Public tools can actually detect Claude’s text watermark. Anthropic announced a detection API on 14 August 2026 and has not shipped it. Every checker currently ranking on page one inspects invisible Unicode characters — which is not how this watermark works.
Source: Anthropic, “How Claude’s text watermarking works” (2026)
The only tool that bypassed Pangram and Turnitin in 2026.
Most humanizers clear one detector and get caught by the other. StealthWriter is the one that gets past both — run Ghost 5.2 Pro at level 7–8, section by section, and re-check before you submit.
Try StealthWriter →Check your own text first
Here is what this tool is and is not. It cannot detect Claude’s watermark — nothing public can, and any tool telling you otherwise is guessing. What it does instead is measure how much watermark your text could carry: how many free word choices it contains, how thin its factual anchoring is, and which paragraphs are most exposed on both counts.
If you also need to strip invisible characters or repair look-alike letters, the Claude watermark remover and checker does both. Everything runs in your browser. Nothing is uploaded, which matters more than it sounds — most paste-in tools transmit your text to a server.
Claude Watermark Checker
Paste an article. Scores 0–100 for carrying capacity, then flags your most exposed paragraphs. Runs locally — nothing leaves this page.
Key Takeaways
- 0 public detectors exist. Anthropic’s detection API is announced, not shipped. (Anthropic, Aug 2026)
- 6 of 6 checker tools we audited on page one either describe the watermark as hidden characters or claim a check they cannot perform. (SERP audit, 27 Aug 2026)
- 98.3% of SynthID watermarks were removed by a single meaning-preserving paraphrase pass. (arXiv 2607.16010, Jul 2026)
- 80% baseline false-negative rate — before any removal attempt at all. (arXiv 2607.16010, Jul 2026)
- 5.4% of paraphrased human-written text was falsely flagged as AI. (arXiv 2607.16010, Jul 2026)
- 0 mentions of watermarks, provenance, SynthID or C2PA in Google’s spam policy. (Google Search Central, updated May 2026)
- 2 Aug 2026 is the date from which Claude models ship watermarked, driven by EU AI Act Article 50. (Anthropic Help Center)
Contents
1How the watermark actually works
Claude’s watermark is a bias in which word the model picks. It is not metadata, not zero-width characters, and not anything a scanner can find by reading your text.
Normally a language model picks its next word by sampling from a probability distribution using a random number generator. Anthropic replaced that generator with a function seeded by a secret key plus the words that came immediately before. In Anthropic’s own wording, watermarking “uses the key and a few words that come before to settle what word the model should pick.”
So when Claude is genuinely torn between swift, quick and rapid, the key quietly decides. Any single choice is meaningless — all three were reasonable. Across thousands of positions, the pattern of which-of-the-tied-options got chosen correlates with the key. A holder of that key can measure the correlation. Nobody else can see anything at all.
The useful mental model is a loaded die. One roll proves nothing. A thousand rolls prove the die is loaded. This is also why the mark is probabilistic rather than binary, and why a detection score is never proof of authorship — Anthropic states plainly that a detection can only answer “what is the likelihood this was partly written by Claude?”
Files behave completely differently. Images and SVGs from Claude carry C2PA signed metadata instead — genuine metadata, genuinely strippable. A re-save, a screenshot, a format conversion, or WordPress generating its own resized thumbnails will typically destroy it. In practice, images you have already published have probably lost it before any reader saw them.
2What page one gets wrong
We audited the six checker and remover tools ranking for “claude watermark checker” and “ai text watermark remover” on 27 August 2026. Every one of them describes or targets the wrong artifact.
| Tool | What it claims | Why that fails |
|---|---|---|
| claudewatermark.com | “may insert invisible characters or subtly modify text” | Leads with invisible characters; the mechanism is statistical word choice |
| overchat.ai | “see every verifiable Claude artifact — hidden Unicode characters, HTML fingerprints” | Inspects Unicode artifacts, which the watermark does not use |
| stealthgpt.ai | “checks a piece of text for that signal and tells you straight” | No public detector exists; this check is not performable by anyone |
| originality.ai | “see all hidden Unicode characters in your text” | Unicode scrubbing has no effect on a sampling watermark |
| cleanpaste.site | “remove hidden metadata and AI watermarks from generated text” | Removes metadata and invisible characters only |
| getgpt.app | “detect and remove 34+ invisible Unicode characters used as AI text watermarks” | Names the wrong artifact explicitly |
This matters beyond pedantry. A tool that strips zero-width characters returns a clean, green, reassuring result on text that is fully watermarked, because it was never looking at the watermark. Hidden-character cleaning is a real technique with real uses — it just has nothing to do with this particular mark.
3Why some pages carry more watermark than others
The watermark needs room to choose. That single fact predicts almost everything about which of your pages are exposed and which are already close to clean.
Flowing prose offers many ways to say the same thing, so the key has thousands of choice points to express itself through. Factual writing does not. There is one correct way to write a price, a date, a version number or a proper noun, and where the model has no freedom, the key cannot leave a trace. Anthropic confirms the mark is “sparser on factual passages.”
The same logic settles a question three widely-shared videos got backwards. If you wrote a draft yourself and Claude only proofread it, there is almost nothing to attach to — Anthropic’s phrasing is that “nearly all the words are the person’s, there’s very little (if anything) for the watermark to attach to.” Editing works the same way in reverse: every sentence you rewrite yourself replaces a keyed choice with your own, which is why heavy paraphrasing degrades detectability so sharply.
That second number deserves more attention than it has received. Nearly every public argument about this watermark — alarmed and reassuring alike — assumes the mark reliably fires on unedited AI text. The published evaluation of this method says it frequently does not, and it flagged 5.4% of paraphrased human writing as AI, a false-positive pattern that historically falls hardest on non-native English writers.

4What Google actually says
Nothing. That is the entire finding, and it is checkable in about twenty seconds.
Google’s spam policy page, last updated 15 May 2026, contains zero references to watermarks, provenance, SynthID or C2PA. The rule that governs AI content targets scaled content abuse — and the operative phrase is “no matter how it’s created,” which is Google explicitly declining to care which tool produced the text.
| Question | What the documentation says | Source |
|---|---|---|
| Does Google’s spam policy mention watermarks? | 0 mentions | Google Search Central, May 2026 |
| Does Google use provider watermarks as a ranking signal? | No statement | No primary source, either direction |
| What did the August 2026 spam update target? | Not published | Google Search Status Dashboard |
| Does SynthID relate to Search ranking? | Not mentioned | Google DeepMind |
Be careful with the direction of that claim. This is not Google confirming that watermarks do not affect rankings. Google has said nothing at all, and absence of evidence is not proof of absence. What it does mean is that anyone telling you the August 2026 spam update went after watermarked content is asserting something Google never documented.

5The exemption nobody read
EU AI Act Article 50 is the reason this watermark exists. Article 50(2) obliges providers like Anthropic to mark their output in a machine-readable format, with penalties up to EUR 15 million or 3% of worldwide annual turnover.
Article 50(4) is the half that went uncovered, and it is the half aimed at you. It places a disclosure duty on the deployer — the publisher — for AI-generated text published to inform the public on matters of public interest. And it exempts content that “has undergone a process of human review or editorial control” where a person or organisation holds editorial responsibility for publication.
Two caveats before anyone redesigns a workflow around this. The scope is narrow: news, politics, health and civic topics plausibly qualify as matters of public interest, while a product roundup or a how-to probably does not. And it exempts you from disclosure only — it does not remove the watermark and has no bearing on search rankings. This is a pointer to a statute, not legal advice; if you publish EU-facing content on public-interest topics, talk to someone qualified.
The practical version is unglamorous and cheap. Keep your drafts and revision history, because process evidence outperforms any detector score when a claim is actually challenged. Record who reviewed what and when. And disclose in proportion rather than over-explaining.
6Methodology
Research conducted 27 August 2026. Primary sources were read directly rather than through secondary coverage: Anthropic’s technical post and help centre documentation, Google’s spam policy and Search Status Dashboard, the EU AI Act text, and the arXiv evaluation of SynthID robustness.
The SERP audit covered the top ten organic results for “claude watermark checker” and “ai text watermark remover” in the US on 27 August 2026; the six entries in the table are those presenting themselves as checkers or removers. Demand context came from 84 Reddit posts across roughly 30 subreddits between 11 and 26 August 2026.
Limitations. The 98.3%, 80% and 5.4% figures were measured on SynthID-Text generally, not on Claude’s deployed implementation, and are transferred here by inference. Because Anthropic holds the key and has shipped no detector, no independent party can currently test Claude’s live watermark — a limitation that applies equally to every claim made by every tool in the audit table, including any claim to the contrary. This page will be updated when the detection API ships.
7Frequently asked questions
Can any tool actually detect Claude’s watermark right now?
No. Anthropic announced a detection API on 14 August 2026 and has not shipped it. Detection requires Anthropic’s secret key, so no third party can perform the check. Any service offering to tell you whether a specific text carries the mark is guessing, however confident the interface looks.
Does removing invisible Unicode characters remove the watermark?
No. The watermark is a statistical bias in word choice, not a character inserted into the text. Zero-width character cleaners return a clean result on fully watermarked text because they never examined the watermark. Hidden-character removal is useful for other reasons, but not this one.
Will Google penalise my content for carrying a Claude watermark?
There is no evidence in either direction. Google’s spam policy contains zero references to watermarks and targets scaled content abuse “no matter how it’s created.” No Google statement on provider watermarks exists. Anyone claiming certainty here — in either direction — is going beyond the documentation.
If I edit Claude’s draft heavily, does the watermark survive?
It degrades. Published evaluation of this watermark family found 98.3% removal after one meaning-preserving paraphrase pass. Every sentence you rewrite yourself replaces a keyed word choice with your own. Rewriting live pages purely to achieve this is rarely worth it, since rewriting reliably damages factual accuracy.
Does the watermark apply if Claude only proofread my writing?
Barely. Anthropic’s own wording is that when “nearly all the words are the person’s, there’s very little (if anything) for the watermark to attach to.” Several widely-shared videos claimed the opposite; the documented mechanism does not support them.
What should I do if someone accuses my work of being AI-generated?
Produce process evidence rather than arguing about detector output. Drafts, revision history and timestamps are far stronger than any score, particularly given the 5.4% false-positive rate recorded on paraphrased human writing. Our guide on what to do in the first 24 hours after an accusation covers the sequence.
Which Claude models are watermarked?
Models launched on or after 2 August 2026. Anthropic describes marking for older models as “in progress” and rolling out over the coming months. Coverage spans the API, Claude Code and Cowork, worldwide.
Sources
- Anthropic. “How Claude’s text watermarking works.” anthropic.com. Accessed 27 Aug 2026.
- Anthropic Help Center. “How Claude marks AI-generated content.” support.claude.com. Accessed 27 Aug 2026.
- Tamim & Khan. “AI Watermark Evidence Fails Forensic Readiness: An Empirical Evaluation.” arxiv.org. Accessed 27 Aug 2026.
- ETH Zurich SRI Lab. “Probing SynthID-Text.” sri.inf.ethz.ch. Accessed 27 Aug 2026.
- Google Search Central. “Spam policies for Google web search.” developers.google.com. Accessed 27 Aug 2026.
- Google Search Status Dashboard. “Ranking updates history.” status.search.google.com. Accessed 27 Aug 2026.
- EU Artificial Intelligence Act. “Article 50: Transparency Obligations.” artificialintelligenceact.eu. Accessed 27 Aug 2026.
- Google DeepMind. “SynthID.” deepmind.google. Accessed 27 Aug 2026.
The only tool that bypassed Pangram and Turnitin in 2026.
Most humanizers clear one detector and get caught by the other. StealthWriter is the one that gets past both — run Ghost 5.2 Pro at level 7–8, section by section, and re-check before you submit.
Try StealthWriter →