Anthropic's Invisible Watermarks Spark a De-Watermarking Race
Anthropic recently rolled out an "imperceptible watermark" for text generated by its Claude models, aiming to make AI output easier to identify. The watermark is embedded through a statistical pattern in Claude's word choices, and it persists even when users copy and paste the content. The company says this move aligns with its commitments under the EU AI Act.
But the tech community didn't take long to push back. Many users and professionals worry that even routine tasks like proofreading, translation, or summarization would carry the hidden mark into the final output. Some users have even canceled their Claude subscriptions in protest. The backlash has fueled a surge in searches for tools that can remove AI markers from text.
Developers have responded quickly. Guillaume Meyer, a Paris-based tech entrepreneur and founder of the AI e-commerce tool Memo, launched an open-source project called Watermarks Remover just days after Anthropic's announcement. The tool strips hidden characters and metadata while rewriting the text to preserve meaning, thereby disrupting the statistical patterns that carry the watermark. Meyer says he built it in about five hours, and it quickly gained over 14,000 stars on GitHub. He admits, though, that it can't guarantee 100% removal.
Meyer has been vocal about his stance: he supports content attribution but opposes what he calls "irrational watermark technology" that reduces authorship to a simple black-or-white classification. Meanwhile, Sabrina Ramonov, who offers AI education services, shared on social media that she developed a free browser-based Watermark Remover. It claims to remove hidden AI markers from text, PDFs, Word documents, web pages, images, and data files. Ansh Aneja, a software developer in Tokyo, also created a dedicated tool for Claude on the same day the feature was announced, later releasing a local open-source version called MarkScrub. He reports a significant uptick in users within a day.
From a technical and legal standpoint, these de-watermarking tools occupy a gray area. Thibaud Gloaguen, a researcher at ETH Zurich, points out that they highlight the long-standing limitations of watermarking technology—there will always be ways to remove watermarks through rephrasing and other methods.
On the legal front, the EU AI Act requires AI service providers to make their content marking systems resilient against common modifications and adversarial operations. It also mandates assessing the potential threats of removing or altering watermarks. However, the act doesn't explicitly forbid third parties from developing or attempting to remove AI watermarks. Legal experts caution that if users employ such tools to maliciously disguise AI-generated content as human-created, they might violate Anthropic's terms of service, which prohibit impersonating humans.
As Anthropic plans to launch a text detection API alongside its next-generation model and gradually extend watermarking to older models, the tug-of-war between watermarking and de-watermarking is likely to intensify. The question remains: can transparency and user freedom coexist in the age of AI?
Key Points
- Anthropic introduced invisible watermarks in Claude to comply with the EU AI Act.
- Users and developers reacted swiftly, with several open-source de-watermarking tools emerging.
- Tools like Watermarks Remover and MarkScrub aim to strip hidden markers while preserving text meaning.
- Legal and technical challenges persist, as watermarking is not foolproof and removal tools operate in a gray area.
- The conflict is expected to escalate as Anthropic expands watermarking to more models.