How to avoid Claude watermarking your content
The answer is where you least expect it.
Follow ZDNET: Add us as a preferred source on Google.ZDNET's key takeaways New watermarks on Claude content are upsetting some people. Reactions reveal company priorities and human over-reliance on AI tools.To avoid possible watermarks, write it yourself (sorry!).Last week, Anthropic announced it would start watermarking text output from several of its LLMs via Claude to comply with Article 50 of the EU AI Act, which requires participating AI companies to provide transparency tools for AI-generated content. Public outrage at the watermarks multiplied as fast as the many watermark-removal tools now populating GitHub. For those who didn't take kindly to the news, the solution seems obvious: find a way to avoid taking watermarks with you out of Claude. But, just like the many re-"humanizing" writing plugins now clogging app stores everywhere, turning to yet another fixer likely won't get us anywhere. A bigger-picture reset on our expectations of AI tools -- and why content provenance matters -- might help instead. How the watermarks work After initially not giving much detail about how the watermarks would work and who could read them, Anthropic released new guidance on Friday, clarifying that watermarks will attach to text based on specific word choices. LLMs generate a word at a time, chosen probabilistically based on the former word. In its explanation, Anthropic referred to synonyms like "overcast" or "gray," in the context of a sentence about the weather, as effectively meaning the same thing. Anthropic explained that these "low stakes" word choices leave a pattern in generated text that readers can't detect, but that is legible to those with the key. Watermarking slightly changes this random word selection process.Also: 'Specialists aren't required' anymore: How to stay valuable in an AI agent workplace today"Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick," Anthropic explained. "The words that Claude picks are still random, but now, one can check the sequence of words and see if it's consistent with the choices Claude would make if it was using the key. If it is, one can assign a probability that the text was generated by Claude." Dissecting the outrageOne technologist in particular had several frustrations with this approach. In a recent blog post, John Gruber, co-creator of the Markdown markup language, disagreed that these word choices are "low stakes," and that the watermarking key won't "corrupt the semantics" of Claude's output. He isn't alone in that fear. "The exact words we choose when writing matter," Gruber wrote. "I want any LLM I use to choose the very best, most precise words at every single decision point." Also: How to spot an AI image: 6 telltale signs it's fake - and my go-to free detectorsAs a writer and editor, I agree that exact words matter. But is Claude the arbiter of "the very best, most precise words"? That's inherently subjective, but I don't know that the gold standard should be an LLM trained on and often used for the average of human language. Wouldn't the solution here be to make those precise word choices yourself, rather than handing them out to a product that's evolving beyond your control? Given that I choose to write for a living, I understand how useless it is to tell someone for whom writing is excruciating to simply figure it out. It's an imperfect comparison, but AI can be a writing tool for non-writers the way Google Sheets is a (rudimentary) data tool for non-analysts. Outsourcing writing to an AI tool doesn't do it for me, but I say that neutrally; I don't believe that AI use (or lack thereof) is about moral superiority. That's a dead-end argument that distracts from the bigger conversations we need to be having. The title of Gruber's blog -- which is "Anthropic's 'Watermark' Text Adulteration in Claude Is a Perversion of Writing" -- assumes several points, all of which could use a closer look: that Claude's text generation can be considered "writing" (a long-held debate); that the "perversion" is in the watermark, not in outsourcing writing (a process, not simply a deliverable) to a machine; and that watermarks -- not pre-training, model updates or changes, or shifting safety standards -- are the first major factor to skew what Claude generates. But this line of Gruber's stuck out to me the most: "The idea that anything other than my needs should factor into the generation of text for me is patently offensive." Claude is, and has always been, a product owned by a tech company; it was never optimized solely for the user. AI as the consumer-facing tool we now know might be unprecedented, but a tech company being a tech company under capitalism (and, increasingly, global policy) is not. We owe ourselves better than to ignore the logical fallacy in this expectation. We cannot afford to believe that Claude, or any tech product like it, is any individual's personal assistant first, regardless of how successfully it's been marketed to you. No matter how much time you've spent giving Claude data on how you prefer your AI-generated text, its loyalty (and Anthropic's) was never to you. The fact that Anthropic is choosing to adapt, if haphazardly, to real policy like the EU AI Act is just another reminder of this. AI labs are companies like any other, with whims and plans of their own -- this is hardly the first or last time one will switch up a product on you. Rather than expect unrealistic consistency or to be prioritized, the better choice is to invest in the writing you want your name on. Why we need AI transparency The point of policy isn't always to improve the quality of products, but to consider what the company behind that product has not (or has, but hasn't acted sufficiently on). Article 5 of the EU AI Act aims to do just that."It's unacceptable for a tool to sacrifice an iota of clarity, coherence, meaning, quality, etc. for the purpose of embedding hidden clues within the text to suggest its provenance," Gruber wrote in his blog.As products, yes, AI tools have a market-driven incentive to deliver the highest-quality responses. But provenance, albeit a deeply imperfect science, is crucial for a reason. Copyright debates aside, global trust in news hit a new low this year as more readers turn to chatbots for information. Misinformation is shaping elections, and human relationships with chatbots, especially for children, are devaluing knowing where information comes from and whether to trust it or not. Also: How AI could close the education inequality gap - or widen itAnthropic's watermarks are still half-baked. Though they will be machine-readable by detectors eventually, we don't yet have an accessible tool (like Google's SynthID Detector, on which Anthropic's watermarks are based) for the public to read them, and AI detectors themselves are notoriously unreliable. It's unclear how much these new watermarks will do for the information pipeline, academic integrity enforcement, and related issues. But provenance is a field worth investing in -- and if it impacts your experience of an AI tool, that might be a good reason to reevaluate your use of it. More reasons to write yourselfThat said, some arguments about the controversy surrounding Anthropic's watermarks are fair. As Sara Simeone, founder of NoCodeLab.ai, wrote on LinkedIn: "These labs scraped our content for years to build their wealth, without consent. Then they built one of the most ingenious revenue models ever: we pay them for regurgitated versions of what we already produced. Now we don't only pay. We also have to 'attribute our own IP to them'." There is an air of hypocrisy to watermarking the product of pirating (and then destroying) books, especially after you've settled a lawsuit with a group of authors over that (OpenAI disappeared its equivalent trove of book data). That doesn't even cover the tons upon digital tons of content AI companies have scraped off the internet, creators uncompensated, to feed their ever-capable, data-hungry models. (Disclosure: Ziff Davis, ZDNET's parent company, filed an April 2025 lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.)Then there's the question of where watermarking ends, as John McCarthy, opinion editor at The Drum, posed: "I'm even working on something that'll help me sort and respond to pitches. Should that be watermarked too? We're using AI to generate captions on our videos, and transcribe our interviews too. Watermark that? We're technically recording those on electrical devices. Is that AI? I have a soft AI filter on my zoom call to reduce my ugliness. Better watermark that too?"Also: Business adoption of AI agents tripled this year - as measurable ROI emergesHe's right to point out that not all editorial-adjacent work done with an AI tool should be watermarked as AI-generated. Anthropic has yet to clarify how it will approach these differences, and admitted in its first announcement that watermarks may or may not attach to smaller-scale edits done with Claude. But there's a deeper reaction to Anthropic, and AI labs writ large, beneath both these posts: that getting the economy hooked on tools that automate your work, only to turn around and place a tracker on said work in ways that could imperil it, stings like betrayal. But you can't be betrayed by a company that was never beholden to you to begin with.