Developers bypassed invisible watermarks in text from Claude models introduced because of the EU AI Act
Anthropic introduced invisible watermarks (SynthID technology) into Claude models because of the EU AI Act. Developer Meyer published an open-source tool on GitHub to remove them, which went viral with over 20 000 bookmarks on X and 100+ contributors.
Anthropic announced last week that it is introducing invisible watermarks into outputs from Claude models to meet the requirements of the European AI Act for labeling synthetic content. The technology used is called SynthID; it was developed by Google, which has used it since 2023 to label its own AI-generated content. According to Anthropic, the watermark embeds a pattern in word choices and phrasing that is imperceptible to humans but detectable by machines, and the company says it does not change the meaning, quality or readability of responses.
Shortly afterward, developer Meyer published open-source code on GitHub that removes the watermark from text. The tool was bookmarked over 20 000 times on X, attracted more than 100 contributors, and many other people incorporated it into their own projects. The process works by having the text rewritten by another large language model that does not insert a watermark, substituting synonyms and slightly reorganizing the content. According to Meyer, some people seek to remove the watermark because they disagree with mandatory labeling of AI content, while others do so for the technical challenge; freelance copywriters and social media content creators also contacted him asking for help. Other developers created their own tools: Erik Hughes used Claude to build a tool in 15 minutes that removes invisible and visually similar characters, changes sentence order and replaces words with synonyms, while Leon Chlon from Oxford described a process in which the text is condensed, translated into another dialect (for example, Arabic) and then translated back.
The rules of the EU AI Act, in effect since August this year, require model providers such as Anthropic or OpenAI to label synthetic audio, images, video and text in a machine-detectable way or face a fine of up to 3 percent of annual turnover; the rules must be incorporated into all new models from August and into existing models by December. The rules prohibit providers from directly offering tools to circumvent labeling, but do not explicitly prohibit independent third-party tools. Anthropic says it is working on a watermark detection tool and plans to release it soon, along with an API for text detection; the company itself acknowledged that heavily edited, paraphrased or translated text may not contain the watermark. According to Wayne Pan, co-founder of the startup Haimaker, who incorporated the open-source tool from Meyer into his platform, it is impossible to create a watermark that can withstand everything.
Meyer said he does not consider watermarking a suitable solution because it does not distinguish between light and heavy use of AI—he himself, as a native French speaker, routinely uses Claude and tools such as Grammarly to edit text—and risks false positives. According to Meyer, using a watermark as evidence, even though Anthropic itself acknowledges that it is only a probabilistic estimate, could lead to unjustified rejection of job applicants or unfounded accusations that researchers have used AI. According to the article, 190 organizations, including OpenAI, Microsoft and Meta, signed the European transparency code, but it is uncertain how many of them will actually introduce watermarking. Computer scientist Scott Aaronson said he had previously proposed a similar method for OpenAI, but the company did not deploy it because of concerns that watermarks would deter customers.
Why it matters
Watermarking was intended to give employers, schools and editorial teams a tool to verify whether text was created using AI, but publicly available and rapidly spreading tools for removing it are weakening this protection before Anthropic even releases its own detection tool. For companies seeking to demonstrate compliance with the EU AI Act, this means that relying on watermarking as the sole proof of compliance remains uncertain for now. Individuals whose text is only lightly edited by AI (for example, grammar corrections) risk unfair suspicion that their text was AI-generated, because according to Anthropic, detection provides only a probabilistic estimate, not certainty.
Two audiences, two different impacts
What this means
For individuals
People who use Claude only for light text editing may face unfair suspicion that their text was AI-generated, because according to Anthropic, the watermark provides only a probabilistic estimate and does not distinguish how much AI was used.
For a business
Companies offering models in the EU must label AI-generated content or face a fine of up to 3 percent of annual turnover, but publicly available watermark removal tools show that relying on watermarking as the sole proof of compliance with the EU AI Act is risky until Anthropic releases a working detection tool.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.