Meyer’s approach sends Claude output through another large language model, which rewrites portions of the text while preserving its broader meaning. His code has been bookmarked more than 20,000 times on X, while other developers have produced variations of the technique.
Software engineer Erik Hughes built another removal tool in about 15 minutes using Claude itself. His approach removes invisible or visually similar characters and modifies the text through changes including synonym replacement and sentence reordering.
Leon Chlon, a Visiting Fellow at the University of Oxford, described another method involving translation. Claude-generated material can be shortened, translated into a linguistically different language such as Arabic and then translated back, altering the patterns the watermark detector is designed to identify.
The demonstrations do not establish that every watermark can reliably be removed. Anthropic plans to release a text-detection API, and until that verification tool is available, the effectiveness of the various removal methods cannot be conclusively measured.
Anthropic has also acknowledged that its watermark has limits. The company said extensive editing, paraphrasing or translation can cause the marking to disappear, while maintaining that the watermark itself does not alter the meaning, quality or readability of Claude’s responses.
The rollout is tied to the EU’s rules for identifying AI-generated material. The requirements cover synthetic text as well as audio, images and video, with providers expected to implement technical methods that allow AI-generated content to be identified by machines.
Anthropic is among 190 organizations that have signed the EU transparency code of practice. Other signatories include OpenAI, Microsoft and Meta.
The rapid emergence of circumvention tools illustrates a practical difficulty with text watermarking. Unlike a fixed image or video file, AI-generated writing can be repeatedly transformed while retaining essentially the same information. Passing text through another model, translating it or substantially editing it can change the statistical characteristics used to establish its origin.
Some developers are also questioning whether probabilistic detection should be used to make consequential judgments about authorship. Meyer has argued that false positives could create problems in settings such as employment or academia, where a detection result might be interpreted as evidence of undisclosed AI use.
The EU framework also creates a distinction between obligations placed on AI providers and the behavior of outside developers. Providers are restricted from promoting tools designed to defeat the requirements, while independent developers can still create their own circumvention software.
For Anthropic, the immediate issue is therefore not whether Claude output can be marked, but how well that marking survives after the output leaves the model. The company says it is continuing to improve the technology while preparing its detection API.
The first wave of developer experiments shows how difficult that durability may be to achieve. A watermark can remain hidden and detectable in untouched Claude output, yet the text itself can be rewritten without necessarily preserving the statistical signature that identifies where it came from.
This analysis is based on reporting from the tech buzz.
Image courtesy of the-decoder.
This article was generated with AI assistance and reviewed for accuracy and quality.