August 17, 2026. Since Anthropic confirmed on August 14 that Claude will watermark the text it generates, one search has climbed faster than any other question about it: how to get the watermark off. Google Autocomplete is now suggesting "remove ai watermark from text free", "website to remove ai watermark from text" and "remove ai text watermarks instantly", and a market of one click scrubbers is arriving to meet those searches. We read Anthropic's technical explainer, the peer reviewed robustness research on the underlying method, and the actual text of the law that caused all of this. The honest answer is not the one being sold, and it is more useful than the one being sold. Here is what removes a watermark, what provably does not, and why the removal question is aimed at the wrong target.
The short answer
- You cannot strip it, because there is nothing to strip. Anthropic states that nothing is added to the text and there are no hidden characters.
- You can degrade it by rewriting substantially. Peer reviewed research confirms this and Anthropic says the same thing from the other side. Both mean the same act: replacing the model's word choices with somebody else's.
- Nobody can currently prove a removal worked, because Anthropic has not shipped the detector yet.
- Removing the mark does not remove your legal obligation. The watermark is the vendor's duty. Disclosure is yours, and scrubbing does nothing to it.
- There is a workflow that solves this properly, it is free, and both the law and the vendor point straight at it. It is the last section of this article.
There are no hidden characters to strip
Most of the advice circulating right now is some version of "paste it into a plain text editor" or "run it through a tool that removes the invisible Unicode characters." That advice is confidently, checkably wrong for this system. In its published explainer Anthropic states that nothing is added to the text, that there are no hidden characters, and that watermarking requires no extra tokens.
The mark is not a thing sitting inside the text. It lives in which words were chosen. When the next word is effectively a coin flip between two equally good options, the model normally settles it with an arbitrary random number. Watermarking changes only the source of that randomness, using a key plus the preceding words, so the resulting sequence can later be tested for consistency with the key. The method is a version of SynthID-Text, published by Google DeepMind in a 2024 Nature paper.
So retyping the text, converting it to plain text, stripping zero width characters, changing the encoding or passing it through a notes app removes exactly nothing. The words are the watermark. Any product whose pitch is that it finds and deletes hidden markers is describing a mechanism this system does not use.
What actually degrades a watermark, per the research
This is where honest coverage has to concede something. Watermarks of this family are not indestructible, and there is published work measuring it.
A TrustCom 2025 paper by Han, Li, Ni and Zulkernine, Robustness Assessment and Enhancement of Text Watermarking for Google's SynthID, reports that SynthID-Text is "vulnerable to meaning-preserving attacks, such as paraphrasing, copy-paste modifications, and back-translation, which can significantly degrade watermark detectability." The authors propose a hardened variant precisely because the base method can be worn down.
Now read that alongside the vendor and notice they agree. Anthropic says light editing probably will not remove the mark, and that a complete rewrite in which every word is replaced will, at which point it is arguable whether the text can still be called AI generated. The researchers call it an attack, Anthropic calls it a rewrite, and they are describing the same act.
Which sets the real price. What degrades the mark is substituting the model's word choices at scale. If you pay a paraphraser to turn 1,500 words into different 1,500 words, you have produced text that no human has quality checked, in a voice nobody selected, still making whatever claims the model made, and you have paid for the privilege. It is also heaviest work exactly where it hurts most: Anthropic notes the mark is already sparse in factual passages and in code, because those have few free choices, and dense in open prose. The passages a paraphraser must maul hardest are your brand voice, your positioning and your opening lines.
Nobody can verify a removal today
Here is the question that disqualifies most of this market in one sentence, and it costs nothing to ask.
Anthropic says a watermark detection API is coming soon and that implementation details are still being worked out. No date is published and no public Claude detector exists. So any vendor advertising that its tool is tested, verified or guaranteed to remove the Claude watermark is claiming to have measured its output against an instrument that has not shipped. Ask what they validated against. There is currently no good answer available to them.
The timing runs the wrong way for buyers, too. The mark is being applied now and becomes readable when Anthropic chooses. A scrubber that appears to work today has not been proven, it has merely not been falsified yet, and the falsification arrives later and points backwards at everything you published in the meantime.
Removing the mark does not remove the obligation
This is the part that reframes the entire question, and it is why the removal search is aimed at the wrong target.
The watermark is not your duty. It is the vendor's. Article 50(2) of the EU AI Act puts the marking obligation on providers of systems that generate synthetic content. Anthropic complied. That box is theirs, and it is already ticked.
Your duty is a different one, and it is about disclosure. The text of Article 50(4) reads that deployers of a system generating text "which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated." Nothing in that sentence mentions a watermark. It is a duty to tell people. You could remove every trace of a mark and still be in breach, because the breach is the undisclosed publication, not the mark. Law firm analysis of the deployer obligations that applied from August 2 puts the penalty exposure under the Act at up to EUR 15 million or 3 percent of worldwide annual turnover.
Worth stating plainly: the Act does not create a general offence of removing a watermark. It creates a disclosure duty on you that survives the removal entirely. Spending money to defeat the mark buys you nothing against the obligation that actually applies. This is a summary and not legal advice. The Article 50 text is the authority and a qualified lawyer in your jurisdiction is the person to ask.
The workflow the law and the vendor both point at
Two independent sources, one a regulation and one a model provider with no stake in the regulation's drafting, converge on the same answer. Almost nobody covering this has put them side by side.
Anthropic, on the technology: when Claude only proofreads or lightly edits text a person wrote, nearly all the words are the person's, so there may be too little for the watermark to attach to. The opposite pole is translation, which carries a full mark because every word is chosen by the model.
Article 50(2), on the marking duty: it "shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof."
Article 50(4), on your disclosure duty: it does not apply "where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content."
Read the three together. The behaviour that leaves almost nothing for a watermark to grip is the same behaviour the law carves out twice. A person writes, or a person takes genuine editorial ownership, and the model assists. Do that and there is little to mark, the marking duty is carved out to the extent the system is assistive, and the disclosure duty has a named exemption you can actually rely on.
One condition does real work and should not be skimmed. The Article 50(4) exemption turns on a natural or legal person holding editorial responsibility. That is a named human or a named entity, accountable for what went out. It is a governance step, not a checkbox, and it is the whole reason the exemption exists.
What it means for operators
- Stop shopping for a scrubber. If you are mid conversation with one, ask which detector they validated against. Anthropic has not released one.
- Sort your content by how the model was used, not by who published it. Model as author is marked and carries disclosure exposure. Model as editor on human writing is barely marked and has a carve-out. Machine translation is the maximum mark case and the one to look at first if you run localised pages.
- Name an editor, in writing. The exemption you would actually rely on requires a person or entity holding editorial responsibility. An unnamed "we review everything" does not obviously satisfy that.
- Disclose where the duty applies. It is free, it is the thing being asked of you, and it is considerably cheaper than the alternative.
- Start the provenance log now. Which pages were drafted by a model, which were edited, which were translated. Once the detector ships it will run backwards over everything, and you cannot reconstruct that record after the fact.
The uncomfortable summary is that the removal industry is selling a solution to the vendor's compliance problem, to people who have a different problem. We wrote up the mechanism itself in our breakdown of how the Claude watermark works, and the duties that landed on August 2 in our guide to Article 50. If you publish AI assisted content at volume and want the editorial trail built into the pipeline instead of reconstructed under pressure, that is the kind of thing our AI engineers and our AI automation work is for.
Frequently Asked Questions
Not by stripping anything, because Anthropic states nothing is added to the text and there are no hidden characters. The mark lives in which words the model chose. Substantial rewriting degrades it, which both Anthropic and published robustness research confirm, but that means replacing the model's word choices with someone else's rather than running a tool over the output.
Any tool advertising that it deletes hidden characters or invisible markers is describing a mechanism this system does not use. Tools that paraphrase can degrade detectability, per peer reviewed research, but that is rewriting rather than removal. No vendor can currently demonstrate that its tool defeats the Claude watermark, because Anthropic has not released a public detector to test against.
No. Retyping, converting to plain text, changing the encoding or running a zero width character scrubber removes nothing, because there is nothing added to the text to remove. Anthropic is explicit on this point. The word choices themselves carry the mark.
The EU AI Act does not create a general offence of removing a watermark. It places a marking duty on the provider and a separate disclosure duty on you as the deployer. Removing a mark does not affect that disclosure duty. This is a summary rather than legal advice, and a qualified lawyer in your jurisdiction is the right person to ask.
Yes. Article 50(4) requires deployers publishing AI generated text to inform the public on matters of public interest to disclose that it was artificially generated. The obligation is about telling people, not about the mark, so it survives any removal attempt intact.
Use it as an editor rather than as the author. Anthropic says that when Claude only proofreads or lightly edits human writing there may be too little for the mark to attach to. The same workflow lines up with both Article 50 carve-outs, including the disclosure exemption for content that has had human review with a named person or entity holding editorial responsibility.