CLI tool
wiltodelta/remove-ai-watermarks avatar
wiltodelta/remove-ai-watermarks

remove-ai-watermarks: a CLI and Python library for stripping AI provenance marks from images and video

AI watermark remover. CLI and Python library to strip visible and invisible AI watermarks (Gemini / Nano Banana sparkle, SynthID) and provenance metadata (C2PA, EXIF, IPTC) from images.

5,682 stars524 forksPythonApache-2.0

At a glance

What is it?
The project targets visible vendor labels, invisible pixel watermarks and C2PA/EXIF/IPTC metadata on content you generated yourself. Metadata work runs on CPU with a four-package install; invisible image removal needs CUDA, and the README is explicit that this is not a tool for defeating third-party stock previews.
Who is it for?
Adopt it if you generate your own images or video and need the provenance metadata, vendor sparkle marks or a pixel watermark gone before publishing, and you are comfortable with a Python 3.11 to 3.14 install that splits into extras. Do not adopt it to strip stock-agency previews, other people's paid content or text watermarks: the README scopes the tool to content you own, and the repository has no text path at all.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 4 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 26, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What remove-ai-watermarks actually removes

The project handles three distinct classes of mark, and conflating them is the fastest way to be disappointed. The first is a visible label: the Google Gemini sparkle, vendor text marks, and named video marks from Sora, Veo, Seedance, Dola, Hailuo AI and Kling AI. The second is an invisible pixel watermark, which the README describes as removable through diffusion regeneration for images and through an oracle-certified VAE profile for video SynthID. The third is provenance metadata: C2PA manifests plus EXIF, XMP and IPTC fields.

The README is blunt about the intended user. It is for people removing marks from images and video they generated themselves, and it states that the project does not target stock agency previews or other watermarks that protect third-party paid content. A docs/legal-and-safety.md file carries the scope and safety notes. That framing matters: this is a provenance-cleaning tool for your own output, not a general watermark eraser for whatever image you found.

One design point worth noticing is that the tool distinguishes a hidden pixel watermark from its linked C2PA manifest. The README states that the all command removes both, while metadata stripping alone removes only the manifest. If you strip metadata and stop, you have removed the paperwork and left the mark in the pixels.

How the visible and metadata paths differ under the hood

Metadata removal is the cheap path. The default install depends on pillow, piexif, click and python-dotenv, and the README lists metadata inspection and stripping as the capability that install buys. For video, the video metadata command does not transcode video or audio streams at all. It reads and rewrites container-level tags: MP4 and MOV inspection covers the native TC260 AIGC tag in moov.udta.meta.keys/ilst, including a moov box placed after the media payload, plus the QuickTime-form meta variants that Doubao's iOS export writes. MKV and WebM use Segment.Tags.Tag.SimpleTag, AVI uses LIST/INFO/AIGC, and FLV uses script.onMetaData.AIGC. The non-ISOBMFF formats are remuxed with stream copy rather than re-encoded.

Visible removal is a different machine. For video, the README says the path scans the entire sequence before changing any pixels, accepts only a mark that repeats at a stable position across adjacent frames, and then reuses the same OpenCV, MI-GAN or LaMa fill backends as image removal. Audio is copied without re-encoding and allowed to reach its natural end, while the video stream is transcoded because its pixels change. A guarded optical-flow pass motion-aligns the preceding accepted fill and blends it only when nearby source context agrees, and --no-temporal-consistency disables that. The encoder preserves supported 8-bit source chroma sampling, color tags and MP4/MOV track timescale, and variable frame intervals survive through a timestamped in-memory NUT bridge instead of being flattened to an average frame rate. That is a lot of engineering aimed at not visibly damaging the clip while removing the mark.

Invisible removal is the expensive one. Image regeneration requires CUDA, and the README marks video SynthID removal as GPU-recommended. The all command is listed as GPU-recommended because it runs visible, invisible and metadata removal together.

Installing remove-ai-watermarks and running a first removal

The README uses uv for installation, and the extras decide which features exist. Start with the metadata-focused default CLI, which is the only path that needs no GPU and no model downloads.

bash
uv tool install remove-ai-watermarks

Then inspect a file before changing anything. The identify command reports provenance signals and watermarks without a GPU.

bash
remove-ai-watermarks identify image.png

Visible mark removal needs the pixel dependencies, so reinstall with the visible extra. The --force flag is what the README uses to replace the existing tool install.

bash
uv tool install --force "remove-ai-watermarks[visible]"
remove-ai-watermarks visible image.png -o clean.png

If you only want the metadata gone, skip the pixel extra entirely. Note the overwrite behaviour: without -o this command overwrites the source in place.

bash
remove-ai-watermarks metadata image.png --remove -o clean.png

Video metadata follows the same shape, but with a different default. The --check flag inspects without writing, and when -o is omitted the command writes <source>_clean and preserves the original, unlike the image command.

bash
remove-ai-watermarks video metadata input.mp4 --check
remove-ai-watermarks video metadata input.mp4 --remove -o clean.mp4

For the product-oriented video path, install the video extra and use video all, which removes a stable registered visible mark when present and always strips verified AI metadata. The README states that if neither signal is found it still writes a same-container passthrough, so callers get one predictable output contract. Proprietary invisible-video removal is excluded unless you pass --invisible, which opts into the lossy, oracle-certified SynthID profile.

bash
uv tool install --force "remove-ai-watermarks[video]"
remove-ai-watermarks video identify input.mp4
remove-ai-watermarks video all input.mp4 -o clean.mp4

A directory of videos goes through video batch with a --mode flag, and a specific video mark can be named with --mark followed by veo, seedance, dola, hailuo or kling.

Where the extras matrix becomes a real constraint

The installation table is not decoration. Metadata inspection and stripping come from the bare package. Visible detection and removal need [visible]. Visible video processing needs [video]. Video SynthID removal needs [video,diffusion]. Torch-free DWT-DCT detection needs [detect]. Invisible image removal needs [qwen-zimage] and CUDA. There is also an [all] extra described as every production feature available on the active Python, plus lower-level extras named pixels, heif, trustmark, migan, lama and diffusion whose dependency composition, Python compatibility and model requirements the installation guide documents separately.

That split is sensible for a metadata-only user and annoying for anyone who installed the default and then hit a visible mark. The failure is not silent in a dangerous way, but it is a reinstall. The [all] extra exists precisely because assembling the right combination by hand is error-prone.

The Python range is another constraint: pyproject.toml declares requires-python >=3.11,<3.15. A 3.10 environment is out. The package is also classified as Development Status :: 4 - Beta, which is consistent with a version line that moved through 0.32.0, 0.34.0 and 0.34.1 within August 2026 and sits at 0.40.3 in pyproject.toml. Pin a version if you are wiring this into a pipeline.

Model downloads are the other hidden cost. The .env.example lists HF_TOKEN for gated or private models, HF_HOME as a shared Hugging Face cache root, XDG_CACHE_HOME as a fallback, RAIW_CLASSIFY_WEIGHTS for local photo-classifier weights, and VIDEOSEAL_CACHE_DIR defaulting to ~/.cache/remove-ai-watermarks-dev/videoseal for development benchmarks. None are required for metadata work, but the diffusion and video paths will fetch models, and that is bandwidth and disk you should plan for.

The wrong tool for text, and the wrong tool for other people's files

The repository contains no text watermark path. There is no command in the README's goal table that touches documents, chat output or Word files, and the top-level layout is image and video oriented: src/, tests/, data/, demo_banana_before.png and demo_banana_after.png. People searching for how to remove AI watermarks from text will not find it here, and no amount of extra installation changes that. Text watermarking is a separate problem with separate tooling.

The second boundary is legal and practical rather than technical. The README states the project is for lawful use on content you own and does not target stock agency previews or other watermarks protecting third-party paid content. A tool that removes a provenance mark is doing something different from a tool that removes a paywall overlay, and the project draws that line itself in docs/legal-and-safety.md.

The third limitation is the invisible path. Image regeneration requires CUDA, which rules out a plain CPU server, and the README calls the video SynthID profile lossy. Lossy is the honest word: you are regenerating pixels, and regenerated pixels are not the original pixels. For an archival copy where fidelity matters, that trade is not obviously worth making. If your goal is only to publish an image without a C2PA manifest attached, the metadata command gets you there without touching a single pixel.

How it compares with generic inpainting and with hosted services

The obvious alternative is a general image editor or inpainting tool where you select the watermark region yourself and run a fill model. That approach is more flexible and works on any mark, including ones this project has never registered. The difference is knowledge. remove-ai-watermarks ships registered marks for specific vendors, and the video path adds a temporal check the README describes as accepting only a mark that repeats at a stable position across adjacent frames, then reusing the same OpenCV, MI-GAN or LaMa backends. A manual editor gives you no such check, so a mark that flickers or moves between frames becomes a frame-by-frame job. Conversely, a manual editor handles a mark this project does not know about, and the README's own table shows the visible path is built around known labels.

The other alternative is the hosted service the README points to at raiw.cc, which it says runs this library with the GPU included and nothing to install. There, visible mark and metadata removal at Standard output up to 12 MP are free, while original resolution above 12 MP and invisible watermark removal are paid. The trade is straightforward: the library is Apache-2.0 and runs locally with no upload, while the service removes the CUDA requirement and the model downloads at the cost of sending your files to someone else's machine and paying beyond 12 MP. If your images are sensitive or your volume is high, local wins on both counts; if you have no GPU and occasional files, the hosted path avoids the whole [qwen-zimage] setup.

A third option is doing nothing but metadata. Plenty of workflows only need the C2PA manifest gone, and the bare package covers that in a single install.

Licence, maintenance and what an upgrade costs you

The project is Apache-2.0, declared both in pyproject.toml and in the repository LICENSE file. Apache-2.0 permits commercial use and modification and includes a patent grant, which is friendlier than a copyleft licence for embedding in a product. It also means you can vendor the code if you need to. That is a statement about the licence text, not advice about your situation; if you are redistributing a modified version, read the NOTICE and attribution requirements yourself.

The last push to the repository was on 2026-08-28, and the most recent release listed is v0.34.1 on the same date. The repository is not archived. The version string in pyproject.toml is 0.40.3, which is ahead of the newest release in the list, so the main branch carries work that has not been tagged. That gap is worth knowing about if you install from git rather than from PyPI.

Upgrade cost is dominated by the extras and the models, not the Python code. A metadata-only install has four runtime dependencies and no model cache, so upgrading is close to free. The diffusion and video paths pull model weights into the Hugging Face cache, and a version bump that changes model requirements means a re-download. The .env.example also hints at optional integrations that read credentials: named OpenAI keys for provider-oracle slots, Azure Content Safety settings read through the authenticated Azure CLI, and ThorData residential proxy routes for explicitly selected Web oracle routes. None of those are needed for core removal, and the file warns not to commit credentials. The Beta classifier is the honest signal here: expect the CLI surface to keep moving, and pin the distribution name remove-ai-watermarks in any lockfile, because pyproject.toml notes that changing it would strand existing installs and the ComfyUI node package that depends on it.

Editorial conclusion

Adopt it if you generate your own images or video and need the provenance metadata, vendor sparkle marks or a pixel watermark gone before publishing, and you are comfortable with a Python 3.11 to 3.14 install that splits into extras. Do not adopt it to strip stock-agency previews, other people's paid content or text watermarks: the README scopes the tool to content you own, and the repository has no text path at all. Before you rely on it, run remove-ai-watermarks identify on a sample of your own files and check which signals it actually reports, then confirm the extra you installed covers the mark you see, because metadata stripping alone removes a C2PA manifest without touching the linked pixel watermark.

Frequently asked questions

Is it possible to remove an AI watermark?

For the marks this project covers, yes. remove-ai-watermarks removes known visible labels such as the Gemini sparkle, disrupts invisible pixel watermarks through diffusion regeneration for images or a VAE profile for video, and strips C2PA, EXIF, XMP and IPTC metadata. The README scopes this to content you generated yourself.

How can I remove an AI watermark from an image?

Install the pixel extra with uv tool install --force "remove-ai-watermarks[visible]", then run remove-ai-watermarks visible image.png -o clean.png. For metadata only, the bare package plus remove-ai-watermarks metadata image.png --remove -o clean.png is enough and needs no GPU.

Can I remove AI watermarks for free?

The library itself is Apache-2.0 and free to install and run locally, though the invisible image path requires CUDA hardware. The README also points to a hosted service at raiw.cc where visible mark and metadata removal at Standard output up to 12 MP is free, while higher resolutions and invisible watermark removal are paid.

How do I remove AI watermarks from a video?

Install the video extra with uv tool install --force "remove-ai-watermarks[video]", then run remove-ai-watermarks video all input.mp4 -o clean.mp4, which removes a stable registered visible mark when present and always strips verified AI metadata. A specific mark can be named with --mark, for example veo, seedance, dola, hailuo or kling.

What is the best AI watermark remover?

That question asks for a ranking, and this article does not rank tools. What it can say is what remove-ai-watermarks covers: visible vendor marks, invisible pixel watermarks through diffusion regeneration or a VAE profile, and C2PA, EXIF, XMP and IPTC metadata, for images and video you generated yourself.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
  4. Release notes
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/wiltodelta-remove-ai-watermarks.svg)](https://hysenlabs.com/projects/wiltodelta-remove-ai-watermarks)