AI companies are increasingly experimenting with invisible watermarks embedded directly into AI-generated text. The idea is to make machine-written material identifiable without changing how it looks to readers. Anthropic, for example, has begun applying an imperceptible watermark to text produced by newer Claude models, using subtle patterns in word selection that can later be detected by a specialized system. Google has also developed SynthID-Text, a similar approach for identifying Gemini-generated content.
The fundamental weakness is that text is extremely easy to transform. Unlike a watermark embedded in an image, a statistical watermark in language depends on the precise words and tokens selected by the model. Rewriting, paraphrasing, translating, or even substantial human editing can disrupt the statistical pattern. Recent developers have already demonstrated approaches for stripping or bypassing such signals, although some of the tools currently advertised as watermark removers cannot yet prove that they actually remove the underlying watermark.
There is also a more fundamental problem: a watermark can indicate that AI was involved, but not how AI was involved. It may not distinguish between a completely AI-written essay, a human-written document that was lightly edited by AI, or human text that was translated or substantially revised using a watermarking model. Researchers therefore warn against interpreting a positive watermark detection as definitive evidence about authorship. Similarly, the absence of a watermark does not necessarily prove that text was written entirely by a human.
That doesn't necessarily make watermarking useless. It could still be valuable for detecting straightforward copy-and-paste use, improving transparency, and discouraging casual misuse. At the International Conference on Machine Learning in 2026, watermarking reportedly helped identify hundreds of reviewers who violated a no-AI policy, suggesting that it can work as a practical deterrent even if it is not technically unbreakable. The larger lesson is that watermarking should probably be treated as one layer of provenance rather than a definitive AI detector—with disclosure, audit trails, source verification, and human accountability providing the other layers.