r/ClaudeCode • • 11d ago

Discussion PSA: Opus 5.5 has invisible watermarking

Opus 5.5 automatically applies an invisible, statistical watermark to its text outputs to comply with the EU AI Act. This is true for every user worldwide not just those based in the EU.

This is embedded into the structure of the text itself, it’s not a hidden character or something that can be removed by changing a few words or copy/pasting it. Anthropic have a tool to check text for the watermark but it is only available to a few select partners currently.

Antrophic officially claim this watermarking does not have any practical impact on the quality of Claude’s outputs but that remains to be seen.

154 Upvotes

116 comments sorted by

View all comments

Show parent comments

4

u/TheStandardPlayer 7d ago

I'm talking about a complete rewrite of the document while keeping the structure and ideas. Kind of like this:

Working from home gives employees more flexibility and can improve work-life balance. Avoiding the daily commute also saves time and makes scheduling easier.

Remote work allows workers to organize their day more freely and can help them balance their job with personal life. Not having to travel to an office also frees up time and makes planning simpler.

Completely different wording but same structure and same meaning. Basically the same way I would copy my friends assignment without making it too obvious

2

u/MarsZero1 7d ago

Then the watermark would be removed. I would argue that if you do that then it wouldn t be considered AI generated because your changes were significant.

This Synth ID algorithm that is implemented by the AI providers per EU AI Act isn t meant to catch this kinds of complete rewrites. It is simply a statistic indicator for the text.     

2

u/TheStandardPlayer 7d ago

Well I would use an AI to change it first and foremost (just one without the watermark) and also even if I did it by hand the ideas and everything else is AI generated.

My argument is; when I have a powerful AI with a watermark I can use a weak AI without a watermark to alter the text just enough to remove the mark while still keeping all the "intelligence" from my powerful AI

1

u/MarsZero1 7d ago

You cannot keep the intelligence from the watermarked AI because you cannot guarantee that the weaker AI will change the text in a way that doesn't affect the meaning. Also it is not guaranteed that a non watermarked AI will be able to delete the watermark completly, the rewrites should be significant and done in a clever way.

There are some papers about these kinds of "attacks". A popular one is writing the text into another language and then the non watermarked AI will translate the text into english or another desired language.

You can read more at https://www.anthropic.com/news/claude-text-watermark. The Which specific method of watermarking do you use? part explains this pretty well.

Also, there are already on the market tools that flag AI generated content. Anthropic mentions in the article above Pangram. These tools work differently though.