Watermark removers can clean hidden characters, strip file metadata, and rewrite text. Only rewriting targets the statistical pattern in the words—and success needs checking.
The three operations at a glance. Tools differ in which ones they support.
First, what is a text watermark?
A statistical text watermark is a detectable pattern in how a model chooses its words. Claude uses a version of SynthID Text, which adds no hidden characters. Anthropic's explanation
Models generate tokens: words, word fragments, or punctuation. When several next tokens are plausible, a secret key and nearby tokens help determine the sampling choices. Repeated across a passage, those choices leave a pattern that a matching detector can recognise. There is no universal list of "watermarked words." How SynthID Text works
The dots illustrate the pattern; they are not extra characters in the text.
1. Clean hidden characters
The tool scans for specific artifacts—zero-width spaces, unusual spacing, or invisible tag characters—and removes or normalises them. The example GitHub project uses scripts for this step.
That cleans the text, but does not remove the statistical pattern in its words. Invisible characters are not proof of AI use; some also serve legitimate formatting or language purposes.
Hidden artifacts are shown as labels so you can see the cleanup.
2. Strip file metadata
A file may record its author, generating application, or editing history. A remover can delete supported metadata fields, including embedded C2PA Content Credentials—signed provenance records. Some credentials can still be rediscovered through external records. C2PA's explainer
Deleting an "Author" field does not change the sentences. Their statistical watermark can remain. This step depends on the file format and metadata present.
Example fields; not every file contains all of them.
3. Rewrite to scramble the pattern
The tool rewrites the text to try to scramble the token sequence while preserving the meaning. Changing the words also changes the context used for subsequent token choices.
Thorough rewriting can reduce detector confidence; light edits may leave the watermark detectable. More rewriting can also change your message, so check the facts and meaning. SynthID Text's limitations
Illustrative rewrite, not a measured result. The highlights show wording changes.
Can Claude remove its own watermark?
Some removers run as Claude Code skills. A skill might run a cleanup script, ask Claude to rewrite, or call another model—the example project supports an external rewrite hook.
My expectation: a watermark-enabled Claude model could scramble the original pattern while generating a fresh one. That is a hypothesis, not a measured result.
That's what I want to test next: does a Claude-powered rewrite reduce detection, or simply leave fresh evidence?