Key takeaways
- Statistical watermarks such as SynthID live in the model's word choices. Nothing is inserted, so nothing can be stripped — only rewriting changes them.
- Invisible Unicode characters are real, are genuinely removable, and are what almost every free watermark remover actually deletes. They are usually chat-interface artefacts, not a deliberate watermark.
- C2PA metadata travels with a file rather than the words. It does not survive a re-save, a format conversion or a screenshot.
- Claude has carried a SynthID text watermark since 2 August 2026. Gemini has carried one for longer. ChatGPT has no deployed statistical text watermark.
- If a tool promises to remove a statistical watermark and shows you a green checkmark instantly, it checked for hidden characters and found none.
The three different things called an AI watermark
This page is about text
If you are trying to remove a visible logo or watermark from a photo or video, this is the wrong page — that is image editing, and it works nothing like what follows. Everything here is about marks in written text.
Most of the confusion in this area comes from one word covering three unrelated technologies. A tool that removes one of them may be completely useless against the others, and the marketing rarely distinguishes them.
| Type | Where it lives | Can you strip it? | Can you verify removal? |
|---|---|---|---|
| Statistical (SynthID) | In which words the model chose | No — only a rewrite changes it | Only if the provider publishes a detector |
| Invisible Unicode | Extra characters inserted between words | Yes, trivially | Yes — you can see them in any inspector |
| C2PA metadata | Attached to the file, not the text | Yes — it is discarded on re-save | Yes — metadata is readable |
Which AI tools watermark text right now
| Model | Statistical text watermark | Notes |
|---|---|---|
| Claude | Yes, since 2 August 2026 | SynthID-Text, worldwide, on models launched on or after that date. No public detector yet. Files also carry C2PA metadata. |
| Gemini | Yes | SynthID across text, image, audio and video. Google operates a public SynthID Detector. |
| ChatGPT | No | OpenAI built a text watermark and did not deploy it. Its images carry C2PA metadata. |
| Open-weight models | Generally no | Anyone running a model themselves controls the sampler, so watermarking is opt-in. |
The direction of travel is one-way. Article 50 of the EU AI Act places a machine-readable marking duty on providers of generative AI systems, and providers have mostly chosen to apply it globally rather than run separate models per region.
How to tell which one you have
Work it out in three steps
- Check for invisible characters first. Paste the text into any Unicode inspector. If it reports zero-width spaces, joiners, byte-order marks or narrow no-break spaces, you have inserted characters — the removable kind. This takes seconds and rules the easy case in or out.
- Ask where the text came from. If it came out of Claude or Gemini after their watermarking rollouts, assume a statistical mark regardless of what step one said. The two are independent and you can have both.
- Check whether you are dealing with a file. If the concern is an image, video or audio clip rather than text, you are almost certainly looking at C2PA metadata or an image watermark, which is a different problem with different answers.
The two are not mutually exclusive
Text copied out of a chat interface can carry invisible characters from the UI and a statistical watermark from the model at the same time. Cleaning the first does nothing to the second, which is exactly the misunderstanding most removal tools rely on.
What removes each type
| Type | What removes it | What does not |
|---|---|---|
| Statistical (SynthID) | A full rewrite in which the word choices change | Character cleaners, find-and-replace, reformatting, re-saving |
| Invisible Unicode | Any character cleaner, or a one-line regex you can run yourself | Rewriting is overkill — deletion is exact and instant |
| C2PA metadata | Re-saving, converting format, or screenshotting | Editing the text has no effect on file metadata |
Anthropic's guidance on the statistical case is the clearest public statement anyone has made about it: light editing probably will not remove the watermark completely, but a complete rewrite where every word is replaced will. Heavy editing, paraphrasing and translation all degrade it to varying degrees.
Why most watermark removers only strip invisible characters
Deleting invisible characters is easy to build, instant to run, and produces a satisfying report showing exactly what was removed. Rewriting a passage is slow, costs money to run, and cannot show you a clean before-and-after count. So the market filled up with the first kind.
That would be fine if the labelling were honest. Instead, a wave of tools launched in August 2026 marketing character cleaning specifically as Claude watermark removal — for a watermark whose own documentation says it adds no characters.
The verification gap
BleepingComputer's survey of these tools concluded that almost none can prove they work. For statistical watermarks that is structurally true right now: Anthropic has not released its detector, so no claim about removing Claude's mark — from any vendor — can currently be checked by anyone outside Anthropic.
Rewriting text with RewriteAI
RewriteAI is a full-rewrite paraphrase engine. It re-expresses a passage rather than scanning it for hidden marks, which is the mechanism that applies to statistical watermarks. It does not strip invisible characters, and it does not claim to verify that a watermark is gone.
Free plan: 500 words per month, 300 words per request, English only, account required.
Is removing an AI watermark legal?
In short: the EU AI Act's marking obligation falls on AI providers, not on individuals using content they generated and own, and the penalties attached to Article 50 apply to providers and professional deployers. Publishing realistic synthetic media carries a separate personal disclosure duty, and institutional rules are a matter of your agreement with the institution rather than the law.
- The full legal picture — who Article 50 actually binds, and the two exceptions
Start with the model you used
- Claude watermark remover — SynthID since 2 August 2026, and no public detector yet
- Gemini watermark remover — the longest-running SynthID deployment, with a published detector
- ChatGPT watermark remover — no text watermark — what those invisible characters really are
Sources
- How Claude's text watermarking works — Anthropic
- Scalable watermarking for identifying large language model outputs — Nature, Google DeepMind
- SynthID: Identifying AI-generated content — Google DeepMind
- Article 50: Transparency obligations for providers and deployers — EU AI Act
- AI watermark removers flood the web. Almost none can prove they work. — BleepingComputer