sözaltı news Science
Science
EN AZ
AI firms are watermarking generated text – here’s why it won’t work

AI firms are watermarking generated text – here’s why it won’t work

newscientist.com 20.08.2026 11:00 34 baxış
AI companies have begun embedding watermarks in the output of their models to improve transparency and help crack down on misinformation, disinformation and cheating on homework, but there are limitations to this approac

As AI chatbots have taken off, you have probably found yourself wondering whether a piece of text you are reading was written by a human or a machine. Now, in response to European Union legislation, many AI firms are adding watermarks to text, images and video created by their models with the aim of letting you do just that. The hope is that these watermarks will help stem the spread of misinformation and bring transparency to the use of AI, but experts point out that, at least when it comes to text, watermarking is unlikely to work.

The requirement to watermark is part of the EU’s AI Act, and came into force on 2 August. OpenAI, the maker of ChatGPT, is already watermarking images and audio, and says it plans to add text watermarking in future. Anthropic, the firm behind Claude, has announced that future models will watermark text.

The AI Act allows a grace period for models that have already been deployed, but all models must provide watermarking by 2 December this year. Why I have changed my mind about AI and you should too James Padolsey at NOPE, an AI safety firm, says that while image and video watermarks are more reliable because they are composed of dense and multi-layered data, watermarks in text will always be more difficult to implement. One approach to watermarking text is to apply a mathematically detectable pattern to the choice of words.

Large language models like ChatGPT create sentences by appending whichever word is statistically most likely to come next. By varying this selection of words, perhaps by choosing alternately the most likely next word and then the second, in repetition throughout a sentence, models can embed a pattern without changing the overall meaning of the text. Under the AI Act, AI companies will be required to offer tools that can look for these patterns, allowing people to identify AI-generated text.

But Padolsey points out that these watermarking patterns are susceptible to deletion by even light edits. To drive home his point, Padolsey has created an online tool called declaude, which takes AI-generated text and lightly changes it in such a way that existing AI detectors no longer work. The same process should work on watermarked text, he says.

Even without such tools, Padolsey says that some open-source AI models that don’t abide by the EU’s rules will always be available, because these aren’t controlled by any one tech firm. And they’ll probably be cheaper and easier to run,” he says. Peter Scarfe at the University of Reading, UK, says lots of companies have pitched products to his department claiming to be able to help spot student plagiarism, albeit using other methods than watermarking, while also including small print that says their systems shouldn’t be used to conclusively prove or punish incidents of plagiarism because they aren’t infallible.

Extract — continue reading at the source.

Read full story