All notes

AI Text Watermarks in Practice

Originally published on LinkedIn

On August 2 Article 50 of the EU AI Act went live. Providers of generative systems now have to mark their output so that a machine can detect it was AI-generated. If your company publishes AI-written text, this one is for you. I went through it so you don't have to.

Short version: AI now has to watermark its output. With photo and video it's clear, but how do we detect AI-generated text?

The main method works at generation time. Before each word the model sorts the candidate tokens into two groups, call them green and red, and leans green. Across a few hundred words the bias becomes measurable and a detector with the key sees it. The reader sees normal prose. Cruder methods exist too: invisible Unicode, file metadata. Many companies now run real processes on AI-generated text, and the law has them nervous.

So I went to check whether that machinery exists yet. Good news: barely, and nobody can check the result anyway.

Two major providers watermark text in production today. Google, with SynthID-Text in Gemini, and Anthropic. OpenAI built one, measured it at around 99.9% accuracy, and shelved it after internal surveys said a third of users would use ChatGPT less :) Neither Google nor Anthropic has released a public detector, so there is no way to verify any of it from the outside so far.

Of course, tools like "watermark removers" appeared almost immediately. Sounds like a solution, but not quite. I installed one (guillaumemeyer/watermarks-remover on GitHub) and measured it on a 200-word paragraph from Gemini.

The invisible-character layer is the easy half, and it handled that well. The statistical layer (the green and red tokens) is harder, because that watermark lives in the word choices. Removing it means literally rewriting the words. 76% of word pairs changed, 60% of the original sequence gone. So what you get in the end is badly rewritten text, because the quality of the rewrite is capped by the quality of the model doing the rewriting. Don't count on open-source solutions here - they provide tiny models. If you want to keep using AI for part of your content, you'll need a custom setup with your own bigger model.

One correction: the marking duty in 50(2) sits with the provider of the system, not with you for using it. What lands on companies is 50(4), covering AI text published to inform the public on matters of public interest. Landing pages, product copy, email sequences, your blog are not that. And even there an exemption applies when the content had real human review with a named person holding editorial responsibility, documented rather than asserted.

Technical write-up, not legal advice. Check your own case with counsel

Back to writing