Nobody needed the key

Responding to How AI text watermarking works: a visual guide declaude.org

Recently Anthropic announced a watermark embedded in any text it generates that will indicate Claude’s involvement. Of course someone already built the solvent.

A tool called declaude takes AI-flavored text and hands it back re-composed. The explainer that ships with it walks through the mechanism it defeats, in interactive figures, better than anything I’ve read on the subject. It came through a developer newsletter this week. The mark it washes out is three weeks old.

Anthropic’s help page describes a statistical lean in word choices that “doesn’t change the meaning, quality, or readability of Claude’s response.” Invisible, and intact through copy-paste. The Anthropic page is careful about what that conveys: a detected mark means content “may have been processed by Claude.” Give Claude your own prose for a proofread and it can come back marked.

When the announcement went around, the sharpest question under it was about the checker. Publish it and anyone can nudge their text until the alarm stops. Keep it secret and the mark is a checkbox nobody outside the company can audit. It looked like a real trap.

declaude answers it by ignoring it. Re-composition needs no key and no detector: you rewrite from the meaning, and the runs of wording the check depends on are gone. Light editing won’t do it. Anthropic says the mark may persist through some of that, and John Kirchenbauer’s team at Maryland , who wrote the 2023 paper these schemes are built on, found that even a strong human paraphrase stays detectable after about 800 tokens. What appears to kill the mark is starting from the idea instead of the sentence. The key was never the lever.

And the mark-erasing solvent is a model. declaude says so on its privacy page, in the section most privacy pages skip: it doesn’t run the language models itself, it ships your text to OpenRouter, and something over there rewrites it.

Which raises a question the tool never answers. OpenRouter brokers across most of the major labs. Google has marked Gemini since 2024, Anthropic marks Claude now, and the open-weights models mark nothing. So stripping Claude’s mark might leave you holding Google’s, or a fresh Claude one, and nothing on the site says which model did the work. The terms decline to promise the wash removes any watermark at all. What you can buy is a re-mint, and you don’t get to pick whose.

Which is worth holding up next to what the mark was built for. The EU provision Anthropic names as its trigger sits inside a rationale about fraud, impersonation, manipulation at scale, consumer deception. The obligation lands on whoever provides the model. It’s not about authorship or academic integrity. It was built so platforms and regulators could catch synthetic content at volume, it does that honestly, and it was never aimed at the question everyone has started asking it.

I disclose AI assistance on every essay here, so presumably the mark rides here. I can’t confirm that. Checking requires the key. Of the two, the disclosure says more, and it says the thing a reader actually wants to know .

A stranger consequence sits further out. Whatever the marked corpus turns out to be a picture of, after this month it still won’t be a picture of who used a machine. Run your text through declaude and you won’t know whether it came back clean, or carrying someone else’s mark.

Becoming Gnarly, by email