Reviewed by Jonathan West · Updated Aug 22, 2026

Which AI Models Watermark Their Output?

A vendor-neutral, factual comparison of how major AI providers mark generated text and files in 2026, where marking is confirmed, where it is image-only, and where the status still needs verifying.

Reviewed by Jonathan West · Updated Aug 22, 2026

Several major AI models now watermark their output, but coverage varies widely by provider and by content type. As of August 2026, Claude is the clearest confirmed example of an embedded, machine-readable text watermark applied with no opt-out. Google's SynthID also watermarks generated text inside Gemini. Most other providers mark images and audio today, and their text-watermarking status is either newer or not publicly confirmed.

This page compares Claude against the other major models on a factual basis. Layer3 Labs is an AI-automation consultancy, not a ranked vendor and not a party in this comparison. There is no winner here, and avoiding a watermark is not a goal. Provenance marking is a compliance and trust feature, so the useful question is which models mark what, and how confident you can be in each status.

Watermarking statuses change fast, and several vendors have shipped image provenance long before any text signal. Where a provider's current text-watermarking status is not clearly confirmed by a primary source, this page says so plainly and tells you to verify it directly. For the full background on how these marks work, see our guide to AI watermarking and the pillar explainer on the Claude AI watermark.

Claude (Anthropic) vs. Other major AI models: Side-by-Side

DimensionClaude (Anthropic)Other major AI models
Invisible text watermarkConfirmed, but only for Claude Fable 5.1 and Claude Mythos 5.1 so far. Older models (Opus 5, Sonnet 5, Haiku 4.5) don't carry it yet. Anthropic is rolling it out to them in an open-ended transition period.Mixed. Google's SynthID watermarks generated text in Gemini (confirmed). For most others, including ChatGPT and Copilot, shipped text watermarking is not confirmed, verify with the vendor.
C2PA / signed file provenanceConfirmed. Claude attaches cryptographically signed C2PA provenance metadata to supported files (.png,.jpg,.svg).Widespread for images. OpenAI, Google, and Microsoft attach C2PA Content Credentials to generated images; Meta and others are C2PA members. Confirm current file coverage per vendor.
Opt-out availableNo opt-out. The marking is applied at the model level, so no product surface can turn it off; free and paid users alike.Varies. Some image and media marks are admin- or setting-gated (for example Microsoft 365 Copilot). Confirm each vendor's controls before relying on them.
Coverage (chat + API)All surfaces. API, claude.ai, Claude Code, Claude Cowork, Claude Tag, plus Claude via AWS, Google Cloud, and Microsoft Foundry.Varies by provider and content type. SynthID spans Gemini text plus Google's image, audio, and video models; other vendors' coverage differs and should be checked.
EU AI Act Article 50 driverYes. Driven by EU AI Act Article 50(2) transparency obligations, but Anthropic applies the marking globally, not only in the EU.Same regulatory pressure applies. Article 50 has extraterritorial reach, so most providers face it; how each has responded on text specifically varies, verify.
Public detection toolForthcoming, not yet released. You cannot verify Claude's text watermark yourself today.Mixed. Google and OpenAI offer public checkers for some image and audio content; text-detection availability differs and should be confirmed per vendor.

Suggest a correction — if you work at one of the products above and something here is out of date, tell us and we'll fix it.


Which AI Models Watermark Their Output in 2026?

In 2026, Claude and Google's Gemini are the clearest examples of major models that watermark generated text, while image and audio watermarking is far more widespread across providers. Claude embeds an invisible text watermark and signed file provenance with no opt-out. Google's SynthID watermarks generated text in Gemini as well as images, audio, and video across Google's models.

Most other major providers watermark images and audio today, not text. OpenAI adds provenance to generated images and audio through ChatGPT and its API. Microsoft marks Copilot media with C2PA metadata and watermarks. Whether any of these ship an embedded text watermark right now is either newer or not publicly confirmed, so treat text and images as two separate questions.

The broader picture is that coverage is uneven and moving quickly. A model can mark images while leaving text unmarked, or mark text in one product but not another. Because statuses change, confirm each vendor's current position from a primary source before you rely on it for compliance or verification.

  • Text watermark confirmed: Claude, and Google's Gemini via SynthID
  • Image and file provenance widespread: OpenAI, Google, Microsoft, plus C2PA members
  • Text status not confirmed for several providers: verify directly before relying on it
  • No mark proves nothing, absence can mean an older model, a human author, or edited output
A Starlink dish mounted on the roofline of a house at dusk
Power Your AI With Starlink

First Month Free

Get one month of Starlink free when you sign up through this link. Fast, reliable internet at home and on the go.

Claim First Month Free

Claude (Anthropic): Text Watermark + C2PA, No Opt-out

As of September 2026, only two Claude models carry the text watermark: Claude Fable 5.1 and Claude Mythos 5.1. Anthropic announced the watermarking initiative on August 11, 2026. Earlier models released before August 2, 2026, including Claude Opus 5, Claude Sonnet 5, and Claude Haiku 4.5, do not carry it yet. Those earlier models remain in an open-ended transition period with no published completion date, per Anthropic's Claude Help Center guidance on marking AI-generated content. The mark itself is designed to survive copy-paste and stay invisible to ordinary readers.

Code counts as text for this purpose. On a model that carries the mark, output from Claude Code and code written in claude.ai or through the API gets the same watermark as prose. Very short snippets or heavily edited code may not carry a readable mark, since the signal needs enough generated text to persist.

The text watermark applies a subtle bias to token selection during generation, while supported image files (.png,.jpg, and.svg) receive signed Coalition for Content Provenance and Authenticity (C2PA) metadata. Anthropic offers no opt-out toggle or setting on any tier. This marking runs across claude.ai, the Application Programming Interface (API), Claude Code, Claude Cowork, Claude Tag, and cloud hosting on Amazon Web Services, Google Cloud, and Microsoft Foundry.

Article 50(2) of the European Union (EU) AI Act prompted this requirement, but Anthropic enforces the marks globally rather than restricting them to European users. A public detection tool for the watermark is forthcoming but not yet released, so you cannot verify it yourself today. A detected watermark shows a Claude model may have processed the text, not that AI wrote it, because human writing edited by Claude also receives the mark. Our pillar explainer covers the mechanism in more detail.

What the Claude mark proves: that text may have been processed by a watermarked Claude model, not that AI wrote it. Absence of a mark proves nothing, since it could come from a Claude model that doesn't carry the mark yet (most do not, as of September 2026), another AI, or a human.

Text Watermarking vs Image Watermarking Across Providers

Text watermarking and image watermarking are different problems, and most providers solved the image side first. Marking a generated image or audio file is more mature: providers embed a signal like Google's SynthID into the pixels or waveform, and attach C2PA Content Credentials as signed metadata. Embedded text watermarking is newer and less universal, because a short block of text carries far less room to hide a durable, machine-readable signal.

On images and files, coverage is broad. OpenAI joined C2PA and adds provenance to images generated through ChatGPT and its API, having supported Content Credentials on DALL-E images since 2024. Microsoft marks Copilot images, audio, and video with C2PA-style metadata and watermarks, some of it gated behind admin or account settings. Meta and many others are C2PA members. So for pictures and media, several major models mark their output today.

On text, the confirmed set is smaller. Claude embeds a text watermark, and Google's SynthID watermarks generated text in Gemini. For providers whose text-watermarking status is not clearly confirmed, this page marks it as not confirmed rather than guessing. Two caveats apply to every provider: C2PA file metadata is trivially strippable by re-saving, screenshotting, or converting a file, and heavy editing may degrade a text watermark, though vendors generally have not published an exact threshold. Our AI watermarking guide explains the mechanics, and generic AI detectors do not read these vendor signals at all.

  • Images and audio: broadly marked (SynthID, C2PA Content Credentials) across major providers
  • Text: confirmed for Claude and Gemini; not confirmed for several others, verify
  • C2PA metadata is strippable by re-saving, screenshotting, or format-converting a file
  • Generic AI detectors do not read these provider watermarks; they only guess from style

The Full Comparison

Here is the full multi-vendor matrix as of August 2026, with unconfirmed statuses marked as such rather than guessed. Read text and images as separate columns, because a provider can mark one and not the other. Where a cell says "Not confirmed (verify)," treat it as a prompt to check the vendor's own documentation, not as a claim that the feature is absent.

ProviderText watermark?C2PA / file provenance?Opt-out?Notes
Claude (Anthropic)Yes, but only on Fable 5.1 and Mythos 5.1 so farYes: signed C2PA on.png/.jpg/.svgNo: model-level, all surfacesOlder models (Opus 5, Sonnet 5, Haiku 4.5) in transition. Detection tool forthcoming. Mark shows processing, not authorship
ChatGPT / OpenAINot confirmed (verify)Yes: C2PA + SynthID on generated images and audioVaries (verify)Text watermarking not publicly confirmed as shipped; image and audio provenance is live
Google GeminiYes: SynthID watermarks Gemini textYes: SynthID across images, audio, videoVaries (verify)SynthID spans text and media; a public checker exists for some content
Microsoft CopilotNot confirmed (verify)Yes: C2PA Content Credentials on images, plus audio/video marksVaries: some marks admin/setting-gatedMedia marking rolled out in 2026; text-watermark status not confirmed
Meta Llama / othersNot confirmed (verify)Partial: C2PA member; open weights cannot guarantee markingNot applicable in practice: self-hosted inference lets an operator bypass any watermarking layer entirely, something a hosted API does not allowOpen-weight models can be run without marking; confirm per deployment
Grok (xAI)Not confirmed (verify)Not confirmed (verify)Not confirmed (verify)No primary source confirms a shipped text or image watermark as of August 2026; verify directly with xAI
DeepSeekNot confirmed (verify)Not confirmed (verify)Not applicable in practice, same open-weight caveat as LlamaOpen-weight releases; an operator running DeepSeek's weights locally decides whether any marking layer runs at all

The verification note matters. Several cells above are deliberately left as "Not confirmed (verify)" because a primary source did not clearly confirm a shipped text watermark for that provider. The same applies to two names that come up often in vendor shortlists: Mistral has not publicly confirmed a shipped text watermark, and Perplexity is a different case since it primarily runs on top of other providers' models rather than shipping one foundation model of its own, so any watermark on its output usually traces back to whichever underlying model produced that answer. Statuses in this space change month to month, so before you rely on any single cell for a compliance decision, confirm it against the vendor's current documentation or announcement.

"Not confirmed (verify)" means exactly that: the current status was not confirmed by a primary source at the time of writing. It is not a claim the feature is missing, check the vendor before relying on it.

What This Means When You Choose an AI Vendor

When you choose an AI vendor, treat provenance marking as a compliance and trust feature to plan around, not an obstacle to route past. If the EU AI Act Article 50 applies to you, marked output actually helps you meet the transparency obligation, because the machine-readable signal is part of what the rule asks for. Article 50 has extraterritorial reach, so US and UK companies serving EU users are affected.

For most businesses, the practical questions are simple. Which models mark the content types you generate, can the marking be turned off in your plan, and does any downstream partner require or forbid a given provenance signal? A model that marks its output can be an asset in regulated or reputation-sensitive work, because you can show where content came from.

Across the content-automation routines we run on our own portfolio of sites, the pattern we see is that provenance and disclosure rarely hurt real publishing workflows, and clarity about what each tool marks saves far more time than trying to detect or defeat a signal after the fact. When we advise clients on AI-vendor selection, we treat watermarking status the same way we treat data residency or security posture: a factual attribute to confirm up front, per vendor and per content type, and to re-check as it changes.

  • Confirm marking status per vendor AND per content type (text vs image vs audio)
  • If EU AI Act Article 50 applies, marked output supports compliance rather than blocking it
  • Check whether marking is model-level (no opt-out) or setting-gated in your plan
  • Re-verify periodically, statuses change and detection tooling is still maturing

The Verdict

Claude is the clearest current example of an embedded, machine-readable text watermark applied with no opt-out, and Google's SynthID also watermarks Gemini text. For text specifically, that confirmed set is small in 2026.

Image and file watermarking is far more widespread: OpenAI, Google, and Microsoft all attach provenance to generated images, and many providers are C2PA members. Read text and images as separate questions when comparing vendors.

For most businesses, provenance marking is a compliance and trust asset, not a problem, especially under EU AI Act Article 50. Because statuses change fast, confirm each vendor's current position from a primary source before you rely on it.

Sources & Disclaimer

Researched from primary Amazon, Anthropic and xAI documentation and public regulator sources. Pricing and availability are accurate as of Aug 22, 2026 and can change — confirm current terms with each vendor before you buy.

Frequently Asked Questions

  • A shipped text watermark for ChatGPT is not publicly confirmed as of August 2026, verify with OpenAI directly. What is confirmed is that OpenAI joined C2PA and adds provenance to generated images and audio through ChatGPT and its API, including Content Credentials on generated images. Text watermarking research exists in the industry, but treat ChatGPT text as not confirmed until OpenAI states otherwise.
  • Yes. Google's SynthID watermarks generated text in Gemini, and also marks images, audio, and video across Google's models. SynthID is an embedded signal designed to stay invisible to readers. Google offers verification for some content types, though SynthID only detects content from Google's own models, and the signal can weaken against paraphrasing, translation, and heavy edits.
  • No. Watermarking coverage is uneven in 2026. Claude and Gemini are the clearest confirmed cases of text watermarking, while image and audio marking is more widespread across providers like OpenAI and Microsoft. For several models, the text-watermarking status is not publicly confirmed, so you should verify each vendor individually rather than assume all models mark their output.
  • Possibly, but the status changes and this page does not frame avoiding a watermark as a goal. Some models' text-watermarking status is not confirmed, and open-weight models can be run without marking, but marking is expanding under transparency rules like EU AI Act Article 50. If your work touches the EU, marked output can help you comply, so weigh provenance as a feature rather than something to dodge, and verify each vendor's current status.
  • Image and file provenance is widespread: OpenAI, Google, and Microsoft attach signals like SynthID or C2PA Content Credentials to generated images, and many providers are C2PA members. Confirmed text watermarking is narrower, Claude and Gemini are the clear cases. Read the two separately, because a provider can mark images while leaving text unmarked, or vice versa.
  • Detection depends on the provider. Google and OpenAI offer public checkers for some image and audio content, while Claude's text-watermark detection tool is forthcoming and not yet released. On removal, C2PA file metadata is trivially strippable by re-saving, screenshotting, or converting a file, and heavy editing may degrade a text watermark, though vendors generally have not published an exact threshold. Whichever method you rely on, see the false positives section of our AI watermark detector guide for why a negative result from a style-based checker is not proof of anything. This page does not provide removal instructions.
  • Yes. Google's Veo carries the SynthID signal across its generated video, the same mark family SynthID uses for Gemini text, images, and audio. OpenAI's Sora attaches C2PA provenance metadata to generated video and adds a visible moving watermark on output from the consumer app; API-specific behavior can differ, so confirm current details on OpenAI's own documentation before you rely on it.
  • No. As of August 2026 there is no federal US law that requires AI systems to watermark their output. The enforceable requirements come from the state level, California's SB 942 (the California AI Transparency Act), and internationally from the EU AI Act's Article 50, which reaches US companies serving EU users. Federal proposals have circulated in Congress, but none has passed into law; verify the current status before relying on it for a compliance decision.
  • No. The mark is applied by biasing the model's choice among near-equal next tokens during the generation it already runs, not through a separate pass or an extra call, so there is no added inference step, meaningful latency, or compute cost. Vendors have not published a measurable performance difference between watermarked and unwatermarked output, and the design intent is that speed and cost stay the same either way.
  • It depends on which layer changes, and no major vendor has published a definitive answer for either case. A custom system prompt sits on top of the base model's normal generation process, so a token-selection watermark should still apply the same way it does to any other output from that model. Fine-tuning is different: retraining the model's weights can shift its underlying token distribution enough to weaken or remove a watermark tied to the base model's original sampling pattern, though no vendor has published how much fine-tuning it takes to do that. In the API integrations we build for clients, we treat a base model's watermarking status as a fixed input to plan around, since our system prompts and any fine-tuning layer sit on top of the model, not underneath it. If your product depends on this, verify current behavior directly with the model vendor before building a compliance claim on top of it.
  • No. A watermark like Claude's shows the text may have been processed by the model, not that AI authored it, because people use these tools to proofread, translate, summarize, and reformat human writing, all of which gets marked too. Likewise, the absence of a mark proves nothing, since content could come from an older model, another AI, or a human. See our guide on AI content and provenance for more.
  • EU AI Act Article 50(2) sets transparency obligations that require providers of generative AI to mark synthetic output as machine-generated in a machine-readable way. It has extraterritorial reach, so US and UK companies serving EU users are affected. That rule is the main driver behind moves like Claude's global watermarking. Verify the current text of Article 50 before relying on specifics.
  • Opt-out means whether a user or admin can turn a mark off for their own output. On this page it applies only to the "Opt-out available" row: Claude's mark is model-level with no opt-out for anyone, free or paid, while some vendors gate certain image or media marks behind an admin or account setting that can be switched off. It is a different concept from a data-training opt-out (a separate control some AI tools offer that stops your inputs from being used to train future models) — check each vendor's own documentation to see which kind of opt-out, if any, applies to a given feature.

Choosing or governing AI vendors with provenance in mind?

Layer3 Labs is vendor-neutral. We help teams select and govern AI tools with watermarking, provenance, and EU AI Act Article 50 obligations factored in from the start, the same way we weigh security and data residency. Book a free AI workflow audit and we will map your use cases to the right models and the marking they apply.

Book a Consultation