Claude Watermark Breached in 4 Hours, EU AI Act Faces Technical Limits
Anthropic introduced an invisible watermark in Claude to comply with the EU AI Act. A developer published a removal tool in just 4 hours, questioning the regulation's enforceability.
EU AI Act Enforcement and Regulatory Background
According to Wired’s Isabella Ward, Anthropic announced last week that it would embed invisible watermarks into all text generated by its Claude models. This move is motivated by compliance with the European Union’s AI Act, a decision accompanying the implementation of the law that mandates the automatic detection of AI-generated content.
The EU AI Act, which came into force earlier this month, requires model providers like Anthropic and OpenAI to label synthetic audio, images, video, and text with markers that machines can detect as AI-generated. Violations can result in fines of up to 3% of annual global revenue. However, while the regulation prohibits the marketing of evasion tools, it does not impose legal restrictions on the development of independent tools.
Anthropic is adopting a technology called SynthID, developed by Google. It works by embedding imperceptible patterns into the word choice and sentence endings of text, which machines trained on these patterns can then detect. Google has been applying this technology to its AI-generated content since 2023. Anthropic guarantees that the watermark will not affect the quality of Claude’s responses.
Rapid Technical Response from Developers
Just four hours after Anthropic’s announcement, freelance developer Guillaume Meyer published code on GitHub to remove the watermark. This tool garnered over 20,000 bookmarks on social media and expanded to involve more than 100 contributors.
Meyer told Wired that part of his motivation was interest in the technical challenge. He also noted that some people object to the very idea of labeling all AI-generated content. Freelance content writers and social media creators have also reached out to Meyer for assistance.
Structural Issues with Watermarking Technology
While Meyer agrees with the principles of transparency and content attribution, he points out that watermarking is “a highly flawed solution with serious drawbacks and risks.” The biggest concern is the risk of false positives.
Meyer, a native French speaker, regularly uses AI assistance tools like Grammarly to edit his writing. Even such minor use could result in a watermark being applied, potentially leading to job candidates being unfairly disqualified or researchers being suspected of AI use. Anthropic itself acknowledges that the watermark only indicates the probability that text involved Claude.
Another fundamental problem is the inability to distinguish between varying degrees of AI usage. From complete text generation to simple grammar checks, all levels of use are marked with the same watermark. Meyer argues this ambiguity fundamentally undermines the credibility of treating detection results as evidence.
Regulation Versus Technology
The EU AI Act was only recently enacted, and its enforcement mechanism is still being established. However, the phenomenon of the technical community immediately presenting evasion techniques for regulated technologies raises fundamental questions about the feasibility of legal implementation.
Watermarking was presented as one means to ensure transparency for AI-generated content. Yet, its technical vulnerabilities were exposed within hours of its public release, suggesting that technical measures alone cannot achieve regulatory goals. There is a significant lag between the monitoring system envisioned by the EU AI Act and the responsive capabilities of the technical community.
For legal frameworks to function effectively, multi-layered approaches beyond watermarking may be necessary, such as cryptographic signatures or audits based on legal procedures. This situation calls into question the role of human-intervened verification flows in the gap between EU law enforcement and technical evasion.
Editorial Opinion
In the short term, the EU AI Act’s enforcement mechanism will take concrete shape in the coming months. Providers like Anthropic will likely implement new technical countermeasures, while the development of evasion tools will progress in parallel. This cat-and-mouse game will become a testing ground for the accuracy of EU law interpretation and enforcement.
Long-term, it seems a pattern will solidify where technological development for detecting AI-generated content runs in tandem. Methods for ensuring transparency—watermarks, digital signatures, backdoor detection technologies, etc.—will diversify, and legal systems will be forced to continuously update their frameworks to encompass them.
As EU AI Act enforcement ramps up, the immediate response from the technical community questions the regulation’s feasibility. The core issues of false positives leading to unfair exclusion and the inability to distinguish the degree of AI use remain unresolved. Designing human-involved verification flows, rather than relying solely on technical countermeasures, appears poised to become a critical issue going forward.
References
- “Coders Say They Already Found Workarounds to Claude’s Invisible Watermarks”, by Isabella Ward — Wired, 2026-08-19T16:44:07.000Z (ARR)
- Source URL: https://www.wired.com/story/coders-say-they-already-found-workarounds-to-claudes-invisible-watermarks/
Comments