An invisible watermark on everything Claude writes
A wave of anger, cancelled subscriptions, and researchers frightened for their careers. The irony is that defeating the watermark is easier than you would think.
Anthropic announced that Claude's text will carry an invisible watermark, mandatorily.
The anger arrived immediately. Cancelled subscriptions, furious posts, and researchers worried about their academic standing.
But before the anger, the reason most coverage leaves out.
Why now, and why at all
This is not a unilateral Anthropic decision. It is compliance with the transparency rules in the EU AI Act, which came into force on 2 August 2026.
And the technique is not newly invented: it is based on SynthID-Text from Google DeepMind.
That detail matters, because it means this is the beginning of a standard rather than one company's whim. Anyone who thinks cancelling a subscription settles it will meet the same thing elsewhere soon enough.
How it works
There are no hidden characters buried in the text. The method is cleverer and harder to strip:
The model biases its word choices probabilistically. Where several acceptable words fit a position, it leans toward a particular set in a calculated way. The bias is tiny in any one sentence and becomes a detectable statistical signature across enough text.
And crucially: it survives copy and paste, because it lives in the word choices themselves rather than in hidden characters.
And the irony
Here is the part that makes the whole argument weaker than it looks: defeating the watermark is simple.
Paraphrase the text through a competing model and it disappears, because the signature lives in Claude's lexical choices and another model re-picks them.
Open source tools built for exactly this have already appeared, rewriting through a non-Claude model and scrubbing the signals.
Which means something uncomfortable: the watermark catches the honest user and misses anyone intending to hide. The researcher who copy-edited their paper carries the mark; the person who paraphrases does not.
What this means for you
If you use Claude on academic writing: know that copy-editing alone may leave a trace. Document your work: drafts, version history, notes. Holding the evidence beats arguing later.
If you teach: this does not make detectors reliable. See are your students cheating?, where the same logic applies: a tool that catches the diligent and misses the dishonest.
If you publish commercially: ask your vendor about watermarking policy and put it in your contracts. This will be a routine clause within a year.
In closing
The idea is reasonable, the implementation punishes the wrong people, and getting around it is easy. Those three rarely coexist in one policy.
Common questions
- How does Claude's watermark work?
- Through a calculated bias in word choice rather than hidden characters. The bias is tiny per sentence, becomes detectable across enough text, and survives copy and paste.
- Why did Anthropic do it?
- To comply with EU AI Act transparency rules that took effect on 2 August 2026, using a technique based on Google DeepMind's SynthID-Text.
- Can it be removed?
- Yes, by paraphrasing through a competing model, because the signature lives in Claude's lexical choices. Which means it catches honest users and misses anyone intending to hide.
- Will my text be treated as machine generated?
- If you used Claude even for copy-editing, it may carry the trace. Keep your drafts and version history; holding evidence beats arguing later.
No comments yet
Leave a comment