{"id":65010,"date":"2026-08-17T12:59:11","date_gmt":"2026-08-17T15:59:11","guid":{"rendered":"https:\/\/manualdousuario.net\/?p=65010"},"modified":"2026-08-17T12:59:11","modified_gmt":"2026-08-17T15:59:11","slug":"how-claude-text-watermark-works","status":"publish","type":"post","link":"https:\/\/manualdousuario.net\/en\/how-claude-text-watermark-works\/","title":{"rendered":"How Claude\u2019s text watermark works"},"content":{"rendered":"<p>All major LLM providers will be required, by the AI Act of the European Union, to add watermarks to the generated content, including text. Anthropic, owner of Claude, explained its method:<\/p>\n<blockquote><p>Large language models like Claude work by generating one word at a time. Each time the model decides on the next word, it chooses among a list of potential candidates, ultimately selecting the most sensible or likely based on the preceding text. Take the sentence \u201cThe weather today was cold and\u2026\u201d. The next word is very unlikely to be \u201csugary.\u201d But it is quite likely to be \u201covercast\u201d or \u201cgrey.\u201d Under most circumstances, it doesn\u2019t matter much to the reader which of these latter two words the model ultimately chooses\u2014the meaning of the sentence is largely the same either way. In cases like this, the choice is settled by a random number.<\/p>\n<p>Watermarking uses low-stakes choices like these\u2014which occur many times over a piece of generated text\u2014to leave a pattern in Claude\u2019s responses. That pattern is undetectable to the reader, but is detectable to anyone who has a key that encodes it. When watermarking is used, choices are still made at random, but the source of the randomness is different. Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick. That is, the words that Claude picks are still random, but now, one can check the sequence of words and see if it\u2019s consistent with the choices Claude would make if it was using the key. If it is, one can assign a probability that the text was generated by Claude.<\/p><\/blockquote>\n<p>The solution is the same one Google created and has used since 2024 in Gemini, called <a href=\"https:\/\/www.nature.com\/articles\/s41586-024-08025-4\">SynthID-Text<\/a>.<\/p>\n<p>Some people are freaking out over this change. As I&#8217;ve been saying for a while now, <a href=\"https:\/\/manualdousuario.net\/en\/escrever-ia-chatgpt\/\">it doesn&#8217;t matter<\/a>.<\/p>\n<p>Besides, simple systems that swap out some words for synonyms are likely to show up (if they don&#8217;t exist already), which (in theory? someone correct me if that&#8217;s the case) would break SynthID-Text&#8217;s digital signature. Still in the realm of guesswork, I&#8217;d imagine that feeding the text into another LLM and asking it to swap out some words and structures would already do the trick.<\/p>\n<p>Regardless of all that, isn&#8217;t it about time people who use generative AI to write text started owning up to their choices?<\/p>\n<p>I think the first thing that comes to mind when this topic comes up is using the watermark to point fingers and shame whoever uses it. It&#8217;s possible to imagine other uses, though, such as helping triage requests sent to public agencies, which, as <a href=\"https:\/\/www1.folha.uol.com.br\/colunas\/ronaldolemos\/2026\/08\/ia-vai-inundar-o-servico-publico-como-um-tsunami.shtml\">Ronaldo Lemos pointed out<\/a> [pt_BR] in his column in <cite>Folha de S.Paulo<\/cite> this past Sunday (the 16<sup>th<\/sup>), are already swamping governments and courts in several countries.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some people are freaking out over the news that Anthropic&#8217;s Claude will watermark text it generates. I think that: 1) whatever; 2) it seems easy to remove the watermark; and 3) people who use generative AI to write text should start owning up to their choices.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"link","meta":{"episode_type":"","audio_file":"","podmotor_file_id":"","podmotor_episode_id":"","cover_image":"","cover_image_id":"","duration":"","filesize":"","filesize_raw":"","date_recorded":"","explicit":"","block":"","itunes_episode_number":"","itunes_title":"","itunes_season_number":"","itunes_episode_type":"","_locale":"en_US","_original_post":"https:\/\/manualdousuario.net\/?p=65006"},"categories":[1575],"tags":[2306,24,593],"_links":{"self":[{"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/posts\/65010"}],"collection":[{"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/comments?post=65010"}],"version-history":[{"count":1,"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/posts\/65010\/revisions"}],"predecessor-version":[{"id":65011,"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/posts\/65010\/revisions\/65011"}],"wp:attachment":[{"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/media?parent=65010"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/categories?post=65010"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/manualdousuario.net\/wp-json\/wp\/v2\/tags?post=65010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}