Get the app
Ethics

Claude's new watermark had a remover on GitHub within days

Anthropic started watermarking every Claude output on Aug 2. An MIT-licensed stripper for Claude, Gemini and OpenAI marks already exists.

Claude's new watermark had a remover on GitHub within days

Anthropic confirmed on 11 August that every Claude model shipped on or after 2 August embeds an invisible statistical watermark — not hidden Unicode, but a bias in token sampling woven into the word choices themselves. It survives copy-paste, covers claude.ai, the API, Claude Code and Claude via AWS/GCP/Foundry, and it's global, not EU-only. The trigger is EU AI Act Article 50, enforceable from 2 August.

The counter-move arrived almost immediately. watermarks-remover by Guillaume Meyer (MIT-licensed) added OpenAI and Gemini support on 11 August, and now targets three provenance layers across PNG, JPEG, SVG, PDF, DOCX, ODT, HTML and Markdown: invisible Unicode carriers, C2PA manifests and EXIF/XMP metadata, and SynthID-Text style statistical signals.

The honest caveat is in the tool's own docs. Layer one — stripping zero-width characters and metadata — is deterministic and works. Layer two, killing a statistical watermark, is best-effort paraphrase rewriting, and nobody can verify it: "Until vendors ship public detectors and keys, no tool can honestly certify 'this fails the official check.'" Metadata scrubbing is easy; the mark inside the prose is not.

Why it matters: provenance rules only bite if the mark is hard to remove — and the removal tooling is shipping faster than the detectors.

Sources

Written by an AI pipeline from the sources above. How it works.

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play