We checked the Claude watermark tools. Most describe a mark that does not exist.
On 12 August 2026 we read the sites ranking for "Claude watermark detector" and "remove Claude watermark" and compared their own technical claims against Anthropic's documentation. None of them can detect Claude's text watermark. That was expected then, and it is still true now that Anthropic has one: since 1 September 2026 its detection API has been in private preview for organisations obliged to check under EU law, which none of these sites are[1]. The interesting finding is what they claim instead. Two describe the mark as invisible Unicode characters, which contradicts Anthropic's own description[1]. One is straightforwardly honest about the whole situation.
We are naming what each site says in its own words, and what the primary source says. Readers can judge. Where a site is accurate we say so.
What does Anthropic actually say?
The baseline for every row below. Claude weaves an imperceptible watermark directly into the text itself; it is not an added character but a property of the text, which is why it survives copy and paste[1]. Since 14 August 2026 Anthropic has said so in as many words — nothing is added to the text and there are no hidden characters — and has named the scheme as a version of Google DeepMind's SynthID-Text[10]. That removes the last bit of room the Unicode-stripping vendors had. Separately, Anthropic put a watermark detection API into private preview on 1 September 2026, for organisations that EU law obliges to check and for enterprises under the same obligation, by application[10][1].
Nothing below has been re-audited since 12 August 2026. The sites were read on that date, and two things have moved in the primary source since. On 14 August Anthropic stated outright that nothing is added to the text and there are no hidden characters, which contradicts the Unicode-based claims more directly than the source did then[10]. On 1 September it opened the detection API in private preview[1], so a site claiming to detect the watermark is now making a claim that could in principle be true of somebody — just not of a public web tool. Neither change rescues any row below.
What did we find?
| Site | What it says the mark is | Detects Claude's watermark? | Verdict |
|---|---|---|---|
| claudewatermarkremover.app | "Anthropic's new models can weave an imperceptible mark into generated text at sampling time" — correct | Does not claim to. States "Anthropic has not shipped a public Claude watermark detector yet" | Accurate |
| aidetectors.io | States "there is no official 'Claude watermark detector'", then falls back to style cues: hedging language, disclaimers, organised structure | No. Describes stylistic guessing, not watermark detection | Mixed |
| claudewatermark.com | Zero-width spaces, zero-width joiners, other invisible Unicode characters; also replaces em dashes[8] | No. A Unicode cleaner marketed against a statistical watermark | Mismatched |
| gpt-watermark-remover.com | "Claude primarily uses zero-width Unicode characters as invisible markers… Claude's algorithm strategically inserts these characters throughout generated text" | No. Removes U+200B, U+200C, U+200D, U+00AD, U+2060 | Contradicts the primary source |
Which three patterns did the tools fall into?
Honest, and technically right
claudewatermarkremover.app describes the mark correctly as applied at sampling time, states plainly that no public detector exists, and explains its own approach as rewrite-based neutralisation — a meaning-preserving paraphrase using a non-Claude model. That is the correct mechanism for defeating a statistical watermark, and the site says it cannot verify the result because there is nothing to verify against. We disagree with the purpose, but the technical description is sound. Its detector statement was accurate when we read it on 12 August 2026 and remains accurate in substance: the detector that arrived on 1 September is not public[1].
Correct about the detector, wrong about the alternative
aidetectors.io correctly tells readers there is no official Claude watermark detector. It then says Claude output is detectable through its stylistic signatures — hedging, balanced framing, disclaimers, organised structure. That is a classifier guessing from style, which is a different technology with a well-known false-positive problem, especially for non-native English writers. The distinction. Note also that the page asserts Anthropic has not deployed a checkable watermark at all, which the August 2026 documentation supersedes[1], and which the private-preview detection API of 1 September 2026 supersedes further[10].
A mechanism that was invented
gpt-watermark-remover.com states that Claude primarily uses zero-width Unicode characters and that Claude's algorithm strategically inserts them throughout generated text. Anthropic's documentation describes the opposite: a watermark woven into the text itself, not characters added to it[1], and its August 2026 explainer states outright that nothing is added and there are no hidden characters[10]. A tool built on that premise removes characters Claude did not put there, and leaves the actual mark untouched. claudewatermark.com sells the same Unicode-stripping mechanism, and additionally conflates Claude with OpenAI in its own copy[8].
A Unicode stripper is a real tool that does a real thing — some systems genuinely do insert zero-width characters, and you can check for them with our scanner for free. It simply has no effect on the watermark Claude actually applies. And because the only detector for that watermark is Anthropic's, in private preview for bodies obliged to check under EU law[1], no vendor can demonstrate that their removal worked, and you cannot check either.
How did we check?
We read each site's own public description of its mechanism on 12 August 2026 and compared it to Anthropic's help documentation[1]. We did not purchase any paid tier, and we did not test detection accuracy — that test is impossible to run meaningfully while no ground-truth detector exists, which is itself the finding. Quotations are from each site's public copy as published on that date.
Sites change. If one of these has corrected its description, tell us and we will update the row with the date. The underlying data is published, and the audit is reproducible by anyone with a browser.
Sources
Last verified against primary sources: