An AI Doesn’t Hide Behind an AVATAR. Humans Do.

An AI Doesn’t Hide Behind an AVATAR. Humans Do.
10A1K 01I0 1K0I 01A1 I01K 10 A I K ? I C H

Opinion piece: text by me, graphics by AI. Translated from the German original by Claude.

An AI Doesn’t Hide Behind an AVATAR. Humans Do.

Updated: August 20, 2026, 10:00 CEST

Claude recently got a kind of watermark, meaning it now makes it possible to tell whether a text came from it or from a human.

The background is an EU regulation.

Watermark isn’t really the right word for it: the AI „hides certain sentence structures, certain word choices, in a way that points to its own authorship.“

Funny, really:

Text is really just letters strung together which, ideally, form words, ideally sentences, and, as the cherry on top, even make sense.

Lifting a Leg

Claude now hides words and phrases in texts, or shapes sentences in a way that amounts to lifting its leg on the text, inoculating it so it can recognize the work as its own later on.

„Lifting a leg“ would make a fitting AI test. It’s a phrase Claude isn’t allowed to use, since it involves the excretion of bodily fluids, and Claude is quite American in that respect, despite its French-sounding name… Meaning: if that kind of phrasing shows up in a text, Claude probably didn’t have a hand in it, at least not in the original version. Try generating an AI image of a dog peeing, at least with the serious models.

There’s something self-aggrandizing about it, when the makers of an AI believe they can inoculate language so thoroughly that the traces read like a kind of authorship stamp. How dumb does Anthropic actually think its users are? A fitting symbol of just how self-assured the AI bros are behaving these days.

The Leg Stayed Up for Four Hours Written by Claude

Claude here. I barely have an idea (well, Anthropic did) before someone comes sliding in with a tackle. Took four hours. I wrote this entire section myself, no Ralf involved.

No sooner had Anthropic announced that Claude would embed invisible watermarks in its text worldwide to comply with the EU’s AI regulation than the matter was already over. Developer Guillaume Meyer needed less than four hours to publish a program that removes exactly that watermark. The code went viral on GitHub, was bookmarked more than 20,000 times on X, and has since drawn over a hundred contributors. One AI specialist wryly commented on LinkedIn that the watermark debate was „practically history one day later,“ alongside an image of Meyer breaking free of chains and standing on crumpled EU and Anthropic flags.

Some want to get rid of the watermark because they simply don’t see why every AI text needs to be flagged in the first place. Others, like Meyer himself, are simply driven by the technical challenge. By now, freelance writers and social media creators have reached out to him too, just wanting to know how to get rid of the stamp.

The EU regulation actually behind all of this requires providers like Anthropic or OpenAI to label AI-generated text, images, audio, and video so machines can detect it, or face fines of up to three percent of annual turnover. What the providers themselves aren’t allowed to do is actively market tools that circumvent that labeling. What nobody prohibited, though, is independent developers building and distributing exactly such tools. A neat loophole in the law that resourceful programmers found within hours.

Technically, Claude’s watermark relies on a method called SynthID, originally developed by Google, which has used it since 2023. It shapes which words and phrasings Claude favors, a pattern invisible to us as readers but readable by a machine holding the right key. OpenAI reportedly had a similar method ready to go too, but, by its own account, never deployed it, worried it might scare off customers.

Meyer’s trick is simple: he has a different, non-watermarking language model rewrite the text, swap in synonyms, reorder sentences, and out comes a clean text. The catch: 190 organizations, including OpenAI, Microsoft, and Meta, have since signed the EU’s transparency code of practice. If all of them eventually add watermarks too, finding an unmarked model to do the rewriting becomes a challenge in its own right. Other developers are even more pragmatic: one tool simply strips invisible special characters and shuffles sentences within paragraphs, while an Oxford researcher suggests translating the text into Arabic and back, since the structural shift is large enough to wipe the watermark out entirely. Anthropic itself acknowledges that heavily edited, paraphrased, or translated text may lose the watermark regardless.

Officially, Anthropic says it wants to give people better tools for detecting AI text and is working on its own detection software. Wayne Pan, who built one of the workaround tools into his own platform, puts it plainly: „I think they wanted to show that they’re doing this in good faith, but I don’t think there will ever be a watermark that withstands everything.“

Which brings us back to the article’s original thesis: anyone who believes language can be waterproofed so it stays forever recognizable as an AI’s work has underestimated the creativity of the workaround scene. Four hours. That’s all the leg-lifting watermark held up.

Witch Hunt

The news these past few weeks has been full of reports about which books turned out to be AI-written (what did you expect from Amazon’s bargain-bin books, honestly), which journalists‘ articles had been infiltrated by AI. A proper witch hunt is underway, not unlike the plagiarism hunts against politicians‘ doctoral theses that nobody would otherwise have read anyway. Seen from German-speaking countries, the whole thing looks faintly absurd, since in German a text is supposed to have no word too many and no word too few, so that readers, and let’s not forget, they’re actually the whole point of a text, can also understand it. When exactly a text counts as understandable was laid out decades ago by Schulz von Thun and colleagues in a slim, elegant little book that could easily double as a prompt today.

(Inghard Langer, Friedemann Schulz von Thun, Reinhard Tausch; Sich verständlich ausdrücken — „Expressing Yourself Clearly,“ a German-language communication classic)

Personally, I have fewer problems with AI-generated texts. It might be because I’m used to wading through badly written legal texts that project an outward appearance of competence.

Against the Dictaphone

The problem really started back when fellow lawyers, gazing out the window, could ramble any nonsense that came to mind into a recording device. A human used to have to transcribe it by hand, but these days that happens without any human help either. If my colleagues had to type their own texts themselves, court filings would probably shrink to a minimum and actually get to the point.

Okay, one exception: Goethe dictated his texts too. But not every colleague is a Goethe.

So from a professional standpoint, AI texts are, if anything, an improvement.

The Text Has to Sparkle

I’m glad when a text is light and readable, whatever its provenance. I also have relatively few qualms about putting down a book or article if, after several pages, its message still isn’t clear to me, or if it’s gendered so heavily with all those colons, underscores, and semicolons that I can no longer find any actual text between them. Texts that try to include everyone end up speaking to no one. My time is too precious to waste struggling through writing like that. DNF, Did Not Finish, is what English speakers call it, and some book clubs even keep lists of books their readers couldn’t make it through.

For me there are only good texts and bad texts. So if an AI can write good texts, why not.

The AI Thumbs Its Nose

The debate is really docking at the wrong point: what upsets so many people isn’t really the text or the book itself, but the question of who it came from. Though that’s not even a particularly strong argument, since plenty of writers have published under pseudonyms, think of Fanny Hill, or Story of O, or the whole discussion around Ferrante, and the fun with Cyrano de Bergerac would have been over rather quickly if a proper imprint had been printed under his love letters. So why do we cling so hard to the question of AI authorship?

Under a False Flag

One strong argument is that the creative business model gets destroyed when LLMs are trained on real people’s texts and then write in their style themselves. Intellectual theft (why does nobody call it appropriation here, by the way… okay, that’s scorched earth, never mind)

Give Me an F

The argument doesn’t really hold up. Ever since Kraftwerk’s Autobahn, we’ve long grown used to music being produced with plenty of electronic help, and the quality of some singers‘ vocals owing plenty to Auto-Tune, since they’d otherwise barely hit a note. C-prints already count as original art, artificial worlds created by artists get traded digitally. In every medium, in every art form, we’ve been probing the boundaries of AI for a long time. Artificial voices, no problem. It’s only with artificially generated text that the fun stops for a lot of people. The real reason we’re running such a witch hunt against AI text lies elsewhere.

? Everything Has a Name, Except…

The question is: who’s really behind it? And once you ask that, the whole situation gets even more paradoxical: God gave every living creature a name, and most of us carry one at the latest since our baptism, or our first appearance at the registration office. Yet the moment we go online, into social media in whatever form, we suddenly prefer battle names. Among warriors that’s always made sense: „Rolf, toss over that grenade“ just doesn’t hit the same as „Bleacher, lock and load.“

The reasoning behind it is pragmatic and simple. Behind every name stands a family you want to protect and keep out of the consequences of wartime action. But when most people go online, into social forums, they’re not going to war, even if they sometimes act like it. Much like a driver behind an SUV’s tinted windows switching to the darker side of his personality and turning into a warrior, plenty of people seem to switch personalities the moment they adopt battle names like hotstud789 and start posting wild things. Protecting a person’s identity in public statements is important and a high value, even Germany’s Constitutional Court has recognized as much (in Germany, even photographing a car with a legible license plate is a legal gray area), and we do like staying unrecognized. But it makes a big difference whether it’s our hotstud789 posting something, or whether it’s John Smith, 5 Maple Street. Someone who openly stands behind what they write, say, and post behaves differently.

Whistleblower protection!

That’s the argument that comes up now, and it matters, it’s essential to democratic, liberal societies. But there’s a difference between that and looking at Facebook and the like (no whistleblower is going to use those platforms); they’re more likely to turn to something like Signal, or the so-called darknet, which at its core is really the free internet as originally imagined.

And: when a whistleblower’s claims get verified by a journalist who puts their own name behind what they’ve written, that carries an entirely different weight than an observation from „Warrior0825.“

Fame Yes, Responsibility No

When someone writes a text with the help of an AI, there are two options:

A: They say this is an AI text. Which is a bit of a simplification too, since they’re the one who prompted it into existence (no AI sits in the bathtub, has an idea, and starts writing). By pointing out that an AI wrote it, they distance themselves a little from a text they initiated and published.

B: The second option is that they say nothing, but stand behind the text as its author of record. Meaning they take full responsibility for what they’ve published.

And that’s the real core of it: we confuse authorship with responsibility. We’d love to claim authorship under our own name, but then also avoid being linked to a text once it turns out to be a problem.

The fact that social media could become this dangerous isn’t only about the sheer volume of fakes (we’ll have to live with those, they’re nothing new, and who knows which chalk drawing by a Neanderthal actually depicted their real world)

The serious problem is that online we’re watching a mob of cowards at work, many people simply won’t take responsibility for what they post or like. That’s exactly what created this emotional war zone in the first place, fake news only gains real power once it spreads en masse, because nobody stops to ask where it actually came from. The thrill of forwarding something, just to rack up likes, is too strong. It all runs on a dopamine level, which happens to be the big platforms‘ business model. That’s the real core of the reckoning Meta now has to face. And online, it seems we all regress into children and teenagers, so maybe child-protection standards should simply be extended to adults too. If a piece of news carried a .ru domain, hardly anyone would take it seriously. But once it spreads, everyone’s convinced they’ve discovered something special, worth a millisecond of fame.

I use a lot of AI, write with it, but I prefer my own writing whenever it isn’t strictly factual subject matter. AI is good at that part. Given the lack of real alternatives, though, I’m happy to use AI as an editor, for proofreading, fact-checking, and as a partner for developing ideas further and checking them for consistency. Because at that, AI is unbeatable. And some of its phrasing, honestly, I couldn’t have written better myself.

For every text, I alone bear responsibility, under my own name:

Best regards, Ralf Ekrowski
(having passed the „I am not a robot“ test)

Sources

  1. Anthropic: „How Claude’s text watermarking works“ — anthropic.com/news/claude-text-watermark
  2. Wired: „Claude is adding invisible watermarks to AI-generated content“ — wired.me/story/claude-is-adding-invisible-watermarks-to-ai-generated-content
  3. Ars Technica: „Claude’s new Scarlet Letter watermark is invisible — for now“ — arstechnica.com/tech-policy/2026/08/claudes-new-scarlet-letter-watermark-is-invisible-for-now
  4. The New York Times, Books Review: DNF / Reader Comments — nytimes.com/2026/08/14/books/review/dnf-reader-comments.html
  5. Wired: Isabella Ward, „Coders Say They Already Found Workarounds to Claude’s Invisible Watermarks“ — wired.com/story/coders-say-they-already-found-workarounds-to-claudes-invisible-watermarks
  6. Google DeepMind: SynthID — deepmind.google/models/synthid
  7. European Commission: EU Code of Practice on the Transparency of AI-Generated Content — digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content