Claude's AI Watermarks Bypassed Within Hours of Launch
Developers published open-source tools to remove Anthropic's invisible text markers, raising questions about compliance enforcement under EU law.

Rapid circumvention of new compliance measure
Within four hours of Anthropic confirming that its Claude AI models would embed invisible watermarks in generated text, developer Guillaume Meyer published code to remove them. His GitHub repository has attracted more than 100 contributors and been bookmarked over 20,000 times on X, according to details first reported by WIRED.
The watermarking technology, which Anthropic deployed to comply with the European Union's AI Act, uses Google's SynthID technique. The system leaves imperceptible patterns in word and phrase choices that machines can detect but humans cannot read. The EU regulation, which took effect earlier this month, requires AI providers to label synthetic content or face fines up to 3 percent of annual revenue.
Why it matters
The immediate availability of circumvention tools exposes a fundamental enforcement challenge in AI regulation. While the EU AI Act prohibits providers from marketing watermark-removal technology, independent developers face no legal restrictions. This gap could undermine transparency requirements before detection infrastructure is even fully deployed—Anthropic has yet to release its watermark-detection API.
Multiple removal methods emerge
Meyer's approach uses non-watermarked language models to generate multiple rewrites, swapping synonyms and reorganizing content structure. Software engineer Erik Hughes developed a tool in 15 minutes that removes invisible characters, reorders sentences, and substitutes words. Leon Chlon, a Visiting Fellow at the University of Oxford, demonstrated that translation through semantically distant languages like Arabic can strip watermarks.
Wayne Pan, chief technology officer at AI startup Haimaker, incorporated Meyer's open-source tool into his platform. Pan and Meyer both expressed concern that watermarks fail to distinguish between heavily AI-generated content and text that received only light editing assistance—a particular worry for non-native English speakers using AI tools for grammar correction.
Meyer told WIRED he supports content attribution but considers watermarking "a really bad solution" due to risks of false positives. Anthropic acknowledges its system can only generate probability estimates, not definitive proof of AI generation. The company also confirmed that heavily edited, paraphrased, or translated content might not retain watermarks.
Implementation timeline and uncertainty
Some 190 organizations, including OpenAI, Microsoft, and Meta, have signed the EU's AI transparency code of practice. New models released after August must include watermarks, while existing models require integration by December. However, the effectiveness of removal tools remains unverified until Anthropic releases its detection software.
In a statement, an Anthropic spokesperson said the company is "working out how to implement watermark detection for text" and plans to release a detection API soon. The spokesperson emphasized that watermarks don't change the meaning, quality, or readability of Claude's responses.
Computer scientist Scott Aaronson, who proposed similar watermarking methods while at OpenAI, noted that company never deployed the technology due to concerns about customer reception. Pan suggested Anthropic's implementation demonstrates good-faith compliance efforts but questioned whether any watermark system can withstand all circumvention attempts.
These details were first reported by WIRED.
This is an original analysis by the Omega editorial team. Source reporting: WIRED.
Want systems like this working for your business?
Book a Call