Claude Remove Watermark

Claude Watermark Remover

Check and remove the invisible watermark characters in Claude's output

This checks AI text for invisible watermark characters and removes them: zero-width spaces, variation selectors, tag characters, bidirectional controls and non-standard punctuation. It runs entirely in your browser and names every character it found. It does not remove Anthropic's statistical watermark, because no character tool can, and the explainer below sources that to Anthropic's own documentation.

100% local · your text never leaves this page No signup · no upload · no logging 90+ character types detected Decodes smuggled messages

Yes, Claude watermarks its text. Anthropic confirmed in August 2026 that Claude embeds an imperceptible watermark directly into the text it generates, as a transparency commitment under the EU AI Act. It applies to models launched on or after 2 August 2026.

That watermark is statistical, and no tool on this page or any other removes it by cleaning characters. It lives in the model's word choices. What this tool removes is a different thing: the invisible Unicode that rides along with AI output and breaks spreadsheets, code and search. The explainer below covers how the real watermark works, why Claude Code output is affected, and what happens when you only used Claude to edit.

Your text
0 chars
Cleaned
0 chars

What to remove

Dashes become
Odd spaces become

Tidy up

Cmd/Ctrl + Enter to copy

What can a Claude watermark remover actually do?

A Claude watermark remover can strip invisible characters, and cannot touch a statistical watermark. Those are two different things, and keeping them apart is the whole point of this page. Here is the split, stated plainly before you use anything on this page:

  • Removable: invisible Unicode. Zero-width spaces, tag characters, variation selectors, bidi controls, lookalike letters and AI typography. Verifiable, and worth removing because it breaks spreadsheets, code and search.
  • Not removable: Anthropic's text watermark. It lives in the model's word choices, not in the characters. Any tool claiming to strip it is describing something it cannot do.

Is this a Claude watermark checker or a remover?

It is both a Claude watermark checker and a remover, and the check runs first. Paste your text and the tool reports what it found before it changes anything: every hidden character, named by its Unicode code point, with a count and a position in the text.

Three of those checks go past what a character stripper reports. It decodes hidden payloads, so a message smuggled inside tag characters or variation selectors comes back as readable text instead of a count. It reads the clipboard markup a chat interface leaves behind in a copied answer. And it inspects an image for a C2PA provenance manifest, which is a separate signal from anything carried in text.

One check no tool can run, this one included. Nothing checks text for Anthropic's statistical watermark. Verifying it takes a key Anthropic has not released to anybody. A checker that hands back a Claude watermark score for your prose is guessing, and the honest report names what it actually read and stops there. The rest of this page covers how that real watermark works instead.

Does Claude watermark its text?

Claude does watermark its text, and Anthropic confirmed it publicly in August 2026. Its support documentation states that Claude embeds "an imperceptible watermark directly into the text itself", one that leaves the meaning, quality and readability of the response unchanged. The marking applies to Claude models launched on or after 2 August 2026, across the API, Claude, Claude Code, Cowork and Claude Tag, including deployments on AWS, Google Cloud and Microsoft Foundry. Anthropic presents it as a transparency commitment under Article 50(2) of the EU AI Act. Separately, Claude attaches signed C2PA provenance metadata to image files it generates, which behaves nothing like the text mark.

How does the Claude watermark work?

The Claude watermark works by biasing which words the model picks. At each step of writing a sentence, a language model holds several near-equivalent candidates for the next word. Published watermarking approaches nudge that choice according to a secret key, so the output stays natural while the pattern of choices carries a signal. Spread across a whole passage, that pattern becomes detectable by anyone holding the key.

How a statistical text watermark is applied during writing At one step of generation the model holds three near-equivalent candidate words with similar probabilities. A secret key biases the selection toward one of them. Repeated across the passage, the pattern of biased choices forms a detectable signal that carries no visible difference in the text. STEP IN GENERATION The results were ...next word? clear.31 obvious.29 plain.27 Near-equivalent. Any reads naturally. SECRET KEY nudges the pick ACROSS THE PASSAGE The results were obvious, and the team moved quickly to publish the finding. Reads normally. Nothing hidden between the letters. The signal is the pattern of choices, not a character. Deleting characters cannot reach it.
Where the watermark lives. A character cleaner operates between the letters, and the signal is in which letters were chosen, which is why the two never meet.

Anthropic has not published its specific scheme, so treat the mechanism above as inference from published approaches rather than a disclosed specification. Alex Cui, CTO of GPTZero, described the technique as subtly changing "the probability of which words a model selects". The practical consequence is the same either way: a find-and-replace has nothing to find, and that also decides whether Claude Code output carries the mark.

Does Claude Code watermark its output?

Claude Code output carries the mark, because Anthropic lists Claude Code among the covered surfaces alongside the API, Claude, Cowork and Claude Tag. The marking attaches to text the model generates, and it does not distinguish prose from anything else the model writes.

For developers that raises a question the writing case does not. Committed code, commit messages, pull request descriptions and documentation all pass through the same generation path. Anthropic has published no guidance on how the scheme treats source code specifically, and we have not tested it, so this is the honest limit of what is known rather than a claim in either direction. What is known is the surface list, and Claude Code is on it. The regulation behind that list explains why the list exists at all.

Does the EU AI Act require this?

The EU AI Act is the stated reason the marking exists. Anthropic presents it as a transparency commitment under Article 50(2), which obliges providers of generative AI systems to mark synthetic output in a machine-readable way so it can be identified as artificially generated.

Two consequences follow that people miss. The obligation sits with the provider, not with you, so removing invisible characters from your own copy breaks no rule in the Act. And the Act carves out content where AI performed "an assistive function for standard editing" without substantially altering it, which is a legal distinction the watermark itself cannot make. That gap between what the law exempts and what the mark can detect is the sharpest practical problem in the whole scheme.

Which marks are fragile and which are durable?

PropertyText watermarkC2PA file metadata
Applies toText Claude generates or editsImage files Claude generates
MechanismStatistical, carried in word choiceSigned manifest attached to the file
Survives copy and pasteYesOften not
Removed by stripping charactersNoNot applicable
Removed by re-saving or screenshottingNoYes, easily
Degraded by heavy rewritingYes, reportedlyNot applicable
Proof of AI authorshipNo, a probabilityNo, a provenance claim

The two marks fail in opposite directions. C2PA manifests are tamper-evident but shed easily: re-saving, converting format, screenshotting or uploading to a platform that reprocesses images usually drops them, so a missing manifest proves nothing. The text mark is the durable one, which is what makes the removal question worth answering honestly.

Can any tool remove Claude's watermark?

No character-level tool can remove Claude's watermark, including this one. The signal is distributed across the word choices themselves, so deleting invisible characters leaves it entirely intact. Reporting on comparable systems indicates the mark degrades under heavy paraphrasing, translation or full rewriting, because those replace the word choices it rides on. Cui told City AM that free paraphrasers had quickly bypassed Google DeepMind's SynthID. We report that because it is published and directly relevant. This site does not provide a paraphraser and does not recommend one.

Two further limits cut against reading too much into any result. Short passages may not carry enough text to score reliably, so both false positives and false negatives are live possibilities. And Anthropic itself frames a detected mark as "a signal rather than conclusive evidence", which is a weaker claim than the phrase "AI detection" usually implies.

There is a trade in the tools that do claim it. Rewriting your text requires sending it to a server, because the rewrite is done by another language model. At least one competing Claude tool routes submissions through a third-party inference provider and retains abuse-prevention signals for thirty days. That is a reasonable engineering choice and it is the opposite of a private one.

This tool cannot rewrite anything, and that limitation is the same fact as its privacy guarantee: character cleaning is arithmetic on a string, so it runs in your browser and the text never leaves your device. You are choosing between a tool that might degrade a signal and has to read your text, and one that cannot degrade it and never sees it. Neither choice touches the invisible characters, which is what this tool actually removes.

What if you only used Claude to edit your own writing?

Text you wrote yourself can still carry the mark if Claude touched it. Because the watermark is applied to text the model produces, asking Claude to proofread, translate or restructure your own draft can return copy that carries it. The EU AI Act exempts content where AI performed "an assistive function for standard editing" without substantially altering it, but that is a legal distinction, not something the watermark can detect. A detected mark is not evidence that a human did not write the underlying work. This is the least discussed consequence of the whole scheme, and it lands hardest on people who use AI as an editor rather than as a writer, which is also the group most likely to reach for a remover.

What does this watermark remover actually remove?

This remover strips 90+ invisible and ambiguous Unicode code points, which is roughly twenty times what a typical zero-width cleaner covers. Most tools in this category delete four or five characters and stop. This one checks every character in your text against the full set that is invisible, ambiguous, or usable as a fingerprint, then reports each one by code point and count.

Zero-width characters

ZWSP, ZWNJ, ZWJ, word joiners, soft hyphens, byte order marks, and the Hangul and Khmer filler characters that render as nothing at all.

Tag characters

The U+E0000 block encodes plain ASCII invisibly. An entire sentence can hide inside one emoji. This tool finds it and decodes it back for you.

Variation selectors

U+FE00 to U+FE0F and the supplement block carry arbitrary bytes. This is the current favourite technique for hiding data inside ordinary-looking text.

Bidirectional controls

Right-to-left overrides and isolates reorder what you see versus what a machine reads. That is the "trojan source" trick.

Lookalike letters

A Cyrillic о is a different character from a Latin o but looks identical. Swapping a few is a durable, invisible fingerprint.

Chat interface markup

Copying rendered text carries the interface's own HTML: data-start, data-message-author-role, font-claude-response-body. Use the rich paste tab to strip it.

Image provenance

The Image (C2PA) tab reads a PNG, JPEG, WebP or SVG and reports whether it carries a signed manifest, an IPTC DigitalSourceType, or an EXIF software tag. It detects, it does not verify, and it never strips.

Typographic tells

Em dashes, curly quotes, ellipsis characters and non-breaking spaces. Visible, legitimate, and still the reason text reads as machine-written.

What does decoding a hidden message mean?

Decoding a hidden message means reading the data those invisible characters encode. Unicode tag characters and variation selectors map onto ordinary bytes, so a run of them sitting after a normal word is not noise, it is a payload. When this tool finds such a run it reconstructs the message and shows it to you. That distinction matters: scattered single characters look like passive marking, whereas a decodable payload means something was deliberately embedded. Free tools in this category typically hand back a count and stop, which is also why the characters are worth understanding beyond the watermark question.

Why do hidden characters matter beyond AI detection?

Hidden characters matter because they break systems quietly. Invisible Unicode corrupts CSV imports, fails string comparisons, breaks URL slugs, throws off word counts, produces mystery bugs when pasted into code, and gets flagged by some CMS and ATS parsers. Stripping it is basic text hygiene, entirely separate from any watermark question.

It also travels. Copy a paragraph out of a chat window into an email, a document, a pull request or a job application, and the hidden characters go with it, because they are real characters rather than formatting. Anyone wanting to fingerprint one specific copy of a document would do it exactly this way, crudely but effectively, and this tool will show you if they did. Those are the practical questions people ask most often.

Common questions

Does this Claude watermark remover remove Anthropic's watermark?

No. It removes invisible watermark characters, which are real and worth removing. Anthropic's text watermark is statistical and lives in word choice, so no character tool reaches it. The name describes the category people search for; the tool describes exactly what it does, on this page, without overstating it.

Why does pasted AI text carry hidden HTML into my CMS?

Because your clipboard holds two versions of what you copied. Selecting rendered text in a chat window copies a plain-text version and an HTML version, and the HTML one carries that interface's own markup: ChatGPT attaches data-start, data-end and data-message-author-role, while Claude's web UI carries class names such as font-claude-response-body. Paste into WordPress, Word, Google Docs or an email and it all comes with you, invisible on screen but sitting in your source.

The plain-text cleaner above cannot see any of it, because a text box only receives the plain-text version. Use the "Rich paste (HTML)" tab for that. It reads the HTML layer, strips the interface markup, scripts and event handlers, and hands back clean markup. Copying with the chat window's own copy button avoids the problem in the first place.

Will removing hidden characters get my writing past an AI detector?

No. Commercial AI detectors score statistical properties of word choice and sentence structure, not invisible characters. Removing hidden Unicode changes nothing about how a detector reads the prose. Any tool selling a character stripper as a detector bypass is overselling it.

Is my text uploaded anywhere?

No. The entire tool is JavaScript running in your browser. There is no server component, no analytics call carrying your content, no logging and no storage. Disconnect from the internet after the page loads and it keeps working, which is the fastest way to prove it to yourself.

What is a zero-width space?

U+200B is a character with no visible width. It occupies a position in the string, counts toward the character count, and displays nothing. It has legitimate uses, such as marking line-break opportunities in long strings. Because it is invisible and survives copying, it is also the simplest way to mark a piece of text so it can be recognised later.

Why remove em dashes if they are legitimate punctuation?

Em dashes are the most recognisable stylistic signature of current language models, and many people want them gone for that reason alone. It is a style choice rather than a correctness one, so it is a toggle. Turn it off if you write em dashes yourself and want them kept.

Does removing characters change my meaning?

Invisible characters carry no meaning, so removing them is lossless. The typography options do change your text: a curly apostrophe becomes a straight one, an em dash becomes a hyphen. Those are off or adjustable by default. Use "Show what was removed" to see every change before you copy.

Does this work on ChatGPT and Gemini text too?

Yes. The tool inspects Unicode, not the model that produced it, so it works identically on output from ChatGPT, Gemini, Copilot, Llama or anything else, and on text no AI ever touched. Invisible characters are invisible characters.

What differs is each provider's marking policy, and that is the part this page keeps Claude-specific: Anthropic confirmed a statistical text watermark in August 2026, and the explainer above covers what that does and does not mean. If you are mainly working with ChatGPT output, there is a companion tool at removechatgptwatermark.com.

Sources

  1. Anthropic, How Claude marks AI-generated content, support documentation.
  2. City AM, Claude to watermark AI slop, including edited human writing, quoting GPTZero CTO Alex Cui.
  3. ExplainX, Anthropic Claude invisible watermarks and C2PA, August 2026.
  4. Coalition for Content Provenance and Authenticity, C2PA specification.

Last reviewed 15 August 2026. Anthropic has said fuller technical documentation is coming. Where this page describes the underlying mechanism it draws on published watermarking approaches and reported commentary, not on a disclosed Anthropic specification, and says so at that point in the text.