Guide

ChatGPT, Claude and Gemini: what each says about watermarking text

Three vendors, three different positions, and a lot of confident writing online that outruns what any of them have actually claimed.

Published 4 September 2026, 6 min read

Who wrote this

DraftMine is an independent editing tool. It is not affiliated with or endorsed by Anthropic, OpenAI or Google, and it does not detect, verify or remove provenance marks.

Claude watermark explained

Why text is harder to watermark than images

An image has millions of pixels, and nudging them imperceptibly leaves plenty of room to hide a signal. A paragraph has a few hundred words, and every one of them is load-bearing. There is far less redundancy to hide a mark in, which is why text watermarking arrived years after image provenance work and remains more fragile.

The common approach is to bias the model's word choice. At each step a model is choosing among plausible next tokens; a watermarking scheme nudges that choice according to a secret pattern, so the finished text carries a statistical signature that a matching detector can look for. Read one sentence and you would notice nothing. Read a long enough passage with the right key and the pattern becomes measurable.

That design explains the failure modes. Short passages carry too little signal to measure. Heavy editing, translation or paraphrasing disturbs the word choices the signal was built from. And because the signature is statistical rather than a hidden string, results are probabilistic: a detector reports a likelihood, not a fact.

Google: SynthID-Text, shipped and published

Google has gone furthest publicly. SynthID began as a system for marking generated images and audio, and Google extended it to text and described applying it to Gemini output. In 2024 the company published the text method in Nature and released an implementation under its responsible generative AI toolkit, which is unusual: most provenance work stays proprietary.

Google's own material is candid about the limits. The mark survives light editing and some paraphrasing but degrades under heavy rewriting or translation, and short outputs may carry too little signal to detect. Publishing the method also means the trade-off is public: openness lets others verify and adopt it, and equally lets anyone read how it works.

Anthropic: machine-readable marks in supported Claude models

Anthropic has said that supported Claude models can weave an imperceptible, machine-readable mark into generated text. Support depends on the model and on rollout, so it should not be assumed that every Claude output carries a detectable mark.

The framing Anthropic uses matters more than the mechanism. A detected mark is described as a signal that Claude may have processed the content, not as conclusive proof of authorship. Anthropic also notes that heavy editing or paraphrasing may affect detectability, which is a statement about the durability of the signal rather than a supported way of removing it.

OpenAI: discussed, largely not shipped for text

OpenAI's position on text has been the most cautious of the three. The company has worked on provenance and has been reported to have a text watermarking method it did not broadly release, citing concerns including the ease of defeating such marks and the risk of unfairly flagging people, notably non-native English writers.

Separately, OpenAI retired its own AI text classifier in 2023 because of low accuracy. It is worth remembering that this was a detector rather than a watermark, and that the withdrawal was an admission that after-the-fact detection of AI text is unreliable.

For images, OpenAI has adopted C2PA content credentials, which attach signed metadata about how a file was produced. That is a different mechanism from a statistical watermark: metadata travels with a file and can be stripped, while a watermark lives in the content itself.

What this means if you are the one writing

Do not assume a passage is marked, and do not assume it is unmarked. Coverage varies by vendor, by model and by when the text was generated. Anyone telling you they can determine which is speaking beyond the evidence.

Detection is probabilistic in both directions. A detector reporting a mark is a signal, not a verdict; a detector reporting nothing does not establish that a human wrote the text. Both errors have consequences, and the second one is the reason several vendors have been reluctant to ship detectors at all.

The practical response is unchanged by any of this: edit your drafts because it makes the writing better, and follow whatever disclosure rules apply to you. Editing to improve a piece is ordinary craft. Editing specifically to defeat a provenance signal is a different act, and one no honest tool should sell you.

Frequently asked

Is all AI-generated text watermarked?

No. Support varies by vendor, by model and by rollout. Google has described applying SynthID-Text to Gemini output, Anthropic has described marks in supported Claude models, and OpenAI has not broadly shipped a public text watermark. Absence of a mark proves nothing about authorship.

Does editing remove a watermark?

Vendors note that heavy editing, paraphrasing or translation can affect whether a mark remains detectable, because the signal lives in word choice. That is a description of a limitation, not a removal method, and no honest editing tool can guarantee a result.

Can a watermark prove who wrote something?

No. Anthropic frames a detected mark as a signal that a model may have processed the content, not proof of authorship. Detection is probabilistic, and both false positives and false negatives occur.

What is the difference between a watermark and C2PA content credentials?

A watermark is a statistical signal inside the content itself. C2PA content credentials are signed metadata attached to a file describing how it was made. Metadata can be stripped when a file is re-encoded; a watermark degrades instead when the content is edited.

Keep reading

Related guides.

Free, no account

Edit the draft because it makes the writing better.

Open the editor