Build1 publisher3 min readPublished
A 14,000-star watermark remover, and no detector to test it against
Anthropic described statistical text watermarking for Claude on August 14 but has published no detector, so neither the mark's durability nor its removal can be independently checked.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Anthropic on August 14 explained text watermarking for future Claude models.
- Anthropic states its watermark is a statistical pattern in word selection, rather than hidden characters added to the output.
- Anthropic says the watermark does not change the practical quality or content of Claude's output, adds no extra tokens or identifying information, and is intended to help determine the likelihood that Claude participated in writing text.
- Anthropic's announcement says its watermarking approach contains no user-, organization-, or chat-specific identifier.
- Anthropic links the watermarking work to EU AI Act requirements that took effect for providers serving the EU market on August 2.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
Anthropic explained on August 14 how it intends to watermark text from future Claude models, describing a statistical pattern in word selection rather than hidden characters bolted onto the output [1][2]. Within days, an open-source removal project had more than 14,000 GitHub stars, and according to BleepingComputer nobody can verify whether it works, because Anthropic has not released a detector [7][6].
That asymmetry is the whole story. Anthropic says the watermark does not change the practical quality or content of Claude's output, adds no extra tokens or identifying information, and is meant to help determine the likelihood that Claude participated in writing a piece of text [3]. It carries no user, organisation, or chat-specific identifier [4]. The company ties the work to EU AI Act obligations that took effect for providers serving the EU market on August 2 [5]. All of that is a description of intent. Without a detector that outside researchers can run, it is not a measurement, and the removal claims stacked against it are not measurements either.
The demand signal is real even if the efficacy is not established. Business Insider reports US Google Trends interest in "AI watermark remover" rose 60 percent week over week [11]. The project it identified, Guillaume Meyer's Watermarks Remover, strips hidden characters and metadata and then rewrites text to preserve meaning while disrupting word-choice patterns, according to Meyer, who said the first version took roughly five hours to build [9][10]. BleepingComputer counted more than 4,500 stars on August 13; Business Insider counted more than 14,000 on August 18 [8][7]. That is roughly a tripling in five days [19]. Note also that the earlier count predates Anthropic's explanation by a day, so the tooling was not purely a response to it [20].
For anyone writing policy, the useful split is between two different controls that get talked about as one [21]. Removing zero-width Unicode characters, bidirectional controls, and provenance fields such as C2PA, EXIF, and XMP is observable and relatively straightforward, per BleepingComputer, and file metadata also disappears through ordinary re-saving, format conversion, or a screenshot [12][13]. A statistical text watermark is a different problem: whether a rewrite defeats it depends on the watermarking and detection methods, how much text was changed, and where the detector sets its thresholds [14]. None of those variables are public here, which means an internal rule that says "check the provenance mark" currently resolves to nothing you can audit.
Treat the vendor claims accordingly. Several offerings advertise coverage beyond Claude, including Google Gemini, OpenAI provenance surfaces, and open-weight models, and those advertised capabilities are not independently validated [15]. StealthGPT's own material concedes that no tool can guarantee a complete bypass, because detectors change [16]. Anthropic did not respond to Business Insider's questions about the removal services [17]. Forbes characterised the surge in removal applications as an environment that attracts deceptive claims and malware, which is a reason to apply normal supply-chain hygiene, including repository review, dependency inspection, and sandboxing, before running any of it [18][23].
What to watch: whether Anthropic publishes a detector with documented performance, known failure modes, and a stated policy for edited or mixed-origin text, because that is the point at which any of these claims become testable [22][6]. Until then, a provenance mark is a signal in someone else's black box. Build the workflow so that a missing or defeated watermark does not silently change an outcome.