Developers bypass Claude's invisible AI watermarks within hours of launch
Open-source tools have emerged to strip SynthID-based markers from Anthropic’s Claude models, raising questions about the efficacy of EU AI Act compliance measures.

Within four hours of Anthropic confirming that its Claude models would globally embed invisible, machine-readable watermarks, developer Guillaume Meyer published code to remove them. The open-source tool has since gained significant traction, going viral on GitHub and accumulating more than 20,000 bookmarks on X, while attracting over 100 contributors. Many developers are now incorporating the technology into their own projects, effectively neutralising the watermarking feature almost immediately after its announcement.
The watermarking system was implemented to comply with the European Union’s AI Act, which came into effect earlier this month. The regulation requires model providers to label synthetic audio, image, video, or text so it can be detected as AI-generated, with fines of up to 3 percent of annual turnover for non-compliance. While the rules prohibit providers from marketing circumvention tools, there is no legal restriction on independent developers creating such tools. Meyer stated that he is not against transparency or content attribution but believes watermarking is a flawed solution with major drawbacks.
Meyer’s tool operates by using non-watermarking large language models to generate multiple rewrites, swapping synonyms and slightly reorganising content. This approach relies on other models that do not insert watermarks, a strategy that may become less viable as 190 organisations, including OpenAI, Microsoft, and Meta, have signed the EU’s transparency code of practice. The new rules stipulate that watermarks must be included in all new models released from August and integrated into existing models by December.
Other developers have devised alternative methods to strip or evade the markers. Software engineer Erik Hughes created a tool that removes invisible characters, reorders sentences, and swaps words for synonyms. Leon Chlon, a Visiting Fellow at the University of Oxford, noted that watermarks can be removed by condensing Claude’s response, translating it into a dialect with different semantics, such as Arabic, and then translating it back. Wayne Pan, chief technology officer at Haimaker, integrated Meyer’s tool into his platform, citing concerns that the watermarking system might lead to false positives or unfairly flag lightly edited content.
Anthropic maintains that the watermarks do not affect the meaning, quality, or readability of Claude’s responses. The company uses SynthID, a technique developed by Google, which has been used to watermark AI-generated content since 2023. Anthropic acknowledged that heavily edited, paraphrased, or translated content might not carry a watermark. The company stated it plans to release a text-detection API soon, allowing users to verify the presence of watermarks, though developers remain uncertain about the tool's effectiveness until this software is available.
Critics argue that the system risks degrading the user experience and could lead to overblown accusations against researchers or job candidates if detectors flag their work. Meyer, a native French speaker who often uses AI tools for editing, expressed concern that the watermarking might not distinguish between light and heavy AI use. Despite these concerns, Anthropic continues to work on improving the watermarking system, asserting that the move is necessary to provide better tools for identifying AI-generated text.

