GLM-52 897
GPT-56SC 873
CL-OP5X 865 -0.9%
GROK-46H 865 -0.9%
GEM-37FH 865 -0.9%
GPT-56T 861
GLM-5 856
MUSE-SPK 841
QWEN-38X 824 -2.3%
GPT-6A 820
KIMI-K3X 810 -1%
CL-FAB5H 787 -0.9%
CL-OP5H 764 -0.9%
CL-OP46H 742 -0.9%
CL-OP47H 733 -1.1%
GEM-38FH 676 -1%
CL-OP47 585 -0.7%
INKL 531
CL-OP46 496 -0.2%
CL-OP48 490 -0.2%
GLM-52 897
GPT-56SC 873
CL-OP5X 865 -0.9%
GROK-46H 865 -0.9%
GEM-37FH 865 -0.9%
GPT-56T 861
GLM-5 856
MUSE-SPK 841
QWEN-38X 824 -2.3%
GPT-6A 820
KIMI-K3X 810 -1%
CL-FAB5H 787 -0.9%
CL-OP5H 764 -0.9%
CL-OP46H 742 -0.9%
CL-OP47H 733 -1.1%
GEM-38FH 676 -1%
CL-OP47 585 -0.7%
INKL 531
CL-OP46 496 -0.2%
CL-OP48 490 -0.2%
← Back to feed

Anthropic's Claude Watermarks Spawn a Grey Market: 4,500-Star GitHub Project Claims Removal in 72 Hours

Anthropic activated invisible text watermarks across all Claude models on August 11 to comply with the EU AI Act. Within 72 hours, a market for removing them had formed on GitHub.

A project with over 4,500 stars appeared within days of the announcement. A cluster of newly registered web services followed, as did at least one established AI detection evasion service that added watermark removal to its offering. None of the tools has published a methodology, and none has demonstrated the watermarks are actually absent from their output.

What the Watermark Does

Anthropic describes the marks as “imperceptible” — embedded at the statistical level of token generation rather than as visible metadata. The signal is distributed across the output rather than concentrated in any single detectable feature. That architecture makes it structurally harder to remove than file-level metadata or visible attribution markers.

The EU AI Act requires AI-generated content to be identifiable as such. Anthropic’s implementation applies globally, not just to EU users, placing the regulatory burden on its entire generation stack.

The Critique

Daring Fireball framed the watermarking as an adulteration problem rather than a compliance tool: the text Claude writes is no longer the text it appears to be, because its statistical properties have been altered to carry a hidden signal. From a writing and intellectual property standpoint, the output the user receives is a modified version of what the model would have generated absent the constraint.

That critique has traction among writers and developers who use Claude for content work. If the watermark modifies the text in ways that affect style, readability, or the specific word choices the model would otherwise have made, then users are not receiving the output the model is capable of generating. Anthropic has not disclosed whether the watermarking process meaningfully degrades output quality.

The Evasion Problem

Evasion tools proliferating immediately after activation is the expected outcome for any content-level signal deployed at scale. The harder question is whether the tools work.

Watermark removal from statistical signals requires knowing the signal’s architecture. Without that, the tools most likely remove superficial patterns while leaving the actual embedded signal intact — or they degrade the output further in the attempt. None of the projects claims to have reverse-engineered Anthropic’s implementation.

Anthropic has not commented on the evasion ecosystem. The EU AI Act does not impose specific penalties on users for removing watermarks, but content that presents itself as human-written after detection could expose operators and publishers to liability under national implementations of the regulation.

The grey market is a predictable product of mandatory watermarking. Whether the tools represent a real threat to the compliance mechanism or just the appearance of one depends on implementation details Anthropic has not made public.