From San Digital, who run live AI courses for engineers and business teams.Live AI training from San Digital. See the courses

declawd

Check text in your browser

This runs the same watermark test on whatever you paste. The calculation stays in this tab; your text is not sent or uploaded.

What the checker result means

This checker looks for one published watermark. Text with fewer than 200 distinct pairs returns “Not enough text” and no score or verdict. Longer text can fall on either side of 2.30, including by chance.

Whether the result is above or below the cut-off, it does not establish where the text came from, who wrote it or whether a model was involved. Do not use any result to judge someone.

The cut-off was measured on English prose. The scanner reads A–Z only, so it splits accented words in two and counts the pieces. Text in French, German, Spanish or any other language written with accents can still return a verdict, and that verdict is not interpretable. Text with no A–Z words at all is refused outright, and so is text that has them but too few distinct pairs. A page written mostly in another script can still return a verdict once its Latin fragments alone reach 200 distinct pairs, and names, quotations, code or a reference list can be enough. That verdict describes the fragments, not the writing around them.

This checker needs JavaScript, because the calculation runs in your browser rather than on a server. With it switched off there is nothing to send and nothing to show.

What the cleaning lab can change

The cleaning lab can lower this site’s own published score through words you approve, or remove listed Unicode characters you select. Anthropic says hidden characters are not Claude’s carrier, so Unicode cleaning does not directly target that carrier or certify removal. Declawd has no compatible key, detector or decision rule.

Tokenisation is the weak point. Change one letter to a lookalike and the scanner splits the text differently, which is why character edits attack watermarks at all. How well they work is another matter. Blind edits at a rate of 0.1 cleared a mark only some of the time, and which model and which watermark made an enormous difference; at 0.5, though, most marks gave way, with somewhere between roughly 83 per cent and nearly all of the tested outputs coming back clean. Random token changes managed about half as much at the low rate, across the three stronger schemes. One more attack in the study used a genetic search guided by a trained reference detector, and got to roughly 65 and 66 per cent on its two target models without exceeding the same editing budget. Every figure in this paragraph is from the 2026 NDSS paper, kept with the rest of the evidence under sources.

Classifier-style AI detectors go wrong in a different way. A 2023 study ran essays by non-native English speakers through seven widely used detectors, which wrongly flagged 61 per cent of them on average. And when the study’s authors set out to beat those detectors, the way in was rewording the prompts, not character edits.

Character cleaning can damage legitimate writing. Joiners, direction controls, variation selectors and spaces can carry meaning, so the cleaning lab selects nothing until you make an explicit choice.