What is being measured is the mark's durability

Anthropic began marking every piece of text Claude produces earlier this month, and within days the counter-market appeared. Gizmodo, citing Business Insider, reports that search interest in AI watermark removers rose 60 per cent week over week, that an open-source project called Watermarks Remover passed 15,000 stars and thousands of forks on GitHub, and that an AI educator, Sabrina Ramonov, put up a web tool of her own. Anthropic applies the mark to satisfy the EU AI Act, which obliges providers to mark what their systems generate; no rule obliges anyone to leave the mark in place.[1]

What that tooling actually exercises is whether the mark survives editing; naming a source lies outside the test. A watermark that decides anything has to reach the reader intact after paraphrase, translation, reformatting and partial rewriting, and every one of these tools is a cheap trial of exactly that boundary. A second reading is at least as plausible: much of the demand may come from users afraid of being accused rather than from anyone systematically probing the mark. In that case the star count measures anxiety about detection and says little about whether the technique holds.[1]

What does the watermark not settle?

When this column looked at the mark on 11 August, the limits were already in the company's own description: editing removes it and proofreading leaves it in place, so the mark travels with a file without settling who composed the file. Anthropic has since written the same thing more directly, saying a watermark helps test whether Claude might have produced or processed a piece of content and says nothing about ownership or authorship. That is an unusually precise disclaimer, and it puts the burden where it belongs. It also means the removal wave is aimed at a signal that never carried the accusation people fear.[1], [2]

The asymmetry in the rules is the part worth holding on to. The EU AI Act places a marking duty on the provider, places no duty on the person who receives the marked text, and there is currently no rule stopping that person from stripping the mark. A duty that binds one end of the chain and leaves the other end free produces exactly the market Gizmodo describes, and it will keep producing it whatever the technique's error rate turns out to be.[1]

What can be measured from here?

The number to wait for is narrow and testable. If an evaluation is published by 31 October 2026 that runs marked Claude output through one of these tools and then through Anthropic's own detector, the figure that decides the mark's usefulness will be the false-negative rate on the transformed text; the accuracy reported on untouched output does not answer that question. Until that rate exists, the absence of a mark supports no conclusion about origin, and its presence supports only the narrow claim Anthropic already makes for it.[1]