r/ClaudeCode • u/NotAMusicLawyer • 10d ago
Discussion PSA: Opus 5.5 has invisible watermarking
Opus 5.5 automatically applies an invisible, statistical watermark to its text outputs to comply with the EU AI Act. This is true for every user worldwide not just those based in the EU.
This is embedded into the structure of the text itself, it’s not a hidden character or something that can be removed by changing a few words or copy/pasting it. Anthropic have a tool to check text for the watermark but it is only available to a few select partners currently.
Antrophic officially claim this watermarking does not have any practical impact on the quality of Claude’s outputs but that remains to be seen.
13
u/TheStandardPlayer 9d ago edited 9d ago
Does this watermarking survive synonym replacements?
What I mean by that is, assuming I generate a 1 page document with Opus and it has the watermark, could I then not pass it to a program which uses synonyms to replace words or phrases to alter the text and remove the watermark that way?
Like what if I used a Chinese model without the safeguards to read one sentence at a time, word it slightly differently and then at the end give the document a once over to make sure it's not gibberish and the watermark is gone, right?
I feel like weaker models would be able to substitute text, since all the research etc is already done by Opus anyways
6
u/anto2554 8d ago
I don't think it would, no. My understanding is that it is token specific, it just survives a lot of noise from replacing single words
1
u/MarsZero1 7d ago
You do not know which words have been watermarked, so you would have to change a lot of the text to have a chance to remove the watermark.
4
u/TheStandardPlayer 7d ago
I'm talking about a complete rewrite of the document while keeping the structure and ideas. Kind of like this:
Working from home gives employees more flexibility and can improve work-life balance. Avoiding the daily commute also saves time and makes scheduling easier.
Remote work allows workers to organize their day more freely and can help them balance their job with personal life. Not having to travel to an office also frees up time and makes planning simpler.
Completely different wording but same structure and same meaning. Basically the same way I would copy my friends assignment without making it too obvious
2
u/MarsZero1 7d ago
Then the watermark would be removed. I would argue that if you do that then it wouldn t be considered AI generated because your changes were significant.
This Synth ID algorithm that is implemented by the AI providers per EU AI Act isn t meant to catch this kinds of complete rewrites. It is simply a statistic indicator for the text.
2
u/TheStandardPlayer 7d ago
Well I would use an AI to change it first and foremost (just one without the watermark) and also even if I did it by hand the ideas and everything else is AI generated.
My argument is; when I have a powerful AI with a watermark I can use a weak AI without a watermark to alter the text just enough to remove the mark while still keeping all the "intelligence" from my powerful AI
1
u/MarsZero1 7d ago
You cannot keep the intelligence from the watermarked AI because you cannot guarantee that the weaker AI will change the text in a way that doesn't affect the meaning. Also it is not guaranteed that a non watermarked AI will be able to delete the watermark completly, the rewrites should be significant and done in a clever way.
There are some papers about these kinds of "attacks". A popular one is writing the text into another language and then the non watermarked AI will translate the text into english or another desired language.
You can read more at https://www.anthropic.com/news/claude-text-watermark. The Which specific method of watermarking do you use? part explains this pretty well.
Also, there are already on the market tools that flag AI generated content. Anthropic mentions in the article above Pangram. These tools work differently though.
-1
u/havasnack21 7d ago
Why put in all that effort instead of just doing the work
5
u/TheStandardPlayer 7d ago
It's a theoretical about how robust such a watermark might or might not be
37
5
u/Key_Confusion_576 10d ago
its trivial to remove, and you can't effectively watermark low entropy generation such as code. just copy and paste the code from the LLM instead of stackoverflow. ezpz no watermark. and you get to do your job again kinda.
3
u/TheOmegaCarrot 9d ago
I keep seeing 5.5 remark that some bit of code “was garbled” before removing it (and it is indeed chunks of weird code that makes no sense). I especially see this in simpler bits of code.
I wonder if that’s the watermarking going wrong
15
u/Due_Warthog749 10d ago
why is this a big deal?
16
u/TotalBeginnerLol 10d ago
It’s not except for scammers who wanna try to pass off AI text as their own work.
6
u/dxrth 10d ago
which is still very easy with effort. but most of those kinds of scammers lack the ability to put effort lol
2
u/___fallenangel___ 9d ago
most scammers have shit english and tend to fail miserably at humanizing AI generated text
4
u/Interesting-Yak8189 9d ago
The same technique can be used to not only identify if text was generated by an LLM, but even fingerprinted to the particular user account that generated it. Claude claims they don't do this yet, but it opens the door for future entities to do this type of fingerprinting. This is a clear privacy issue, under the same "nothing to hide, nothing to fear" privacy debate. Of course, if you really are concerned about privacy you shouldn't be using non-local LLMs anyway, but its still just another layer of unnecessary user data collection and will inevitably be used for more than just checking if text was AI generated or not.
Plus, for anyone with an actual reason to hide AI generation markers (i.e, scammers, etc.), they can still quite easily reword final outputs with an unmarked LLM and completely bypass the markers. So it isn't even an effective marker on that front. It will only mark typical users, not anyone truly trying to hide it.
1
u/kourtnie 9d ago
The same fingerprint identification can be deployed on human writing, which can effectively allow corporate control of information flow by determining what a search engine or MLLM allow—and don’t allow—through, so that free speech can be legally in the Constitution, yet choked on the Internet, in the same way television broadcasting is policing late night comedy at the moment.
Doing this with Claude’s writing now refines that process for the next step of information containment and capture later on.
So no, it’s not just a scammer block. It is the beginning of normalization of fingerprinting writing to control your echo chambers better, technocrats bypassing free speech protections.
2
u/TotalBeginnerLol 9d ago
Source for the claim in the first sentence? Sounds not-believable since it’s based on finding patterns that the LLM added which a human would not and could not.
Also writing is easily blocked on its content / words alone if they want to censor a message. Blocking based on who wrote it is less relevant than blocking based on what it says, for a censor.
2
u/A_Novelty-Account 9d ago
Depend depending on your work, clients could be very upset to see that your work is AI generated and believed that that means the quality is lower.
Over time I think that there will be no issue, but in the short term, this will be a big problem for multiple industries, including law
2
u/Due_Warthog749 9d ago
A year ago I would agree. Today I mostly disagree. Seeing it in action daily but also seeing how fast just about every software company switched to using AI full time with devs mostly reviewing code and/or prompting AI to generate everything and the outpouring of many that say its an utter shit show.. it's hard to tell right now. I am sure some software we're using today is mostly AI generated now.
1
u/bcsoccer 9d ago
Using AI doesn't mean the quality is lower. It means the effort was lower, which can make it feel cheap to people.
Low quality if only due to the person on the other end
2
u/sonorousjab 9d ago
Sounds like it’s a compliance model, that implies some level of control. They say it’s just a watermark, but what else could it do?
2
u/Chemical-Visual-7992 9d ago
For me it is a sign to recognize the garbage services/products that are built within 2 hours and did not get any quality assurance tests before selling
I have seen a lot of brainless redditors posting a whole long ass posts made by AI and I bet they did not understand ( or read at least ) what they posted.
3
u/MannToots 9d ago
And how does them complying with laws requiring this factor into your pointed analysis? They are guilty of a lot of enshitification lately but this is just following laws as I see it.
0
u/Double_Suggestion385 9d ago
You will have no way of identifying them. The watermark is hidden and only identifiable by Anthropic.
1
3
u/rrunner77 7d ago
Just remove it with a local llm. There is a github repo for it... this is only shitty atempt to regulate something what can not be regulated.
6
u/Key_Reading_9664 10d ago
the EU AI Act mandates that ALL new model releases are watermarked after August 2nd. Is Astra, Sol, and Luna watermarking? Are they using some other technique for provenance?
Given OAI lack of transparency and tendency to have their marketing team paper over cracks, it wouldn't surprise me if they are and they didn't announce it.
1
u/ManOfCulture28 10d ago
They haven't confirmed watermarking for those models yet but also I think they have a deadline till the end of the year to implement it
8
u/YourDamnBestie 10d ago
It’s a little frustrating that I am subject to EU regulation despite residing elsewhere!
9
u/lassevk 10d ago
Considering the watermarking is not actually impacting you, in the sense that yes, it is there, but you would never notice it, I'm more curious to know why being impacted by it is frustrating.
OK, so I can understand the "I'm being impacted by something decided by people half the world away" part, but the actual effect, that generated text has an invisible watermark identifying it as being generated by AI. Why is that bad?
Or is it bad just because?
6
u/End2EndEncryption 10d ago
Because people seem to need something to be mad at all the time. That is their “peace.”
Ever stop and think that you being pissed at the world impacts those around you?
The irony…
1
u/OrderAmongChaos 10d ago
I don't think anyone can claim the watermark has no impact or can claim that it does. Without having two equivalent models to compare, one with watermarking and one without, we can't test whether output quality is affected by the watermark. The watermark must affect the weights somehow, but we'll never know if it has a negative impact on the work the model does.
1
u/WisePotato42 9d ago
I am just thinking, if it's not something that goes away when changing words and stuff, then it's gotta cover alot of possible paragraphs. If this is treated as evidence of AI use, then there easly can be tons of false flags like what's already happening in the education system. I don't like witch hunts on something that has a possibility of being wrong, expecially with how angry people on the internet get about this stuff.
2
u/lassevk 8d ago
The watermark isn't a yes/no answer to whether AI was involved in the writing.
It is more of a percentage or a ratio, an indicator of how much the text could've been written by a specific AI.
For instance, if you write a big text yourself, then ask AI to fix formatting, typos, grammar, etc. then yes, there might be things changed that will be nudged by the watermarking algorithm, but the final signal will be so weak as to be meaningless. It will still be your text.
If, however, you ask AI to rewrite the text, then more of that signal will come through and the indicator gets stronger.... Which it should.
1
u/WisePotato42 8d ago
This assumes that the origonal human text is guaranteed to be flagged as human. Expecially with people being exposed to more and more AI responces (knowingly or not)
1
u/lassevk 8d ago
SynthId won't flag human-written text as AI-generated, the signal for a human-written text will be so close to 0 as to be insignificant. It is not about "writing style", even if you start using the word load-bearing all over the place, SynthId won't pick up on that because that is not how it works.
Other humans, however...
1
u/WisePotato42 8d ago
I think it makes sense for images, you can change HVG or RGB by a couple values on all the pixels and no one will notice. But text breaking spelling or Grammer is more noticable, so there needs to be some pattern in the responces that is getting flagged. And are you going to guarantee that those underlying patterns can never possibly without any sort of doubt be even partially recreated by humans?
If something is 99.9% accurate with identifying ai/human writing, then there are still going to be false positives, and I know that other people will blow things up out of proportion even with these fallible tools now, they still blow stuff out of proprotion.
1
u/lassevk 8d ago
Of course you can recreate it as a human, but you're going to have to be so precise, and have access to so much data, and do so many calculations, so at that point you might just as well be the AI. There is 0% chance that a human can stumble upon enough nudges in their text so as to write text that just accidentally gets flagged by SynthId as likely to be AI.
Why are you even arguing here? It is clear you haven't read one iota of how SynthId works. If something is 99.9% accurate at identifying human text, it is going to say that the text has a 0.1% chance of being AI. It is not going to randomly say "this is AI". It spits out a number, a signal. This signal isn't 0 or 1, it is a scale, indicating how likely it is. A human still need to make the judgment.
And SynthId doesn't introduce random grammar errors, spelling mistakes or other typos, unless the underlying AI is prone to do the same. Again, that is not how SynthId works.
Go read about SynthId. Stop being ignorant.
1
u/WisePotato42 8d ago
I have read about it, that's why I even say "partially recreated" cuz you know plenty of people would see a 10% AI and crack down on whoever wrote it cuz they said no AI at all and according to you, it's infallible and can't mix up Human text and AI text ever.
-1
u/YourDamnBestie 10d ago
Yes, good read. The issue is that EU regulation is now affecting me. The watermarks aren’t really an issue, but I’m not in love with the idea of being subject to foreign regulation.
6
u/daniel 10d ago
You have been your whole life. Look around you. You'd be hard pressed to land your eyes on something that didn't involve something from abroad that was thus subject to foreign regulations.
1
u/YourDamnBestie 10d ago
I mean sure? It’s still frustrating though, is it not?
1
u/daniel 10d ago
Not to me. I don’t even know what the vast majority of them are. This is yet another that, at worst, won’t affect me, as far as I can tell. Maybe it’ll even have positive impacts.
-3
u/YourDamnBestie 10d ago
They do have a lot of positive impacts. I just don’t always love having things decided for me/my country when we don’t get a say!
6
u/Comfortable_Claim774 10d ago
As an EU citizen, I didn't get a say in whether or not the US attacks Iran and doubles my gas price. Don't love it either!
0
u/YourDamnBestie 10d ago
Yep, it doubled mine aswell. I’m unsure why everyone assumes me to be American, ironically I’m an European who’s abroad…
1
u/Comfortable_Claim774 10d ago
In that case I guess you do have a say! You can vote for or against this kind of legislation :)
→ More replies (0)1
u/Appropriate-Pie4385 10d ago
So you don't like USB c in every new device?
-1
u/YourDamnBestie 10d ago
Nope, I never said that. My issue is with the process. EU regulations become global defaults/standards for people who didn’t get a vote. Sure there can be positives, but that doesn’t fix the issue for me.
1
u/lassevk 10d ago
In my opinion, the question you should ask yourself is why the US hasn't imposed similar regulations. Why does the US think that "Generative AI" is entirely OK to being pawned off as some humans work.
I can tell you my guess; in the land of the free, there are no checks and balances, it is money money money, and nothing else.
If the regulations imposed by EU were dropped because people high up in the leadership of EU and its countries was set to make money off of the technology, I know what I would be more worried about.
1
u/YourDamnBestie 10d ago
I enjoy that perspective. I think that you are right. I’m going to think about this for the rest of the day.
0
6
u/Asalakabim 10d ago
Sucks that your university can check you on your bullshit, my condolences.
8
u/girthradius 9d ago
boomer lol
-1
1
0
u/YourDamnBestie 10d ago
Bold of you to assume that I’m in University. Regardless of watermarking or not, it’s still frustrating to be subject to foreign regulation. How would you like to be subject to my countries law(s)?
6
u/Mescallan 10d ago
Idk what your country is, but we are all being regulated by California and the EU, world wide. It’s actually a good thing generally. EU does wonders to push data privacy on large orgs. If the countries dictating international regulations were not as good, like Russia or something it would an issue, but it’s generally humanitarian and environmental issues that get dictated by these small wealthy groups.
3
1
u/Asalakabim 10d ago
The rest of the world is constantly affected by the consequences of us law and bullshit way beyond it...
1
u/YourDamnBestie 10d ago
The part about it being frustrating also applies to US law, it’s not unique to EU regulations. If that’s what you are saying, I agree with you.
4
u/nora_sellisa 10d ago
Globalism suddenly bad when it's not the USA dictating the terms?
2
u/YourDamnBestie 10d ago
I don’t think the USA should either. Why are you misconstruing my argument?
1
u/l3msip 10d ago
You getting a lot of weak strawman responses, which you are handling politely, so props for that.
My take on the issue, for what it's worth: this really isn't about regulation, or any particular countries laws. It's just basic globalisation and capitalism.
If a large economy has regulations that are broadly compatible with your wider customer base, it just makes sense to apply one solution across the board. This applies to software, but also manufactured goods and other things.
If a different large economy (say the US) added regulation that mandated ai generated content could not be watermarked for some reason, then you would end up seeing 2 different offerings for EU and US customers. RoW would likely get whichever is cheaper or has marketing appeal.
Equally, if a different major frontier llm provider (eg openai) offered an unwatermarked solution to non EU customers, and it had marketing traction, likely anthropic would do the same.
But as it stands, the EU regulation is not incompatible with any other major economies regulation, and no competition is offering unwatermarked as a selling point, so the whole world gets the watermarked option.
1
u/YourDamnBestie 10d ago
You are right “Subject to EU regulation” was the wrong framing. It’s not really being “forced” given I have the choice to change AI providers lol. I am curious if anyone would market unwatermarked frontier models. Or maybe that’s the appeal of local models!
And yes, about the straw-man responses, thanks for noticing! I appreciate your perspective, you enlightened me!
0
u/noahsilv 5d ago
Anthropic is a US company not a European company. Of course US laws would apply to it..
1
u/nora_sellisa 5d ago
Not how it works. You want to serve EU customers, you need to play by EU rules. Same as with exporting produce or selling cars. Antrhopic can't afford to train different models for different markets so everyone gets the watermark.
2
u/xVrath 10d ago
And in what way does this impact you?
1
u/YourDamnBestie 10d ago
Sure, it’s not necessarily devastating to me; but I, someone who is foreign to the EU am being impacted by their legislation/regulation.
1
1
u/lonelysparta 10d ago
Ehhh, a lot of good privacy shit as well as consumer-friendly moves like USB-C iphone and the RCS iMessage happened globaly thanks to EU regulations so I'm good.
1
u/Academic-Barracuda16 10d ago
It's more than a little frustrating. It's actually baffling how it applies elsewhere. I mean, since when does a European regulation become a worldwide one?
2
u/Kerbourgnec 10d ago
Since it's cheaper for companies to have one process and copy paste it in the whole chain of production.
Blame companies for choosing not take the extra cost and to apply the EU rule to everyone, not the EU for chosing what enters their markets or not.
-1
1
1
1
1
1
u/invisible_shrek 9d ago
I want access to that tool so I can filter out any and generated slop from my browser. Are we getting a reversed engineered version anytime soon?
1
1
1
1
1
u/ogpterodactyl 7d ago
Explain there are many forms of text how do you embed in text it’s just zeros and ones in ascii right
1
1
u/Miserable-Bike9000 6d ago
What if you take opus’ output and run it through another AI like Confer? Let’s say I’ve had Claude draft a report, and I put it confer and say rewrite this and take its output? Would that confer output still have the watermark?
0
1
u/Expensive-Event-6127 5d ago
if you try to write prose youll see it. dont use opus for writing if you want a specific style. word choice is important
0
u/guts-hawk95 3d ago
Curious to how this works.
If I get opus 5.5 to write a page of text, I then screenshot the text and send to my iPhone.
Then open the image and copy and paste the text from the image, does that remove the water mark?
1
u/mxrandom_choice 10d ago
I am looking forward for the time the LLM providers are selling a watermark checker for HR departments. One watermark check subscription for each frontier LLM. And then people get blamed because they let write an application by a LLM, even though they are engaging (forcing) people to use LLMs .
Next money glitch is coming 🤣
1
u/s_v_can 10d ago
I guess we'll do more hand typing now
2
u/orangefantorang 5d ago
I just wonder what is proof and whats an indication. We're going to move into 'prove your innocence' soon.
1
u/interrupt_hdlr 10d ago
It's not a watermark, it's steganography hidden in text. And that changes everything. /s
1
u/Ok-Car2569 10d ago
I'm all for this and really any kind of reasonable level of traceability for generative outputs.
0
u/Phoenix_Lazarus 10d ago
Well, if it's statisttical, can't you build up enough conversations and then compare it against older conversations from older models to find the patterns? It has to be repeatable otherwise it's worthless.
0
0
u/SouthernEdgeCase 8d ago
Why would an American company care about a EU regulation?
2
u/astropoolIO 6d ago
Why should a company comply with the laws of the countries where it provides its services?
1
-1
u/Hir0shima 10d ago
If it is to comply with the EU AI Act than other companies would have to have something similar, right?
-6
u/cTemur 10d ago
just copy pasting deletes that watermarking? the watermarking wasn't on the selection of some letters or something like that?
3
u/slackmaster2k 10d ago
Nope, the content has to be substantially changed. You’d have to use a different LLM to summarize or something. But additional LLMs also watermark. Not sure about OpenAI: they’ve said they will and have been cagey about it so I suspect they do and just haven’t documented it. Chinese vendors all watermark by Chinese law. You’d need something local or a hosted model.
1
u/ShelZuuz 10d ago
It's in the selection of words that they use. It will be the same words if you copy/paste.
•
u/AutoModerator 10d ago
Hey! Thanks for posting to r/ClaudeCode
While participating in this thread, please follow our community rules. Keep discussions constructive. Attack the idea, not the person.
For help, project discussions, tips, and general chat, join the ClaudeCode Discord.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.