Anthropic announced last week it would embed invisible watermarks in Claude’s AI-generated content to comply with new EU regulations. The watermarks lasted about as long as it takes to read the blog post announcing them.
Within hours of the announcement, developers were posting workarounds online. Some claimed they’d already found ways to strip the watermarks or bypass them entirely. The speed of the circumvention isn’t just embarrassing for Anthropic. It’s a stress test for the entire premise of the EU’s approach to AI regulation.
The EU AI Act, which came into force earlier this year, requires providers of general-purpose AI models to implement technical measures that enable the detection of AI-generated content. Watermarking is the obvious solution. Embed a signal in the output that’s invisible to humans but detectable by software, and you’ve got traceability.
Anthropic’s implementation was supposed to be sophisticated. Unlike simple metadata tags that disappear when you copy and paste text, these watermarks were meant to survive reformatting and minor edits. The company positioned the move as responsible compliance, getting ahead of the August deadline.
But technical mandates only work if the technology actually works. And if the early reports are accurate, this one doesn’t.
The details posted online vary. Some developers claimed simple text transformations were enough to break the watermark. Others suggested the watermarks could be detected and removed. A few said they’d found ways to use Claude without triggering watermark insertion at all.
Anthropic hasn’t confirmed which, if any, of these workarounds actually work. The company declined to comment on specific bypass techniques, which is standard practice. Confirming a vulnerability just teaches more people how to exploit it.
But even if half the claimed workarounds are vaporware, the pattern is clear. When you require a technical control that users are motivated to bypass, they will bypass it. Coders have been defeating DRM, bypassing geoblocks, and jailbreaking devices for decades. Watermarks are just another challenge.
Here’s where it gets legally interesting. The EU AI Act has teeth. Violations can trigger fines up to 35 million euros or 7% of global annual turnover, whichever is higher. But who gets fined when the watermarks fail?
If Anthropic implemented watermarking in good faith and users strip it out, that’s probably not Anthropic’s problem. The AI Act regulates providers, not end users. But if the watermarking was never robust enough to survive basic countermeasures, does that count as compliance? The regulation requires “effective” technical measures. What happens when effectiveness is measured in hours?
EU regulators haven’t addressed this yet. They’re still ramping up enforcement capacity for the AI Act generally. The AI Office, the new Brussels body tasked with oversight, is barely staffed. Expect this to take years to shake out in practice.
The quick circumvention of Anthropic’s watermarks is a microcosm of a bigger problem with AI regulation. Policymakers want technical solutions to policy problems. Make the AI detectable. Make it explainable. Make it auditable. But those requirements assume the technology exists and works reliably.
Sometimes it doesn’t. AI-generated text detection has been a mess for years. Explainability methods are disputed. Auditing tools are immature. Regulators keep writing these requirements into law anyway, hoping the tech will catch up.
When it doesn’t, you get situations like this: a major AI company scrambling to comply with a legal mandate, only to watch the solution fall apart immediately. That’s not good for Anthropic, which wasted engineering time on a system that doesn’t work. It’s not good for the EU, which looks like it’s regulating based on wishful thinking. And it’s not good for anyone who wanted watermarking to actually solve the provenance problem.
The coders who broke the watermarks probably thought they were being clever. What they really did was expose how far regulation has run ahead of what’s technically possible. The law says watermark it. The code says good luck with that.
One email at dawn. The five stories that mattered, with the bits removed and the meaning kept. Free, for now.