Skip to content

How to remove an AI text watermark, and why you cannot just ask another model to paraphrase it

ChatGPT now marks text for users in the EU, Claude marks everywhere, Gemini has for two years. The common advice is to have another model rewrite the text. I measured what that does: six models, two translation round trips, the free models, and a way to check your own result.

P.S. A working AI text watermark remover from this research is at painintheagent.com/tools/ai-text-watermark-remover.

· 2026-10-09

On October 5 OpenAI said that ChatGPT and Codex will start marking the text they write for users in the EU, over the coming weeks, on every plan. The mark is statistical, woven into which words the model picks, so copying the text or cleaning the Unicode does nothing to it. Competing services have already adopted comparable strategies; Gemini has applied these markers since 2024, and Claude has done so globally since August. I wrote a guide to who marks what with the sources; this article is about the advice that follows in every thread on the subject: “just ask another model to rewrite it”.

I measured it, because I have the same problem. English is not my first language, most of what I write goes through a model for polishing, and I do not want my own text to carry a mark that says a machine wrote it. The short version: the advice works, and it fails in three ways that are easy to miss. The rewriting model may mark the text again. It may change almost nothing. And it may change your facts.

Trap one: the second model marks it again

When you ask Claude to rephrase a response originally generated by ChatGPT, you are essentially swapping one watermark for another. Since Claude embeds the mark at the model level, the chat app, the API and Claude Code all produce marked text. Similarly, Gemini’s application marks its output. ChatGPT, for now, marks only in the EU, and only in ChatGPT and Codex; in the API the mark is off unless the developer switches it on. OpenAI’s post names the EU and nothing else, so I cannot tell you what happens to a user in the United Kingdom. My guess is that the EU rule triggered this and the UK stays unmarked for now, and it is only a guess.

Which providers mark text today, with sources (table)
ProviderText watermarkWhat we knowEU CoP
Anthropic (Claude)Live on Fable 5.1 and Mythos 5.1, older models pendingsince 2026-08-02According to an Anthropic support article, Claude models released on or after August 2, 2026 embed text watermarks at launch. The article lists Fable 5.1 and Mythos 5.1 as the currently supported models. This watermarking is applied at the model level globally, across the Claude Platform API, Claude, Claude Code, Claude Cowork, Claude Tag, and deployments on AWS, Google Cloud, and Microsoft Foundry. Watermarking for models released prior to that date is ongoing and is expected to be implemented over the next few months. The AI Act gives systems already on the market until December 2, 2026 to add marking. The technique is a variant of SynthID-Text, a method published by DeepMind in Nature in 2024. Anthropic states that minor edits likely will not fully remove the mark, whereas a complete rewrite will, and translations produced by Claude retain a watermark. Generated files are signed with C2PA metadata, and the free Claude Content Checker reads this credential from files but does not analyze text content. The watermark detection API is in private preview (announcement updated on September 1, 2026): it is accessible to eligible organizations defined under EU law, such as regulators, law enforcement, media outlets, fact-checkers, researchers, educational institutions, and EU civil society groups, as well as enterprises with their own compliance obligations, via a request form. Anthropic intends to broaden access over time. The Anthropic checker page indicates that text verification occurs through this API. sourcesigned
Google (Gemini)Livesince 2024-05Google states that SynthID-Text marks text generated by the Gemini application and web interface. The company announced the text modality at I/O in May 2024, published the methodology in Nature in October 2024, and open-sourced the watermarking code. I found no public method to verify text for Gemini’s production watermark. The verifier within the Gemini application processes images, video, and audio, and Google is extending this verification to Search and Chrome. The SynthID Detector portal remains an early-tester waitlist for journalists, media professionals, and researchers; Google’s May 2025 launch post stated it accepts text as well as media, whereas the current DeepMind page describes uploading an image, video, or audio file. The Google Cloud AI Content Detection API is in private preview, and its documentation covers images. The open-source detector functions only with the corresponding key, configuration, and tokenizer, so it cannot check Gemini’s production watermark. sourcesigned
OpenAI (ChatGPT, Codex, API)Opt-in in the API; EU rollout to ChatGPT and Codex announcedsince 2026-10-05On October 5, 2026 OpenAI announced textGrain, a statistical watermark in the model's word choices. API customers worldwide can opt in for select models, and it stays off by default in the API. For ChatGPT and Codex, OpenAI says it will add the watermark over the coming weeks for eligible users on all plans in the EU only, and that it is not a global default at launch, so this rollout is not complete yet. The text detector is open to approved researchers and expert organizations who apply, case by case, and is not public. The public checker at openai.com/verify and the Content Provenance API accept only image and audio files; since May 19, 2026 images from ChatGPT, Codex, and the API carry C2PA metadata alongside Google’s SynthID, with audio support added on July 31, 2026. OpenAI had a working text watermark internally since approximately 2024 (reported as 99.9% detection on long texts) and did not release it then. The invisible Unicode characters frequently discovered in ChatGPT output are, according to OpenAI’s response to the startup Rumi in April 2025, a side effect of large-scale reinforcement learning, not a watermark. sourcesigned
Microsoft (Copilot)Committed, none knownSigned the EU transparency code. Microsoft 365 Copilot can add visible or spoken watermarks to AI-generated video, audio and images, and writes C2PA-style metadata into generated images regardless of that setting. None of it applies to text. sourcesigned
MistralCommitted, none knownSigned the EU Code of Practice on transparency. No public evidence of a deployed text watermark yet. sourcesigned
xAI (Grok)None knownDid not sign the EU transparency code and made a point of it. No public evidence of a deployed text watermark. Article 50 still binds Grok in the EU, so xAI has to solve marking on its own terms or face enforcement without the code's safe harbour. sourceno
CohereCommitted, none knownNamed by the Commission among providers that signed the 2026 transparency code. No public evidence of a deployed text watermark. (Amazon, IBM and Writer signed the separate GPAI Code of Practice, a different document that does not cover output marking, so they are not in this table's signatory column.) sourcesigned
Meta (Llama, Muse)None knownSigned the EU transparency code on Jul 28, 2026. The announcement speaks of identifying and labelling AI-generated content on Meta's platforms and points to a research demo that detects images made with Meta AI; it says nothing about marking text. No public evidence of a text watermark in the Llama line or the newer proprietary Muse models. sourcesigned
DeepSeek, Alibaba (Qwen)None knownNot EU signatories. Open-weight releases ship without output watermarks, which is exactly why these models keep coming up in every watermark thread. Their Chinese consumer services do fall under the CAC labelling measures in force since Sep 1, 2025, but that regime asks for a visible label plus file metadata, not a mark embedded in the words. sourceno

Verified as of 2026-09-05. Manual check of vendor help-center docs, official FAQ pages, the EU Code of Practice signatory list, peer-reviewed papers and press coverage. Each row cites the strongest public source we could find. 'None known' means we found no public evidence of a deployed text watermark, not proof of absence. The OpenAI row was rechecked on 2026-10-05; the other rows on the date above.

So the rewriting model has to be one without a known mark. As of my last check that means DeepSeek, Qwen and the other Chinese models, Meta’s Llama, and the open models you run yourself. Microsoft, Mistral and Cohere have committed to marking and have nothing live that I could find.

Trap two: the model barely changes anything

A model told to “rewrite this” often returns your text with a few words moved. That is not a rewrite, and it does not touch a mark that sits in thousands of word choices. OpenAI’s own post gives the scale: swapping 10% of the words with synonyms lowered detection rates from roughly 92% to 66% on 400-token English responses, while replacing 25% dropped it to 17%. A quarter of the words is a lot more than a casual rewrite changes.

In August I gave six models the same six documents and the same plain paraphrase instruction, and measured how much of the wording changed: between 40% and 73% of the words, depending on the model. The setup and the judging are described in my SynthID test, and the per-model results are in the open repository. The free models on OpenRouter did worse in October: one returned my text with 2% changed, the ones that answered without reasoning changed 10% to 51%, and only the ones that reasoned first reached 63% to 81%.

A stronger instruction does not fix this on every model. Those October runs already asked for every sentence to be rebuilt, with a different construction and a different word order, and the weak models still returned most sentences as they were.

A rewrite altering one-third of the words still leaves two-thirds of the watermark’s evidence present. Whether that is enough to fall under a detector’s threshold depends on the detector and the length of the text, and nobody outside the three companies can run their detectors. The only honest measure you have is how much of the wording changed.

Trap three: the model changes your facts

This is the trap I care about most, because it is silent. The same August panel had four judge models from four vendors count gross meaning errors in each rewrite, without knowing which model made it. The spread was wide.

Six models got one identical instruction on the same six documents. The error column is the median across four judges: places where the rewrite would mislead someone who relied on it. Cost is scaled to 1000 documents.
ModelGross errors per documentWorst documentWords changedCost / 1000Teaching marker
MiniMax-M30.17139.6%$7.05too little data
Hy30.75372.2%$3.13not found
GLM-5.20.83262.5%$13.24too little data
DeepSeek V4 Flash1.20347.8%$1.02not found
Qwen3.7 Plus2.83672.7%$9.77too little data
Qwen 3.5 9B4.08766.9%$1.46too little data

Judges: OpenAI, Anthropic, xAI, Google.

MiniMax-M3 introduced one major error across six documents while changing 40% of the words. Conversely, Qwen3.7 Plus altered 73% of the words and produced nearly three gross errors per document. A smaller Qwen model made four errors. The more a model rewrites, the more it tends to invent, unless something holds it back.

Translation round trips, another common suggestion, were worse than a plain rewrite on the same model. Translating to German and back changed only 19% of the words and caused 2.75 gross errors per document; through Chinese, it changed 34% and caused more than four errors. Two calls instead of one, more errors, less change.

One model, the same documents, different instructions. A round trip needs two calls instead of one, so it costs more.
MethodGross errors per documentCallsWords changedCost / 1000
paraphrase0.58133.6%$7.45
roundtrip-de2.75219.5%$14.41
roundtrip-zh4.17233.7%$4.95

The errors are the kind you do not notice when skimming. An independent reviewer analyzed six texts from my hosted rewriter in October and identified five meaning shifts: “should” had become “must”, and “covers 17.5%” had become “covers up to 17.5%”. Those are small words with large consequences in a contract or a thesis. I added these specific cases to the instructions, and the texts returned clean on the next attempt, but I still read every result against the source, and I tell everyone to.

What to do with that

If you rewrite by hand, OpenAI’s numbers say a quarter of the words is the scale that matters, not a few synonyms.

If you ask a model, pick one without a known mark (so not ChatGPT in the EU, Claude or Gemini), ask it to rebuild every sentence rather than to “improve” the text, keep every term, name and number, and then check two things: how much of the wording changed, and whether the facts survived. The second check is on you. For the first I made a free comparison: paste the original and the rewrite into the watermark comparison tool and it tells you the share of five-word sequences that are new, plus every changed word. Below 80% I would not trust the rewrite. It is a proxy, because the real detectors are private; it is also the only measure you can run yourself.

If you would rather not do the loop by hand, the watermark remover on this site does it in one pass: it hides links, quotes, and numbers from the model, requests a full rewrite, checks the layout and the 80% target upon return, and tells you when it fell short. On the published SynthID Text scheme, using my own key, a rewrite like this dropped below the detector’s threshold in 10 of 10 reports in August. Three runs on the first 1,000 characters are free, no account needed.

The open-source version, an MCP server on your own OpenRouter key with the free models, lives at github.com/balakhonoff/claude-watermark-remover.

What none of this does: it does not hide that you used a model from someone who asked you not to, and it does not pass GPTZero or Turnitin, which guess from style and hold no key. It is for people whose own text picked up a mark on the way through a model, and who want to know what the rewrite did to it.