Original research
AI Watermark Lab
Most writing about AI watermarks restates what providers said. The Lab measures what can actually be observed, publishes the data and the script, and says plainly which questions the instruments cannot reach.
The constraint everything runs into
Anthropic confirms Claude's text carries a watermark but has published no detector. Google's SynthID detector portal is access-gated. That means nobody outside those companies can measure whether a statistical text watermark is present in a given passage: not us, not the tools selling removal. Every study here measures something genuinely observable instead, and states which question it leaves open.
Studies
- Published96 outputs · 19,364 words · 3 modelsPublished 2026-08-12
Invisible-character census in Claude output
Do Claude's text outputs contain invisible Unicode characters, which are the mechanism most often claimed online to be the Claude watermark?
No. Across 96 outputs and 19,364 words from three Claude model tiers, zero zero-width or bidirectional-format characters appeared.
Cannot answer: Whether Anthropic's statistical text watermark is present. No public detector exists, so nobody outside Anthropic can measure that.
Read the study and data - Published18 characters × 12 transformationsPublished 2026-08-12
Which invisible characters survive ordinary software
When text carrying invisible characters passes through normalisation, JSON, URLs, base64, or a whitespace cleanup, which characters survive and which are silently destroyed?
The truly invisible ones survive almost everything; only the space-like ones get cleaned up. 12 of 18 characters came through every transformation that was not deliberately trying to remove them.
Cannot answer: Anything about Google Docs, Word, or Notion. Those pipelines cannot be run and verified here, so the matrix covers only transformations that execute in code.
Read the study and data - Blocked
Do commercial AI detectors check for watermarks at all?
When a detector reports a confidence score, is it reading a provider's watermark or inferring from writing style?
Blocked on paid accounts for the major detectors, which is the only way to test their behaviour honestly.
Cannot answer: Nothing yet: the study has not run. The design is published so the method can be criticised before any number exists.
How the Lab works
Every study states its question and what would count as evidence before it runs, records the full configuration, publishes aggregated data plus the analysis script, and puts its limitations next to the finding rather than in a footnote. The full protocol is on the methodology page.
Studies that are blocked stay listed as blocked. A design published before it can run is still useful: it can be criticised, and someone with the access we lack can run it.
Data and code are free to reuse with attribution and a link back. If you reproduce a finding, please carry its sample size and limitations with it.