Build1 distinct publisher3 min readUpdated
Anthropic says its Claude text watermark can survive editing; Guillaume Meyer's five-hour remover says otherwise. With no public detector, nobody outside Anthropic can settle it.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
The useful split inside the repository is between what a stranger can check and what nobody can. Stripping invisible Unicode characters and C2PA, EXIF, XMP and document metadata is verifiable on the spot: run the tool, open a metadata reader, see whether the fields are gone [9]. The statistical text watermark is different, because the signal lives in word choices, and Meyer's own documentation calls the rewriting path best-effort and says it cannot certify that a vendor detector will fail [11]. The loud half of this story is the half with no scoreboard.
Anthropic's half is unscored in exactly the same way. The company says the text mark travels through copy and paste and may survive some editing [6], while also conceding that its marks cannot establish authorship and may disappear after heavy editing [7]. Both statements describe the behaviour of a detector that outside researchers cannot run, because the detection mechanism and full technical guidance have not been published [8]. Durability claim and removal claim rest on the same missing instrument.
That is what makes the marking a deterrent rather than a control. A signed C2PA manifest is a positive assertion attached to a PNG, JPEG or SVG [5]; delete it and you do not get a file flagged as tampered with, you get a file that looks like every other unmarked file [9]. Provenance metadata raises the cost of casual laundering and creates something a platform can point at when it is present. It cannot answer the question people actually ask, which is whether unlabelled text came from a model, and Anthropic has already said its marks do not settle authorship [7].
The effort asymmetry is the number worth holding onto. Anthropic's marking programme spans Claude, Claude Code, Claude Cowork, Claude Tag, its API and supported cloud platforms, with models launched in the EU on or after August 2, 2026 supporting machine-readable marking from launch [4]. Against that, one developer with more than 20 years in technology and prior experience running open-source models produced a first version in roughly five hours [2][15]. The 14,000-plus stars work out to about 2,800 per hour of build time [18], which measures curiosity and nothing about efficacy; Meyer himself says the attention caught him unprepared [14], that the tool is still difficult to use, and that it will need months of adjustment as Anthropic ships or changes detectors [13]. The repository warns that removal is not guaranteed [17].
Untestability is also a business model. Unmarker is a pre-launch commercial service advertising Claude-focused scoring, rewriting, meaning checks and planned API access, and Unmarkr claims to remove visible marks, hidden AI tags, SynthID and C2PA metadata from images [16]. A paid service that says it defeats a statistical watermark is selling a claim its customers cannot check and reviewers cannot check either, for as long as the only working detector sits inside the lab that made the mark [8]. Meyer's stated purpose, educational use and people working on their own content [12], is a README sentence, not a constraint on who clones the code.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Guillaume Meyer's open-source project Watermarks Remover had more than 14,000 GitHub stars at the time of the Business Insider reporting.
Meyer says he built the first version of the tool in roughly five hours after researching Anthropic's marking system.
By August 11, Meyer's second post about the project had generated more than 2 million impressions on X, according to his account of the launch in Business Insider; attention also spread to LinkedIn and other networks.
Under Anthropic's published policy, Claude models launched in the European Union on or after August 2, 2026 support machine-readable marking from launch, and the marks apply worldwide across Claude, Claude Code, Claude Cowork, Claude Tag, Anthropic's API and supported cloud platforms.
Anthropic uses two systems: generated text receives an imperceptible watermark embedded through the model's output, and supported files such as PNG, JPEG and SVG receive signed provenance metadata based on the C2PA standard.
Anthropic says the text watermark travels when content is copied and pasted and may survive some editing.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Documented on both sides, testable on neither
The cluster rests on one publisher relaying a Business Insider report plus repository and vendor documentation. Policy scope, tool capabilities, and the caveats from both Anthropic and the repository are consistently documented. But the central contested question — whether the statistical text watermark can be stripped — has no independent test anywhere in the material, and cannot have one while the detection mechanism is unpublished. The deterministic claims (Unicode, C2PA/EXIF/XMP metadata) are the only checkable ones.
Heavy attention, unmeasured use
There are real, dated adoption signals: 14,000-plus GitHub stars, a launch post past 2 million impressions, an announced Anthropic marking rollout across multiple surfaces, and two commercial entrants. All of them measure attention or announcement rather than usage — no download counts, no deployments, no enterprise commitments, no evidence of Claude marking coverage in the field, and one commercial service is still pre-launch. Meyer's own note that the tool is difficult to use argues against inferring broad practical use from stars.
Framing outruns what can be verified
Mild overstatement, mostly in framing rather than in sourced fact. Both the vendor's durability claim and the project's removal capability are presented as a contest, when the material shows only that neither is testable; the '2,800 stars per hour of build time' construction is a rhetorical ratio with no engineering or adoption meaning, and stars are used adjacent to efficacy. The article is credited for carrying both sets of caveats explicitly, which keeps the gap modest rather than large.
Attention and product incentives on both sides
Documented incentives are visible without inference. Meyer is a founder of another AI product who gained major visibility from the launch and frames the tool as educational and own-content use, which is also the framing that minimizes liability. Anthropic's marking is a compliance-driven rollout tied to EU launch dates, and it has not published the detector that would allow its durability claim to be checked. Two commercial services are positioning to sell removal against the same policy. What is absent is any funding, pricing or revenue disclosure, so the commercial incentive is evident in direction but not in magnitude.
Consistent single-chain account, unresolved core question
Confidence is limited by structure more than by contradiction. One publisher, relaying one originating report, with no Anthropic comment and no second outlet to corroborate the star, impression or capability figures. Within those limits the account is internally consistent and unusually explicit about both parties' caveats, and the policy and repository details are the kind that can be checked directly. The unresolvable item — whether the statistical watermark survives the tool — is correctly left open rather than asserted.
build
A 14,000-star watermark remover, and no detector to test it against1 distinct publisher
product
A five-hour script beats Claude's watermark, so stop treating it as provenance3 distinct publishers
build
Half of Claude's watermark ships with a reference tool. Your PDF pipeline eats it.1 distinct publisher
build
Google Makes the Visible Watermark Optional. Your Pixel Check Is Now Decoration.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.