How Claude's text watermarking works

surprisetalk 45 points 54 comments August 14, 2026
www.anthropic.com · View on Hacker News

Discussion Highlights (20 comments)

whalesalad

Seems pretty easy to defeat by running text output through a random reworder process that would effectively repeat the same routine on low-stakes words, replacing them with similar ones. We learned this in high school, jumping through your paper and hitting random words with the thesaurus to 'sound smarter'

mrcwinn

“How does affect Claude’s outputs?” Is poor proofreading a form of watermarking? Clever, I suppose, but they should consider running posts through Sol for clarity.

soupspaces

Yesterday https://news.ycombinator.com/item?id=49292932

mlmonkey

Can anybody take a body of text and determine if it's from Claude or not? (Or if it's AI-generated or not)?

jazzpush2

Anthropic: doing everything they can to own any output they produce/prevent scrubbing of association for them - except when it comes to the CEO's wife's porn funding attempt from Epstein: https://www.wsj.com/tech/ai/claude-dario-amodei-wife-anthrop...

absoluteunit1

> Google DeepMind tested this impact by serving a model that used watermarking to a portion of their Gemini traffic and comparing thumbs-up and thumbs-down ratings. They found no statistically significant differences from the unwatermarked model. And in a controlled study, human raters comparing watermarked and unwatermarked answers side-by-side saw no difference in quality. For some reason I had assumed testing this would be more sophisticated than just checking the thumbs up/down stats and user "vibes"

visiondude

I’d like to better understand the minimum text length to get a confident result, i would presume it would need to be quite long, perhaps > 1000 words to get an accurate result.

jluysvi

Opus 5 must be the pilot becuase it's writing style is so grating it has to be intentional. Let's hope they make it more subtle in the future.

pr337h4m

We are very fortunate open source models have reached parity for virtually all non-coding use cases.

arjie

Interesting. Here's the section of the EU Act that mandates this: > Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng It definitely makes Pangram's job a bit easier.

johnfn

> We will soon be offering a watermark detection API. We’re in the process of working out the details of its implementation. Dumb question - doesn't this defeat the purpose of a watermark? i.e., anyone who wants to avoid detection can simply run `while (has_watermark(text)) text = slightly_rewrite_with_non_anthropic_llm(text)` until it's gone? I feel I am missing the intent of the watermark if it is so easily defeated.

efavdb

The method of identifying authorship isn’t new. I guess the main new thing here is to ensure Claude has a specified word distribution so you can identify its writing. https://towardsdatascience.com/text-classification-and-the-b...

himata4113

From what I understand when you re-tokenize the output you can simply look at how often certain tokens show up and the position of them, enough of these matches would result it watermarked text. Let's say we are at token 431 and there is 49% to generate token 1 and 51% to generate token 2, we apply bias to our token 1 which would make it win causing a repeating pattern invisible to the human eye. Now you apply this to multiple tokens and a reversible source of random you have a pretty strong watermarking system... That is rather annoying to defeat as you essentially have to rewrite most of the text. The alternative is to use a diffusion model and spray some gaps across non-literal information such as ids, links, etc.

cantalopes

Tldr: prng seed

lowbloodsugar

>But if we could see the sequence of all the moves after the game (and we knew the value of pi), we could work out whether this was a game that likely used pi to determine its moves. The game that used pi is, in a sense, “watermarked”. Wouldn't pi contain any such sequence of numbers? Therefore you'd have to allow only certain regions of pi, and therefore, its not random anymore and we could just shortcut the whole game?

aleksiy123

Curious if you can prompt Claude to sue some scrambling scheme and then unscramble to defeat this. E.g. prompt Claude to write all sentence in reverse, or swap every 2 words etc. Then use a script to put reorder in the right ordering?

jti107

anthropic speed running its way into irrelevance. wtf would i use AI for writing that screams AI generated especially when I'm not in the EU and open models are so good now

SubiculumCode

How I use claude in my grant writing. I write a rough paragraph. I invoke /concise-mode skill (a supposed instruction that Claude used for their previous concise writing style), and ask it to revise for clarity. I re-read to ensure it says what I wanted, ask for another revision with a specific request, or manually edit. This is a productivity enhancement for me. I am not writing art. I am delivering information for my research plan. While I would not mind a flag that indicated AI assisted for clarity, I do not want to be accused of using AI-wholesale. I put a lot of work into it, and I do not want to be maligned.

brap

I’m entirely confident that this technically pointless, especially when you consider open models exist. I believe they know damn well that this will lead nowhere, and are only doing this to mitigate criticism.

0gs

this is so funny. it's literally just the claude voice. that's not just load-bearing, it's belt and braces

Semantic search powered by Rivestack pgvector
4,128 stories · 37,281 chunks indexed