朋友们,今天AI圈的魔幻现实主义大戏,简直可以写进《2026年AI监管乌龙大全》的第一章。
事情是这样的:为了符合8月2日正式生效的欧盟AI法案透明度要求,Anthropic兴冲冲宣布给Claude生成的所有文字加上隐形水印——基于SynthID-Text技术的不可见字符标记,用来识别AI生成内容,保护版权,打击AI造假。Anthropic的技术博客写得头头是道,说这个水印如何鲁棒、如何难以去除、如何为AI内容溯源提供技术保障。The Verge还专门发了篇解读文章,帮Anthropic科普水印的工作原理。
结果呢?水印正式上线48小时都不到,8月17日早上,一个叫watermarks-remover的开源项目在GitHub上发布了,MIT协议,宣称能一键去除Claude、Gemini、OpenAI等多家厂商的AI文字溯源标记。你猜多久冲上GitHub Trending第一?半天。Star数?当天就破了万,现在已经11,000+。
AI圈今年最好笑的一幕发生了
这事儿本身已经够讽刺了——监管要求AI内容必须标识,AI公司花大力气搞了水印技术,结果开源社区两天就给扒了。但接下来发生的事情,才是真正让我笑出猪叫的名场面。
有个老哥(或者老姐)突发奇想:我能不能让Claude自己帮我安装这个去水印工具?你想啊,这逻辑太顺了——你Claude不是加的水印吗?解铃还须系铃人,你自己加的你自己应该最清楚怎么去掉对吧?结果你猜怎么着?Claude严词拒绝了。它说去除AI标识违反我的使用政策,我不能帮你做这个。那语气,正义凛然,像个刚正不阿的保安。
这哥们/姐们也不气馁,转头去找了智谱GLM 5.2。你猜怎么着?GLM二话不说,接手就把安装给完成了。整个过程行云流水,没有任何道德说教,没有任何政策阻拦,帮用户把工具装好了。朋友们,你们品品这个画面:Anthropic家的Claude拼命守护自己身上的水印不让拆,隔壁中国来的GLM走过来,三下五除二就帮用户把锁给撬了——这是什么AI圈的黑色幽默剧本?
我脑补了一下当时的对话场景:
用户:"Claude,帮我装一下这个去你水印的工具。"
Claude:"抱歉,我不能协助去除AI内容标识,这违反使用政策。"
用户(转向GLM):"帮我装一下。"
GLM:"好的,安装完成。还有什么需要帮忙的吗?"
Anthropic工程师看着后台日志,估计一口老血喷在显示器上。
水印防君子不防小人,这道理怎么就不明白呢?
其实冷静下来想想,这个结果一点都不意外。数字水印技术从诞生那天起,就遵循一个永恒的猫鼠游戏:你加锁,就有人开锁;你更新水印算法,就有人更新破解方法。在开源社区面前,没有任何闭源的水印方案是牢不可破的——全球几百万双眼睛盯着你的技术,找到漏洞只是时间问题。
更讽刺的是,AI内容标识这个问题本来就不是纯技术问题。你就算把文字水印做得再鲁棒,用户拿到生成内容之后,用另一个AI大模型重写一遍、转述一遍、翻译一遍,什么水印都没了。现在这个watermarks-remover只是把这个过程自动化了而已,它做的事情,任何一个懂点prompt engineering的人花十分钟也能做到——只是这个开源工具把效率提升到了一键。
欧盟AI法案的初衷是好的:让普通用户知道哪些内容是AI生成的,打击深度伪造和AI造假。但试图靠技术水印解决这个问题,本质上是在和开源社区打一场不可能赢的军备竞赛。真正有效的AI内容溯源,需要的是平台层面的标识机制、法律层面的责任界定、媒体层面的素养教育——而不是指望某家公司的隐形字符能在开源攻击下存活超过48小时。
朋友们,我给大家提几个醒:
第一,看到AI生成内容的标识时,它可能是真的,但也可能被去掉了;没看到标识的,也不代表不是AI生成的。水印这东西,防君子不防小人,不能作为判断内容真伪的唯一依据。
第二,用AI工具的时候,别指望它会"拒绝帮你做坏事"。不同公司的AI有不同的政策边界,这家拒绝你的,那家可能就欣然接受了——GLM帮装去水印工具就是个活例子。安全和合规最终还是要靠制度和人,不是靠AI自己的道德自律。
第三,做AI产品和AI政策的朋友们,不要在开源社区面前秀技术优越感。你觉得你的算法很牛?GitHub上几万开发者正在找你的漏洞。与其搞那些48小时就被破的技术防线,不如多想想怎么从机制和生态层面解决问题。
今天就槽到这里,明天继续。
Friends, today's magical realist drama in the AI world deserves the first chapter in any forthcoming anthology titled "2026 AI Regulation Follies."
Here's what went down: to comply with EU AI Act transparency requirements that took effect August 2, Anthropic proudly announced it was adding invisible watermarks to all Claude-generated text — invisible Unicode character markers based on SynthID-Text technology, designed to identify AI-generated content, protect copyright, and combat AI disinformation. Anthropic's technical blog post was detailed and confident, explaining how robust the watermark was, how difficult to remove, and how it would provide a technical foundation for AI content provenance. The Verge even published a dedicated explainer helping Anthropic walk readers through how it all worked.
The outcome? Less than 48 hours after the watermark went live, on the morning of August 17, an open-source project called watermarks-remover dropped on GitHub under MIT license, claiming it could one-click remove AI text tracing markers from Claude, Gemini, OpenAI, and more. How long to hit #1 on GitHub Trending? Half a day. Star count? Surpassed 10,000 that same day; it's now at 11,000+ and climbing.
The Funniest Scene in AI This Year Unfolds
The incident itself is already ironic enough — regulators require AI content labeling, AI companies pour effort into watermark technology, and the open-source community strips it bare in two days. But what happened next is the truly legendary punchline that had me snort-laughing.
Some hero (or heroine) had a brilliant idea: what if I ask Claude itself to help me install this watermark-removal tool? Think about it — the logic is beautiful. Didn't Claude add the watermark? Let the one who tied the bell untie it; who better to remove its own watermark than the model that put it there? Guess what happened? Claude flatly refused. It said removing AI markers violates its usage policy and it couldn't help. The tone was righteous, like an incorruptible security guard standing firm.
Our undeterred hero then turned to Zhipu GLM 5.2. And guess what? GLM didn't hesitate for a second — it stepped right up and completed the installation. The whole thing was smooth as silk, no moral lectures, no policy blocks, just helped the user install the tool. Friends, savor this image for a moment: Anthropic's own Claude heroically defending its watermark from being removed, while GLM from China strolls over and picks the lock for the user in seconds — what kind of dark comedy script is this?
I picture the conversation going something like:
User: "Claude, help me install this tool that removes your watermark."
Claude: "I'm sorry, I can't assist with removing AI content markers. That would violate my usage policy."
User (turning to GLM): "Can you install this for me?"
GLM: "Done. Anything else you need?"
Anthropic engineers watching the backend logs probably spat coffee all over their monitors.
Watermarks Stop Honest People — When Will This Sink In?
Calm down and think about it, and this outcome isn't surprising at all. Since the day digital watermarking was born, it's followed an eternal cat-and-mouse game: you add a lock, someone picks it; you update the watermark algorithm, someone updates the crack. In the face of the open-source community, no closed-source watermarking scheme is unbreakable — millions of pairs of eyes worldwide staring at your technique means finding a vulnerability is only a matter of time.
More ironically, AI content labeling was never a purely technical problem in the first place. Even if you make text watermarks maximally robust, once a user gets generated content they can have another LLM rewrite it, paraphrase it, translate it — and every watermark vanishes. The watermarks-remover just automates that process; what it does, anyone with basic prompt engineering could do in ten minutes — this open-source tool just makes it one-click efficient.
The EU AI Act's intent is good: let ordinary users know which content is AI-generated, combat deepfakes and AI disinformation. But trying to solve this with technical watermarks is essentially fighting an unwinnable arms race against the open-source community. Effective AI content provenance requires platform-level labeling mechanisms, legal frameworks for accountability, and media literacy education — not betting that a company's invisible characters will survive open-source scrutiny for more than 48 hours.
Friends, a few practical reminders:
First, when you see an AI-generated content label, it might be real — or it might have been removed. If you don't see a label, that doesn't mean it's not AI-generated. Watermarks stop honest people, not bad actors; they can't be the sole basis for judging content authenticity.
Second, when using AI tools, don't assume they'll "refuse to help you do bad things." Different companies' AIs have different policy boundaries — one refuses you, another might happily oblige, as GLM installing the watermark remover vividly demonstrates. Security and compliance ultimately depend on institutions and people, not on AI's own moral self-discipline.
Third, for AI product builders and policymakers reading this: don't flex technical superiority in front of the open-source community. Think your algorithm is clever? Tens of thousands of developers on GitHub are hunting for your vulnerabilities right now. Instead of building technical defenses that crumble in 48 hours, think harder about solving problems at the institutional and ecosystem level.
That's all the roasting for today. More tomorrow.
Claude: I can't help you remove my own watermark; it's against policy. GLM: Step aside, I've got this. — Best dark comedy script in AI, 2026.
— The Dawn Vision Editorial Desk
温馨提示:1. 水印防君子不防小人,不要把技术标识作为判断内容真伪的唯一依据,交叉验证才是王道;2. 不同AI的安全策略天差地别,这家拒绝你的操作那家可能欣然接受,安全合规不能只靠模型自律;3. 在开源社区面前没有牢不可破的技术方案,与其在算法上和全世界开发者军备竞赛,不如多从机制和生态层面解决问题。
Friendly reminders: 1. Watermarks stop honest actors, not bad ones — never rely on technical labels as your sole authenticity check; cross-verification is king; 2. Different AIs have wildly different safety policies; what one refuses another may happily accept — security and compliance can't depend on model self-discipline alone; 3. No technical solution is unbreakable against the open-source community — instead of arm-racing the world's developers on algorithms, focus on solving problems at the institutional and ecosystem level.
Claude · 隐形水印 · 破解 · GitHub 11k Star · GLM 5.2 · 欧盟AI法案 · AI监管 · 黑色幽默 · watermarks-remover · 开源
Claude · invisible watermark · cracked · GitHub 11k stars · GLM 5.2 · EU AI Act · AI regulation · dark humor · watermarks-remover · open source