NewAnthropic is watermarking Claude’s text output from 2 August 2026.See which models carry it →
Claude Watermark

AI watermark detectors: what actually exists

By Claude Watermark Research · Updated

There is no working public detector for AI text watermarks, from any vendor. Google's SynthID-Text and Anthropic's Claude watermark are both keyed schemes: verification requires a secret the vendor holds and neither has released one publicly. Every tool marketed as an AI watermark detector is doing one of two other things — finding copy-paste artifacts such as HTML class names and invisible characters, which is real and verifiable, or running a style classifier like GPTZero, which is a probability rather than a detection. Knowing which of the three you are being sold is the entire subject.

Check your own text for these artifacts. Runs in your browser, no account, nothing uploaded.

The three different things sold under one name

Watermark detection. Verifying a keyed statistical mark the model embedded while generating. Requires the vendor's key. Does not exist publicly for any major model. Anthropic says it is working toward third-party detection; Google publishes SynthID-Text research without a public verifier for arbitrary text.

Artifact checking. Finding what a chat interface physically left in the text — provider HTML class names, `data-` attributes, zero-width characters. Completely reliable, because it is reading bytes rather than inferring. This is what most so-called detectors actually do.

AI-style classification. GPTZero, Pangram, Turnitin and similar. They score how predictable and uniform the writing is and return a probability. Real products with real research behind them, but they judge style, not provenance, and they are wrong in both directions.

How to tell which one you are looking at

Read what it reports. Counts and positions — *4 zero-width characters, 2 class attributes* — mean artifact checking, and the result is a fact. A percentage means classification, and the number is a guess. A confident yes or no about a vendor's watermark means the tool is describing a check nobody can currently run.

The strongest tell is whether a tool states its limits. We audited six tools in the Claude watermark category by reading their own marketing verbatim: two overclaim outright, three state their limits correctly, and the most honest documentation belongs to a free open-source repository.

What you can verify yourself, today

Artifacts, completely. If text carries `class="font-claude-response-body"` or a zero-width joiner, that is in the bytes and any checker will find it, including free ones.

We measured what this means in practice. Across roughly 50,000 words of human writing spanning 1813 to 2026 — Austen, Melville, Dickens, Joyce, an IETF specification and Wikipedia — zero deterministic artifacts appeared. Those classes really do indicate text passed through a chat interface.

The stylistic classes are the opposite, and this is where false accusations come from. Melville uses 87 em dashes in 3,400 words of Moby Dick; Austen and Bram Stoker use none at all. A signal ranging from 0 to 26 per thousand words across canonical human authors has no baseline to accuse anyone against.

One class we had to correct ourselves on: non-breaking spaces are byte-exact but appear in ordinary web copy constantly, because HTML ` ` is standard typography. We measured them on bbc.com, gov.uk and smashingmagazine.com, and fixed our own tool's wording when it implied otherwise.

What to do if you have been accused

Nothing detected a watermark. No such detector was available to whoever accused you, so whatever they ran was a style classifier returning a probability.

The useful response is to ask which tool produced the score and what its published false-positive rate is, and to note that the same tools flag writing from before large language models existed. Documented process, drafts and version history are worth more than any counter-score.

Questions

Is there an AI watermark detector that works?
Not publicly, for any major model. Watermark verification requires the vendor's key, and neither Anthropic nor Google has released one for arbitrary text. Tools sold as watermark detectors are either artifact checkers or style classifiers.
Can anyone detect Google's SynthID in text?
Not as a public tool for arbitrary text. SynthID-Text is published research and a reference implementation exists, but detection needs the key used at generation. The same limitation applies to Anthropic's Claude watermark.
Are AI detectors like GPTZero the same thing?
No. They classify writing style and return a probability. They cannot read any vendor's watermark and would behave identically if no watermark existed. They also produce false positives on human writing, which is the source of most wrongful accusations.
What can I check for free?
Copy-paste artifacts — HTML class names, data attributes, zero-width and exotic Unicode characters, typography. Several free tools do this correctly, including ours, and the checking runs in your browser so nothing is uploaded.

Check your own text. Free, unlimited, no account, and it runs in your browser so nothing is uploaded.

Open the checker
Nick Launches — featuredNick Launches — featuredDang.ai — featuredDang.ai — featuredFazier — featuredFazier — featuredStartup Fame — featuredStartup Fame — featuredTurbo0 — featuredTurbo0 — featuredTinyLaunch — featuredTinyLaunch — featuredToolPilot — featuredToolPilot — featuredTwelve Tools — featuredTwelve Tools — featuredNick Launches — featuredNick Launches — featuredDang.ai — featuredDang.ai — featuredFazier — featuredFazier — featuredStartup Fame — featuredStartup Fame — featuredTurbo0 — featuredTurbo0 — featuredTinyLaunch — featuredTinyLaunch — featuredToolPilot — featuredToolPilot — featuredTwelve Tools — featuredTwelve Tools — featured