AI Text Forensics
Hidden Unicode AI Watermark: Proves Almost Nothing
Invisible characters turn up in AI chat output constantly, and almost every one of them is a formatting artifact that predates chatbots by years or decades. No major provider has documented a watermark built on zero-width spaces, joiners, byte-order marks, or non-breaking spaces, and Anthropic has now ruled the idea out for Claude in writing: "Nothing is added to the text and there are no hidden characters." Homoglyphs are the one category that deserves a second look, and even there the only concrete claim is a single unverified report about a discontinued Claude Code behavior.
Key takeaways
- Four characters explain nearly every find: zero-width space (U+200B), zero-width joiner and non-joiner (U+200D and U+200C), byte-order mark (U+FEFF), and non-breaking space (U+00A0). Each has a mundane, documented purpose unrelated to AI.
- Zero-width joiners and non-joiners are load-bearing for Arabic and other complex scripts, and the joiner is what builds compound emoji. Byte-order marks are usually left behind by whatever software last saved or exported the text.
- Homoglyphs are the genuine exception. A Cyrillic character standing in for a Latin lookalike has no everyday formatting purpose, and security researchers already treat character swapping as a real obfuscation technique.
- The one concrete homoglyph claim: in a post dated July 2, 2026, developer Sean Goedecke argued text watermarks are "trivially removable" and wrote that Claude Code had once used Unicode homoglyphs in date strings as a since-discontinued steganographic flag. He said himself he wasn't certain how Anthropic's current system works, and the article he cited for corroboration is no longer reachable.
- Community threads reacting to Claude's 2026 watermark confirmation listed hidden Unicode as one guess among seven. Anthropic settled it on August 14, 2026: the mechanism is keyed word selection, a SynthID-Text variant, and "Nothing is added to the text and there are no hidden characters." Separate marketing claims about hidden Unicode in Grok's text still have zero corroboration from xAI.
- Finding one of these characters doesn't identify which model wrote the text, or that a model wrote it at all, unless a provider has published documentation of a scheme built on that exact character. None has.
- We measured it rather than assuming it: across 96 outputs and 19,364 words from three Claude model tiers, zero zero-width or bidirectional-format characters appeared, verified against a positive control proving the capture path preserves them. The only invisible characters found were 30 ideographic spaces inside Japanese-language output, which is ordinary Japanese typography.
Figure 1
Invisible character diagnosis: where each one actually comes from
Every character on this list predates chatbots by decades. Finding one tells you something about how the text was copied, not about which model produced it.
| Character | Common source | Visible effect | Safe to remove? | Evidence of a watermark? |
|---|---|---|---|---|
| Zero-width spaceU+200B | Copy-paste from web pages, CMS line-break hints | None | Yes | No |
| Zero-width joinerU+200D | Emoji sequences, Indic and Arabic scripts | None, but load-bearing in some scripts | Careful | No |
| Byte-order markU+FEFF | File encoding headers, exports from Excel | None | Yes | No |
| Non-breaking spaceU+00A0 | Word processors, HTML entities | Looks like a space | Usually | No |
| Narrow non-breaking spaceU+202F | French typography, unit spacing | Thin space | Usually | No |
| Soft hyphenU+00AD | Justified text, PDF extraction | None until line-wrapped | Yes | No |
| Word joinerU+2060 | Typesetting, deliberate no-break points | None | Yes | No |
| HomoglyphsCyrillic а, Greek ο | Mixed-script paste, phishing, deliberate obfuscation | Identical to Latin letters | Careful | No |
The column that matters is the last one. Removing these characters cleans up text that will be diffed, searched, or parsed. It does not touch a statistical watermark, because a statistical watermark is not made of characters. It lives in which words the model chose.
Method Sources are the ordinary provenance for each character in normal document handling. The watermark column reports whether any provider has documented that character as part of a marking scheme. None has.
Checked 2026-08-13
The 96-output scanWhich invisible characters turn up most often in AI text?
ConfirmedHere's what is actually sitting in your clipboard, and why each character was there long before any chatbot existed.
Four characters account for the overwhelming majority of invisible-character finds in AI output.
- Zero-width space (U+200B): no glyph, no width, used to create line-break opportunities inside long unbroken strings like URLs and hashtags.
- Zero-width non-joiner (U+200C) and zero-width joiner (U+200D): control whether adjacent letterforms connect in Arabic and other complex scripts.
- Byte-order mark (U+FEFF): written at the start of a file to signal byte order or confirm UTF-8 encoding.
- Non-breaking space (U+00A0): keeps two words on the same line, like a name and a title.
Every one of those predates the modern chatbot, in some cases by decades. And each has an ordinary explanation for how it ended up in your text.
The zero-width space does have a less charitable use. Some content generators and spammers sprinkle it to pad word counts or slip past duplicate-content filters, which is a spam signal, not a provider signature.
The joiner is the one people underestimate. It's what glues emoji sequences together, so the family emoji and most skin-tone and profession combinations are literally built out of U+200D.
A byte-order mark is an encoding artifact left by whatever editor, export tool, or paste pipeline last handled the text. It tells you something about the software that saved the file and nothing about who wrote the words inside it.
The non-breaking space is the most common false alarm of the lot. Enormous numbers of web pages use it in their markup in place of a plain space, so any text copied from a browser is likely to carry a few.
Do Unicode homoglyphs prove that AI wrote the text?
Community discussionA Cyrillic letter posing as a Latin one has no innocent formatting excuse. The one concrete claim about it names a tool, a date, and then stops.
No, though homoglyphs are the one category worth a second look. A homoglyph swaps a letter for a visually identical character from another script, like a Cyrillic character standing in for a Latin a. Your eye can't catch it. A Unicode-aware tool can.
Unlike a byte-order mark or a non-breaking space, there's no everyday formatting reason to do this. Security researchers already treat homoglyph substitution as a real technique, used in phishing domains and text obfuscation.
That's why one specific claim deserves naming. In a post dated July 2, 2026, developer Sean Goedecke argued that text watermarks are "trivially removable" and separately wrote that Claude Code had at some earlier point used Unicode homoglyphs inside date strings as a steganographic flag, since discontinued.
That's far more concrete than the usual folklore. It names a tool, a character class, and a use that has ended.
It's also unconfirmed. Goedecke said himself he wasn't certain how Anthropic's current implementation works, and the article he pointed to for corroboration is no longer reachable.
What should you do with an invisible character you found?
ConfirmedStrip them, for the ordinary reasons: broken search, corrupted pastes. Just don't mistake that cleanup for defeating a watermark with no character to delete.
Stripping invisible characters is worth doing on its own merits. They break search-in-page, corrupt pastes into code and spreadsheets, and occasionally trip duplicate-content checks.
This site's cleaner runs entirely in your browser and reports per-character counts across eight of them: U+200B, U+200C, U+200D, U+2060, U+FEFF, U+00AD, U+00A0, and U+202F. Nothing is uploaded anywhere.
What it won't do is touch a statistical watermark, because there's no character to delete. Cleaning invisible Unicode and defeating a watermark are separate jobs, and only one of them is available to you in a text box.
FAQ
If I find a zero-width character in text I copied from an AI chatbot, does that prove which model wrote it?
No. Zero-width spaces, joiners, byte-order marks, and non-breaking spaces all have ordinary technical explanations with no connection to any specific AI provider. Unless that provider has published documentation of a watermark built on that exact character, its presence identifies nothing, and doesn't even confirm the text is AI-generated.
Are lookalike Unicode characters as harmless as zero-width spaces?
No, and it's worth separating the two clearly. Homoglyphs have no everyday formatting purpose, which is why security researchers treat character swapping as a real obfuscation technique. One unconfirmed report claims Claude Code briefly used homoglyphs this way in date strings, but that's a single blogger's account of a feature that no longer exists, not documentation of any watermark running today.
Does finding a hidden character at least confirm the text passed through some AI tool?
Not reliably. Word processors, CMS pipelines, and ordinary web copy-paste all insert these characters with no AI involved. A stray zero-width space or byte-order mark is a weak signal of almost nothing, let alone proof of which system produced the text.
Has any provider ever documented a Unicode-based watermark?
Not one, and Anthropic has now documented the opposite: its explainer of August 14, 2026 says "Nothing is added to the text and there are no hidden characters." Google documents SynthID Text as a change to token sampling during generation, and Anthropic describes its watermark as a version of the same approach. Neither inserts a character you could find and delete.
Next steps
- See the measurement behind this: 96 Claude outputs across three model tiers, scanned character by character, with the data and the script published. The invisible-character census
- Run a suspicious passage through the free in-browser cleaner and see exactly which characters are in it, with counts per character. Scan your text
- Read how zero-width steganography actually encodes a hidden message, and why deleting the characters destroys it completely. Zero-width space watermarks
- Check what Anthropic has and hasn't said about Claude's real, confirmed text watermark. The Anthropic watermark, sourced
- If it was punctuation rather than an invisible character that made you suspicious, start with the em dash myth. Do em dashes mean AI?
Sources and citation status
- CommunityHacker News: "Text AI watermarks will always be trivial to remove"
- CommunityHacker News: "Remove-AI-Watermarks" CLI tool discussion
- Communitygetgpt.app: invisible Unicode character scanner
- Communityclaudewatermark.com: "Claude Watermark Remover and Checker"
- OfficialAnthropic: How Claude's text watermark works
- OfficialAnthropic Help: how Claude marks AI-generated content