Claude のコンテンツに埋め込まれるウォーターマーク回避方法について
本文の状態
日本語全文を表示中
詳細モードで約12分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
ZDNET AI
Anthropic は EU AI 法第 50 条の要件である AI 生成コンテンツの透明性確保のため、Claude を通じて出力されるテキストに自動透かし埋め込みを開始した。
AI深層分析を開く2026年8月18日 23:35
AI深層分析
キーポイント
EU AI 法への対応としての透かし導入
Anthropic は EU AI 法第 50 条の要件である AI 生成コンテンツの透明性確保のため、Claude を通じて出力されるテキストに自動透かし埋め込みを開始した。
ユーザーからの反発と除去ツールの台頭
透かし導入に対する公衆の不満が急速に拡大しており、これに対応して GitHub 上で透かし除去ツールが多数作成されつつある状況である。
企業優先事項と人間依存の矛盾
今回の反応は企業のコンプライアンス優先事項を浮き彫りにすると同時に、AI ツールに対する人間の過度な依存や所有権への意識の高まりを示している。
ウォーターマーク除去ツールの台頭と根本的解決の必要性
ウォーターマークに対する公衆の怒りが拡大し、GitHub に除去ツールが次々と登場している。しかし、既存のリ人間化プラグインと同様に、単なる修正ツールの利用では根本的な解決にはならない。
Claude のテキストウォーターマークの仕組み
Anthropic は、生成されるテキスト内の特定の語彙選択(例:天候文脈での「overcast」や「gray」)に基づいてパターンを埋め込むと説明した。これはモデルが単語を選ぶ確率的プロセスにわずかな変化を加えるものである。
重要な引用
New watermarks on Claude content are upsetting some people.
Reactions reveal company priorities and human over-reliance on AI tools.
"Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick."
"The words that Claude picks are still random, but now, one can check the sequence of words and see if it's consistent with the choices Claude would make if it was using the key. If it is, one can assign a probability that the text was generated by Claude."
編集コメントを表示
編集コメント
EU AI 法の実施に伴い、企業のコンプライアンス対応がユーザー体験に直結する事例として注目される。透かし埋め込みの導入は透明性向上という目的を持つ一方で、コンテンツの自由な利用や改変に対する懸念を引き起こしており、今後の技術的・制度的な調整が求められる局面である。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

*ZDNET のフォロー: 優先ソースとして追加* on Google.*
ZDNET の注目ポイント
- クラウド(Claude)のコンテンツに付与される新しい透かしに、一部の人々が不満を表明しています。
- 反応からは、企業の優先順位や人間が AI ツールに対して抱きすぎている依存度が浮き彫りになりました。
- 潜在的な透かしを回避するには、結局のところ自分で書くしかありません(ごめんなさい!)。
先週、Anthropic は EU 人工知能法(AI Act)の第50条に準拠するため、Claude を通じて複数の大規模言語モデル(LLM)からのテキスト出力に透かしを埋め込む方針を発表しました。この規定では、参加する AI 企業が生成されたコンテンツの透明性を確保するためのツールを提供することを求めています。
しかし、その透かしに対する一般の反発は、GitHub に次々と登場している多くの透かし除去ツールの数と同様に急速に高まっています。
このニュースを快く思わない人々にとって、解決策は明白に見えます。つまり、Claude から出力する際に透かしを受け取らない方法を見つけることです。しかし、App Store を埋め尽くす「AI による文章を人間のように見せる」プラグインの数々が示すように、別の修正ツールに頼るだけでは何も変わりません。
むしろ重要なのは、AI ツールに対する私たちの期待を見直すこと、そしてコンテンツの出自(プロヴェナンス)がなぜ重要なのかを理解することです。
ウォーターマークの仕組み
当初、Claude の生成コンテンツに付与されるウォーターマークがどのように機能し、誰がそれを読み取れるのかについて Anthropic はあまり詳細を明かさなかった。しかし金曜日、同社は新たなガイダンスを発表し、ウォーターマークは特定の語彙選択に基づいてテキストに付与されることを明確にした。
大規模言語モデル(LLM)は単語を一つずつ生成するが、その際、直前の単語に基づいて確率的に選択が行われる。Anthropic の説明では、「曇り」や「灰色」といった同義語が、天気に関する文脈においてほぼ同じ意味を持つと例示されている。
Anthropic は、これらの「リスクの低い」語彙選択が生み出すパターンは読者には検出できないものの、鍵を持つ者には読み取れるものであると説明した。ウォーターマーク化はこのランダムな単語選択プロセスにわずかな変化を加えることで機能する。
関連記事:'専門家である必要はない':AI エージェント職場で価値を維持する方法
「次に来る単語をランダムな数値生成器で選ぶのではなく、ウォータマーキングでは鍵と直前の数語を用いて、モデルが選択すべき単語を決定します」とアンソロピックは説明しています。「Claude が選ぶ単語自体は依然としてランダムですが、その単語の並びを調べれば、それが鍵を使って Claude が行うはずの選択と整合しているかを確認できます。もし整合していれば、そのテキストが Claude によって生成された確率を算出できるのです。」
反発の背景
このアプローチに対して特に不満を抱いた技術者が一人います。最近の ブログ記事 で、Markdown 記法言語 の共同開発者であるジョン・グラバーは、こうした単語の選択が「取るに足らない問題」だとか、ウォータマーキングの鍵が Claude の出力の「意味を損なうものではない」という主張に異議を唱えました。この懸念を抱いているのは彼一人ではありません。
グラバーはこう記しています。「文章を書く際、私たちが選ぶ正確な単語は重要です。私が利用するあらゆる大規模言語モデルには、すべての判断ポイントで最も最適で精密な単語を選んでもらいたいのです。」
関連記事: AI 画像を見分ける方法:偽物である 6 つの決定的兆候と私が愛用する無料検出ツール
ライターであり編集者として、私は正確な言葉の選び方が重要だと考えています。しかし、「最も最適で精密な言葉」を決めるのは Claude なのでしょうか?それは本質的に主観的な問題ですが、人間の言語の平均を学習し、しばしばそれを用いて訓練された大規模言語モデル(LLM)が「黄金基準」となるべきだとは考えにくいです。
ここで必要な解決策は、その精密な言葉選びを製品に任せるのではなく、自分自身で行うことではないでしょうか?
私は生業として文章を書く立場にあるため、書くことが苦痛である人に対して「自分で工夫すればいい」と言うのがいかに無意味かを理解しています。これは完全には比較できませんが、AI は非専門家のためのデータ処理ツールである Google スプレッドシートの役割のように、非ライターのための執筆ツールとなり得ます。
執筆を AI ツールに外注することは私には合いませんが、私はこれを中立的な立場から述べています。AI を使うかどうかは道徳的な優劣の問題ではなく、その議論自体が行き詰まり、本来取り組むべき大きな対話の妨げになるからです。
グリューバー氏のブログ記事「Anthropic's 'Watermark' Text Adulteration in Claude Is a Perversion of Writing」のタイトルには、いくつかの前提が含まれており、これらすべてがより慎重な検討を要します。
Claude のテキスト生成を「執筆」と見なせるかどうかは、長年議論されてきたテーマです。
また、「執筆の外部委託」そのものに問題があるのではなく、そのプロセス(単なる成果物の提供ではなく)に潜む歪みこそが本質的な問題であるという点も重要です。
さらに、Claude が生成する内容に偏りをもたらす最初の主要な要因は、事前学習やモデルの更新、あるいは安全基準の変化ではなく、むしろ「透かし」にあると考えられています。Anthropic がウェブサイトからバイデン政権時代の責任ある AI へのコミットメントを静かに削除した件も、この文脈で捉える必要があります。
しかし、グリューバーの発言の中で最も強く印象に残ったのは以下の部分です。
「私のためにテキストを生成する際、私自身のニーズ以外の要素が考慮されるべきだという発想は、明らかな侮辱である。」
Claude は、そしてこれからも、テック企業が所有する製品であり、ユーザーのためにのみ最適化されたものではありません。AI が消費者向けツールとして現在知られるようになったことは画期的かもしれませんが、資本主義(およびますます強まるグローバルな政策)の下でテック企業がテック企業として振る舞うこと自体は、決して前代未聞の出来事ではありません。
私たちは、この期待に含まれる論理的欠陥を無視してはなりません。Claude や同様のテック製品が、いかに成功裏にマーケティングされていようとも、個人にとって第一義的な「パーソナルアシスタント」であるという信念を抱くことは許されません。あなたが Claude に、自分が望む AI 生成テキストの形式に関するデータをどれだけ提供してきたかに関わらず、その忠誠心(および Anthropic の忠誠心)はあなたに向けられたものではありませんでした。Anthropic が EU AI 法のような現実的な政策に対して、たとえ不器用であっても適応しようとしている事実は、この事実を改めて思い起こさせるに過ぎません。
AI ラボも他の企業と同様、独自の思惑や計画を持っています。製品を突然変更されることも決して珍しいことではありません。
非現実的な一貫性を期待したり、自社の優先順位を主張するよりも、自分の名前で発表できる質の高い文章を書くことに投資する方が賢明です。
なぜ AI の透明性が必要なのか
ポリシーの目的は、常に製品の品質向上にあるわけではありません。むしろ、その製品背後にある企業が何を行っていないか(あるいは行っているが不十分だったこと)を考慮することが主眼です。EU の AI 法第 5 条もまさにそのためのものです。
「テキストに隠された痕跡を埋め込み、その出自を示すために、明確さや一貫性、意味、品質などのわずかな価値さえ犠牲にするツールは許容できません」とグルバー氏は自身のブログで述べています。
製品としての AI ツールには、高品質な回答を提供するよう市場が後押しするインセンティブが存在します。しかし、出所(プロヴェナンス)は完璧ではない科学ではあるものの、それゆえに極めて重要な役割を果たしています。
著作権論争を脇に置くとしても、ニュースに対する世界的な信頼はこの年、新たな最低水準に達しました 2026 年のデジタルニュースレポート。これは、より多くの読者が情報源としてチャットボットを利用するようになった結果です。誤情報は 選挙に影響を与え始めており、人間とチャットボットの関係、特に子供たちにおいては、「情報の出所がどこか」や「それを信頼すべきかどうか」という判断能力そのものが希薄化しつつあります Threads の投稿。
関連記事:AI が教育格差を縮めるのか、それとも広げるのか
Anthropic のウォーターマークはまだ未完成です。将来的には検出機で機械可読になるかもしれませんが、現時点では一般公開されたツール(Google の SynthID Detector など)がなく、同様に Anthropic のウォーターマークもその基盤技術に依存しています。また、AI 検出器自体が信頼性に欠けることはよく知られています。これらの新しいウォーターマークが情報流通や学術的誠実性の維持などにどの程度寄与するのかは不明です。ただし、情報の由来(プロヴェナンス)の分野への投資は価値があります。もし AI ツールの利用体験に悪影響を与えるなら、その利用を見直す理由にもなり得ます。
自分で書くべきもう一つの理由
とはいえ、Anthropic のウォーターマークを巡る議論には正当な指摘もあります。NoCodeLab.ai の創設者であるサラ・シメオン氏は LinkedIn で以下のように述べています。
「これらの企業は長年にわたり、私たちのコンテンツを許可なくスクレイピングして富を築きました。そして彼らは最も巧妙な収益モデルの一つを構築しました。つまり、私たちがすでに作成したものを再生産された形で提供してもらうために、私たちがお金を払うのです。今や私たちはお金を支払うだけでなく、『自分の知的財産権を彼らに帰属させる』ことも強いられています。」
書籍を海賊版化(そして破壊)する行為に対して、その成果物に透かしを入れることには偽善的な空気が漂います。特に、そのような行為で著者グループとの訴訟を和解した直後であればなおさらです(OpenAI も同様の書籍データ収集について、著作権侵害の集団訴訟を起こされた際、関連データを消去しました)。これらは、AI 企業が自社の高性能かつ大量のデータを必要とするモデルを動かすために、補償も受け取らずにインターネットから無断で収集した膨大なデジタルコンテンツの問題にはまだ触れていません。
(開示事項:ZDNET の親会社である Ziff Davis は、2025 年 4 月に OpenAI を提訴し、AI システムの訓練および運用における著作権侵害を主張しています。)
さらに、透かし付けの適用範囲はどこで終わるのかという問題もあります。The Drum の意見編集者ジョン・マッカーシーが指摘した通りです:
「ピッチの整理や返信を助けるツールも開発中ですが、それにもウォーターマークをつけるべきでしょうか?動画のキャプション生成やインタビューの文字起こしには AI を活用しています。これも対象になるのでしょうか?電気機器で録音しているだけなのに、それが AI 扱いされるのでしょうか?Zoom の通話では『美顔フィルター』のようなソフトな AI フィルタをかけています。これもウォーターマークが必要なのでしょうか?」
あわせて:AI エージェントのビジネス導入が今年3倍に拡大、明確な ROI も確認
指摘されている通り、AI ツールを活用した編集関連業務すべてを AI 生成物としてウォーターマークする必要はありません。Anthropic はまだこれらの違いに対する具体的な方針を明らかにしておらず、最初の発表 でも、Claude を用いた小規模な編集作業にはウォーターマークが付けられるかどうかはケースバイケースであることを認めています。
しかし、これらの投稿の背後にあるのは、Anthropic だけでなく広範な AI ラボ全体に対するより深い反発です。自らの業務を自動化するツールに経済を依存させた挙句、その成果物に監視機能を埋め込み、結果としてそれを脅かすような形でウォーターマークをつけるという行為は、裏切りを感じさせるほど痛烈です。しかし、そもそも自社に対して何の責任も負っていない企業から裏切られることなどあり得ません。
原文を表示

*Follow ZDNET: *Add us as a preferred source* on Google.*
ZDNET's key takeaways
- New watermarks on Claude content are upsetting some people.
- Reactions reveal company priorities and human over-reliance on AI tools.
- To avoid possible watermarks, write it yourself (sorry!).
Last week, Anthropic announced it would start watermarking text output from several of its LLMs via Claude to comply with Article 50 of the EU AI Act, which requires participating AI companies to provide transparency tools for AI-generated content. Public outrage at the watermarks multiplied as fast as the many watermark-removal tools now populating GitHub.
For those who didn't take kindly to the news, the solution seems obvious: find a way to avoid taking watermarks with you out of Claude. But, just like the many re-"humanizing" writing plugins now clogging app stores everywhere, turning to yet another fixer likely won't get us anywhere. A bigger-picture reset on our expectations of AI tools -- and why content provenance matters -- might help instead.
How the watermarks work
After initially not giving much detail about how the watermarks would work and who could read them, Anthropic released new guidance on Friday, clarifying that watermarks will attach to text based on specific word choices. LLMs generate a word at a time, chosen probabilistically based on the former word. In its explanation, Anthropic referred to synonyms like "overcast" or "gray," in the context of a sentence about the weather, as effectively meaning the same thing.
Anthropic explained that these "low stakes" word choices leave a pattern in generated text that readers can't detect, but that is legible to those with the key. Watermarking slightly changes this random word selection process.
Also: 'Specialists aren't required' anymore: How to stay valuable in an AI agent workplace today
"Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick," Anthropic explained. "The words that Claude picks are still random, but now, one can check the sequence of words and see if it's consistent with the choices Claude would make if it was using the key. If it is, one can assign a probability that the text was generated by Claude."
Dissecting the outrage
One technologist in particular had several frustrations with this approach. In a recent blog post, John Gruber, co-creator of the Markdown markup language, disagreed that these word choices are "low stakes," and that the watermarking key won't "corrupt the semantics" of Claude's output. He isn't alone in that fear.
"The exact words we choose when writing matter," Gruber wrote. "I want any LLM I use to choose the very best, most precise words at every single decision point."
Also: How to spot an AI image: 6 telltale signs it's fake - and my go-to free detectors
As a writer and editor, I agree that exact words matter. But is Claude the arbiter of "the very best, most precise words"? That's inherently subjective, but I don't know that the gold standard should be an LLM trained on and often used for the average of human language. Wouldn't the solution here be to make those precise word choices yourself, rather than handing them out to a product that's evolving beyond your control?
Given that I choose to write for a living, I understand how useless it is to tell someone for whom writing is excruciating to simply figure it out. It's an imperfect comparison, but AI can be a writing tool for non-writers the way Google Sheets is a (rudimentary) data tool for non-analysts. Outsourcing writing to an AI tool doesn't do it for me, but I say that neutrally; I don't believe that AI use (or lack thereof) is about moral superiority. That's a dead-end argument that distracts from the bigger conversations we need to be having.
The title of Gruber's blog -- which is "Anthropic's 'Watermark' Text Adulteration in Claude Is a Perversion of Writing" -- assumes several points, all of which could use a closer look:
- that Claude's text generation can be considered "writing" (a long-held debate);
- that the "perversion" is in the watermark, not in outsourcing writing (a process, not simply a deliverable) to a machine;
- and that watermarks -- not pre-training, model updates or changes, or shifting safety standards -- are the first major factor to skew what Claude generates.
But this line of Gruber's stuck out to me the most:
"The idea that anything other than *my* needs should factor into the generation of text *for me* is patently offensive."
Claude is, and has always been, a product owned by a tech company; it was never optimized solely for the user. AI as the consumer-facing tool we now know might be unprecedented, but a tech company being a tech company under capitalism (and, increasingly, global policy) is not.
We owe ourselves better than to ignore the logical fallacy in this expectation. We cannot afford to believe that Claude, or any tech product like it, is any individual's personal assistant first, regardless of how successfully it's been marketed to you. No matter how much time you've spent giving Claude data on how you prefer your AI-generated text, its loyalty (and Anthropic's) was never to you. The fact that Anthropic is choosing to adapt, if haphazardly, to real policy like the EU AI Act is just another reminder of this.
AI labs are companies like any other, with whims and plans of their own -- this is hardly the first or last time one will switch up a product on you. Rather than expect unrealistic consistency or to be prioritized, the better choice is to invest in the writing you want your name on.
Why we need AI transparency
The point of policy isn't always to improve the quality of products, but to consider what the company behind that product has not (or has, but hasn't acted sufficiently on). Article 5 of the EU AI Act aims to do just that.
"It's unacceptable for a tool to sacrifice an iota of clarity, coherence, meaning, quality, etc. for the purpose of embedding hidden clues within the text to suggest its provenance," Gruber wrote in his blog.
As products, yes, AI tools have a market-driven incentive to deliver the highest-quality responses. But provenance, albeit a deeply imperfect science, is crucial for a reason. Copyright debates aside, global trust in news hit a new low this year as more readers turn to chatbots for information. Misinformation is shaping elections, and human relationships with chatbots, especially for children, are devaluing knowing where information comes from and whether to trust it or not.
Also: How AI could close the education inequality gap - or widen it
Anthropic's watermarks are still half-baked. Though they will be machine-readable by detectors eventually, we don't yet have an accessible tool (like Google's SynthID Detector, on which Anthropic's watermarks are based) for the public to read them, and AI detectors themselves are notoriously unreliable. It's unclear how much these new watermarks will do for the information pipeline, academic integrity enforcement, and related issues. But provenance is a field worth investing in -- and if it impacts your experience of an AI tool, that might be a good reason to reevaluate your use of it.
More reasons to write yourself
That said, some arguments about the controversy surrounding Anthropic's watermarks are fair. As Sara Simeone, founder of NoCodeLab.ai, wrote on LinkedIn:
"These labs scraped our content for years to build their wealth, without consent. Then they built one of the most ingenious revenue models ever: we pay them for regurgitated versions of what we already produced. Now we don't only pay. We also have to 'attribute our own IP to them'."
There is an air of hypocrisy to watermarking the product of pirating (and then destroying) books, especially after you've settled a lawsuit with a group of authors over that (OpenAI disappeared its equivalent trove of book data). That doesn't even cover the tons upon digital tons of content AI companies have scraped off the internet, creators uncompensated, to feed their ever-capable, data-hungry models.
(Disclosure: Ziff Davis, ZDNET's parent company, filed an April 2025 lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.)
Then there's the question of where watermarking ends, as John McCarthy, opinion editor at The Drum, posed:
"I'm even working on something that'll help me sort and respond to pitches. Should that be watermarked too? We're using AI to generate captions on our videos, and transcribe our interviews too. Watermark that? We're technically recording those on electrical devices. Is that AI? I have a soft AI filter on my zoom call to reduce my ugliness. Better watermark that too?"
Also: Business adoption of AI agents tripled this year - as measurable ROI emerges
He's right to point out that not all editorial-adjacent work done with an AI tool should be watermarked as AI-generated. Anthropic has yet to clarify how it will approach these differences, and admitted in its first announcement that watermarks may or may not attach to smaller-scale edits done with Claude.
But there's a deeper reaction to Anthropic, and AI labs writ large, beneath both these posts: that getting the economy hooked on tools that automate your work, only to turn around and place a tracker on said work in ways that could imperil it, stings like betrayal. But you can't be betrayed by a company that was never beholden to you to begin with.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み