What Is AI Watermarking? Labeling and Tracing AI-Generated Content Explained

AI WatermarkingContent ProvenanceC2PA

AI watermarking embeds a machine-detectable mark in AI-generated text, images, audio, or video to show that the content was made by AI. Article 50 of the EU AI Act has applied since August 2, 2026, and mainstream models such as Claude began watermarking by default.

AI watermarking means embedding a machine-detectable mark in AI-generated content to show that "this was produced by AI." It can be a statistical signal invisible to the human eye, or signed metadata attached to a file.

It used to be mostly a research topic and a voluntary practice at a few vendors. On August 2, 2026, the transparency obligations in Article 50 of the EU AI Act began to apply, requiring providers of generative AI to mark outputs in a machine-readable, detectable format. That turned AI watermarking from an optional feature into part of a compliance requirement.

Grab It in One Sentence First

AI watermarking stamps AI-generated content with a mark that machines can see, even if people can't.

An everyday analogy is the watermark on a banknote: you don't notice it in normal use, but hold it up to the light or run it through a checker and you can tell. It doesn't change what the content is for; it just makes "who produced this" verifiable.

What It Usually Includes

"Labeling AI content" actually covers several different approaches that often get lumped together:

  • Invisible watermarks: a statistical signal embedded during generation. For text, a common approach is to nudge the model's choice of the next word slightly toward certain words according to a key; ordinary readers can't tell, but whoever holds the detection method can compute whether a passage carries the watermark. Google DeepMind's SynthID-Text follows this route; its paper appeared in Nature in October 2024, and an open-source implementation ships in Hugging Face Transformers.
  • Provenance metadata: signed metadata attached to a file recording who generated it and with what tool. The industry standard is C2PA (Content Credentials). It suits images, video, and documents, but metadata can be lost when files are re-saved or screenshotted.
  • Visible labels: stating "AI-generated" directly in the interface, such as a label a platform places next to content. It's the most direct, but it depends on the publisher declaring honestly.

These three are often combined, each addressing a different stage of the same problem.

AI-generated content Invisible watermarkembedded in content Provenance metadataC2PA signature Visible labelplatform notice Machine detection Seen directly by readers

What Happened in 2026

Regulation took effect. Article 50 of the EU AI Act has applied since August 2, 2026: providers of AI systems that generate synthetic audio, images, video, or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated. According to the European Commission, generative systems already on the market before that date have until December 2, 2026 to meet the machine-readable marking requirement; fines can reach €15 million or 3% of worldwide annual turnover, whichever is higher. In July the Commission published final guidelines on the transparency obligations and confirmed that the related code of practice can be used to demonstrate compliance.

Mainstream models watermark by default. On August 11 Anthropic updated its help documentation to confirm that Claude models released on or after August 2, 2026 embed an invisible watermark in generated text, while images and other files carry signed C2PA provenance metadata. The marking happens at the model level, covering the web app, the API, and Claude Code, and there is currently no option to turn it off.

Platforms require declaration. In August Apple Music told record labels and distributors that songs substantially generated by AI would carry a visible label within the year, with the content provider responsible for declaring it—though the notice didn't explain how this would be verified.

How It Differs from AI Detectors

An AI detector uses another model to "guess" whether text looks AI-written. There's no pre-embedded signal to check, and false positives have long been a point of contention. A watermark is deliberately embedded at generation time and verified afterward using an agreed method—provided the generator chose to add it and the checker has access to the detection method.

So their reliability comes from different places: detectors rely on statistical inference, watermarks on a prior agreement. Content without a watermark leaves you back on the less reliable detector route.

Common Misunderstandings

The first is "watermarks can identify all AI content." A watermark can only detect content that carries that particular watermark. When an open-weight model runs locally, whether to add a watermark is up to the user, and different vendors' schemes aren't necessarily interoperable.

The second is "watermarks can't be removed." Text watermarks rely on statistical word preferences, so heavy rewriting, translation, or keeping only a very short excerpt all weaken detection; metadata can simply be lost in screenshots or transcoding. Watermarks raise the cost of removal; they don't make removal impossible.

The third is "detecting a watermark means fraud." AI involvement in writing isn't itself a violation. A watermark answers "was this AI-generated," not "is this content trustworthy or compliant."

How It Might Affect You

If you're a content creator or business user: when you use models such as Claude that now watermark by default, be aware that outputs may carry a mark. For content you publish, label it according to your platform's and region's rules; there's no need to try to strip the mark.

If you're building a generative AI product used in the EU: Article 50 also applies to companies headquartered outside the EU whose outputs reach EU users. Assess your mix of watermark, metadata, and labels early, and keep the December 2 date in mind.

If you run a platform or do moderation: treat watermark detection as one clue, not the only evidence, and combine it with metadata, publisher declarations, and human judgment. For related content-reliability issues, see Hallucination and Generative AI.

Sources