Try all features for free — 3 credits included on sign-upTry for free
Skip to main content
Regulation · AI Transparency

Anthropic rolls out invisible C2PA watermarking for Claude.

The leader in secure AI models integrates the C2PA standard for its multimodal outputs, an industry first. This decision, effective ahead of the regulatory deadline, lays the groundwork for proactive compliance with Article 50 of the AI Act.

Jérémy Pierre
Jérémy Pierre
AI Act Compliance Expert
19 August 2026 6 min read
Anthropic Rolls Out Invisible C2PA Watermarking: What the AI Act Requires from August 2026
Key takeaways · 4 figures to remember
100%
of images generated by Claude 3.7 to be C2PA-watermarked
2 August 2026
application date of Article 50 of the AI Act
3 standards
recognised by the AI Act for machine-readable watermarking
72h
deadline to report a compliance incident to authorities
01 - Technical

C2PA: A technical standard for transparency of synthetic content

The Coalition for Content Provenance and Authenticity (C2PA) is an open standard developed by Adobe, Microsoft, Intel and other stakeholders to trace the origin of digital content.

Anthropic announces the systematic integration of C2PA metadata into images generated by its Claude 3.7 and later models. These metadata, invisible to the naked eye but detectable by specialised tools, indicate:

  • the origin of the content (AI-generated),
  • the model used (Claude 3.7, 3.8, etc.),
  • the date and time of generation,
  • a unique identifier for each output.

The C2PA relies on a cryptographic signature that ensures the integrity of the metadata. Any modification of the content after generation invalidates the signature, indicating potential tampering. This mechanism partially meets the requirements of Article 50 of the AI Act, which mandates machine-readable watermarking of synthetic content.

02 - Regulation

What the AI Act actually requires of providers of generative AI

Article 50 of the AI Act establishes distinct obligations for providers and deployers of generative AI systems.

For providers such as Anthropic, the requirements include:

  • machine-readable watermarking of synthetic content, compliant with recognised standards (C2PA, IPTC, Schema.org),
  • accessible technical documentation describing the system's capabilities and limitations,
  • implementation of mechanisms to detect AI-generated content,
  • publication of a summary of the training data used, except where industrial secrets apply.

The C2PA meets the first requirement but does not cover all obligations. Anthropic will need to complement this approach with:

  • detailed technical documentation, compliant with Annex IV of the AI Act,
  • a public summary of training data, accessible via its website,
  • detection tools for content generated by its models.
The AI Act does not prescribe a single standard for watermarking. While the C2PA is one solution among others, its adoption by a major player like Anthropic could make it a de facto industry standard.
03 - Limitations

Limitations of C2PA under EU requirements

While technically robust, the C2PA standard has several limitations in relation to the obligations set out in the AI Act.

First, the C2PA only covers multimodal content (images, videos, audio). Text generated by AI, such as that produced by Claude, is not included. However, Article 50 requires transparency for all types of synthetic content, including text. Anthropic will therefore need to complement its approach with other mechanisms for textual outputs.

Second, the C2PA relies on metadata embedded in the file. This metadata can be removed or altered by editing tools or sharing platforms. The AI Act requires persistent transparency, which poses a technical challenge for providers.

Third, the C2PA does not provide information on training data or model limitations, two elements required by Article 50. This information must be communicated separately, via technical documentation and the public summary of data.

Finally, the C2PA is a technical standard, but the AI Act also imposes organisational obligations, such as implementing compliance procedures and incident reporting. These aspects are not covered by the standard.

04 - Responsibilities

Deployer responsibilities and residual risks

Anthropic's integration of C2PA does not relieve deployers of their obligations under the AI Act.

Deployers, i.e. businesses or organisations using Claude to generate content, remain responsible for:

  • verifying the provider's (Anthropic) compliance with Article 50,
  • implementing transparency mechanisms for content disseminated to the public,
  • training users on risks associated with synthetic content,
  • reporting compliance incidents to authorities within 72 hours.

Residual risks for deployers include:

  • removal of C2PA metadata during content dissemination,
  • use of Claude for use cases not covered by Anthropic's documentation,
  • failure to detect AI-generated content in the absence of appropriate verification tools.

Deployers must therefore complement Anthropic's technical approach with organisational measures, such as implementing internal transparency policies and training teams.

05 - Verification

How to verify compliance of your AI tools

Businesses must ensure their generative AI tools comply with Article 50 obligations by 2 August 2026.

To verify a provider's compliance, such as Anthropic's, the following steps are recommended:

  1. Check for C2PA metadata: Use tools like Content Credentials Verify to detect metadata in generated images.
  2. Review technical documentation: Ensure it covers the requirements of Annex IV of the AI Act, including the model's capabilities, limitations and training data.
  3. Verify publication of the training data summary: This document must be publicly accessible, except where industrial secrets apply.
  4. Test detection mechanisms: Use tools like AI Detection to assess the provider's ability to detect its own generated content.
  5. Evaluate compliance procedures: Request evidence of the provider's internal procedures, such as compliance audits and incident reporting mechanisms.

For deployers, it is also recommended to:

  • implement internal transparency policies for disseminated content,
  • train teams on risks associated with synthetic content,
  • document use cases and compliance measures implemented.

Identify your obligations under the AI Act

Our free 3-minute assessment helps you determine whether your AI tools comply with Article 50 and which priority actions to take.

06 - FAQ

Frequently asked questions

Everything you need to know about C2PA watermarking and Article 50 obligations.

No, the AI Act does not prescribe a single standard for watermarking synthetic content. C2PA is one of three standards recognised by the Regulation, alongside IPTC and Schema.org. Providers may choose the standard best suited to their use case, provided it is machine-readable and compliant with Article 50 requirements.

Penalties for non-compliance with Article 50 can reach up to €15 million or 3% of global turnover, whichever is higher. Supervisory authorities, such as the CNIL in France, may also impose corrective measures, such as halting the dissemination of non-compliant content or requiring additional transparency measures.

No, the C2PA standard currently only covers multimodal content (images, videos, audio). For AI-generated text, such as that produced by Claude, providers must use other transparency mechanisms, such as digital watermarks or embedded metadata in files. Anthropic has not yet communicated its solution for text.

Yes, deployers remain responsible for the transparency of content they disseminate, even if metadata is removed. The AI Act requires deployers to implement mechanisms to preserve transparency, such as explicit disclosures in content or internal verification policies. If metadata is removed, the deployer must demonstrate that all reasonable steps were taken to meet their obligations.

The AI Act recognises three standards for machine-readable watermarking of synthetic content: C2PA, IPTC and Schema.org. Providers may also use proprietary solutions, provided they are interoperable and compliant with Article 50 requirements. For example, Google uses an invisible digital watermark for its Imagen models, while Microsoft integrates metadata into its Office 365 tools.

Jérémy Pierre
Jérémy Pierre
Founder aiacto.eu · AI Act Compliance Expert

Supports providers and deployers of AI in meeting regulatory compliance requirements.

Share this article

Related articles

Article 50 of the AI Act: Practical Impacts for Businesses with Real-World Examples
Article 50 AI Acttransparence IA générativeobligations déployeurs IA 2026

Article 50 of the AI Act: Practical Impacts for Businesses with Real-World Examples

Article 50 of the AI Act comes into force on 2 August 2026. Beyond general obligations, this article examines its concrete impacts on business processes, compliance costs, and legal risks for providers and deployers. Featuring sector-specific use cases (media, finance, healthcare, HR) and an analysis of available tools to meet transparency and watermarking requirements.

10 August 202612 min
AI Transparency: What Article 50 Really Requires from Businesses
Article 50 AI Acttransparence IA générativeobligations déployeurs IA

AI Transparency: What Article 50 Really Requires from Businesses

Article 50 of the AI Act introduces transparency obligations for generative AI systems from November 2026. This article details the concrete requirements for deployers and providers, synthetic content marking methods, and non-compliance risks. Featuring sector-specific examples and an analysis of the latest clarifications from the AI Office.

3 August 20266 min
Article 50 of the AI Act: What Actually Applies on 2 August 2026
AI Act Article 50transparence IA générativeobligations fournisseurs IA

Article 50 of the AI Act: What Actually Applies on 2 August 2026

2 August 2026 marks the entry into force of the transparency obligations under Article 50 of the AI Act. Contrary to common misconceptions, the Omnibus agreement did not postpone all requirements to 2027. Only the machine-readable marking of synthetic content benefits from a four-month extension until 2 December 2026. This article clarifies the four affected scenarios, the roles of providers and deployers, and key steps for compliance.

1 June 202610 min