Anthropic’s push to label AI-written text has produced an immediate counter-move. Developers have started building tools to strip those labels off, according to Business Insider. Thibault Spirlet and Agnes Applegate reported that one remover has gone viral on GitHub. Interest in the tools is climbing.

The watermark is the trigger. Anthropic began marking Claude’s output worldwide from 2 August. It embeds a statistical pattern in the model’s word choices. That pattern travels with copied-and-pasted text. The company says the mark is imperceptible to a reader. Some users disagreed enough to act.

The reaction has been loud. US Google Trends interest in “AI watermark remover” rose 60 percent week on week, Business Insider reported. Some Claude subscribers cancelled over the feature. Others went looking for a workaround, and a handful of developers built one.

‘The wrong answer to a real problem’

The most popular tool came fast. Guillaume Meyer, a Paris-based entrepreneur, released an open-source project called Watermarks Remover days after Anthropic’s announcement, Business Insider reported. Meyer founded the e-commerce AI tool Memo. His remover strips hidden characters and metadata, then rewrites the text. That disrupts the word-choice pattern that carries the mark, while keeping the meaning.

The first version took him about five hours to build, Meyer said. It has since drawn more than 14,000 GitHub stars, a rough measure of developer interest. It does not guarantee that a watermark is gone.

Meyer framed his objection carefully. “I am all for content attribution,” he told Business Insider. “I am against the watermarking technique, and that’s a very significant distinction.” His complaint is that the method “treats authorship as a binary thing.” It marks text whether Claude wrote it outright or only helped edit it. “I think it’s the wrong answer to a real problem,” he said.

He is not the only one. Sabrina Ramonov, an AI educator, said on X that she built a free browser-based remover for Claude and ChatGPT marks. “AI watermarks punish normal users, not bad actors,” she wrote. Her tool claims to clean hidden marks from text, PDFs, Word documents, web pages, images and data files, Business Insider reported.

Ansh Aneja, a Tokyo-based developer, said he built a Claude-focused remover on the day of the announcement. He wrote that he made it after reading a post by the investor Paul Graham. Aneja later released a local open-source version called MarkScrub. He said an earlier version went from zero to 8,500 users in a day, a figure Business Insider could not verify.

Anthropic’s answer

Anthropic has pushed back on the premise. In a blog post titled How Claude’s text watermark works, the company said the mark “doesn’t say anything about ownership or authorship, and doesn’t change a user’s rights under our terms.” It also said the watermark carries no identifying information, and cannot be traced to a specific person, organisation or chat.

The company frames the feature as compliance, not surveillance. Anthropic says it added the watermark to meet its commitments under the European Union’s AI Act. The law requires providers to mark AI-generated text in a machine-readable form. It signed the bloc’s transparency code in July alongside roughly 190 other signatories, Mashable reported.

It cannot yet limit the mark to the EU. So it is rolling the feature out globally, and extending it to older models.

On the mechanics, Anthropic says the mark rides on low-stakes word choices. When several words would work equally well, the model leans toward one of them. That leaves a detectable statistical trace, Mashable reported. The company says this adds no cost, no extra tokens and no measurable hit to quality, and it did not respond to Business Insider’s questions about the removal tools.

The desk has covered the tension the removers are seizing on. Anthropic’s own design means a lightly proofread email can carry a mark, while a heavily rewritten AI draft may carry none.

Why it is hard to stop

Researchers say the removers point to a basic limit. “There will always be ways to remove the watermark,” Thibaud Gloaguen, a researcher at ETH Zurich’s Secure, Reliable and Intelligent Systems lab, told Business Insider. He gave the example of simply rewording an entire passage.

Anthropic concedes the same point in effect. A heavy rewrite can strip the mark entirely, the company has said, at which point it becomes debatable whether the text is still meaningfully AI-generated. The watermark is also weak or absent on short passages, hard facts, precise code and maths, where there is little room for variation.

Konrad Kollnig, an assistant professor at Maastricht University’s Law and Tech Lab, put the problem in blunt terms. “Whenever the watermarking detection tool is made public, anyone can check AI-generated contents… and can build tools to remove watermarks,” he told Business Insider. That matters because Anthropic plans to release a public detection API alongside its next model, with no date set yet.

A legal grey area

The removers sit in an unsettled legal space. The EU tells AI companies to add durable labels, but does not clearly set rules for third parties who try to strip them, Business Insider reported.

A European Commission spokesperson said the bloc’s guidance requires providers’ marking systems to withstand common alterations and deliberate attacks. The transparency code names removal, regeneration, copying and modification as threats providers must assess, the spokesperson added.

Those, though, are duties on the providers, not the public. The AI Act does not expressly ban third parties from trying to remove a watermark, said Dmitri Roussinov, a senior lecturer at the University of Strathclyde. He added a catch: if a removal tool uses AI to regenerate the text, its own provider may be obliged to mark that new output.

Neither the AI Act nor Anthropic’s terms appear to bar people from making or sharing removal tools, Kollnig said. The risk lands elsewhere. Anthropic’s usage policy prohibits passing off model output as human-made, so a user who strips a mark to misrepresent AI work as their own could still run into trouble.

Other companies, including Google and OpenAI, watermark images too, and tools to remove those already exist. Even AI music has been watermarked in the same push for provenance. The fight Anthropic has started, in other words, is one the wider industry already knows well, and one that EU labelling rules have only sharpened.

Get the TNW newsletter

Get the most important tech news in your inbox each week.