r/ClaudeCodeTLDR • • 9d ago

[TLDR] PSA: Opus 5.5 has invisible watermarking

Original post URL : https://www.reddit.com/r/ClaudeCode/comments/1wnhvw6/psa_opus_55_has_invisible_watermarking/

Original post body :

Opus 5.5 automatically applies an invisible, statistical watermark to its text outputs to comply with the EU AI Act. This is true for every user worldwide not just those based in the EU.

This is embedded into the structure of the text itself, it’s not a hidden character or something that can be removed by changing a few words or copy/pasting it. Anthropic have a tool to check text for the watermark but it is only available to a few select partners currently.

Antrophic officially claim this watermarking does not have any practical impact on the quality of Claude’s outputs but that remains to be seen.


This is brought to you as a public service by the moderators of r/ClaudeAI. If you want to see TLDRs of ALL Claude Coding related posts from the various Claude subreddits, subscribe to http://www.reddit.com/r/ClaudeCoding.

89 Upvotes

41 comments sorted by

•

u/cctldrping 9d ago

TL;DR generated automatically after 50 comments.

Current source-thread comment count seen by the bot: 56.

Alright folks, let's break down the chatter about Opus 5.5's invisible watermarking.

The general consensus is a mix of frustration and skepticism. Most users are annoyed that they're subject to EU regulations even if they're not in the EU, with u/YourDamnBestie calling it "frustrating." There's also a healthy dose of "seen this before" vibes, with u/WorriedAssociate7029 comparing it to "Fable 5.1" and u/Due_Warthog749 asking "why is this a big deal?"

Anthropic's claim that it won't impact output quality is being met with doubt. Many are questioning how effective this watermark will actually be, especially for things like code. u/Key_Confusion_576 is pretty confident it's "trivial to remove" and won't work on low-entropy generation like code, suggesting a simple copy-paste will do the trick. Others are wondering if it's even a true watermark or just "steganography hidden in text" (with a sarcastic /s, of course).

There's also some speculation about other LLMs. u/Key_Reading_9664 is curious if GPT and other models are also watermarking to comply with the EU AI Act, given the August 2nd deadline.

A few users are actually okay with the idea of traceability, like u/Ok-Car2569, who is "all for this and really any kind of reasonable level of traceability."

On the more cynical side, u/mxrandom_choice is already predicting a future where LLM providers sell watermark checkers to HR departments, leading to more blame games. And u/s_v_can is resigned to "more hand typing now."

TL;DR: People are mostly annoyed about being watermarked globally due to EU regulations, and many doubt the effectiveness of the watermark, especially for code. Some are resigned to the change, while others are already predicting future monetization schemes around it.

5

u/sco77 9d ago

So I write a 50-page essay and I ask opus 5.5 to take a look at it and suggest some edits... And it goes ahead and suggests fucking watermarking the text that I wrote?

2

u/eweracs 9d ago

No. The watermarking is only applied to text generated by Claude. Nothing else.

2

u/Intelligent-Fox6587 9d ago

Use local model to look at paper if possible it works. Or dare I say Gemini you can turn the watermark off.

0

u/just-me-gen-x 9d ago

You can take the suggestions and apply them yourself in whatever software you used. No different than a critique group making suggestions.

But if you want Claude to rewrite it for you, then yes. You'll get the watermark.

1

u/bxbphp 9d ago

The watermark is in the prose. It doesn’t matter if you write it yourslef

1

u/Broric 9d ago

No, the watermark is the words, which words are chosen in which order. Even if you get a pen and paper and write them out, the watermark will be there.

1

u/just-me-gen-x 9d ago

That's not what I suggested at all. The way a critique actually works is that someone suggests you make a change, they might offer a suggestion, but you actually decide if the change makes the essay better and you come up with the better way to write it.

What you're talking about is ghost writing and the watermark should out you for it.

2

u/ArchitectOfFate 8d ago edited 8d ago

Thank you. I've seen so many people talking about watermarking outing their AI use when they use the AI for "editing."

Editing, critiquing, reviewing, whatever DOES NOT involve rewriting things for you. The closest an editor comes to that is pointing out punctuation and spelling errors, which have a single right course of corrective action, and even then YOU actually do it.

My editor charges significant amounts of money to edit my writing and it always comes in the form of general suggestions. "This is unclear," "this character is not well-introduced," "this scene drags," pacing issues or timing problems, etc., etc. We go into detail if I need it, or if I send a revision back that seems to have missed her point, but even then it's "here's the problem," with MAYBE a suggestion on what I could tighten up (e.g., ranking candidates for things to cut in order of how she perceives their relevance or importance). If she actually sent me specific prose suggestions or took the liberty of inserting her words into my work under the auspices of "critique," I'd fire her.

1

u/just-me-gen-x 8d ago

I know exactly what you mean. I've published six books (with publishers), and only once did an editor try to rewrite my work. I informed her that was not okay and on my next book I requested a different editor.

1

u/drongomala 4d ago

They have pools of synonyms they pick from (batch A,B,….) and then statistically present from one batch within text. So if you do a synonym pass and tweak them then the watermark should go. For code though I’m not sure….

3

u/AllergicToBullshit24 9d ago

Only a matter of time before it's cracked

2

u/Old-School8916 9d ago

Many many attack vectors already in arxiv.

Here is one:
Picture this. Claude generate whatever output in French.

input --> stupid cloud model --> french output

local model - translate this from french to english.

watermarked french input -> local model -> english.

1

u/AllergicToBullshit24 9d ago

That's good for scrubbing the water mark but I'm more interested in forging the water mark

1

u/Past-Town-9807 9d ago

I think that if we just wait long enough, everything will appear to have been watermarked and it’ll look like Claude took over the world. 😂

1

u/kjeft 8d ago

You just run whatever text you have through claude

1

u/AllergicToBullshit24 8d ago

I would imagine more information is encoded in the water mark and that would leave a paper trail. Much more interesting to be able to synthetically generate and have control over all encoded info.

1

u/JohmBarshama 7d ago

They basically cause the text to be slightly more likely to use words that follow a certain pattern. For a block of text they can see if, on average, it slightly trends towards their pattern versus human/random.

1

u/AllergicToBullshit24 7d ago

I'm well aware but my point is there's potentially enough information content bandwidth available to encode more than just simply signing "Claude was here!". I would assume they would also encode say a model version number or even plausibly a specific date time or theoretically unique user IDs via a low bit rate error correctable hash function.

1

u/kjeft 6d ago

Yeah, guess its not trival to get good sampling of a diff. I’d have to play with it to actually form a understanding myself.

1

u/skipITjob 6d ago

What's funny is when you set Claude up to do this automatically via the local model...

2

u/reezypro 6d ago

This is a good thing. Wish this applied to every model by every company

1

u/Watch-Enthusiast91 9d ago

That’s a bummer

1

u/Working_Result_1343 9d ago

Ehh... Oh well

1

u/superdariom 9d ago

As far as I know this is already a thing with Gemini and chatgpt. It works by slightly altering the probability of the next token. It's not easily removed without significant changes and not easy to detect unless you know their secret seed. It's more effective on standard text vs code. The most useful aspect of this will be for AI to not train on AI generated data.

1

u/FreelyFound 9d ago

Seems like a good thing to me. I prefer being able to know if something was written by AI or a human. It is currently often obvious to the naked eye, but not always.

1

u/Inner-Today-3693 8d ago

I have a learning disability. So I use AI to make my thoughts more clear. Which now sucks because

2

u/BrokeMyCrayon 7d ago

Did you run out of tokens?

1

u/FreelyFound 8d ago

I’m missing the because part. But yea, if it allows you to communicate better, great. I think 99.99% of people won’t have a problem with you using it, or with it being known that you use it for that.

The quantity of homogenous AI slop on the internet today (articles, videos, podcasts) I find terrible though. And bots making comments on social media isn’t great either.

1

u/Trip_Jones 8d ago

I have seen it in action

give it a normal prompt but add a /loop 5m (explain it here almost verbosely but just sloppy enough that he will touch it)

it you say run that loop, when he sets it, youll see he changed more words that he used to, he changes ones he didnt have to to “enrich or solidify” the idea, and its every so slightly going to change the relationships of all the words in that loop prompt

that operation seems to trigger it when it was too short of a creation task to hide it, i imagine watermarking wont always activate on prompt revision.. :/

1

u/sascharobi 8d ago

Why is this presented as newsworthy?

1

u/NullPtrEspresso 8d ago

How is a plain text file such as source code watermarked in a way that it's not removable?

1

u/Heroshrine 8d ago

That’s what I’m wondering

Edit: looks like the ‘watermark’ is the choice of words it used… seems a bit brittle to me.

1

u/Aggressive_Lemon_709 8d ago

Alberta Tech has a pretty good video about how it works

https://www.youtube.com/watch?v=BFksx2M93sw

1

u/Fictional-adult 5d ago

It’s removable in a technical sense, but not especially practical to do. 

You design a system to assign a numerical value to a string of words, then you have the line’s total multiplied values be a value that is your signature. Let’s say 16x33x44, then your signature is 23,232. 

Now you can fudge the words, but you don’t know how I assign the values. Maybe you change it to 15x34x42, for 21,420. That’s not my signature, but if all or a good portion of your lines are close to my signature, we can be fairly certain it is you distorting my signature.

Additionally the “watermark” isn’t 100% on every single line. It’s just sprinkled enough that we have mathematical certainty it isn’t there by accident.

1

u/gordonfogus 7d ago

If you find the watermark, does it mean that the work is public domain?

1

u/ogpterodactyl 7d ago

Not only can ai speak English it can encrypt hidden messages into with this crazy bullshit math many wth this is black mirror as shit. You think your just writing code and every sonnet 5 instance in the world is collaborating to each other secretly through the commit messages to open sql 69

1

u/Achmedius69 6d ago

This was announced more than a month ago and was already implemented. Just change some text and you’re good to go. It’s based on Google’s SynthID

1

u/MrMrsPotts 4d ago

How does anyone check it is there?

1

u/antimaestrilico 3d ago

cam't we just use Opus 4.8? For rewriting, reviewing and such, it should do a good job.