Claude Now Embeds Invisible Machine-Readable Watermarks Across All Products
新智元 · wechat · 2026-08-17
On Aug 11, 2026, Anthropic announced that Claude models released since Aug 2 embed invisible, machine-readable watermarks directly in generated text, traceable even after copying and redistribution. The watermark doesn't change semantics, quality, or readability, covers web, API, and Claude Code globally, cannot be disabled; images also carry C2PA provenance metadata. It follows Anthropic signing the EU AI Act Article 50 transparency code of practice.
The article traces provably secure steganography from Shannon (1949) and Cachin (1998) through Blum's computational-security framework (2002), long bottlenecked by requiring exactly samplable cover distributions. In 2018 a USTC team pioneered generative provably secure steganography (black-box sampling and compress-invertible sampling), followed by Tsinghua, BU/JHU, and Oxford; the line evolved from symmetric keys to public-key schemes (ECC + generative models), box-free extraction (Disreo), and gray-box settings (SpecStega via speculative sampling, 20x+ payload over black-box), with SyncPool resolving subword token ambiguity.
Finally: since provably secure steganography preserves the sampling distribution, it yields "provably lossless" watermarks. USTC's system already serves 13,000 developers on iFlytek Spark and other platforms; image-side work includes training-free GaussianShading (CVPR 2024), extending to provably lossless black-box model watermarks. Watermark attack-defense is a cost game under quality constraints—losslessness is both sides' shared constraint.
More from Safety
- OpenAI's Astra hit Critical capability threshold in cyber, parts of development paused — johnseach · 2026-08-17
- Do LLM Watermarks Degrade Quality? Anthropic Example Sparks Debate — JeremyNguyenPhD · 2026-08-17
- JPMorgan CEO on AI: Cyber is the biggest risk, work week to shrink — Roger_M_Taylor · 2026-08-17
- Will hosted models remain useful with increasing watermarks and limits? — vboykis · 2026-08-17
- Zvi on OpenAI/HF attack: HF didn't ask to use closed models, issues existed in non-cyber training too — TheZvi · 2026-08-17
- MCP SSH server lets agents run commands on servers without ever holding keys — NoStrawberry1162 · 2026-08-17