Is it April 1st again already? That sounds like BS when applied to text. For code, this doesn’t work at all. A linter will kill any statistical shenanigans they would introduce. And if they have a mechanism whatsoever to see the watermark, then others will see it too, which will make it easy to remove it.
EDIT there is a paper about how this is supposed to work. They acknowledge that an attack on the algorithm can only be prevented when the algorithm is not disclosed to the public. They also explain how it is basically useless to detect AI generated code. And on top of it all, one would have to force the same non-public watermarking algorithm on every LLM out there to be effective. Which seems unlikely to happen. While it might be a fancy way for an owner of an LLM to detect whether their product was used, it is totally useless as a measure of detecting AI generated texts in general.
I’d love to see something like this become a standard. It’d be even better if it could also be used to embed instructions to the AI in the prompt — poisoning the well, as it were
Print AI generated content. Retype in MSword, notepad, open office. These AI pushing mother fuckers are some of the dumbest chuds on the face of the earth.
Needed reminder that OpenOffice is long dead and LibreOffice is the one to use
They know it’s super easy to circumvent…
If it wasn’t, it would hurt their company.
So they do some security theater that can be beat by “paste as plain text”. The people who use it will figure out how to beat it easily. The people who don’t use it but know nothing (politicians) will think it works.
And people who understand it and don’t like it, aren’t going to have our opinions changed anyways.
That’s not how it works. The “watermark” is a statistical pattern in the output, not a background picture.
The “watermark” is a statistical pattern in the output,
Where did you see that?
They added that the watermark “may persist through some editing” for anyone who thought they could get away with Claude’s newest update.
A watermark is generally a faint image, logo or text embedded into a picture or document to help prove ownership, while reducing theft and plagiarism.
However, Anthropic assures the embedded watermarks for AI-generated texts will not affect the readability of said texts, remaining invisible to the human eye.
The new embedded watermarks are meant to be detected by third party tools only, using coding that is unique to the text, even when copypasted.
AI companies use very specific language that sounds like an obvious thing, but really it’s a weird interpretation that’s worse.
Like, they flat out said “even when copy pasted”.
That does not mean retyping wouldn’t hide it.
It doesn’t even mean copying and then “paste as plain text” would get flagged, it would likely pass.
If it was what you’re saying, it would be a lot of false flags, especially on short texts.
It’s way more likely they’re just doing something to the output text, and it persists with the “copy/paste” just like when you copy/paste from an article, only to discover the text includes a plug for the website…
Like, this is literally why “paste as plain text” has always been a thing.
That’s almost certainly all this is.
Especially since the article links to fucking polymarket tweet like it’s a source
It might be some weird, visually indistinguishable character combination. For example, some “random” spaces might be non-breaking or actually a pair of thin spaces, hanging spaces at the end of lines/paragraphs/code tab breaks or any number of zero-width characters might be inserted.
I was thinking that but how would that work with Claude Code? Inserting invisible characters will either break code in the most sociopathic way or a formatter will just remove it
It’s not that obvious. They have ways of subtly statistically manipulating the output of their models, so that a computer can analyze it and recognize patterns that deviate in distinctive ways from what humans normally do. Just typing it out again won’t change the statistics. Rewording might. But if you’re going to rewrite the output, you lose the time savings you gained by getting AI to write your stuff, whether it’s code or an essay.
They said it “wouldn’t affect quality” but that’s been said about lots of things that do, like analog copy protection schemes. Yeah, it could be subtle stylistic choices in text and code.
I mean, Occams Razor its:
like when you copy/paste from an article, only to discover the text includes a plug for the website…
It won’t actually get displayed with a “paste”, it’ll stay hidden to a human but be visible to the third party program.
Technically a solution, and if it wasn’t possible to just retype the words, it would actually be effective.
But if it can be defeated by someone manually retyping it, then it’s pointless. And that seems to be what their press release dances around.
So just add one typo
That wouldn’t help much. Consider a toy example: maybe the AI uses the letter “v” much more often than humans do. You’d need to make enough typos to shift the frequency of that letter all the way from the AI distribution to the human distribution. If a human would typically use that letter 5 to 10 times and the AI uses it 25 to 30 times, one typo won’t make much difference.
Real AI watermarks can use more sophisticated patterns than letter frequencies, but the basic idea is similar: the watermark is spread across many choices in the text, so changing one character generally doesn’t remove it.
And retyping the text that’s been output, manually, not a copy paste, circumvents this.
It does not. They’re not talking about hidden characters - they’re talking about patterns in the distribution of letters or words, patterns that you would replicate if you retyped the output. Consider, for example, a pattern like “Sentences may contain only even numbers of seven-letter words.” That’s preserved if you manually retype, and it’s even preserved through light editing - the edited output will no longer have 100% of sentences containing even numbers of seven-letter words, but it will have enough that having that many by random chance would be very unlikely. Note that this example is one that I just made up - what they’re doing is presumably a lot more subtle.
deleted by creator
Does this effect coding output?
Read the article: yes, it does affect Claude Code. I think it’s going to be extra spaces before line or tab breaks.
It can’t be that. A linter would just remove them. It’s got to be detectable in the prose itself.
Probably means even worse comments!





