Anthropic, a leading artificial intelligence company, recently introduced invisible watermarks into text generated by its Claude models. This measure, implemented to comply with the European Union's AI Act, aims to provide transparency by indicating when content has been produced or processed by AI. However, within hours of the announcement, coders and developers began sharing methods and tools designed to circumvent these new watermarks.
The watermarking system embeds subtle statistical biases in the model's word choices. These patterns are imperceptible to human readers but are intended to be detectable by specialized algorithms. Anthropic stated that this method does not affect the quality, content, or readability of Claude's outputs. The company's announcement indicated that these watermarks are designed to persist through copying, pasting, and some forms of editing, traveling with the text across different platforms. Anthropic's implementation is global, applying to all users regardless of their location, not just within the EU.
The EU AI Act's Code of Practice on Transparency of AI-Generated Content requires AI providers to implement methods for marking AI-generated content. Anthropic, along with nearly 200 other organizations, signed this code in July 2026. The goal is to help consumers identify AI-generated material, including deepfakes and other manipulated content. Anthropic plans to release detection tools to allow users and third parties to verify the presence of these watermarks.
Despite Anthropic's efforts, the speed at which workarounds emerged highlights potential challenges in maintaining the integrity of such systems. Guillaume Meyer, an entrepreneur and founder of the e-commerce AI tool Memo, released an open-source project called "Watermarks Remover" shortly after Anthropic's announcement. This tool reportedly strips hidden characters and metadata and then rewrites the text, disrupting the word-choice patterns that carry the watermark while aiming to preserve the original meaning. Meyer stated that the initial version of his tool took approximately five hours to build and has since gained significant traction on platforms like GitHub. Other developers have also created similar tools, with one reportedly reaching over 14,000 GitHub stars, indicating widespread developer interest and perceived demand for such bypass methods.
Researchers and developers have noted that watermarks are not foolproof. Konrad Kollnig, an assistant professor at Maastricht University's Law and Tech Lab, commented that once a detection tool is public, methods to remove watermarks can be developed. Anthropic itself acknowledges that heavy editing, paraphrasing, translation, or mixing content with other writing can weaken or remove the watermark. Manual rewriting, where a user significantly alters the original text's structure and phrasing, is considered a more reliable method for disrupting the watermark signal. However, light editing or minor synonym changes may not be sufficient to eliminate the mark.
The rapid development of watermark removal tools raises questions about the practical effectiveness and longevity of Anthropic's watermarking strategy, and potentially similar systems from other AI providers. While Anthropic's system aims to comply with regulatory requirements for transparency, the ease with which these marks can reportedly be circumvented suggests an ongoing technological arms race between AI developers and those seeking to obscure AI-generated content. The company has stated that the presence of a watermark indicates that Claude may have processed the content, but does not definitively prove authorship, and its absence does not confirm human origin.
