Claude’s watermark is not hidden ink.It is which word came next.
Anthropic published the method. Claude models launched on or after 2 August 2026 pick each next word with a secret key and the words so far. The sentence looks ordinary because it is. A key holder can ask whether Claude was likely involved. Nothing is added to the text.
There are two jobs. Do not buy the wrong one. How to remove a Claude watermark
Reviewed by Can Balkaya
Published
or type below, or drop a file
Inspected in your browser. A plan is required to finish.
Choose the surface, then the tool
| Surface | Gifi action | What can be verified |
|---|---|---|
| Ordinary words | Rewrite the prose | The words changed; no private detector certificate |
| C2PA, EXIF, XMP, properties | Strip named metadata | Action list plus an independent reinspection |
| Visible Gemini corner mark | Patch the selected area locally | The visible pixels changed; SynthID may remain |
| Embedded pixel marks, audio, or video | Not supported | No removal claim |
The dice are keyed
Anthropic’s method is in the same statistical family as Google’s SynthID-Text, but it is not Google’s product and does not use Google’s key. When two words would do, Anthropic’s key settles which one. Light edits usually keep the trail. A full rewrite does not. Short text, code and tight facts have fewer forks, so the mark is weaker there.
A hit means Claude was likely involved. It does not mean a person never touched the page. Anthropic has said a detector is coming. Until it ships, nobody outside Anthropic can verify the mark.
Applied at the model, not the product
Anthropic’s write-up puts the mark at model level. There is no request header, plan tier or “off” switch in the published story. Text from the Claude app, Claude Code or the API is the same job if the model is in the marked set.
Older models are still in transition. Do not assume every historical Claude completion carries the new mark.
What a rewrite can say
New wording breaks the original keyed sequence. That is the paid job. We cannot see Anthropic’s key, so we cannot certify their detector. A rewrite also does not prove the text was never AI-assisted.
For a client draft, inspect first, preserve the approved claims and citations, rewrite only when changed wording is actually wanted, then run the ordinary editorial pass. Publishing hygiene is the goal; a detector score is not an acceptance criterion.
The file is only a note
Supported images and documents get a C2PA credential — a signed note in metadata, not a pattern in the words. We can strip the local label. Soft binding can survive.
What this cannot promise
- A rewrite does not prove the text was never AI-assisted.
- No one outside the lab can certify their detector. The key is private.
- Invisible pixel-embedded watermarks, audio and video are out of scope.
Questions this usually raises
- Is Claude’s watermark Google SynthID?
- No. Anthropic describes a related keyed word-choice method, but Google’s SynthID name and production key belong to Google. One lab’s detector cannot stand in for the other’s.
- Will a light edit remove it?
- Usually not. Anthropic said so. Replacing the wording does.
- Can it identify me?
- No. It tests whether Claude was involved, not who asked.
- Can you certify Anthropic’s detector?
- No. The key is private.
Primary sources
Claude
Statistical signal? Rewrite the prose.
A Claude mark, if it is in the words, needs different words. Hidden characters and C2PA need the file cleaner.