Product3 distinct publishers3 min readUpdated
Anthropic began marking Claude's output on 2 August. Within days an open-source stripper had more than 14,000 GitHub stars, which settles what the mark can and cannot prove.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Anthropic switched on a statistical watermark for Claude's output worldwide on 2 August, embedding a pattern in the model's word choices that travels with copied-and-pasted text [1]. Days later a Paris-based entrepreneur, Guillaume Meyer, published an open-source project called Watermarks Remover, which Business Insider reports has since drawn more than 14,000 GitHub stars [3][4].
The mechanism is not exotic on either side. Anthropic says the mark rides on low-stakes word choices: where several words would work equally well, the model leans toward one, leaving a detectable statistical trace, Mashable reported [2]. Meyer's tool strips hidden characters and metadata, then rewrites the text, disrupting the word-choice pattern while keeping the meaning [7]. He told Business Insider the first version took him about five hours to build [5], and he does not claim it guarantees the mark is gone [6].
Demand is not marginal either. US Google Trends interest in "AI watermark remover" rose 60 percent week on week, according to Business Insider [8], and some Claude subscribers cancelled over the feature [9]. Sabrina Ramonov, an AI educator, said on X that she built a free browser-based remover covering Claude and ChatGPT marks, and that it handles text, PDFs, Word documents, web pages, images and data files [11]. Ansh Aneja, a Tokyo-based developer, said he built a Claude-focused remover on the day of the announcement and later released a local open-source version called MarkScrub; he said an earlier version went from zero to 8,500 users in a day, a figure Business Insider could not verify [12].
There is no patch for this. "There will always be ways to remove the watermark," Thibaud Gloaguen of ETH Zurich's Secure, Reliable and Intelligent Systems lab told Business Insider, giving the example of rewording an entire passage [13]. Anthropic has said the same thing in effect: a heavy rewrite can strip the mark entirely [14].
For anyone shipping a feature or writing a policy, the consequence is that the signal is one-directional and weak in both directions. Absence of the mark is not evidence that text was not machine-generated, because removal is public and a full reword is sufficient; presence only indicates that unrewritten Claude wording survived [23]. Worse, the error modes fall on the wrong people. Anthropic's own design means a lightly proofread email can carry a mark while a heavily rewritten AI draft may carry none [15]. Meyer's objection is exactly that: the technique "treats authorship as a binary thing," and he called it "the wrong answer to a real problem," while saying he is "all for content attribution" [10]. Ramonov's version was blunter: "AI watermarks punish normal users, not bad actors" [11].
Anthropic's framing is narrower than the uses people will invent for it. In a blog post the company said the mark "doesn't say anything about ownership or authorship, and doesn't change a user's rights under our terms" [16], and that it carries no identifying information and cannot be traced to a specific person, organisation or chat [17]. It says it added the watermark to meet commitments under the EU AI Act, which requires providers to mark AI-generated text in machine-readable form [18]; it signed the bloc's transparency code in July alongside roughly 190 other signatories, Mashable reported [19]. It cannot yet limit the mark to the EU, so it is rolling out globally and extending to older models [20]. The company says the feature adds no cost, no extra tokens and no measurable hit to quality [21], and it did not respond to Business Insider's questions about the removal tools [22].
Watch whether machine-readable marking is still treated as satisfied by regulators once strippers are a package install, whether Anthropic narrows the rollout regionally rather than globally [20], and whether any platform, school or publisher starts making decisions on detector output. That last one is where a weak signal turns into a false accusation.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Anthropic began marking Claude's output worldwide from 2 August, embedding a statistical pattern in the model's word choices that travels with copied-and-pasted text; the company says the mark is imperceptible to a reader.
Meyer's remover has drawn more than 14,000 GitHub stars, a rough measure of developer interest.
Meyer told Business Insider: "I am all for content attribution... I am against the watermarking technique, and that's a very significant distinction." He said the method "treats authorship as a binary thing" and marks text whether Claude wrote it outright or only helped edit it, adding: "I think it's the wrong answer to a real problem."
Sabrina Ramonov, an AI educator, said on X that she built a free browser-based remover for Claude and ChatGPT marks, writing "AI watermarks punish normal users, not bad actors"; her tool claims to clean hidden marks from text, PDFs, Word documents, web pages, images and data files, Business Insider reported.
Ansh Aneja, a Tokyo-based developer, said he built a Claude-focused remover on the day of the announcement after reading a post by the investor Paul Graham, and later released a local open-source version called MarkScrub; he said an earlier version went from zero to 8,500 users in a day, a figure Business Insider could not verify.
Anthropic's design means a lightly proofread email can carry a mark, while a heavily rewritten AI draft may carry none.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Well sourced on mechanics and countermeasures, unverifiable on removal efficacy
Three independent publishers converge on the rollout, the compliance driver, the removal tooling and the robustness limit, with named on-record sources (Meyer, Gloaguen at ETH Zurich, Kollnig, Roussinov, Pan) plus Anthropic's own blog language and a spokesperson statement to WIRED. The gap is decisive for the story's headline claim: no source can test whether any remover actually defeats detection until Anthropic ships its detection API, and the cluster's own reporting says so.
Marking is default-on globally; removal tooling is virally adopted but mostly measured in vanity metrics
The watermark side is real adoption: shipped globally from 2 August and being extended to older models, under a code signed by roughly 190 organisations. The removal side shows fast, broad uptake — 14,000 to 15,000-plus GitHub stars within hours of each other, thousands of forks, 100-plus contributors, 20,000-plus X bookmarks, a 60 percent search surge, and at least one commercial platform integration — but most figures are stars and bookmarks rather than verified usage, and the one hard user number (8,500 in a day) is explicitly unverified.
Directionally right, slightly ahead of the proof
The cluster's core conclusion — that a watermark hit or miss is not provenance — is understated rather than overstated: Anthropic concedes paraphrase and translation defeat the mark and says detection yields only a probability. What runs ahead of the evidence is the framing that a five-hour script demonstrably beats the watermark. No remover has been tested against a detector that does not yet exist publicly, star and bookmark counts are being read as capability, and the loudest usage figure is unverified. Hence a small positive gap.
Regulatory compliance on one side, attention and product on the other
Motives are stated openly across the cluster and cut both ways. Anthropic's incentive is documented: AI Act compliance under a code it signed, with providers facing fines up to 3 percent of annual turnover, and Pan's read that the company 'wanted to show that they're in good faith doing it'. It declined to answer Business Insider on removal tools while giving WIRED a statement. On the other side, remover builders gain visibility and product: a founder promoting his own repository, an AI educator distributing a free branded tool, and a startup CTO integrating the code into a commercial platform. Only the publishers' own commercial motives are unaddressed by the sources.
High confidence in the provenance conclusion, lower in the efficacy narrative
Three publishers, named experts and direct vendor statements make the rollout, the compliance driver and the robustness limit solid. Confidence is reduced by the unresolved release-timing discrepancy, unverified traction and user figures, an unquantified cancellation claim, and the fact that the entire removal-works premise remains untestable until a public detector exists.
build
A 14,000-star watermark remover, and no detector to test it against1 distinct publisher
leadership
Anthropic's invisible watermark lands hardest on the customers paying $100 a month1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
gizmodo.com
1 article · August 19, 2026
thenextweb.com
1 article · August 19, 2026
wired.com
1 article · August 19, 2026