Is removing Claude's watermark allowed?
What the EU AI Act actually requires of users versus providers, what institutional rules cover, and where the real risk sits.
Removing the watermark · 3 min read
Three separate questions get collapsed into this one. They have different answers.
1. Does the EU AI Act prohibit it?
Article 50 places its marking obligation on providers of generative AI systems — whoever supplies the model. Anthropic satisfies it by marking Claude's output. The article does not make editing that output an offence for the person who received it.
It also does not require the mark to survive editing. It requires marking; it sets no durability threshold. Anthropic's own documentation says the mark may not survive heavy editing, paraphrasing or translation — which would be a strange thing to publish if surviving editing were a legal requirement.
So: the regulation is not aimed at you, and normal editing of text you received is not what it regulates.
2. Does it breach Anthropic's terms?
Read them for your own situation rather than trusting a summary. But the ordinary use of a writing tool — receiving output and editing it — is what the product is for. There is a meaningful difference between editing text you were given and, say, building a service to strip provenance from material you intend to pass off as someone else's work.
3. Does it satisfy your institution?
This is the one that actually matters, and no tool touches it.
If your university, employer, journal or platform requires you to disclose AI assistance, that requirement is about what you did, not about what is detectable in the file. Removing a mark does not change the history. A disclosure rule is not satisfied by making non-disclosure harder to catch.
That is worth stating plainly because it is the actual risk. The legal exposure of editing text is negligible; the academic or professional exposure of undisclosed use is not, and it does not depend on any watermark existing.
Where legitimate use sits
Plenty of people have reasons to clean text that have nothing to do with concealment:
- Publishing workflows. Claude output is full of em dashes, curly quotes and single-codepoint ellipses. If your CMS or house style wants ASCII, you normalise it — same as you would with text from Word.
- Documents from third parties. If you are handed a file to publish, knowing what invisible characters are in it is basic diligence. Tag characters have been used as a prompt-injection vector.
- Your own writing that Claude proofread. You wrote it. The mark says "may have been processed by Claude", which is true and says nothing about authorship — but it is also indistinguishable from Claude having written it, which is a reason people want it gone.
- Privacy from per-recipient tracking. Hidden characters can distinguish copies of a document. Not wanting that is not suspicious.
What we will and will not tell you
We will not tell you removal is verified. Anthropic has not published a detector, so nobody can confirm a mark is present or gone.
We will tell you exactly what the character-level pass removed, with counts you can re-verify yourself, and that the rewriting pass is a paraphrase — the mechanism Anthropic itself names as degrading the mark.
And we will say clearly that if you have a disclosure obligation, this tool does not discharge it. That is between you and whoever set the rule.
Related: EU AI Act Article 50 · Claude's watermark and Turnitin · how to remove it