Will Claude's Text Watermark Show Up in a Turnitin Report?
Anthropic publishes two documents about the Claude text watermark, and between them they answer most of what people are actually asking. Which models carry a mark, how much of a draft it can attach to, who holds the key, and what a detected mark would prove if anyone could read it.
HumanPen Team
· 16 min read
The short answer
Whether your draft carries a mark depends on which Claude model wrote it. Anthropic's help center page on how it marks AI-generated content says marking applies to models launched on or after 2 August 2026, and today it names two of them: Fable 5.1 and Mythos 5.1.
Whoever reads your submission cannot see the mark. Anthropic's wording on the page announcing those two models is that "this watermark is invisible to anyone who does not have the detection API", and that API is in private preview.
And none of the six detectors I checked, Turnitin included, says it can read a watermark. Anthropic gives the reason itself in its news post on how the watermark works, answering a question about how this differs from AI detection software: "AI detection software uses a different method, because the companies that provide it don't have our key."
I did not generate any watermarked text or run it through anything. Everything below is what the documents say, with the pages and the counts so you can check them yourself.
Which Claude output carries a mark right now
The date you have probably seen is 2 August 2026. It is a real date, but it is not the day Claude output started carrying watermarks. It is the day the EU AI Act's marking obligation began to apply, and Anthropic uses it as a cut-off line for models.
Models. Claude models launched on or after August 2, 2026 support marking at launch. Models currently supported include Fable 5.1 and Mythos 5.1.
Fable 5.1 and Mythos 5.1 were announced on 1 September 2026, per the date on their card on Anthropic's own news index. So for most of August there was no shipping Claude model on that supported list. Anything written with an older model falls under the next sentence of the same paragraph:
We're working to add marking support to other Claude models released before that date, and we'll update this article as that becomes available.
Present progressive, no date. The news post says the same thing and gives the reason: "The EU law includes a transition period for Anthropic models launched before August 2, 2026, and we're working to add watermarking for those models as well."
Where marking does apply, it applies broadly. The help center lists the surfaces:
Marks will apply to output from supported Claude models across Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, and wherever Claude is offered, worldwide.
Read the next sentence too, because it is Anthropic's own caveat and it is the easiest sentence on the page to skip: "Some platforms or features may not support certain marking types." Resale through the big clouds is covered as well: "When supported Claude models are accessed through AWS, Google Cloud, or Microsoft Foundry they will carry watermarks."
So the question you can settle tonight is a narrow one: which model produced the text. Two support pages say where to look. The one on model settings puts it plainly, "The selected model and effort level appear next to the send button", and adds that you can change it "at any point in a conversation", with changes applying "starting with Claude's next response". One chat can therefore span two models.
There is also a case where Claude changes the model without being asked. The support page on fallbacks says a blocked request gets re-run on an Opus model in the same conversation, and that "the response will be labeled with the model that answered". The categories that trigger it are narrow, offensive cybersecurity and a large fraction of dual-use biology among them, so an essay will almost never see one. If your subject is virology or toxicology, it is worth scrolling back for that label: Opus 5 is dated 24 July 2026 on Anthropic's news index, before the cut-off, so it is not on the supported list.
How much of your draft it can attach to
The next part changes the answer for a lot of drafts, and it sits in the news post rather than the help center.
The watermark only applies to words Claude chooses. When Claude proofreads text written by a person, what it gives back has generally only been lightly edited; because nearly all the words are the person's, there's very little (if anything) for the watermark to attach to.
The two sentences after that give the scale. "Depending on the length of the text and how heavily Claude has edited it, those changes might not be enough to make Claude's involvement detectable." Then: "The more Claude writes, the more decisions it has to make, and the more space there is for a watermark."
Translation runs the opposite way:
Yes. A translation produced by Claude carries a watermark, because in this case every word is chosen by Claude.
If you wrote a draft in your own language and had Claude put it into English, every English word on the page was chosen by Claude. That is the case with the most signal in it, not the least.
One sentence in the help center is worth reading slowly, because it uses two different verbs:
Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing.
"Will travel" for copying and pasting. "May persist through some editing" for editing. Those are not the same strength, and the difference is the first thing a summary loses. Short passages get their own line elsewhere on the page, as a case where a mark may not be detectable at all: "The passage is very short, leaving too little text for a reliable signal"
Who can read it
How much any of this matters comes down to who can check. Here is the whole passage about access, from the news post, because the qualifiers in it do the work:
We are releasing a detection API in private preview. It is currently available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups). It is also available for enterprises who are similarly obligated to verify watermarking for their own compliance with the Act. We plan to expand access to the detection API over time.
"Educational organizations" is on that list, and that is the phrase people fix on. Three qualifiers sit around it: private preview, organizations rather than individuals, and "as required under EU law". Anthropic publishes no list of who has been granted access, and none of the six detection vendors in the next section says anything about it in either direction. If you go looking for that passage on the help center page instead, you will not find it word for word; the help center carries its own version, which opens "Watermark detection is in private preview."
The blunt version is on the Fable and Mythos announcement page: "this watermark is invisible to anyone who does not have the detection API."
Google is the other provider with a text watermark in a consumer product. Its own SynthID page says so, "We've expanded SynthID to watermarking and identifying text generated by the Gemini app and web experience", and its public checking tool is not a text tool. The same DeepMind page introduces the verification portal and then says what you can put into it: "Just upload an image, video or audio file." The same block adds that the portal is still in testing, "We are currently collaborating with journalists and media professionals to test the portal and collect their feedback", above a "Join the early tester waitlist" button.
Pangram, which builds a detector, summarized the state of play on 14 September 2026: "As of September 14th, 2026, no AI company has released an AI watermark detector for text publicly, although Gemini has a public image detector."
What six student-facing detectors say about watermarks
Rather than assert that nobody reads watermarks, I counted. Everything here was read on 15 September 2026, and every count uses one rule, because a count without a rule cannot be rerun.
The rule: take the page body, drop `script`, `style` and `noscript`, read `textContent`, and click every collapsed panel open first. `textContent` rather than `innerText` because `innerText` skips whatever is collapsed, and on the Turnitin FAQ alone that is the difference between 31,739 characters and 40,991. I took a probe string from inside each panel afterwards to confirm it had landed in the reading.
Term counts are case-insensitive substring matches, with three exceptions that need spelling out or you will not reproduce the control numbers. `the` is a whole word, counted case-insensitively: that is where 263 on the Turnitin FAQ comes from, and counting it case-sensitively gives 243. `AI` is a whole word counted case-sensitively, because `originality.ai` appears all over Originality's own page and a case-insensitive count turns its 111 into 160. `key` is a whole word and comes out 0 either way. Sitemap counts are unique URLs after deduplication, with every sitemap index expanded.
| Vendor | What I searched | Result | Control on the same instrument |
|---|---|---|---|
| Turnitin | The help center search box at guides.turnitin.com | `watermark`: no results, the page says "Try searching another keyword." `SynthID` and `provenance`: one result each, both stem matches on unrelated pages, "synched" in a Moodle plugin guide and "proven" in a submission troubleshooting page | `ai writing`: 152 results. `Claude`: 3 results |
| Turnitin | The FAQ page I counted, 40,991 characters with all four panels open, page timestamp 2026-08-28 | `watermark` 0, `synthid` 0, `provenance` 0, `key` 0 | `detect` 142, `the` 263, `Claude` 14 |
| Turnitin | The turnitin.com sitemap: 2,473 `<loc>` entries, 1,801 unique URLs | Exactly one of those URLs has "watermark" in it, and it turns out to be a company: "Watermark was launched in 2018 with a vision to empower better learning at institutions across the U.S. and beyond." | Same file, same pattern |
| Pangram | A post it published on 14 September 2026 | Answers the question outright: "Pangram does not currently support AI watermarking detection." | Not applicable, this is a statement rather than a count |
| GPTZero | gptzero.me/technology, 13,040 characters with all nine FAQ panels open | `watermark` 0, `synthid` 0, `provenance` 0 | `AI` 66, `detect` 53 |
| Copyleaks | Its help center search at help.copyleaks.com | `watermark`: the Articles panel reads, No results for "watermark" in Articles. `SynthID`: the same message with its own term in it | `AI Detector`: the Articles panel fills with results instead of that message |
| Originality.ai | Sitemap, 1,386 unique URLs, plus the checker page, which redirects to originality.ai, 17,155 characters | Two watermark slugs, both explainers. Checker page: `watermark` 0, `synthid` 0, `provenance` 0 | Checker page: `AI` 111, `detect` 50 |
| Winston AI | The gowinston.ai sitemap index expanded to three sub-sitemaps, 932 unique URLs, plus the detection product page, 34,324 characters | No watermark slugs. Product page: `watermark` 0, `synthid` 0, `provenance` 0 | Product page: `AI` 57, `detect` 58 |
Winston's is the only sitemap row that claims an absence, so it is the only one of the three that needs a complete list. Its `sitemap.xml` is not a list of pages, it is an index pointing at three more sitemaps. Read the first two and you get 896 URLs. Read all three and you get 932. The Turnitin and Originality rows say something is present, and a presence survives an incomplete list.
Two things about what this does and does not establish, because it cuts both ways.
It establishes that none of these six says it reads a watermark. It does not establish that any of them cannot, and I would not read it that way if I were a vendor either. Somebody who had quietly obtained detection API access and written nothing about it would look exactly like this from the outside.
The sitemap rows search URL slugs only, and they cover one host each. The Turnitin sitemap is `www.turnitin.com`; `guides.turnitin.com`, where the help center lives, is a different host and is not in it, which is why the help center gets its own two rows. The full-text rows cover the pages named in the table, not every page on those sites. A mention on some page I did not open would not show up here.
Originality.ai deserves a second look, because it publishes an interactive tool with SynthID in the name. The phrase "does not run Google's or Anthropic's detector" appears twice on that page, in two differently worded sentences: "It does not generate text with Gemini or Claude and does not run Google's or Anthropic's detector.", and under the animation itself, "Words, values, and thresholds are illustrative. This does not run Google's or Anthropic's detector." Something named after a watermark is not necessarily a watermark reader.
The only piece I could find from GPTZero on the subject is from October 2024, and it is about Google rather than Anthropic, so treat it as background and not a current position. It does contain a clear conditional: "If Google were to release to developers a secure and reliable way of accessing its abilities to detect its own watermark, GPTZero would be the first to integrate any offering they have into our product."
One more thing you can check on that Turnitin FAQ yourself, and it comes with a wrinkle. The page prints its list of detectable models twice, once under "How does it work?" and again under "Which AI writing models can Turnitin's technology detect?". The newest Claude entry in both copies is Claude Sonnet-4.6, but the two copies give it different release dates, 2026-02 in the first and 2026-05 in the second. Ctrl-F will show you both. Either way Fable and Mythos appear zero times on the page, and the list ends with a sentence that makes clear it is a snapshot rather than a prediction: "and tools based on these LLMs as well. We will continue to expand our detection capabilities to other models in the future." Does Turnitin detect Claude specifically goes through that list in full.
That separation is the thing to hold onto. The AI writing report your institution runs and the watermark are two different channels. Our earlier pieces on the report said so before the watermark existed: AIGC detection for English papers puts it as "the detector does not look for specific AI tool signatures or watermarks", and does Turnitin detect Gemini and Copilot as "the detector is not looking for a watermark or a single telltale feature". Both still hold. What changed is that a watermark now exists, on a separate track, with the key held by someone else.
If someone did read it, what would it prove
Less than the word "watermark" suggests, and that is true in both directions.
Start with a mark that gets detected. The help center will not let it stand as proof of anything: "A detected mark provides a signal that content was processed by Claude, but is not fully conclusive." The reason it gives covers the most common way people use it: "Claude may not be the original author. People often use Claude to proofread, translate, summarize, or convert files." The news post compresses the same point into two sentences:
A watermark can only determine that Claude was likely involved with the content at some point. It cannot distinguish "Claude wrote this" from "Claude heavily edited this."
Now the other direction, where the same page is equally careful: "Lack of a detected mark doesn't mean the content wasn't AI-generated or processed." Five reasons follow, and the first one is the one that applies to any draft written with an older model: "It was generated by a model released before marking was supported"
So a watermark is not an authorship test. It cannot confirm that you wrote something, and its absence cannot confirm that you did not. What it can indicate, on Anthropic's own account, is that Claude was probably involved somewhere in the history of a passage.
The EU law is aimed at Anthropic, not at you
The reason any of this exists is Article 50 of the EU AI Act, and the paragraph that produced the watermark names who has to comply in its first four words:
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.
The European Commission put it in plainer language when the transparency code of practice was signed: "Although the legal obligation applies only to providers of AI systems, Section 1 can also be signed by providers of marking and detection solutions..."
One paragraph in Article 50 does reach past providers and touch people who use AI to write. It is paragraph 4, and coursework does not meet it:
Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated.
Published. Informing the public. Matters of public interest. An assignment handed to your department fails all three. Nothing in Article 50 puts a disclosure duty on you, and no paragraph of it tells a university to go looking for watermarks.
The article does touch the detecting side once, in its last paragraph, and it is worth reading because it is aimed somewhere else entirely:
The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection and labelling of artificially generated or manipulated content.
That is a job for the EU's own AI Office. It is not a duty handed to whoever receives your essay.
What does govern you is your university's or your journal's own AI policy. That is a separate document with its own rules, and it is the one with consequences attached.
What to do with the week you have left
- Find out which model produced the draft. The model name sits next to the send button, it can be changed mid-conversation, and a response that fell back to another model is labeled with the model that answered. If it was Fable 5.1 or Mythos 5.1, it is on Anthropic's supported list today. Anything older sits under "we're working to add marking support", with no date given.
- Work out which of the three cases you are in: Claude wrote the prose, Claude translated it, or Claude proofread text you wrote. Anthropic's own answer is that proofreading leaves "very little (if anything) for the watermark to attach to" and translation leaves the most.
- Open your course or program AI policy and read it properly. Look for three things: whether AI assistance has to be declared, in what wording, and by when. That is the document that can affect your grade, and unlike Article 50 it was written with you in mind. What AI percentage is acceptable on Turnitin covers how institutions have handled the report side of this.
- If a declaration is required, write it the way the policy asks and hand it in with the paper, rather than producing it after a question.
- Keep whatever record you already have of how the draft came together. Version history speaks to "did you write this", which is the question a watermark cannot answer in either direction. What Google Docs version history actually records and can WPS or Tencent Docs version history show you wrote it go through what those records do and do not contain.
- Then stop thinking about the watermark. None of the six detectors above says it reads one, the API that can read one is in private preview, and the report your institution actually runs works on a different signal.
If any of the counts above matter to your situation, rerun them. Every page is public, every search term is in the table, and the controls are there so you can tell a real zero from a search box that quietly stopped working.
KEEP READING