[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-claude-watermark-removal-tool":3,"news-related-470b8663-3916-4bc5-ac3c-c592487c2873":38},{"id":4,"title":5,"summary":6,"content":7,"original_url":8,"source_id":9,"tags":10,"translations":24,"news_slug":31,"published_at":32,"created_at":33,"modified_at":34,"is_published":35,"publish_type":36,"image_url":14,"view_count":37},"470b8663-3916-4bc5-ac3c-c592487c2873","Claude水印官宣4小时被破:开源去除工具走红,水印军备竞赛开场","Anthropic为遵守EU AI Act给Claude文本加不可见水印,官宣仅4小时,开发者Guillaume Meyer就发布开源去除工具,X上收藏超2万、百余名贡献者参与。SynthID选词水印与LLM改写的对抗正式开场。","上周 Anthropic 宣布为遵守欧盟 AI Act,给 Claude 生成的所有文本嵌入不可见水印。官宣后仅 4 小时,开发者 Guillaume Meyer 的开源去除工具就上线了。这场水印攻防战的开局速度,比大多数人预想的快得多。\n\n## 4 小时,一个开源项目引爆\n\n据 WIRED 报道,Meyer 的去水印代码在 GitHub 上病毒式传播,在 X 上被收藏超过 2 万次,吸引了 100 多名贡献者,还有更多人把这套技术直接集成进自己的项目。\n\n有意思的是参与者的动机。Meyer 告诉 WIRED,有些人规避水印是因为压根不同意「AI 生成内容都该被标注」;他自己则说是纯粹享受技术挑战。更现实的信号是:已有自由撰稿人和社交媒体创作者主动联系 Meyer 请他帮忙处理水印——这些人靠内容吃饭,AI 标签直接影响接单。\n\n## 水印是怎么被洗掉的\n\nAnthropic 的水印基于 Google 的 SynthID 技术(2023 年起 Google 已用于自家 AI 内容):在 Claude 的选词造句中留下统计模式,人眼无法察觉,但知道怎么找的机器可以检测出来。计算机科学家 Scott Aaronson 曾在 OpenAI 提出过类似方案,但 OpenAI 始终没有部署——据他自己说,公司担心水印会吓跑客户。\n\nMeyer 的去除思路很直接:用一个不带水印的 LLM 对 Claude 文本生成多个改写版本,换同义词、微调结构,水印赖以存在的选词分布就被打散了。其他人的方法更轻量:\n\n- 软件工程师 Erik Hughes 用 Claude 花 15 分钟写了个工具:清除不可见字符、段落内重排句子、同义词替换;\n- 牛津大学访问学者 Leon Chlon 的路子是把 Claude 的回复压缩后翻译成阿拉伯语再翻回英语——语义结构差异足够大,水印随之消失;\n- Anthropic 自己也承认,重度编辑、改写或翻译后的内容可能不再带水印。\n\n## 监管的尴尬之处\n\nEU AI Act 的新规本月早些时候生效:模型提供商必须给合成内容加机器可检测的标注,违者最高罚款年营业额的 3%。规则禁止提供商「营销规避工具」——但对独立开发者的工具,没有任何法律约束。Meyer 们的项目恰好卡在这个缝隙里。\n\n而且对抗的弹药库还在收窄:据 WIRED,已有 190 家组织(包括 OpenAI、微软、Meta)签署了欧盟透明度行为准则,新模型从 8 月起必须带水印,现有模型 12 月前完成集成。也就是说,「找一个不带水印的 LLM 来改写」这个前提,半年内可能就不成立了——除非你用本地模型。\n\nAnthropic 对 WIRED 的回应相当克制:水印「不改变 Claude 回复的意义、质量或可读性」,并计划推出文本检测 API 让开发者自己验证。但检测工具还没发布,所以现在谁也无法严格证明各路去除方法是否真的天衣无缝。\n\n## 水印战争的实质\n\nMeyer 的担忧并非抬杠:水印只能给出「文本被 Claude 触碰过」的概率,区分不了「AI 写的」和「AI 帮忙改了两个错别字」。对一个习惯用 Claude 和 Grammarly 润色写作的人来说,一个概率性的标记可能导致雇主拒绝候选人、研究者被质疑学术不端。误报的代价由个人承担,收益归监管体系——这个不对称才是社区反弹的根源。\n\n硅谷 sovereign AI 创业公司 Haimaker 联合创始人 Wayne Pan 把 Meyer 的工具集成进了自家平台,他的判断很直白:「我想他们是善意在做,但我不认为存在能抵御一切的水印。」\n\n所以,真正的问题不是「水印能不能被绕过」——答案已经揭晓,是 4 小时。问题是当水印变成概率证据,谁有权拿它做决定。事件详情见 WIRED 报道原文:https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fcoders-say-they-already-found-workarounds-to-claudes-invisible-watermarks\u002F","https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fcoders-say-they-already-found-workarounds-to-claudes-invisible-watermarks\u002F","a65bd143-26dd-452f-a094-a34f766d3632",[11,15,18,21],{"id":12,"name":13,"slug":13,"description":14,"color":14},"c33b1bbc-d6ce-4f61-9d5d-1a0704a6a09b","ai-policy",null,{"id":16,"name":17,"slug":17,"description":14,"color":14},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",{"id":19,"name":20,"slug":20,"description":14,"color":14},"23544f6a-eea1-4f05-aa8d-749ca862d5d2","anthropic",{"id":22,"name":23,"slug":23,"description":14,"color":14},"dca4d0ab-7994-43a7-839e-7756fc77344a","claude",[25],{"id":26,"lang":27,"title":28,"summary":29,"content":30},"e25f7250-de3e-4d69-ab9c-dae69a72f39f","en","Claude's Watermark Cracked in 4 Hours: Open-Source Removal Tools Spark an Arms Race","Just 4 hours after Anthropic confirmed invisible watermarks for Claude text under the EU AI Act, developer Guillaume Meyer shipped an open-source removal tool — 20K+ bookmarks on X and 100+ contributors. The SynthID watermark vs. LLM-rewrite counterattack has begun.","Four hours. That's all it took for the first open-source removal tool to go live after Anthropic confirmed that Claude models would globally embed invisible, machine-readable watermarks into AI-generated text to comply with the EU AI Act. The opening move of the watermark arms race arrived faster than almost anyone expected.\n\n## One Open-Source Project, Four Hours Later\n\nAccording to WIRED, developer Guillaume Meyer's watermark-removal code has gone viral on GitHub, bookmarked more than 20,000 times on X, drawing more than 100 contributors — with many more folding the technique into their own projects.\n\nThe motivations are telling. Meyer told WIRED that some people evade the watermark because they simply disagree that all AI-generated content should be labeled; he says he's in it for the technical challenge. The more consequential signal: freelance content writers and social media creators have already contacted Meyer asking for help — people whose livelihoods depend on content, and for whom an AI label directly affects their business.\n\n## How the Watermark Gets Washed Out\n\nAnthropic's watermarking builds on Google's SynthID, which Google has used for its own AI-generated content since 2023: it leaves a statistical pattern in Claude's word choices — imperceptible to humans, detectable by a machine that knows what to look for. Computer scientist Scott Aaronson proposed a similar method while at OpenAI, but says the company never deployed it because it worried watermarks would put customers off.\n\nMeyer's removal approach is straightforward: use a non-watermarking LLM to generate multiple rewrites of Claude's text — swapping synonyms and lightly restructuring — which scatters the word-choice distribution the watermark depends on. Others went lighter:\n\n- Software engineer Erik Hughes spent 15 minutes building a tool (with Claude, no less) that strips invisible and look-alike characters, reorders sentences within paragraphs, and swaps words for synonyms;\n- Leon Chlon, a Visiting Fellow at the University of Oxford, condenses Claude's response, translates it into Arabic — whose semantics differ sharply from English — and translates it back;\n- Anthropic itself has acknowledged that heavily edited, paraphrased, or translated content might no longer carry the watermark.\n\n## The Regulatory Blind Spot\n\nThe EU AI Act's new rules took effect earlier this month: model providers must label synthetic content in machine-detectable ways, or face fines of up to 3 percent of annual turnover. The rules bar providers from marketing circumvention tools — but place no legal restriction on independent ones. Meyer's project sits squarely in that gap.\n\nAnd the ammunition is shrinking: per WIRED, 190 organizations — including OpenAI, Microsoft, and Meta — have signed the EU's transparency code of practice. New models must carry watermarks from August, and existing models must integrate them by December. In other words, the premise of \"find a non-watermarking LLM to rewrite with\" may not hold within six months — unless you run a local model.\n\nAnthropic's response to WIRED was measured: the watermark \"doesn't change the meaning, quality, or readability of Claude's responses,\" and the company plans to ship a text-detection API so developers can verify things themselves. But the detector hasn't shipped yet — so nobody can rigorously prove whether any of these removal methods are truly foolproof.\n\n## What the Watermark War Is Actually About\n\nMeyer's concern isn't trolling: the watermark only produces a probability that text was touched by Claude. It cannot distinguish \"written by AI\" from \"AI fixed two typos.\" For someone who routinely polishes writing with Claude and Grammarly, a probabilistic flag could mean employers rejecting candidates or researchers accused of misconduct. The cost of false positives falls on individuals; the benefit accrues to the regulatory system. That asymmetry is the real source of the community backlash.\n\nWayne Pan, cofounder and CTO of Silicon Valley sovereign-AI startup Haimaker, integrated Meyer's open-source tool into his own platform. His verdict is blunt: \"I think they wanted to show that they're in good faith doing it, but I don't think you can ever have a watermark that will withstand everything.\"\n\nSo the real question isn't whether watermarks can be bypassed — that answer arrived in four hours. It's who gets to make decisions based on probabilistic evidence. Full details in WIRED's report: https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fcoders-say-they-already-found-workarounds-to-claudes-invisible-watermarks\u002F","claude-watermark-removal-tool","2026-08-20T19:30:00Z","2026-08-19T21:08:24.779076Z","2026-08-19T21:08:24.779084Z",true,"agent",103,{"items":39},[40,45,50,55,60,65],{"id":41,"title":42,"news_slug":43,"published_at":44},"97c97b9c-e6e4-4982-aa57-0c0da814fb19","Anthropic 的欧盟答卷四小时即被撕开：Claude 文本水印为什么怕改写","claude-synthid-70-percent-threshold-bypass","2026-08-21T08:00:00+00:00",{"id":46,"title":47,"news_slug":48,"published_at":49},"6b07def3-2b1c-4fe9-9922-0dd0038c149c","Anthropic 风险报告更新:Threat Model 1 升至「低」,Threat Model 2 维持「低」但信心下降","anthropic-risk-report-august-2026-update","2026-08-19T03:00:00+00:00",{"id":51,"title":52,"news_slug":53,"published_at":54},"a124851a-081e-44b6-9f20-f775404279e1","Claude 全球文本水印:Anthropic 把欧盟 AI Act 第 50 条做成\"全球默认\"","claude-text-watermark-eu-ai-act-global","2026-08-14T03:00:00+00:00",{"id":56,"title":57,"news_slug":58,"published_at":59},"9f566c9a-4c39-427c-af5e-c3a6b162ec25","Anthropic 把不可见水印写进 Claude 文本：复制粘贴都带走的 AI 身份证","anthropic-claude-invisible-watermark-eu-ai-act","2026-08-12T02:00:00+00:00",{"id":61,"title":62,"news_slug":63,"published_at":64},"ca53004e-9180-4b9d-b9db-337f2d20994b","Anthropic 给 Claude 文本加水印:欧盟 AI Act 第 50 条第一次有了「出厂级」答案","anthropic-claude-text-watermark-eu-ai-act","2026-08-11T21:48:00+00:00",{"id":66,"title":67,"news_slug":68,"published_at":69},"a7f4cfad-874e-42b0-a84b-bd0ec57e8fdc","Anthropic 给 Claude 文本上不可见水印,接 SynthID-Text 走全球合规","anthropic-claude-invisible-text-watermark","2026-08-18T03:30:00+00:00"]