Text AI watermarks will always be trivial to remove
![]()
Sean Goedecke, writing a month before Article 50 of the EU AI Act becomes enforceable, argues that its demand for AI output to be "detectable as artificially generated" cannot be met robustly for text. Google's SynthID biases token sampling towards a pattern a verifier can check, and OpenAI and Anthropic are, in Goedecke's words, "definitely using homoglyphs", though Goedecke is "not sure" they are meant as a watermark. Both, the post shows, are stripped by replacing the homoglyphs with their real characters or by paraphrasing with even a weak un-watermarked model, and C2PA signing covers files, not plain text. Hence the title: text AI watermarks will always be trivial to remove.
Was this useful?