Claude watermarks spur quick bypass tools
Open-source removers and simple rewriting tricks appeared within hours, as developers argued the new provenance mark was too easy to disrupt in practice.
Developers moved almost immediately to find ways around Anthropic's new Claude watermarking system. WIRED reported that Guillaume Meyer published removal code within four hours of Anthropic confirming the feature, and the project spread quickly across GitHub and X.
Meyer's code drew more than 100 contributors, and many more people folded the same ideas into their own projects. The repository was bookmarked more than 20,000 times on X.
As reported on 14 August, Anthropic said it would soon offer a text-detection API for Claude. The company says the watermark is embedded in low-stakes word choices, is invisible to readers and can travel with copied text, but heavy editing, paraphrasing, translation and short passages can make it harder to detect.
Meyer's open-source Watermarks Remover tries to strip hidden characters and metadata before rewriting the text with synonym swaps and small reordering to disrupt the statistical pattern. Meyer said the first version took about five hours to build, and the GitHub repository has more than 14,000 stars.
Other coders published quicker workarounds too. Erik Hughes built a tool in about 15 minutes that removes invisible and look-alike characters, reorders sentences and swaps words for synonyms, while Leon Chlon said a watermark can be disrupted by condensing Claude's response and translating it into a dialect such as Arabic before translating it back.
The response has also become a small backlash. TNW said searches for "AI watermark remover" rose 60% week on week in the US after Anthropic's rollout, and some Claude subscribers cancelled over the feature. Meyer said he supports attribution but opposes the watermarking technique, while Anthropic says the mark carries no identifying information and does not change a user's rights under its terms.
Anthropic says the watermark is meant to comply with the EU AI Act and that a detected mark is only a signal content may have been processed by Claude, not proof of full authorship. The company also says lack of a detected mark does not mean content was not AI-generated, because heavy editing, paraphrasing, translation or very short passages can erase it.