Product3 publishers3 min readPublished
A five-hour script beats Claude's watermark, so stop treating it as provenance
Anthropic began marking Claude's output on 2 August. Within days an open-source stripper had more than 14,000 GitHub stars, which settles what the mark can and cannot prove.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Anthropic began marking Claude's output worldwide from 2 August, embedding a statistical pattern in the model's word choices that travels with copied-and-pasted text; the company says the mark is imperceptible to a reader.
- Anthropic says the mark rides on low-stakes word choices: when several words would work equally well, the model leans toward one of them, leaving a detectable statistical trace, Mashable reported.
- Guillaume Meyer, a Paris-based entrepreneur who founded the e-commerce AI tool Memo, released an open-source project called Watermarks Remover days after Anthropic's announcement, Business Insider reported.
- Meyer's remover has drawn more than 14,000 GitHub stars, a rough measure of developer interest.
- Meyer said the first version of his remover took him about five hours to build.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Anthropic switched on a statistical watermark for Claude's output worldwide on 2 August, embedding a pattern in the model's word choices that travels with copied-and-pasted text [1]. Days later a Paris-based entrepreneur, Guillaume Meyer, published an open-source project called Watermarks Remover, which Business Insider reports has since drawn more than 14,000 GitHub stars [3][4].
The mechanism is not exotic on either side. Anthropic says the mark rides on low-stakes word choices: where several words would work equally well, the model leans toward one, leaving a detectable statistical trace, Mashable reported [2]. Meyer's tool strips hidden characters and metadata, then rewrites the text, disrupting the word-choice pattern while keeping the meaning [7]. He told Business Insider the first version took him about five hours to build [5], and he does not claim it guarantees the mark is gone [6].
Demand is not marginal either. US Google Trends interest in "AI watermark remover" rose 60 percent week on week, according to Business Insider [8], and some Claude subscribers cancelled over the feature [9]. Sabrina Ramonov, an AI educator, said on X that she built a free browser-based remover covering Claude and ChatGPT marks, and that it handles text, PDFs, Word documents, web pages, images and data files [11]. Ansh Aneja, a Tokyo-based developer, said he built a Claude-focused remover on the day of the announcement and later released a local open-source version called MarkScrub; he said an earlier version went from zero to 8,500 users in a day, a figure Business Insider could not verify [12].
There is no patch for this. "There will always be ways to remove the watermark," Thibaud Gloaguen of ETH Zurich's Secure, Reliable and Intelligent Systems lab told Business Insider, giving the example of rewording an entire passage [13]. Anthropic has said the same thing in effect: a heavy rewrite can strip the mark entirely [14].
For anyone shipping a feature or writing a policy, the consequence is that the signal is one-directional and weak in both directions. Absence of the mark is not evidence that text was not machine-generated, because removal is public and a full reword is sufficient; presence only indicates that unrewritten Claude wording survived [23]. Worse, the error modes fall on the wrong people. Anthropic's own design means a lightly proofread email can carry a mark while a heavily rewritten AI draft may carry none [15]. Meyer's objection is exactly that: the technique "treats authorship as a binary thing," and he called it "the wrong answer to a real problem," while saying he is "all for content attribution" [10]. Ramonov's version was blunter: "AI watermarks punish normal users, not bad actors" [11].
Anthropic's framing is narrower than the uses people will invent for it. In a blog post the company said the mark "doesn't say anything about ownership or authorship, and doesn't change a user's rights under our terms" [16], and that it carries no identifying information and cannot be traced to a specific person, organisation or chat [17]. It says it added the watermark to meet commitments under the EU AI Act, which requires providers to mark AI-generated text in machine-readable form [18]; it signed the bloc's transparency code in July alongside roughly 190 other signatories, Mashable reported [19]. It cannot yet limit the mark to the EU, so it is rolling out globally and extending to older models [20]. The company says the feature adds no cost, no extra tokens and no measurable hit to quality [21], and it did not respond to Business Insider's questions about the removal tools [22].
Watch whether machine-readable marking is still treated as satisfied by regulators once strippers are a package install, whether Anthropic narrows the rollout regionally rather than globally [20], and whether any platform, school or publisher starts making decisions on detector output. That last one is where a weak signal turns into a false accusation.