3 Sources
[1]
What to Know About Anthropic's New Claude Watermarking on AI-Generated Text and Files - CNET
Ever since being admittedly fascinated by the Cambridge coffee webcam from the 1990s, I've written about VPNs, the NFL, smartphones, living wages, over/unders and everything in between. Read full bio If you use Anthropic's AI chatbot Claude to do your homework, everyone will be able to tell soon. Anthropic said this month that text and files generated by its family of AI models will be watermarked to let consumers know. The change will allow the company to comply with EU regulations governing the transparency of AI use. The EU's Code of Practice on Transparency of AI-generated Content requires companies that provide and deploy AI systems to inform customers when they are interacting with AI and to include watermarks on AI content. Consumers also must know when they're exposed to deepfakes and emotion-recognition and biometric-categorization tools. Nearly 200 organizations have agreed to the measures, the European Commission said. Watermarking -- an authentication process that originated in Italy in the 13th century -- is entirely different for AI content. The AI system can automatically embed markers in text indicating that the content originated from AI and not a human. Examples could be different spacing between words and numbers, word sequencing and other invisible signals that remain with the text even if the person copies and pastes it across different platforms. Readers can't see these markers, but computer systems can. In its announcement, Anthropic said Claude models launched on or after Aug. 2 would include watermarking. That includes content created by Claude through the API, Claude, Claude Code, Claude Cowork and Claude Tag. Watermarking will apply to all Claude-generated content wherever the AI system is offered, not just in the EU. Anthropic said it would "soon" share details about how customers can check whether text was generated by AI. AI transparency is a growing trend. Substack partnered with Pangram to let readers know how much, if any, a post was generated by AI. Suno recently announced changes to help listeners know if a song was created by AI. If LinkedIn customers suspect AI slop, they can let LinkedIn know. Spotify's new feature, AI Persona, allows listeners and creators to know which music was created with AI. How text will be watermarked To boil down an otherwise complicated process, Anthropic said that text generated by Claude models will be detectable because of how the words are chosen. If there is enough text, the AI detection tool will be able to spot a pattern that only Claude models would use to generate the text. Anthropic said that text watermarking would not lessen the quality of the content and that readers will not be able to tell the difference between watermarked text and non-watermarked text, without using the AI detection tool. "In internal testing, we've seen no impact of watermarking on the content, level of creativity or readability of Claude's text," the company said. Anthropic said its tool is based on the SynthID system that Google is using to detect AI in text, images, video and audio. How SynthID detects AI in text content is described in a Nature paper published in 2024. The watermarks Claude adds to text will remain, even if the text is copied and pasted from text editors such as Windows Notepad or MacOS's TextEdit. The marks also might not be eliminated through human editing, either. "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from," the company said. How images will be watermarked Anthropic said Claude will attach cryptographically signed notes in the metadata of files such as .png, .jpg or .svg to specify that the files were generated or processed with Claude. This is part of a standard practice, known as C2PA, used in photo-editing software and camera manufacturers to record where an image came from, Anthropic said. If someone tries to tamper with it -- for example, trying to hide that it was generated by AI -- the cryptographic signature will break and thus will show the reader that it was tampered with. It's not foolproof Anthropic included a caveat in its announcement. The presence of watermarking doesn't necessarily mean the content or image was created by Claude, nor does the absence of watermarking mean Claude wasn't involved, either. For example, let's say someone wants to repurpose an essay from another writer. They punch the essay into Claude and ask the AI to reword it. The output will have watermarking, but the content's facts and details came from a writer, not AI. People often use Claude for proofreading, translating and summarizing, the company said. Someone might also take content from Claude and edit it and combine it with other text. Even if only a small portion of the final draft is from Claude, there could be a watermark, perhaps undermining the legitimacy of the document for the reader. "Light editing probably won't remove the watermark completely," Anthropic said. "A complete rewrite where every word is replaced will." Anthropic said content generated or processed by Claude might not have a watermark, for various reasons. It could be that the amount of AI-generated content is too small, or perhaps the content has been "heavily edited, paraphrased, translated or mixed into other writing." It's also possible that a Claude-generated image doesn't have a watermark, either. For example, if someone takes a screenshot of the image and re-saves it as a different file, it won't have the metadata. "A watermark can only determine that Claude was likely involved with the content at some point," the company said. "It cannot distinguish 'Claude wrote this' from 'Claude heavily edited this,'" the company said. Although Anthropic is trying to comply with EU rules, AI detection has been significantly less than reliable, according to some reports. For example, content from non-native English speakers is often falsely flagged as AI-generated. Anthropic said Claude's watermarking process will not reveal any information about the person using a Claude model, their organization or chats with Claude. Swift backlash Many Claude customers weren't pleased with Anthropic's announcement. Some people canceled their paid subscriptions, according to Business Insider, and some derided the decision with postings on X. Some consumers feared that some pieces of content, even with little or insignificant Claude-generated text, would be flagged as coming from AI and become a sort of "scarlet letter" that dooms that content to illegitimacy. Alon Yamin, CEO of content integrity platform Copyleaks, said in a statement that AI watermarking creates too much risk of false positives and doesn't let the reader know how much text was truly generated by AI. "Watermarks are binary," Yamin wrote. "If someone writes a highly original piece but uses an AI tool just to polish the grammar or structure, the watermark will flag the entire document as 100% AI. This penalizes the modern workflow and completely ignores the value of original human thought." Yamin pointed out that several websites -- claudewatermark.com, claudewatermarks.com and StealthGPT -- were already advertising how to remove Claude watermarks.
[2]
The Mark of the Machine
Last week, Anthropic announced an unexpected policy change: text created with Claude, the company's large language model, would now contain an invisible watermark. If a person were to copy and paste a chatbot-crafted passage into a separate document, an A.I. detector would be able to determine the likelihood that it had been processed by Claude. A.I.-detection systems aren't new, of course; programs such as Pangram and Turnitin have become entrenched in academic and publishing practices. But, while those tools train on huge data sets to recognize statistical patterns that constitute a discernible A.I. writing "style," Claude's watermark is embedded within the text itself, at the individual word level, making it potentially harder for L.L.M. users to edit away evidence that they used A.I. Across the internet, criticism of the allegedly broken contract between machines and their human prompters ballooned. Weren't L.L.M.s specifically advertised as being able to present a machine's work as one's own? Wasn't that possibility indeed why many people used L.L.M.s in the first place? Now, for the students who'd grown accustomed to writing essays with chatbots, the journalists and authors who secretly used L.L.M.s to draft their articles and newsletters and books, and even the lawyers who relied on Claude to write briefs and motions, the jig was seemingly up. "Those guys come out of the process with a digital tattoo on their forehead," one Reddit user wrote in a viral post that itself appeared to be A.I.-generated. (I ran it through an A.I.-detection system and, yeah, one hundred per cent L.L.M.-"assisted.") "The stigma," the poster continued. "Jesus, the stigma." In the absence of comprehensive federal regulations for A.I., and with inconsistent and often contradictory rules governing its use in professional, academic, and artistic contexts, few forces have proved as powerful at tempering A.I.'s threat to human ingenuity as public shaming has. "Put plainly, you should feel bad for using AI," the editors of n+1 wrote, last year, in a polemic against L.L.M.s. "Stigmatization is a powerful force, and disgust and shame are among our greatest tools." As generative A.I. is increasingly deployed across our cultural and political life -- from winners of prestigious short-story prizes to major-label album releases to Presidential propaganda -- the average person is now tasked with policing machine-generated infractions in an effort to preserve whatever ethical dignity and critical acumen our species has left. Accusers can occasionally be overzealous, making allegations that aren't always ironclad, especially when the phrase "100% AI Generated" has emerged as a kind of cultural scarlet letter. But with Claude's new watermark, maybe this process of discerning the "real" from the "fake" would become more streamlined, and more foolproof -- a stepping stone to a more transparent and cautious relationship with L.L.M.s and gen A.I. writ large.
[3]
Anthropic's AI watermark already has removal tools
Days after Anthropic began watermarking Claude's text to meet EU rules, developers have released tools to strip the mark, according to Business Insider. One remover has passed 14,000 GitHub stars, and searches for 'AI watermark remover' jumped 60% in a week. Anthropic says the mark does not establish authorship, and researchers say it will always be removable. Anthropic's push to label AI-written text has produced an immediate counter-move. Developers have started building tools to strip those labels off, according to Business Insider. Thibault Spirlet and Agnes Applegate reported that one remover has gone viral on GitHub. Interest in the tools is climbing. The watermark is the trigger. Anthropic began marking Claude's output worldwide from 2 August. It embeds a statistical pattern in the model's word choices. That pattern travels with copied-and-pasted text. The company says the mark is imperceptible to a reader. Some users disagreed enough to act. The reaction has been loud. US Google Trends interest in "AI watermark remover" rose 60 percent week on week, Business Insider reported. Some Claude subscribers cancelled over the feature. Others went looking for a workaround, and a handful of developers built one. 'The wrong answer to a real problem' The most popular tool came fast. Guillaume Meyer, a Paris-based entrepreneur, released an open-source project called Watermarks Remover days after Anthropic's announcement, Business Insider reported. Meyer founded the e-commerce AI tool Memo. His remover strips hidden characters and metadata, then rewrites the text. That disrupts the word-choice pattern that carries the mark, while keeping the meaning. The first version took him about five hours to build, Meyer said. It has since drawn more than 14,000 GitHub stars, a rough measure of developer interest. It does not guarantee that a watermark is gone. Meyer framed his objection carefully. "I am all for content attribution," he told Business Insider. "I am against the watermarking technique, and that's a very significant distinction." His complaint is that the method "treats authorship as a binary thing." It marks text whether Claude wrote it outright or only helped edit it. "I think it's the wrong answer to a real problem," he said. He is not the only one. Sabrina Ramonov, an AI educator, said on X that she built a free browser-based remover for Claude and ChatGPT marks. "AI watermarks punish normal users, not bad actors," she wrote. Her tool claims to clean hidden marks from text, PDFs, Word documents, web pages, images and data files, Business Insider reported. Ansh Aneja, a Tokyo-based developer, said he built a Claude-focused remover on the day of the announcement. He wrote that he made it after reading a post by the investor Paul Graham. Aneja later released a local open-source version called MarkScrub. He said an earlier version went from zero to 8,500 users in a day, a figure Business Insider could not verify. Anthropic's answer Anthropic has pushed back on the premise. In a blog post titled How Claude's text watermark works, the company said the mark "doesn't say anything about ownership or authorship, and doesn't change a user's rights under our terms." It also said the watermark carries no identifying information, and cannot be traced to a specific person, organisation or chat. The company frames the feature as compliance, not surveillance. Anthropic says it added the watermark to meet its commitments under the European Union's AI Act. The law requires providers to mark AI-generated text in a machine-readable form. It signed the bloc's transparency code in July alongside roughly 190 other signatories, Mashable reported. It cannot yet limit the mark to the EU. So it is rolling the feature out globally, and extending it to older models. On the mechanics, Anthropic says the mark rides on low-stakes word choices. When several words would work equally well, the model leans toward one of them. That leaves a detectable statistical trace, Mashable reported. The company says this adds no cost, no extra tokens and no measurable hit to quality, and it did not respond to Business Insider's questions about the removal tools. The desk has covered the tension the removers are seizing on. Anthropic's own design means a lightly proofread email can carry a mark, while a heavily rewritten AI draft may carry none. Why it is hard to stop Researchers say the removers point to a basic limit. "There will always be ways to remove the watermark," Thibaud Gloaguen, a researcher at ETH Zurich's Secure, Reliable and Intelligent Systems lab, told Business Insider. He gave the example of simply rewording an entire passage. Anthropic concedes the same point in effect. A heavy rewrite can strip the mark entirely, the company has said, at which point it becomes debatable whether the text is still meaningfully AI-generated. The watermark is also weak or absent on short passages, hard facts, precise code and maths, where there is little room for variation. Konrad Kollnig, an assistant professor at Maastricht University's Law and Tech Lab, put the problem in blunt terms. "Whenever the watermarking detection tool is made public, anyone can check AI-generated contents... and can build tools to remove watermarks," he told Business Insider. That matters because Anthropic plans to release a public detection API alongside its next model, with no date set yet. A legal grey area The removers sit in an unsettled legal space. The EU tells AI companies to add durable labels, but does not clearly set rules for third parties who try to strip them, Business Insider reported. A European Commission spokesperson said the bloc's guidance requires providers' marking systems to withstand common alterations and deliberate attacks. The transparency code names removal, regeneration, copying and modification as threats providers must assess, the spokesperson added. Those, though, are duties on the providers, not the public. The AI Act does not expressly ban third parties from trying to remove a watermark, said Dmitri Roussinov, a senior lecturer at the University of Strathclyde. He added a catch: if a removal tool uses AI to regenerate the text, its own provider may be obliged to mark that new output. Neither the AI Act nor Anthropic's terms appear to bar people from making or sharing removal tools, Kollnig said. The risk lands elsewhere. Anthropic's usage policy prohibits passing off model output as human-made, so a user who strips a mark to misrepresent AI work as their own could still run into trouble. Other companies, including Google and OpenAI, watermark images too, and tools to remove those already exist. Even AI music has been watermarked in the same push for provenance. The fight Anthropic has started, in other words, is one the wider industry already knows well, and one that EU labelling rules have only sharpened.
Share
Copy Link
Anthropic rolled out invisible watermarks on all Claude AI-generated text worldwide to meet EU transparency requirements. Within days, developers released open-source removal tools that gained over 14,000 GitHub stars. The controversy highlights tensions between AI transparency regulations and user expectations around content authorship.

Anthropic announced that all text and files generated by Claude, its large language model, would include invisible watermarks starting August 2. The move aims to comply with the EU's Code of Practice on Transparency of AI-generated Content, which requires companies to inform users when they interact with AI-generated content
1
. Nearly 200 organizations have agreed to these measures under the European Union's AI Act1
.The watermarking applies to all Claude models launched on or after August 2, including content created through the API, Claude Code, Claude Cowork, and Claude Tag
1
. While designed for EU regulations, Anthropic implemented the feature globally across all regions where Claude operates. The company stated it would soon share details about how customers can verify whether text was generated by AI1
.The watermarking system embeds a detectable signal at the word level through statistical patterns in how Claude selects words. When multiple words work equally well in a sentence, the model systematically favors certain choices, creating a pattern that only Claude would use
1
. This invisible watermark persists even when text is copied and pasted across platforms like Windows Notepad or MacOS TextEdit1
.Anthropic based its system on Google SynthID, which detects AI in text, images, video, and audio. The company emphasized that internal testing showed no impact on content quality, creativity, or readability
1
. For images, Claude attaches cryptographically signed notes in metadata of files like .png, .jpg, or .svg, following the C2PA standard used by photo-editing software and camera manufacturers1
.Within days of the announcement, developers released open-source removal tools that gained significant traction. Guillaume Meyer, a Paris-based entrepreneur who founded the e-commerce AI tool Memo, released Watermarks Remover just days after Anthropic's policy change
3
. The tool, which took approximately five hours to build, attracted over 14,000 GitHub stars3
.Meyer's remover strips hidden characters and metadata, then rewrites text to disrupt the word-choice pattern while preserving meaning. He clarified his position: "I am all for content attribution. I am against the watermarking technique, and that's a very significant distinction"
3
. His objection centers on the binary treatment of authorship, where Claude marks text whether it wrote content entirely or merely helped edit it3
.Sabrina Ramonov, an AI educator, built a free browser-based remover for Claude and ChatGPT marks, arguing that "AI watermarks punish normal users, not bad actors"
3
. Tokyo-based developer Ansh Aneja released MarkScrub, a local open-source version, claiming an earlier iteration went from zero to 8,500 users in one day3
.Related Stories
The controversy reflects deeper tensions around AI transparency and ethical implications. Critics on Reddit and social media expressed concern about the "digital tattoo" effect, with one viral post describing the stigma attached to watermarked content
2
. Students who used chatbots for essays, journalists who relied on AI for drafts, and lawyers using Claude for briefs suddenly faced potential exposure2
.Google Trends data showed US interest in "AI watermark remover" rose 60 percent week-over-week following Anthropic's announcement
3
. Some Claude subscribers cancelled their accounts over the feature, while others actively sought workarounds3
. The reaction underscores questions about whether L.L.M.s were specifically marketed to present machine work as human-created2
.Anthropic acknowledged significant limitations in its watermarking approach. The company stated that watermark presence doesn't necessarily mean Claude created the content, nor does absence mean Claude wasn't involved
1
. For example, if someone inputs another writer's essay and asks Claude to reword it, the output carries a watermark despite originating from human-written content1
.The watermark also performs poorly on short passages, hard facts, precise code, and mathematics where word choice flexibility is limited
3
. Thibaud Gloaguen, a researcher at ETH Zurich's Secure, Reliable and Intelligent Systems lab, told Business Insider that "there will always be ways to remove the watermark," pointing to simple rewording as one method3
. Anthropic itself concedes that heavy rewrites can strip the mark entirely, raising questions about whether such text remains meaningfully AI-generated3
.The company emphasized that its watermark "doesn't say anything about ownership or authorship, and doesn't change a user's rights under our terms"
3
. The mark carries no identifying information and cannot be traced to specific individuals or organizations3
. This positions the feature as regulatory compliance rather than content surveillance, though critics argue the distinction matters little in practice. The rapid emergence of removal tools suggests that technical solutions to AI transparency may require approaches beyond embedding detectable signals in AI-generated content.Summarized by
Navi
[1]
[2]
[3]
11 Aug 2026•Technology

20 Nov 2024•Technology

24 Oct 2024•Technology

1
Technology

2
Technology

3
Technology
