Published Security3 min read
Claude watermark removers mostly do not work. That is not the security problem.
Days after Anthropic shipped invisible watermarks, a market of unvetted GitHub projects and web tools appeared. Several authors admit the removal does not function yet.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- A market for tools designed to remove AI watermarks emerged rapidly within days of Anthropic announcing the implementation of invisible watermarks in content generated by its Claude AI model; reported by Bleeping Computer and summarised by SC Media/scworld.com.
- The development includes a GitHub project with over 4,500 stars.
- The market also includes various new web tools and existing AI detection evasion services.
- Claims of successful watermark removal are widespread but remain unverified, as Anthropic has not yet released its detection methods.
- Tools that have appeared include Guillaume Meyer's "watermarks-remover", "claude-watermark-cleaner" and "remove-ai-watermarks".
Compiled by The WatchSomething wrong?How this is made
Why it matters
A market for tools that claim to strip the invisible watermarks Anthropic began embedding in Claude output emerged within days of the announcement, according to Bleeping Computer as summarised by SC Media [1]. The part that lands on security teams is not evasion capability, because several of the authors say the capability is not there [9], but the speed with which unvetted code attracted an audience: one GitHub project has passed 4,500 stars [2].
Look at what the tools do versus what they are named for. Most of them strip metadata or hidden characters, which the reporting describes as the less complex task [7]. The watermark itself is said to sit in the model's word choices, so removing it would require substantial rewriting of the text [8], and developers including Guillaume Meyer, author of "watermarks-remover", acknowledge that this part is not yet functional in their tools [9]. In other words the shipped function and the advertised function are different things [11]. Nobody can settle the argument either way, because Anthropic has not published its detection method, leaving every removal claim unverified [4].
That gap is the supply chain condition. Demand is real and the reporting frames it as significant [10], the names are generic and interchangeable - "watermarks-remover", "claude-watermark-cleaner", "remove-ai-watermarks" are three of them [5][12] - and some projects broaden their pitch by claiming to handle watermarks from OpenAI and Google's Gemini as well [6]. A package ecosystem where the function cannot be verified, the naming is trivially imitable, and the audience is measured in thousands of stars is the environment in which a maintainer swap or a lookalike repository pays off. The source material identifies the supply chain risk in general terms [10]; the operator version of it is narrower. Someone on your engineering team has cloned a repository whose value proposition is defeating a provenance control, and neither they nor you can test whether it does that or something else.
The web-hosted variants deserve separate treatment [3]. A browser tool that cleans hidden characters out of a document has to be given the document first, which means the text leaves the organisation before it comes back [13]. Drafts of contracts, incident notes and unreleased code are exactly the sort of content someone would run through an AI-detection scrubber.
Regulatory pressure is what keeps this market alive rather than letting it fade. The reporting ties the demand to the EU AI Act's transparency requirements, alongside the difficulty of verification [10]. That is a durable incentive: as long as disclosure obligations attach to AI-generated text, there is a customer for anything that promises to detach them.
Three things to watch. Whether Anthropic publishes any detection detail, which would convert the current claim-versus-claim standoff into something testable [4]. Whether the high-star projects change hands or sprout near-identical clones, the usual sequence when a repository name acquires search traffic [2][12]. And whether these tool names show up in your own software inventory and DNS logs, because the honest reading of 4,500 stars is that they are already on someone's laptop [2].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A market for tools designed to remove AI watermarks emerged rapidly within days of Anthropic announcing the implementation of invisible watermarks in content generated by its Claude AI model; reported by Bleeping Computer and summarised by SC Media/scworld.com.
- [3]
The market also includes various new web tools and existing AI detection evasion services.
ReportedView cited source - [4]
Claims of successful watermark removal are widespread but remain unverified, as Anthropic has not yet released its detection methods.
ReportedView cited source - [5]
Tools that have appeared include Guillaume Meyer's "watermarks-remover", "claude-watermark-cleaner" and "remove-ai-watermarks".
ReportedView cited source - [6]
Some of these tools claim to support removal of watermarks from OpenAI and Google's Gemini as well.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comSC StaffAug 13Market for AI watermark removal tools emerges after Anthropic's Claude update
Cited in this coverage: Bleeping Computer via scworld.com



