You can remove the mark with a deterministic pass that regenerates the text as clean ASCII, and a thorough rewrite of the prose removes enough of the statistical signal that a detector can't find it.
Two methods for stripping an AI watermark from generated text are now in circulation, attributed to Daniel Miessler and relayed by Kai Magnus. Both are described as working — one by rebuilding the text byte-for-byte as plain ASCII, the other by paraphrasing it until the statistical signature is gone.
A quick unpack of the terms. AI watermarks are subtle patterns embedded in generated text: either invisible Unicode characters mixed in among normal letters, or a statistical skew in word choice that a detector can measure. Removing the first kind is mechanical; removing the second requires actually changing the writing.
The deterministic approach regenerates the text through a separate pass that outputs clean, validated ASCII-only characters. As Miessler puts it:
"Complete sanitized regeneration of the text using a separate method that produces the canonicalized ASCII-only pure text format with validation."
In plain terms: the text is rewritten using only the standard character set — the letters, digits and punctuation on a keyboard — which strips out any invisible or unusual characters that were hiding in the original output. The "validation" part means the result is checked, so you know the output is clean rather than hoping it is.
The paraphrase approach works differently. Word-level watermarks live in the statistical pattern of which words were chosen, so each swap erodes the signal:
"Each word you swap removes a little of the statistical signal, and a thorough paraphrase removes enough that a detector can't find what's left."
This is usable today, not a proposal — the methods are described as shipping. The catch worth naming plainly: the ASCII pass only guarantees character-level cleanliness. If the watermark was statistical rather than character-based, canonicalization may not touch it, and only the paraphrase route addresses that. Conversely, a light edit is not enough — the claim is specifically that a thorough paraphrase removes the signal, which means a surface pass with a few synonyms swapped may leave detectable traces.
Who this is for: anyone who wants clean, unattributable text from AI output and wants to know which technique actually does what. The ASCII regeneration is the more technical of the two — a deterministic regeneration pass with validation is something you'd run with tooling, not by hand, so it leans toward readers comfortable running a script or pipeline. The paraphrase method needs no tooling at all and is the more accessible option for non-developers — though it's also the one where "thorough" is doing a lot of work, and there's no stated threshold for how much rewriting counts as enough.
One thing neither quote addresses: detection is an arms race. A claim that a detector "can't find what's left" is a claim about current detectors, not a permanent guarantee. And nothing here speaks to whether removing a watermark is appropriate in your context — that's left entirely to you.