# AI Watermark Removal > Independent reference on AI watermarking, AI provenance (C2PA, SynthID, statistical token watermarking), and what detecting or removing an AI watermark actually requires. Every provider claim is tied to a primary source and labelled by evidence strength: Confirmed, Official announcement, Reported, Research/proposal, Community discussion, or Rumor/speculation. Not affiliated with any AI provider. The core position, and the thing most coverage gets wrong: "AI watermark" names four unrelated mechanisms (a visible label, signed C2PA metadata, an invisible media watermark, and a statistical text watermark) plus a fifth thing that is not a watermark at all, the AI detector, which infers origin from style and is wrong in both directions. Anthropic is currently the only provider whose own documentation says its text output is watermarked. Its help page names Claude Fable 5.1 and Claude Mythos 5.1, both marked since 2026-09-01, and an email to Claude for Work administrators seen 2026-09-04 says Claude Opus 5 responses carry the watermark from 2026-09-09 with other current models following over the coming weeks; that notice text is on no public Anthropic page, and the help page had not been updated to match as of 2026-09-05. The same notice says there is no admin or user setting to turn the watermark off. Google's SynthID text claim is contested between its own marketing page and its own developer forum; OpenAI describes text provenance as an unmet goal. There is still no public detector for any production text watermark: Anthropic's text detection API shipped on 2026-09-01 into a private preview for eligible organizations under EU law, while its free, ungated checker at claude.com/check-content reads C2PA Content Credentials on files and states outright that it does not check text. So files have a public check, text does not, and any tool promising to verify or remove a text watermark is promising a result its buyer cannot check. Full text of every article, the status database and the lab studies in one file: https://www.aiwatermarkremoval.com/llms-full.txt Last updated 2026-09-05. ## Original research and data - [AI Watermark Lab](https://www.aiwatermarkremoval.com/lab): Original testing: methodology, published datasets, reproducible scripts, and an explicit list of the questions our instruments cannot answer. - [Invisible-character census in Claude output](https://www.aiwatermarkremoval.com/lab/claude-invisible-characters): No. Across 128 outputs and 26,093 words from four Claude models, zero zero-width or bidirectional-format characters appeared. That now includes Fable 5.1, the first model Anthropic confirms carries the watermark. Sample: 128 outputs · 26,093 words · 4 models. Cannot answer: Whether Anthropic's statistical text watermark is present. Its only detector is an Anthropic API in private preview, limited today to eligible organizations under EU law and not open to this lab, so nothing we or you can run measures that. The corpus was also captured before 2026-09-09, the date Anthropic's 2026-09-04 administrator notice schedules Claude Opus 5 marking from, a date its public help page had not confirmed as of 2026-09-05. - [Which invisible characters survive ordinary software](https://www.aiwatermarkremoval.com/lab/transformation-survival): The truly invisible ones survive almost everything; only the space-like ones get cleaned up. 12 of 18 characters came through every transformation that was not deliberately trying to remove them. Sample: 18 characters × 12 transformations. Cannot answer: Anything about Google Docs, Word, or Notion. Those pipelines cannot be run and verified here, so the matrix covers only transformations that execute in code. - [AI Watermark Status Database](https://www.aiwatermarkremoval.com/ai-watermark-status): Which providers watermark text, images, audio and video, by product surface, across 18 rows and 11 providers, each cell carrying a primary source and a verification date. Machine-readable copy at https://www.aiwatermarkremoval.com/ai-watermark-status.json ## Core - [AI Text Watermark Removal](https://www.aiwatermarkremoval.com/ai-text-watermark-removal): Before you pay for a remover: the under $50 lab attack that did work, the signal loss found inside SynthID Text, and the EU exemptions few ever cite. - [AI Text Watermark: How Statistical Watermarking Works](https://www.aiwatermarkremoval.com/ai-text-watermark): No hidden characters to find. A statistical watermark rigs which words the model picks. The mechanism, the one concrete number, and where it breaks. - [What Is AI Watermarking?](https://www.aiwatermarkremoval.com/what-is-ai-watermarking): Visible labels, invisible signals, C2PA metadata, statistical watermarking: four mechanisms hiding behind one name, and how each one actually works. - [AI Watermark Removal: What It Can and Cannot Mean](https://www.aiwatermarkremoval.com/ai-watermark-removal): Metadata strips. Invisible characters clean off. The statistical watermark is another story. What removal really means, and the $50 attack that broke one. - [Can AI Watermarks Be Removed?](https://www.aiwatermarkremoval.com/can-ai-watermarks-be-removed): Metadata, pixels, audio, and text all fail differently. The signal-by-signal answer, and where the evidence flat-out contradicts the marketing. - [AI Watermark vs AI Detector](https://www.aiwatermarkremoval.com/ai-watermark-vs-ai-detector): GPTZero, Originality.ai, and ZeroGPT don't check for watermarks at all. Why a planted signal and an after-the-fact guess disagree, with the evidence. ## Provider trackers - [Claude Watermark: Confirmed Facts, Reports, and Rumors](https://www.aiwatermarkremoval.com/claude-watermark): Opus 5 gets Claude's watermark from Sep 9, 2026, per an admin notice not yet on the help page. Fable 5.1 and Mythos 5.1 already carry it. Model by model. - [Anthropic Watermark: The Company, the Law, the Timeline](https://www.aiwatermarkremoval.com/anthropic-watermark): Anthropic didn't pick August 2026, EU AI Act Article 50 did. The commitments, the C2PA stance, and the full dated timeline behind the rollout. - [ChatGPT Watermark: Is Anything Actually Watermarked?](https://www.aiwatermarkremoval.com/is-chatgpt-watermarked): What the ChatGPT watermark is, what OpenAI shelved, and what removal can mean. Images and audio carry real provenance signals; ordinary chat text carries none. - [Gemini Watermark: Is Gemini Watermarked, and Where?](https://www.aiwatermarkremoval.com/is-gemini-watermarked): Is Gemini watermarked? SynthID is confirmed on images, audio and video. For text, Google's own pages contradict each other, and this is where they split. - [Is Grok Watermarked? Images and Video Yes, Text Not Documented](https://www.aiwatermarkremoval.com/is-grok-watermarked): xAI puts a visible watermark on Grok images and video and documents nothing about text. What's confirmed, what's contested, and what's just marketing. - [Is Llama Watermarked? Meta's Own Documents Say Nothing](https://www.aiwatermarkremoval.com/is-llama-watermarked): Meta marks its images and audio, yet Llama's model cards never mention text watermarking. Even Meta's EU paperwork skips text. The silence is the answer. - [DeepSeek Watermark: Is DeepSeek Output Watermarked?](https://www.aiwatermarkremoval.com/deepseek-watermark): Is DeepSeek watermarked? Chinese law forces visible AI labels in three places. No DeepSeek document describes a hidden mark, and its terms forbid removing them. - [Meta AI Watermark: Content Seal, Audio, and Shelved Research](https://www.aiwatermarkremoval.com/meta-ai-watermark): Meta ships two watermarking product lines and open-sourced a third for text. So why does Meta AI chat text carry no mark today? The full map, verified. - [LLM Watermarking: Claude vs Gemini vs ChatGPT vs Llama](https://www.aiwatermarkremoval.com/llm-watermarking): Claude, Gemini, ChatGPT, Grok, Llama, and DeepSeek compared on text watermarking in 2026, plus the real reason OpenAI shelved its own system. ## Removal guides - [Remove Claude Watermark: Real Mark, No Way to Check Yet](https://www.aiwatermarkremoval.com/remove-claude-watermark): Anthropic's detector shipped in Sep 2026, to regulators and newsrooms only. You still cannot check your own text, so no remover can prove it worked. - [Remove Gemini Watermark: What SynthID Text Can Survive](https://www.aiwatermarkremoval.com/remove-gemini-watermark): Google says SynthID survives light edits but not a full rewrite. One forum reply even disputes the API applies it. Read the fine print before you act. ## How the mechanism actually works - [Token Probability Watermarking](https://www.aiwatermarkremoval.com/token-probability-watermarking): Token probability watermarking biases word choice mid-generation. The patent describing SynthID without naming it, and the $50 attack that stole its rule. - [Statistical Text Watermarking](https://www.aiwatermarkremoval.com/statistical-text-watermarking): Statistical text watermarking adds nothing to your text: a secret key steers word choice instead. How the scheme works, and how researchers cracked one. - [Text Watermark Robustness: What Actually Survives an Edit](https://www.aiwatermarkremoval.com/text-watermark-robustness): Text watermark robustness has a floor: detection wants roughly 800 tokens. What survives an edit, and why four SynthID Text audits tell a rockier story. - [Paraphrasing AI Watermarks: What One Rewrite Actually Does](https://www.aiwatermarkremoval.com/paraphrasing-ai-watermarks): Paraphrasing is the most-studied attack on AI text watermarks. The 2023 paper that said it wins, and 2026 data showing 98.3% signal loss from one rewrite. - [Hidden Unicode AI Watermark: Proves Almost Nothing](https://www.aiwatermarkremoval.com/hidden-unicode-ai-watermark): Found an invisible character in Claude or ChatGPT text? Four Unicode characters explain nearly all of them, and none proves AI wrote it. See which four. - [Zero-Width Space Watermark: Real Technique, Wrong Mechanism](https://www.aiwatermarkremoval.com/zero-width-space-watermark): Zero-width space steganography is real and decades old. It is also not how Claude or Gemini watermark text. We scanned 96 Claude outputs and found 0. - [SynthID Watermark: Text, Images, Audio, and Video](https://www.aiwatermarkremoval.com/synthid-watermark): How SynthID hides its mark in images, audio and video, how SynthID Text steers token sampling as the model writes, and what red teams found attacking it. - [AI Watermarking Research: A Map of the Literature](https://www.aiwatermarkremoval.com/ai-watermarking-research): The whole field on one page: the 2023 green-list paper, the schemes built on it, the under $50 attack that steals watermarks, and SynthID's patents. - [AI Watermark Spoofing: Forging Someone Else's Signal](https://www.aiwatermarkremoval.com/ai-watermark-spoofing): Spoofing forges a model's watermark onto text it never wrote. One lab pulled it off for under $50, then published the test that catches the forgery. - [Do Em Dashes Mean AI Wrote It? What the Data Shows](https://www.aiwatermarkremoval.com/do-em-dashes-mean-ai): Two of six chatbots wrote zero em dashes on identical prompts. Where the rule came from, and why it fails, before you accuse a human writer. ## Detection - [AI Text Watermark Detector](https://www.aiwatermarkremoval.com/ai-text-watermark-detector): How AI text watermark detectors actually work, why Claude has no public one, why Google's checker may verify nothing, and where GPTZero really fits. - [Claude Watermark Detector: Private Preview, Not Public](https://www.aiwatermarkremoval.com/claude-watermark-detector): Anthropic's detection API shipped on 1 Sep 2026, to regulators, media, fact-checkers and researchers only. What that leaves you, and what to check instead. - [AI Watermark Detector](https://www.aiwatermarkremoval.com/ai-watermark-detector): AI watermark detectors scan image, video, and audio, yet one scheme mismatch turns real AI content into a false negative. A clean result proves nothing. - [AI Detector False Positives: Why They Happen So Often](https://www.aiwatermarkremoval.com/ai-detector-false-positives): AI detector false positives are documented, common, and mechanical. Why honest writing gets flagged, and why a watermark check beats any detector score. ## Regulation and disclosure - [EU AI Act and AI Watermarking: Article 50 Explained](https://www.aiwatermarkremoval.com/eu-ai-act-ai-watermarking): EU AI Act Article 50 now makes marking AI content the law. Who is covered, what counts as compliance, the deadline, and what noncompliance costs. - [Machine-Readable AI Marking: EU AI Act Article 50 Rules](https://www.aiwatermarkremoval.com/machine-readable-ai-marking): Article 50 makes machine-readable AI marking law without naming a technology. What it demands, who it binds, and why EU enforcement is so uneven. - [AI-Generated Content Disclosure: EU Article 50 Duties](https://www.aiwatermarkremoval.com/ai-generated-content-disclosure): Article 50's disclosure duty is not the marking duty, and it lands on different people. Who must disclose AI-generated content, and who is exempt. ## Provenance and metadata standards - [C2PA Content Credentials for AI Provenance](https://www.aiwatermarkremoval.com/c2pa-content-credentials): Inside a C2PA Content Credentials manifest: what it records, how hard binding makes tampering visible, and what a verified credential still can't prove. - [C2PA vs SynthID](https://www.aiwatermarkremoval.com/c2pa-vs-synthid): C2PA credentials and SynthID watermarks fail in opposite ways. See which one survives a screenshot, and who is actually allowed to run each detector. - [AI Content Provenance: What It Proves, and What It Doesn't](https://www.aiwatermarkremoval.com/content-provenance): What AI content provenance really records, how it differs from watermarking and AI detection, and the limits the vendors admit in their own words. - [AI Signature: Watermarks, Metadata, and Style Signals](https://www.aiwatermarkremoval.com/ai-signature): Four things get called an AI signature: a signed C2PA manifest, an invisible watermark, a detector's verdict, and a writing tic like the em dash. - [Metadata AI Watermarking](https://www.aiwatermarkremoval.com/metadata-ai-watermark): What a C2PA manifest quietly stores about your file, the two free tools that read and delete one, and why metadata is not a hidden watermark at all. ## Other media (image, video, audio) - [Image AI Watermarking: OpenAI, Google, Meta, and Amazon](https://www.aiwatermarkremoval.com/image-ai-watermark): OpenAI, Google, Meta and Amazon each hide a mark in AI images. See what the invisible layer survives and the exact point where tests saw it fade. - [Video AI Watermarking: Sora, SynthID, and Nova Reel](https://www.aiwatermarkremoval.com/video-ai-watermark): Sora, SynthID and Nova Reel all watermark AI video, each differently. One test even found OpenAI's own provenance claim backwards. Here's who marks what. - [Audio AI Watermarking: OpenAI, Meta, and Google SynthID](https://www.aiwatermarkremoval.com/audio-ai-watermark): OpenAI shipped its audio watermark two days before an EU deadline. Meta did it a year earlier, and its patent names Ian Goodfellow. How each one works. ## Community - [Community AI Watermark Questions and Rumors](https://www.aiwatermarkremoval.com/community-ai-watermark-questions): What Reddit, Hacker News, and X really believe about AI watermarks, including the viral SynthID crack claim a correction cut down to just 16 percent. ## Tools - [Claude Watermark Remover and Checker](https://www.aiwatermarkremoval.com/claude-watermark-remover): Local, in-browser tool that finds and cleans invisible Unicode characters in pasted text. It does not claim to remove Anthropic's statistical text watermark, for which no public detection or removal method exists. - [Eliminar Marca de Agua de Claude](https://www.aiwatermarkremoval.com/es/eliminar-marca-de-agua-claude): Spanish-language version of the same local checker. ## About this site - [About AI Watermark Removal: What We Refuse to Claim](https://www.aiwatermarkremoval.com/about): Who runs this site, how it stays independent of the AI companies it covers, and the one claim you will never see it make. Plus how to reach the editors. - [Methodology: How Every Watermark Claim Gets Checked](https://www.aiwatermarkremoval.com/methodology): Every claim on this site is sourced, dated, and re-verified on a schedule. See the exact protocol behind our watermark experiments, limits included. - [Editorial Policy: How We Use AI and Admit Mistakes](https://www.aiwatermarkremoval.com/editorial-policy): The writing standard we hold ourselves to, exactly where AI assistance is disclosed, and a public log of every correction with the date it changed. - [Privacy Policy: Your Pasted Text Never Leaves Your Browser](https://www.aiwatermarkremoval.com/privacy): What this site collects, what it refuses to collect, and why text pasted into the watermark checker is processed in your browser, never on a server. - [Rowan Vale](https://www.aiwatermarkremoval.com/about/rowan-vale): The byline on every article, experiment and status row here. Rowan Vale is a pen name, disclosed as one: no employer, credential or affiliation is claimed, and the page lists the work the name covers. - [Contact and Corrections](https://www.aiwatermarkremoval.com/contact): The only inbound channel. No email address is published anywhere on this site by design. Corrections are logged publicly with the date and what changed.