A Flood of AI ‘Watermark Removers’ Hits the Web, But Most Can’t Prove They Work
In a bizarre turn of events, a market for tools that claim to remove AI-generated watermarks has emerged in just days, following Anthropic’s decision to embed invisible marks in text produced by its Claude model. The rush to offer “watermark removers” has resulted in a proliferation of online services and GitHub repositories promising to strip the digital signatures from AI-generated content.
The problem is that almost none of these tools can prove their effectiveness. According to Anthropic, it has yet to publish details on how the watermark works or release a detector that would verify whether a cleaned document still carries the mark. This lack of transparency has left experts scratching their heads and raising questions about the legitimacy of these services.
One of the most prominent players in this market is Guillaume Meyer’s “watermarks-remover” tool, which claims to remove watermarks from text generated by Claude, Gemini, SynthID-Text, OpenAI, and other models. The tool’s developer has been unusually candid about its limitations, acknowledging that it currently only removes metadata, not the actual watermark. However, many of the commercial sites offering similar services are less forthcoming with their methods and promises.
The reality is that most of these tools work by removing hidden characters from text or stripping file metadata, neither of which is particularly challenging. But when it comes to removing the actual watermark – a subtle manipulation of word choices made by the AI model – the task becomes much more difficult. Independent testing has already revealed gaps in some of these tools, with at least one popular text cleaner failing to catch a common hidden-payload technique.
So why are these services popping up left and right? The answer lies in Anthropic’s decision to implement Article 50 of the EU AI Act, which requires that models launched on or after August 2 carry an imperceptible watermark. This mark is woven into the wording itself, making it nearly impossible to detect without specialized tools.
The trigger for this development was the enforcement of penalties reaching up to €15 million or 3% of global turnover for non-compliance. While Anthropic acknowledges that a detected mark indicates content was processed by Claude, not necessarily written by it, the commercial sites offering watermark removers seem more interested in cashing in on the trend than providing genuine solutions.
In the end, this situation raises important questions about the transparency and accountability of AI model developers and the tools designed to manipulate their output. As the market for watermark removers continues to grow, consumers should be cautious not to get caught up in the hype. Instead, they should demand clear explanations of how these services work and what guarantees they offer.
For now, it’s essential to remember that rewriting text heavily using a second model is currently the only known way to remove AI watermarks effectively. Until more robust solutions emerge, it’s best to approach these services with a healthy dose of skepticism and consider the risks and consequences of relying on them.
Source: Bleeping Computer — 2026-08-13