AI Firms Are Watermarking Generated Text — But It May Not Work

AI Firms Are Watermarking Generated Text — But It May Not Work

AI companies are increasingly experimenting with invisible watermarks embedded directly into AI-generated text. The idea is to make machine-written material identifiable without changing how it looks to readers. Anthropic, for example, has begun applying an imperceptible watermark to text produced by newer Claude models, using subtle patterns in word selection that can later be detected by a specialized system. Google has also developed SynthID-Text, a similar approach for identifying Gemini-generated content.

The fundamental weakness is that text is extremely easy to transform. Unlike a watermark embedded in an image, a statistical watermark in language depends on the precise words and tokens selected by the model. Rewriting, paraphrasing, translating, or even substantial human editing can disrupt the statistical pattern. Recent developers have already demonstrated approaches for stripping or bypassing such signals, although some of the tools currently advertised as watermark removers cannot yet prove that they actually remove the underlying watermark.

There is also a more fundamental problem: a watermark can indicate that AI was involved, but not how AI was involved. It may not distinguish between a completely AI-written essay, a human-written document that was lightly edited by AI, or human text that was translated or substantially revised using a watermarking model. Researchers therefore warn against interpreting a positive watermark detection as definitive evidence about authorship. Similarly, the absence of a watermark does not necessarily prove that text was written entirely by a human.

That doesn't necessarily make watermarking useless. It could still be valuable for detecting straightforward copy-and-paste use, improving transparency, and discouraging casual misuse. At the International Conference on Machine Learning in 2026, watermarking reportedly helped identify hundreds of reviewers who violated a no-AI policy, suggesting that it can work as a practical deterrent even if it is not technically unbreakable. The larger lesson is that watermarking should probably be treated as one layer of provenance rather than a definitive AI detector—with disclosure, audit trails, source verification, and human accountability providing the other layers.

About the author

TOOLHUNT

Effortlessly find the right tools for the job.

TOOLHUNT

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to TOOLHUNT.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.