Anthropic's invisible watermarking system for Claude lasted about four hours in the wild before developer Guillaume Meyer published a working override on GitHub. His removal code has since been bookmarked more than 20,000 times on X and drawn more than 100 contributors, with additional projects folding the technique into their own tooling. Anthropic announced the watermarking last week to comply with the European Union's AI Act, which threatens fines of up to 3% of annual turnover for providers that fail to label AI-generated content.
The rules, which took effect earlier this month, require providers to mark synthetic audio, image, video, and text so machines can identify it as AI-generated. New models must ship with watermarking from August; existing models have until December to integrate it. Anthropic is one of 190 organizations, including OpenAI, Microsoft, and Meta, that have signed the EU's transparency code of practice.
Anthropic's implementation is based on SynthID, a technique Google developed and has used on its own AI output since 2023. The system biases Claude's word and phrase choices in patterns invisible to a human reader but detectable by software that knows the key. Computer scientist Scott Aaronson proposed a similar approach while at OpenAI, but the company never shipped it, reportedly worried customers would defect to unmarked competitors.
Key facts
- 01Developer Guillaume Meyer published a working watermark override within 4 hours of Anthropic's announcement.
- 02The removal code has been bookmarked more than 20,000 times on X and drawn 100+ GitHub contributors.
- 03EU AI Act mandates watermarking for new models by August and existing models by December, with fines up to 3% of annual turnover.
- 04190 organizations, including OpenAI, Microsoft, and Meta, have signed the EU transparency code of practice.
- 05Engineer Erik Hughes built a competing removal tool in 15 minutes using Claude itself.
Meyer, a native French speaker who edits his own writing with Claude and Grammarly, said his objection is not to transparency but to watermarking as a mechanism. He argues detection produces only a probability score, not proof, and that employers or academic reviewers could use false positives to reject candidates or accuse researchers of undisclosed AI use.
His removal method routes Claude's output through a non-watermarking large language model that generates rewrites, swaps synonyms, and lightly reorganizes content. The approach depends on the existence of models that do not watermark, a shrinking pool given the EU code's reach, though it remains unclear how uniformly the 190 signatories will implement the requirement.
Other developers have shipped their own tools. Software engineer Erik Hughes built a remover in 15 minutes using Claude itself; the tool strips invisible and look-alike characters, reorders sentences within paragraphs, and swaps synonyms. Leon Chlon, a Visiting Fellow at the University of Oxford, said watermarks can be stripped by condensing Claude's output, translating it into a semantically distant language such as Arabic, and translating back.
Anthropic has acknowledged the limits. In a statement, the company said heavily edited, paraphrased, or translated content may not carry a watermark, and that the marking does not change the meaning, quality, or readability of responses. The company said it plans to ship a text-detection API so users can verify content themselves and is continuing to refine the system.
Until that detection tool ships, none of the removal methods can be verified as fully effective. But Wayne Pan, CTO and cofounder of Silicon Valley sovereign AI startup Haimaker, said the underlying SynthID-text approach is well enough understood that the removal techniques are likely sound. Pan integrated Meyer's tool into his platform, citing objections to watermarking lightly edited content and to the invisibility of the mark itself.
The speed of the workaround exposes a structural problem for the EU's approach: the rules bar providers from marketing circumvention tools but place no restriction on independent developers building them. Meyer said freelance writers and social media creators have contacted him asking for help using the code.
The watermarking rollout is the first real test of the EU AI Act's technical enforcement provisions, and the early scoreboard reads badly for regulators. Anthropic gets to say it complied. Developers get a one-line workaround. The EU gets a rule that works against the honest use case, essays edited with Claude that get flagged, and fails against the adversarial one. Expect the next round of enforcement to focus less on watermarks in the model output and more on provenance signatures at the API layer, where users cannot as easily strip them out.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




