AikanAI
Back to feed
News feedGlobalai

AI Models Are Watermarking Text—Will You Notice?

SourceIEEE Spectrum(spectrum.ieee.org)20 days ago · 9/9/2026
AI Models Are Watermarking Text—Will You Notice?

On 11 August, Anthropic announced that all future Claude models will generate text that contains a watermark that identifies its results as AI generated. The company is not alone. Google has its own text watermark (which Anthropic’s is based on) that it uses on the output of its Gemini models . OpenAI has yet to introduce a text watermark but it plans to do so .

The rapid spread of watermarking is in part a response to the European Union’s AI Act , which mandates watermarks for AI models released after 2 August, 2026, along with other planned and proposed regulations aimed at curbing the spread of deceptive or manipulative AI-generated content. But the new rules may come at a cost for AI users who simply want the best possible results.

AI watermarks can apply to many forms of content: The EU Artificial Intelligence Act also requires them for images, audio, and video. Such media watermarks have been in use for years , and while their effectiveness as a holistic solution to marking AI remains up for debate , they can achieve detection rates above 99 percent . Image and video watermarks are already deployed by OpenAI, Google, and Meta, among others. (Anthropic doesn’t provide an image generation model.)

Text watermarks have been less frequently deployed, however, and not everyone is convinced that text watermarking can work without compromising the quality of an AI model’s response. John Gruber, a prolific technology writer and co-creator of the Markdown language, calls the watermark a “ perversion of writing ” and disputes Anthropic’s assertion that a watermark doesn’t change the meaning or quality of text. Images consist of millions of pixels, he notes, whereas text responses often span just dozens or hundreds of words. Text seems to provide far less space to alter AI output in a way that is detectable yet not disruptive.

John Kirchenbauer , postdoctoral fellow at the Vector Institute and co-author of a 2023 paper which was among the first to describe a text watermarking method, disagrees. “[A watermark] wouldn’t be detectable if there wasn’t a change. This is a very fundamental point,” he says. “The question is, do you care if it’s not the exact original distribution if, for all intents and purposes, it doesn’t change the utility to you?”

Realistically, the issue comes down to that word, “utility.” Does watermarking AI-generated text meaningfully degrade the experience of the person using it? The answer is still under dispute.

How AI Text Watermarks Work

The term “watermark” is so familiar that it can cause confusion about how the technology works when applied to AI. A text watermark is not metadata or invisible characters; it is something much more subtle. The exact details vary between methods, but text watermarks are generally impossible for a human (and, in many cases, even a computer) to detect without access to the specific key used to detect a specific watermark. Understanding why requires an understanding of how LLMs work.

An LLM produces a probability for every word that could come next at each step in its response to a prompt. (From here on, I’ll be using “words” interchangeably with “tokens,” although tokens also represent numbers, punctuation, and more.) A likely word might get a 40 percent probability, a plausible alternative 10 percent, and an unlikely one a fraction of a percent. The model then picks a word at random, weighted by those numbers. The most probable word usually wins, but not always.

“[A watermark] wouldn’t be detectable if there wasn’t a change. This is a very fundamental point.” —John Kirchenbauer, Vector Institute

This process provides an opportunity to hide a text watermark by introducing subtle changes to how words are selected.

The 2023 paper by Kirchenbauer and his colleagues provided one of the first examples of how to implement a text watermark, and it remains the most widely cited technique. The researchers describe a watermark which sorts words into a red list and a green list. The red list words are unaltered, but the green list words are nudged to be slightly more probable.

“If we sample from this modified distribution, then while any one token choice won’t necessarily come from that preferred set, over many samples, we’ll preferentially pick words from that up-weighted subset,” Kirchenbauer says.

The text watermark is embedded in the choice of words used, which is why it is effectively invisible to humans. Kirchenbauer and colleagues reported a detection rate of 98.4 percent, and zero false positives, in responses that contain about 200 tokens. The embedded pattern of word probabilities also means that simple paraphrasing won’t obscure the watermark. The paper reports that removing the watermark from a long response requires changing roughly one quarter of its words or more.

Does Watermarking Degrade AI Text?

Although AI text watermarking is designed to be invisible to human readers, by definition it influences the word patterns in AI-generated text. That algorithmic meddling is what makes critics like Gruber concerned that watermarking reduces the overall quality of the output.

The strongest evidence that text watermarking doesn’t impact quality comes from a 2024 paper by a team from Google , which introduced the company’s watermarking scheme called SynthID-Text . Anthropic’s watermark is also based on SynthID-Text, though altered in ways that Anthropic hasn’t detailed.

To show that the SynthID-Text watermark doesn’t impact quality, the Google authors randomly routed Gemini user queries to watermarked and non-watermarked variants of Google’s text models. Then they compared overall user feedback on the output. The authors found no significant difference in user feedback across 20 million responses.

Still, some researchers remain skeptical that watermark methods have no impact on the quality of an AI-generated response. Their skepticism stems from edge cases that can make a watermark more difficult to implement.

Vinu Sankar…

News is gathered automatically from public robotics & AI feeds on a schedule.

Related

Globalai

Trump orders US government to call AI ‘Super Intelligence’

The US executive branch is no longer acknowledging the existence of "artificial intelligence." Going forward, official policy websites, policy documents, and press releases will refer only to "Super Intelligence," thanks to a new executive order signed by President Donald Trump. "The word super is t

SourceThe Verge1 hour ago
Globalai

The internet is convinced Elon Musk’s xAI trolled OpenAI’s ‘Dots’ launch

Before OpenAI launched its new AI agent, Dots, on Tuesday, Elon Musk's xAI had already acquired the domain name "dot.com," which now redirects to the Grok chatbot download page.

SourceTechCrunch1 hour ago
Globalai

Protests against OpenAI get increasingly creative

New sculpture depicts AI leaders escaping a sinking ship.

SourceArs Technica2 hours ago
Globalai

Elon Musk’s AI-powered Grokipedia is updating again

Grokipedia, the AI-powered online encyclopedia from SpaceXAI, appears to be updating articles once again after a months-long pause. In August, Lawfare reported that articles on Grokipedia hadn't reviewed edits since April, but the platform's live updates site is now showing various recent changes to

SourceThe Verge2 hours ago
Globalai

AMD acquires World Labs AI startup, upping the ante against Nvidia

The deal, which is expected to close by year's end, is worth $8.2 billion.

SourceArs Technica3 hours ago
Globalai

OpenAI’s latest features take direct aim at the app store model

OpenAI is building out the pieces of an alternative to the traditional app store model, turning ChatGPT into a place where software can be discovered and used by people and AI agents alike.

SourceTechCrunch3 hours ago