MEMO · WATERMARK · AUGUST 2026

The Claude watermark remover, and what it actually strips

8 min read · every claim sourced below

The short version: Claude now watermarks the text it writes, and a wave of free “watermark removers” appeared within days. They delete invisible Unicode characters. Anthropic’s own announcement says the watermark adds nothing to the text and contains no hidden characters, so those tools cannot reach it. The mark lives in which words were chosen. The only thing that removes it is rewriting the text substantially, which costs you your own voice. What the best tool genuinely does remove is the signed label inside image and PDF files, and that part works properly.

On 14 August 2026 Anthropic published how Claude’s text watermarking works. Within days the search results filled up with free removers, and every one we opened was doing the same thing: scrubbing invisible characters out of your paragraph.

That is a real operation on a real problem. It is just not this problem. Below is where the mark actually is, what the tools really delete, the one tool worth installing and how to run it, and the honest list of what it can and cannot take off.

The mark is real. It is just not a character anybody can delete.

What actually changed

Anthropic signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026, and from 2 August 2026 the EU requires providers serving its market to mark AI-generated content. Claude models launched on or after that date support machine-readable marking at launch, and Anthropic says it is working to add it to earlier models during the transition period.

Two details matter more than the date. It applies worldwide, not only in the EU. And it applies across the API, Claude, Claude Code, Cowork and Tag, as well as the AWS, Google Cloud and Microsoft Foundry deployments. There is no region to move to and no surface that quietly opts out.

Where the mark actually lives

When a model writes, it repeatedly chooses the next word. Several candidates usually mean roughly the same thing, and normally a random number generator settles which one it takes. Watermarking replaces that randomness: a secret key, plus the handful of words just before, decides the pick instead.

Do that a few hundred times and the choices carry a faint pattern. You cannot see it, because every individual choice was a legitimate word. Somebody holding the key can run a statistical test across enough text and see it clearly.

The sentence that settles the whole argument

Anthropic, describing the mechanism: “Nothing is added to the text and there are no hidden characters.”

If nothing was added, nothing can be removed. Every tool that works by finding and deleting characters is, by the vendor’s own description, looking for something that was never put there.

So what are the removers deleting?

Something genuine, and worth cleaning for entirely different reasons. We read the source of the most popular tool rather than its marketing. Its Unicode pass strips around sixty codepoints and normalises sixteen more, including the zero-width space (U+200B), the zero-width non-joiner and joiner (U+200C, U+200D), the soft hyphen (U+00AD), the word joiner (U+2060), the byte-order mark (U+FEFF), the bidirectional controls, variation selectors, and lookalike spaces such as the narrow no-break space (U+202F).

Those really do end up in pasted text. They break URL slugs, split search matches, corrupt spreadsheet cells, and make two identical-looking strings compare as different. Removing them is sensible hygiene.

None of them is Claude’s watermark. Two different jobs got the same name, and the second one sells better.

The honest list: what comes off, and what does not

Genuinely removable, losslessly. Signed C2PA provenance metadata on files, which is what Anthropic attaches to supported image types (.png, .jpg, .svg). EXIF and XMP metadata. The generator tags embedded by editing software. Stray invisible Unicode in text. All of this is real data sitting in a real place, and stripping it changes nothing about how the file looks or the text reads.

Not removable, by anything. The text watermark itself. It is spread across the word choices of nearly every sentence, so there is no field to clear and no character to delete. The only operation that touches it is rewriting the words, and that is a different thing from removing a mark.

Partly, at a cost. Anthropic says light editing probably will not remove the watermark completely, and that a complete rewrite will, while noting it is then arguable whether the result is the same AI-generated text at all. The tool’s README agrees and adds the bill: rewording replaces your word choices with the rewriting model’s, which flattens tone, voice and precision. It also warns not to rewrite Claude text with Claude, because you just re-stamp it.

What nobody selling a remover tells you

“Until vendors ship public detectors and keys, no tool can honestly certify ‘this fails the official check’.”

That is not our line. It is in the README of the most-starred watermark remover on GitHub, written by the person who built it.

The tool worth installing

watermarks-remover by Guillaume Meyer is a public GitHub repository under the MIT licence, around 9,500 stars at the time of writing. It is not ours, we had no hand in it, and we are recommending it because we read its source and because it is honest about its own limits in a category where almost nothing is.

It does three separate things, and it is worth knowing which one you are asking for: a lossless Unicode scrub of text, a metadata and C2PA scrub of files, and an optional rewrite pass that is explicitly described as best-effort. The first two are the reason to install it.

1

Check you have Python 3.10 or newer

The quick path has no other dependencies at all: no virtual environment, no package install, no Docker. If this prints 3.10 or higher you are ready.

Terminal
python3 --version
2

Get the repository

Clone it anywhere you like. Nothing is installed system-wide and nothing runs in the background.

Terminal
git clone https://github.com/guillaumemeyer/watermarks-remover.git
Then
cd watermarks-remover
3

Clean a document

This is the lossless pass. It strips the invisible characters and normalises the lookalike spaces, and leaves every visible word exactly as you wrote it. Add --stats to see a count of what it found, which is the interesting part the first time.

Text or Markdown
python3 service/scripts/clean_text.py draft.md -o draft.cleaned.md --stats

For anything binary, such as a .docx or a .pdf, use the file version instead. The text scripts deliberately refuse binary input rather than quietly mangling it.

Documents
python3 service/scripts/clean_file.py report.docx -o report.cleaned.docx
4

Strip the label out of an image or PDF

This is the pass that genuinely removes provenance. It takes the signed C2PA credentials, the EXIF block and the XMP packet off the file. Supported types run from PNG, JPEG, WebP and SVG through PDF, DOCX, ODT, HTML and Markdown.

Images
python3 service/scripts/clean_image.py photo.png -o photo.cleaned.png

One caveat worth knowing before you trust a PDF: the metadata writer works incrementally, so a structural removal needs qpdf as well. The repository documents this rather than hiding it.

PDFs, after cleaning
qpdf --linearize report.cleaned.pdf report.final.pdf
5

Optional: wire it into your AI agent as a skill

The repository ships an agent skill called remove-ai-marks, so you can ask your coding agent to clean a file instead of remembering the commands. The skill is a thin client and calls a local service, so start that first. It runs on 127.0.0.1 and talks to nothing outside your machine.

Start the local service
make serve

Then link the skill into your agent’s skills folder. The README documents the Grok Build paths shown below; for Claude Code the equivalent directory is .claude/skills in your project.

Link the skill
mkdir -p .grok/skills && ln -sfn "$(pwd)/skills/remove-ai-marks" .grok/skills/remove-ai-marks

After that, /remove-ai-marks works inside the agent, or you can simply ask it to strip the marks from a file by name.

You can be marked on writing that is yours

Anthropic’s help page is explicit that a detected mark shows content was processed by Claude, and is not conclusive proof Claude wrote it, because people use it to proofread, translate, summarise and convert files.

So the awkward case is not the person who generated an essay. It is the person who wrote every word themselves, asked Claude to fix the commas, and now has a marked document. That is worth knowing before you hand anything in.

Can anyone actually check you right now?

No. Anthropic says it is working to enable users and third parties to detect the watermarks and provenance metadata, and that it will share details in forthcoming technical documentation. Until that lands there is no public detector, so any site offering to test your text for Claude’s watermark today is doing something else.

When it does arrive, the result will be a signal rather than a verdict. Anthropic notes that a mark is not fully conclusive, that content may have changed after Claude processed it, and that the absence of a mark does not mean no AI was involved, since heavy editing, paraphrasing or format conversion can remove one. The watermark is also sparser in factual passages, simply because there are fewer ways to say a fact without changing it.

If you have been told there are hidden tricks for beating AI detection, the memo on why the viral ChatGPT codes are folklore is the same shape of story with the same ending.

What we would actually do

Run the lossless Unicode pass on anything you paste out of a chat window, because stray invisible characters cause real problems that have nothing to do with watermarks. Strip metadata from images and PDFs when you have a reason to, and know that this one genuinely works. Skip the rewrite pass unless you have thought hard about it, because it trades your writing for a weaker model’s.

And treat any product promising to remove Claude’s text watermark as making a claim its own upstream author refuses to make.

Questions people actually ask

Do Claude watermark removers actually work?

Not on the watermark. The free tools going around delete invisible Unicode characters such as zero-width spaces. Anthropic's own announcement says the watermark adds nothing to the text and that there are no hidden characters in it, so there is no character for those tools to find. They do delete real stray characters that ride along when you copy out of a chat window, which is worth doing for other reasons. It is simply not the same job.

What is Claude's watermark, exactly?

It is a pattern in which words were chosen. When the model picks the next word it normally uses a random number generator; with watermarking it uses a secret key plus the words just before to settle that choice instead. The result reads identically to you, but somebody holding the key can run a statistical test over enough text and see the pattern. Nothing is inserted, so nothing can be deleted.

Can anyone detect it right now?

Not publicly. Anthropic says it is working to let users and third parties detect the marks and that details will come in forthcoming technical documentation. Until that ships, no website can check your text for Claude's watermark, and any site claiming to detect it today is guessing.

So does deleting invisible characters do anything at all?

Yes, just not what the videos claim. Stray zero-width spaces, soft hyphens, byte-order marks and odd space characters genuinely do end up in pasted text, and they can break search, corrupt slugs, confuse spreadsheets and make two identical-looking strings compare as different. Cleaning them is good hygiene. It has no effect on whether a watermark detector would flag the passage.

Will rewriting it with a different AI remove the watermark?

Partly, and it costs you something. Anthropic says light editing probably will not remove the mark, and that a complete rewrite will, though at that point it is arguable whether the text is the same AI-generated text at all. The tool's own README is blunter: removal means rewording rather than restructuring, and any rewrite swaps your word choices for the rewriting model's, which flattens tone, voice and precision. You also cannot rewrite with Claude, or you simply re-stamp it.

Can I get marked on text I wrote myself?

Yes, and this is the part almost nobody mentions. Anthropic's help page notes that people use Claude to proofread, translate, summarise and convert files, so a detected mark shows content was processed by Claude and is not proof Claude wrote it. If you write a paragraph yourself and ask Claude to tidy it, the tidied version can carry the mark.

Is the tool free?

Yes. watermarks-remover is a public GitHub repository under the MIT licence, written by Guillaume Meyer. The quick command-line path needs Python 3.10 or newer and no other dependencies. It is not ours and we had no hand in it; we read the source before recommending it.

Want this built for you?

We write these memos because we build this stuff every day. If you want it working in your business instead of sitting on your reading list, that is literally our job.