AI Watermark Check

About WatermarkCheck

This site exists because the AI watermarking category is full of tools that promise things no browser can do. Our only real asset is being accurate about a narrow subject, so this page describes how we work and how to hold us to it.

What we are

WatermarkCheck is an independent reference and a free browser-based tool, maintained by a small team with backgrounds in text processing and web engineering. We are not affiliated with Anthropic, OpenAI, Google, Microsoft, xAI, DeepSeek or Perplexity, and we do not receive anything from them.

The site is intended to be funded by advertising. Advertising does not influence what the vendor pages say, the whole point of the pages is that they say what is true, including when what is true is "this cannot be done".

About the author

Oleh Vozniak builds and maintains WatermarkCheck: the detection engine, the character table it runs on, and the vendor pages and guides published here. His background is in web engineering and text processing, and every blog post on this site carries his byline because he is the one accountable for what it claims.

He also writes about AI text watermarks and hidden Unicode characters on Medium. If a page here says something he cannot verify against a primary source, that is a bug, and the contact page is the way to report it.

What we will not claim

  • That any browser tool can remove a statistical watermark such as Anthropic's token-selection mark or Google's SynthID. It cannot, and we explain why on every page where the question arises.
  • That hidden characters indicate AI authorship. They indicate a copy-paste journey through editors, PDFs and web pages.
  • That we can detect which model wrote a piece of text. Nobody can do this from text alone without the provider's key.
  • That cleaning text helps anyone evade a detection system. We do not link to services that market themselves that way, and we do not describe our tool in those terms.

How the vendor pages are researched

  1. Primary sources only for factual claims. Provider documentation and help centres, the text of Regulation (EU) 2024/1689, Google DeepMind's SynthID documentation, the Unicode Standard and its annexes, and the original Trojan Source paper by Nicholas Boucher and Ross Anderson. News coverage is used to find sources, never as one.
  2. Distinguishing status from trajectory. "Signed a code of practice" and "has deployed a watermark" are different statements, and the pages keep them apart explicitly.
  3. Dating everything. Every vendor page carries a "Last verified" date. If the date is old, treat the page as old. We would rather show you a stale date than imply freshness we have not earned.
  4. Saying when we do not know. For providers with no published scheme, the page says that no scheme has been documented, not that no scheme exists. A statistical watermark cannot be observed from outside, so the absence of documentation is the strongest honest claim available.

How the tool is built

The detection engine and the published character table are generated from a single data file, so the documentation cannot drift away from the behaviour. Every code point in the table carries a category, a risk level, a stated action and a note on where it comes from.

Classification is contextual rather than list-based. The same code point can be kept in one place and removed in another, because a zero-width joiner inside a family emoji and a zero-width joiner between two Latin letters are not the same problem. Where the engine cannot determine context, in a browser too old to support Unicode property escapes, it keeps the character rather than removing it, because damaging Persian, Khmer or emoji text is worse than leaving one invisible character behind.

Everything runs in your browser. There is no server-side processing, no upload and no logging of anything you paste. That is an architectural property, not a policy promise: the page makes no network request while you type, and the tool keeps working with the network disconnected.

Corrections policy

If something here is wrong, we want to fix it, and we would rather hear about it from you than leave it in place.

Scope

We cover two subjects and deliberately stay inside them: how AI text watermarking works in practice, and what hidden Unicode characters do to real systems. We do not review AI detectors, we do not offer writing services, and we do not publish general AI commentary.

Related pages