
Layer3 Labs is vendor-neutral. We help teams select and govern AI tools with watermarking, provenance, and EU AI Act Article 50 obligations factored in from the start, the same way we weigh security and data residency. Book a free AI workflow audit and we will map your use cases to the right models and the marking they apply.
Book a Consultation