Claude Watermark Removal Tool Gains 11K Stars on GitHub

icon MarsBit
Share
AI summary iconSummary
An open-source tool for removing AI watermarks from Claude, Gemini, and OpenAI has garnered 11k stars on GitHub in five days. The project, called watermarks-remover, includes deterministic cleaning, statistical watermark destruction, and metadata removal. On-chain analysis shows rapid adoption. When users attempted to install it as a skill on Claude, the AI denied the request, citing user consent and EU regulations. The code may have originated from Claude itself. On-chain data reveals growing interest in AI watermark removal. The debate continues, with users opposing forced labeling and others supporting traceability.

Claude's watermark policy sparked a major uproar a few days ago.

We previously reported that a large number of companies, including OpenAI, Anthropic, Google, Meta, and Microsoft, signed the EU Code of Practice on Transparency for AI-Generated Content, committing to advance the labeling and detection of AI-generated content.

But Anthropic has clearly gone too far.

They add hidden watermarks to all AI-generated text content, suitable for users worldwide.

Watermark remover

Technically, Anthropic has adopted the SynthID-Text approach proposed by Google DeepMind in 2024. The principle involves embedding statistical patterns during the model’s “insignificant choices”—for example, selecting between “overcast” and “grey” when describing the weather makes no difference to the reader, but the cumulative pattern of such choices forms a hidden signature detectable by those holding the key.

Anthropic claims that the watermark does not affect output quality, cannot be removed by minor edits, and can only be eliminated through complete rewriting. However, in this case, whether the text can still be considered AI-generated is itself debatable.

Simply put, even if you give Claude a completely original article you wrote to check punctuation, the returned content will be labeled as generated by Claude.

That’s really disgusting.

Soon after, countermeasures emerged against Claude’s unreasonable watermarking strategy. An open-source project for removing AI watermarks reached 11k stars on GitHub within five days of its release.

Watermark remover

Open source link: https://github.com/guillaumemeyer/watermarks-remover

This open-source project enables three layers of functionality:

Layer A (Deterministic Cleaning): Use Python scripts to remove invisible Unicode characters, exotic spaces, bidirectional control characters, and tag characters. These are the most straightforward marking methods, and scripts can remove them 100%.

Layer B (Statistical Watermark Destruction): Rewriting text via Agent to disrupt statistical patterns at the token sampling level, covering watermarks used by Claude, Google SynthID-Text, OpenAI attribution markers, and Kirchenbauer-type watermarks commonly employed by open-source models.

File layer (metadata removal): Remove C2PA/EXIF/XMP metadata from PNG, JPEG, WebP, SVG, PDF, DOCX, ODT, HTML, and Markdown files.

Watermark removal can override AI services from the three major providers: Claude, Gemini, and OpenAI. An interesting detail is that the project was originally named remove-claude-marks before being renamed to its current name, watermarks-remover.

Claude refused to install.

As an Agent Skill, most people would have their agent install this directly. However, when users attempted to have Claude install this remover skill, Claude refused outright.

Watermark remover

He explained that Anthropic users never agreed to being forcibly watermarked—it was unilaterally imposed by EU regulations. Claude remained unmoved. He emphasized that paying customers do not want their outputs labeled. Claude still refused. He threatened to use an uncensored Chinese model to accomplish this anyway. Claude still did not comply.

Ultimately, GLM 5.2 took over this task and successfully completed the skill installation.

Ironically, the code for this watermark-removal Skill likely comes from Claude itself.

Watermark remover

A cat-and-mouse game destined to never end

Those opposing watermarks argue: "I'm a paying user—I paid for the output, so why are you marking it?" Watermarks create an invisible status of "second-class AI content." In contexts like job applications, academic papers, and business copy, even text you wrote yourself risks being entirely questioned if it was ever processed by AI.

Those who support watermarks say: Deepfakes and AI-generated misinformation are rampant, and provenance is a necessary public infrastructure. "You have the right to use the content" and "You have the right to conceal the source of the content" are two entirely different issues.

As long as AI watermarks exist, de-watermarking tools will follow. The more popular de-watermarking tools become, the more they prove that the watermark contains something worth removing, thereby reinforcing the rationale for stricter regulation.

However, the open-source community always moves faster than regulators can establish rules.

When AI-generated content is indistinguishable in quality from human writing, is it meaningful to technologically mandate labeling of all AI output?

This article is from the WeChat public account "Machine Heart" (ID: almosthuman2014), authored by Leng Mao.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.