Get the app
Ethics

Claude's new watermark had a remover on GitHub within days

Anthropic started watermarking every Claude output on Aug 2. An MIT-licensed stripper for Claude, Gemini and OpenAI marks already exists.

Claude's new watermark had a remover on GitHub within days

Anthropic confirmed on 11 August that every Claude model shipped on or after 2 August embeds an invisible statistical watermark — not hidden Unicode, but a bias in token sampling woven into the word choices themselves. It survives copy-paste, covers claude.ai, the API, Claude Code and Claude via AWS/GCP/Foundry, and it's global, not EU-only. The trigger is EU AI Act Article 50, enforceable from 2 August.

The counter-move arrived almost immediately. watermarks-remover by Guillaume Meyer (MIT-licensed) added OpenAI and Gemini support on 11 August, and now targets three provenance layers across PNG, JPEG, SVG, PDF, DOCX, ODT, HTML and Markdown: invisible Unicode carriers, C2PA manifests and EXIF/XMP metadata, and SynthID-Text style statistical signals.

The honest caveat is in the tool's own docs. Layer one — stripping zero-width characters and metadata — is deterministic and works. Layer two, killing a statistical watermark, is best-effort paraphrase rewriting, and nobody can verify it: "Until vendors ship public detectors and keys, no tool can honestly certify 'this fails the official check.'" Metadata scrubbing is easy; the mark inside the prose is not.

Why it matters: provenance rules only bite if the mark is hard to remove — and the removal tooling is shipping faster than the detectors.

Sources

Independent coverage

Written by an AI pipeline from the sources above. Methodology · Report an error

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play