Short answer: copy and paste, yes. Light editing, usually. Heavy rewriting, translation, or trimming to a couple of sentences, often not. And for files, the answer is a much blunter no, because file metadata dies the moment anything rewrites the bytes.
Anthropic is unusually direct about this in its own documentation, which is worth noting because most vendors describe watermarking as if it were a permanent tattoo. It isn’t. It’s a signal with a strength, and ordinary content workflows weaken it.
Persistence at a glance
| What happens to the content | Text watermark | C2PA file metadata |
|---|---|---|
| Copy and paste into another app | Survives | Not applicable |
| Save into a database, render on a page | Survives | Not applicable |
| Light editing, a few word swaps | Usually survives | Not applicable |
| Heavy rewriting or paraphrasing | Often lost | Not applicable |
| Translation to another language | Often lost | Not applicable |
| Cutting to a very short excerpt | Often lost | Not applicable |
| Resize, crop, or re-encode a file | Not applicable | Lost |
| Convert PNG to WebP or JPEG to AVIF | Not applicable | Lost |
| Screenshot | Not applicable | Lost |
| Serve through an image CDN | Not applicable | Usually lost |
| Alter bytes without re-signing | Not applicable | Signature breaks, detectably |
Two very different durability profiles, and the reason is architectural.
Why the text watermark travels
Claude’s text watermark is woven into the text itself, not attached to it. There’s no wrapper, no metadata block, no hidden character sequence bolted onto the end of a response.
That design decision buys the one property metadata can never have: container independence. Copy a paragraph out of Claude and drop it into Gmail, Notion, a WordPress editor, a commit message, or a Slack thread, and the signal comes along, because the signal is the words. Nothing in the transfer strips it, because there’s nothing separable to strip.
Anthropic puts it plainly: because the watermark is part of the text, it travels with the text when it’s copied and pasted elsewhere, and may persist through some editing.
Note the hedge in the second half. “May persist through some editing” is doing real work.
Why editing erodes it
A watermark embedded in generated text is a statistical pattern spread across many word choices. Detection works by measuring how strongly a passage matches that pattern. More text means more signal. Fewer, altered words mean less.
So erosion is gradual, not binary:
Swapping a few words: the pattern is distributed, so changing “however” to “but” in three places removes a small fraction of the evidence. The signal typically holds.
Rewriting most sentences: now you’re replacing a large share of the choices that carried the pattern. What’s left may fall below the threshold where detection can call it confidently.
Paraphrasing wholesale: functionally, you’ve generated new text with the same meaning. The pattern is gone.
Translating: a translated passage has almost no word-level overlap with the original. Anthropic lists translation as a case where a mark may not be detectable. The irony is that people often translate using Claude, in which case the output picks up a fresh mark from the translation pass.
Trimming to a short excerpt: this is the one people underestimate. Anthropic explicitly notes that a very short passage leaves too little text for a reliable signal. Pull one sentence out of a 2,000-word Claude draft and there may be nothing measurable left. Not because the sentence was altered, but because a sentence is a small sample.
The practical consequence: a mark surviving is evidence, a mark not surviving is nothing. That asymmetry is the core of how to detect Claude’s watermark.
Why file metadata doesn’t survive at all
C2PA provenance metadata is the opposite architecture. It’s a cryptographically signed manifest attached to a file, following the C2PA standard. It carries far richer information than a watermark, including who signed it and what edits were claimed, and it’s tamper-evident: change a byte without re-signing and the signature fails validation.
The cost is that it lives in the container. Rewrite the container and it’s gone.
Every one of these destroys it by default:
- Resizing or thumbnailing with Sharp, ImageMagick, or Pillow
- Converting between formats
- Re-saving through an image editor
- Taking a screenshot, which produces an entirely new file with no relationship to the original
- Passing through an image CDN that does automatic optimization
- Uploading through a service that normalizes images on ingest
Anthropic lists metadata stripping through format conversion, re-saving, and screenshots among the reasons a Claude-generated file may carry no detectable mark. Google’s answer to the same problem is to put a watermark in the pixels alongside the manifest, which is why SynthID survives a screenshot when C2PA cannot. The vendor-by-vendor picture is in Claude vs ChatGPT vs Gemini watermarking.
This is not an exotic failure. It’s what happens to a typical image between generation and a user’s screen. If your product promises provenance on images, the interesting question is not whether Claude signed the file. It’s whether your own pipeline preserved the signature, which is why the round-trip test in your API is stripping C2PA metadata is worth ten minutes of your time.
There is one bright spot. Because the manifest is signed, a broken one is detectable. A verification tool can distinguish three states: no manifest at all, a valid manifest, and a manifest whose signature no longer matches the bytes. That third state is genuinely informative, and collapsing it into a boolean throws away your best signal.
What this means for content teams
If you publish, three implications follow from the persistence profile.
Claude touching your draft marks the draft. Proofreading, tightening, and reformatting all produce marked output. Anthropic says so directly: the output can carry a Claude mark even if the underlying ideas, text, or data originated from another source. If your policy is “no AI in our content,” a grammar pass violates it in a way that’s now machine-visible.
A mark is not an accusation. Anyone reading a positive detection result as proof of wholesale generation is over-reading it. It’s compatible with a human writing everything and asking for a copyedit.
Removing the mark isn’t a strategy. Not because it’s impossible, but because the things that reliably remove it are the things you’d do anyway if you were genuinely rewriting, and doing them cosmetically to hide provenance is a bad idea under Article 50, which puts disclosure duties on deployers publishing AI-generated text on matters of public interest. Fines run to €15 million or 3% of worldwide annual turnover. That’s covered in EU AI Act Article 50 for API developers.
What this means for engineering teams
If you build on Claude, the persistence profile shapes what you can promise.
Don’t promise text provenance downstream. You can’t verify the text watermark yourself right now, and even when detection ships you won’t be able to guarantee it survived your editing pipeline. If your API returns Claude output, disclose it with a field, not a watermark check. That’s the case in adding AI disclosure to your own API.
Do preserve file provenance deliberately. Preserving a C2PA manifest through a transformation means either passing the original bytes through untouched or re-signing after each transformation with an appropriate action assertion. Some image services now handle this natively. Most do not.
Test the boundary, not the theory. The place provenance dies is a specific line of code in your pipeline, and you find it by round-tripping a known-good fixture. Assert on the way out, not just on the way in.
A test scenario that catches it:
POSTa signed fixture image to your upload endpoint.GETit back through the exact URL your frontend uses, CDN and all.- Verify the returned bytes still carry a valid manifest.
- Assert the response distinguishes absent from broken.
In Apidog you can hold binary fixtures, chain the upload and fetch, and assert on the result with a post-response script, then run the whole scenario from apidog-cli in CI. The setup mirrors testing file upload APIs with multipart/form-data and plugs into a pipeline the same way as automating API tests in GitHub Actions. Download Apidog to build it against your own stack.
FAQ
Does copying Claude’s text into a document keep the watermark? Yes. The watermark is part of the text, so it travels with copy and paste into email, documents, CMS fields, and chat.
Does editing remove the watermark? Light editing usually leaves it detectable. Heavy rewriting, paraphrasing, or translation often pushes it below the threshold. There’s no fixed percentage; it depends on how much of the original wording remains and how long the passage is.
Why does a short quote lose the watermark? Detection is statistical and needs enough text to measure. Anthropic notes that a very short passage leaves too little text for a reliable signal.
Does translating Claude’s output remove the mark? Often, yes, since a translation shares almost no wording with the original. If you translate using Claude, the translated text picks up its own mark.
Do screenshots preserve C2PA metadata? No. A screenshot creates a new file with no connection to the original manifest.
Can I tell the difference between a stripped manifest and a tampered one? Yes, and you should. A missing manifest returns nothing. A manifest whose bytes changed without re-signing fails signature validation, which is a distinct and more interesting result.
Does an unmarked response mean the content is human-written? No. Older models, heavy editing, short passages, stripped file metadata, and unsupported platforms all produce unmarked content. Absence proves nothing.
If you need to go further than light editing and want to strip the signal entirely, what it takes to remove Claude's watermark is covered in our companion piece on the available options for API users.
The takeaway
Claude’s text watermark is durable against the thing that kills metadata, which is moving content between containers, and fragile against the thing metadata survives, which is being left alone but shortened or rewritten. C2PA metadata is exactly the reverse: rich, verifiable, and destroyed by a resize.
That’s why Anthropic ships both. Neither one alone gives you a provenance story, and even together they give you a signal rather than a proof.



