Anthropic rolls out invisible C2PA watermarking for Claude.
The leader in secure AI models integrates the C2PA standard for its multimodal outputs, an industry first. This decision, effective ahead of the regulatory deadline, lays the groundwork for proactive compliance with Article 50 of the AI Act.

C2PA: A technical standard for transparency of synthetic content
The Coalition for Content Provenance and Authenticity (C2PA) is an open standard developed by Adobe, Microsoft, Intel and other stakeholders to trace the origin of digital content.
Anthropic announces the systematic integration of C2PA metadata into images generated by its Claude 3.7 and later models. These metadata, invisible to the naked eye but detectable by specialised tools, indicate:
- the origin of the content (AI-generated),
- the model used (Claude 3.7, 3.8, etc.),
- the date and time of generation,
- a unique identifier for each output.
The C2PA relies on a cryptographic signature that ensures the integrity of the metadata. Any modification of the content after generation invalidates the signature, indicating potential tampering. This mechanism partially meets the requirements of Article 50 of the AI Act, which mandates machine-readable watermarking of synthetic content.
What the AI Act actually requires of providers of generative AI
Article 50 of the AI Act establishes distinct obligations for providers and deployers of generative AI systems.
For providers such as Anthropic, the requirements include:
- machine-readable watermarking of synthetic content, compliant with recognised standards (C2PA, IPTC, Schema.org),
- accessible technical documentation describing the system's capabilities and limitations,
- implementation of mechanisms to detect AI-generated content,
- publication of a summary of the training data used, except where industrial secrets apply.
The C2PA meets the first requirement but does not cover all obligations. Anthropic will need to complement this approach with:
- detailed technical documentation, compliant with Annex IV of the AI Act,
- a public summary of training data, accessible via its website,
- detection tools for content generated by its models.
Limitations of C2PA under EU requirements
While technically robust, the C2PA standard has several limitations in relation to the obligations set out in the AI Act.
First, the C2PA only covers multimodal content (images, videos, audio). Text generated by AI, such as that produced by Claude, is not included. However, Article 50 requires transparency for all types of synthetic content, including text. Anthropic will therefore need to complement its approach with other mechanisms for textual outputs.
Second, the C2PA relies on metadata embedded in the file. This metadata can be removed or altered by editing tools or sharing platforms. The AI Act requires persistent transparency, which poses a technical challenge for providers.
Third, the C2PA does not provide information on training data or model limitations, two elements required by Article 50. This information must be communicated separately, via technical documentation and the public summary of data.
Finally, the C2PA is a technical standard, but the AI Act also imposes organisational obligations, such as implementing compliance procedures and incident reporting. These aspects are not covered by the standard.
Deployer responsibilities and residual risks
Anthropic's integration of C2PA does not relieve deployers of their obligations under the AI Act.
Deployers, i.e. businesses or organisations using Claude to generate content, remain responsible for:
- verifying the provider's (Anthropic) compliance with Article 50,
- implementing transparency mechanisms for content disseminated to the public,
- training users on risks associated with synthetic content,
- reporting compliance incidents to authorities within 72 hours.
Residual risks for deployers include:
- removal of C2PA metadata during content dissemination,
- use of Claude for use cases not covered by Anthropic's documentation,
- failure to detect AI-generated content in the absence of appropriate verification tools.
Deployers must therefore complement Anthropic's technical approach with organisational measures, such as implementing internal transparency policies and training teams.
How to verify compliance of your AI tools
Businesses must ensure their generative AI tools comply with Article 50 obligations by 2 August 2026.
To verify a provider's compliance, such as Anthropic's, the following steps are recommended:
- Check for C2PA metadata: Use tools like Content Credentials Verify to detect metadata in generated images.
- Review technical documentation: Ensure it covers the requirements of Annex IV of the AI Act, including the model's capabilities, limitations and training data.
- Verify publication of the training data summary: This document must be publicly accessible, except where industrial secrets apply.
- Test detection mechanisms: Use tools like AI Detection to assess the provider's ability to detect its own generated content.
- Evaluate compliance procedures: Request evidence of the provider's internal procedures, such as compliance audits and incident reporting mechanisms.
For deployers, it is also recommended to:
- implement internal transparency policies for disseminated content,
- train teams on risks associated with synthetic content,
- document use cases and compliance measures implemented.
Frequently asked questions
Everything you need to know about C2PA watermarking and Article 50 obligations.
No, the AI Act does not prescribe a single standard for watermarking synthetic content. C2PA is one of three standards recognised by the Regulation, alongside IPTC and Schema.org. Providers may choose the standard best suited to their use case, provided it is machine-readable and compliant with Article 50 requirements.
Penalties for non-compliance with Article 50 can reach up to €15 million or 3% of global turnover, whichever is higher. Supervisory authorities, such as the CNIL in France, may also impose corrective measures, such as halting the dissemination of non-compliant content or requiring additional transparency measures.
No, the C2PA standard currently only covers multimodal content (images, videos, audio). For AI-generated text, such as that produced by Claude, providers must use other transparency mechanisms, such as digital watermarks or embedded metadata in files. Anthropic has not yet communicated its solution for text.
Yes, deployers remain responsible for the transparency of content they disseminate, even if metadata is removed. The AI Act requires deployers to implement mechanisms to preserve transparency, such as explicit disclosures in content or internal verification policies. If metadata is removed, the deployer must demonstrate that all reasonable steps were taken to meet their obligations.
The AI Act recognises three standards for machine-readable watermarking of synthetic content: C2PA, IPTC and Schema.org. Providers may also use proprietary solutions, provided they are interoperable and compliant with Article 50 requirements. For example, Google uses an invisible digital watermark for its Imagen models, while Microsoft integrates metadata into its Office 365 tools.



