Anthropic's AI watermark has already led to the creation of tools designed to eliminate it.
Anthropic's initiative to identify AI-generated text has led to an immediate reaction. Developers have begun creating tools to remove these identifying labels, as reported by Business Insider. Thibault Spirlet and Agnes Applegate noted that one such tool has gone viral on GitHub, indicating a rising interest in these applications.
The watermark is the catalyst. Starting on August 2, Anthropic began embedding a statistical pattern in the output of its model, Claude, which accompanies copied text. The company claims this watermark is unnoticeable to readers, but some users disagreed and took action.
The response has been significant. According to Business Insider, interest in “AI watermark remover” surged by 60 percent in the US on Google Trends week-over-week, leading some Claude subscribers to cancel their accounts and others to seek alternatives. A handful of developers have created solutions.
Describing it as "the wrong answer to a real problem," Guillaume Meyer, a Paris-based entrepreneur, quickly launched an open-source project called Watermarks Remover just days after Anthropic's announcement. Meyer, the founder of the e-commerce AI tool Memo, designed his remover to eliminate hidden characters and metadata, then rewrites the text to disrupt the watermark pattern while preserving the meaning. He stated that the initial version took him about five hours to create and has since garnered over 14,000 stars on GitHub, indicating developer interest; however, it doesn't ensure complete removal of the watermark.
Meyer expressed his concerns thoughtfully: “I fully support content attribution,” he told Business Insider, “but I oppose the watermarking method, and that’s a significant distinction.” He criticized the process for treating authorship as binary, marking text whether it was entirely created by Claude or just edited by it, adding, “I believe it’s the wrong response to a legitimate issue.”
He is not alone in this view. Sabrina Ramonov, an AI educator, mentioned on X that she developed a free browser-based tool for removing Claude and ChatGPT marks. “AI watermarks penalize everyday users, not wrongdoers,” she noted. Her tool claims to eliminate hidden marks from various formats, including text, PDFs, Word documents, web pages, images, and data files, as reported by Business Insider.
Ansh Aneja, a developer in Tokyo, created a tool targeting Claude on the announcement day, inspired by a post from investor Paul Graham. He later introduced a local open-source version named MarkScrub, noting that an earlier iteration gained 8,500 users in a single day, a figure that Business Insider could not verify.
In response to these developments, Anthropic has clarified its position. In a blog post titled "How Claude’s text watermark works," the company stated that the watermark "doesn’t imply ownership or authorship, and doesn’t alter a user's rights under our terms." It further explained that the watermark does not contain identifying details and cannot be traced back to any individual, organization, or conversation. The company emphasizes that this feature is designed for compliance, not surveillance, indicating that it has implemented the watermark to fulfill its obligations under the European Union's AI Act.
The law mandates that AI-generated text be marked in a machine-readable format. In July, Anthropic signed the bloc's transparency code along with approximately 190 other signatories. As it cannot limit the watermark to the EU, it is launching the feature globally, extending it to older models as well.
Regarding the mechanics of the watermark, Anthropic explained that it relies on subtle word choices. When multiple words are suitable, the model leans toward one, leaving a detectable statistical signature. The company claims this process incurs no additional costs or tokens and does not affect quality. It did not respond to Business Insider's inquiries regarding the removal tools.
The situation reveals a conflict, as Anthropic's watermark function means that a lightly proofed email could retain a mark, while a heavily reworked AI draft might not.
Researchers highlight a fundamental limitation in the removers. Thibaud Gloaguen from ETH Zurich’s Secure, Reliable, and Intelligent Systems lab stated, “There will always be ways to eliminate the watermark,” citing the simple act of rephrasing a section of text. Anthropic acknowledges this reality, admitting that a significant rewrite can completely remove the watermark, raising questions about whether the text still qualifies as AI-generated.
The watermark’s effectiveness diminishes or disappears in brief passages and factual statements, as well as precise code and math, where there's limited variation to exploit. Konrad Kollnig, an assistant professor at Maastricht University's Law and Tech Lab, articulated the issue plainly: “Once the watermark detection tool is made public, anyone can check AI-generated content… and create tools to eliminate watermarks.”
This concern is heightened since Anthropic intends to release a public detection API with its next model, although no timeline has been established yet.
The status of the removers exists in a legal gray area. The EU mandates that AI firms
Other articles
Anthropic's AI watermark has already led to the creation of tools designed to eliminate it.
Just days after Anthropic started watermarking Claude's text for the EU, developers introduced tools to eliminate it. One of these tools has already garnered over 14,000 stars on GitHub.
