AI Watermarks Are Coming for Text and Code — And They Could Change How We Trust Software
- Get link
- X
- Other Apps
Artificial intelligence is becoming increasingly difficult to distinguish from human work. A chatbot can produce an essay in seconds, write a marketing campaign in minutes and generate functioning software with surprisingly little human input.
Now the AI industry is moving toward a new solution: watermarking the output itself.
Anthropic, the company behind Claude, says it will introduce invisible watermarks into AI-generated text as part of its effort to comply with the European Union’s AI transparency requirements. The company has also provided new details about how the technology will work—and what it means for everything from school essays to professional writing and computer code.
The implications are much bigger than simply catching students using AI.
Watermarking could become part of a new digital infrastructure for determining where synthetic content came from.
What Is an AI Watermark?
Traditional watermarks are visible. A photographer might place a logo across an image. A banknote contains patterns that can be difficult to reproduce.
AI text watermarks work differently.
Instead of adding something visible to a document, an AI model can make carefully controlled choices during generation.
Imagine Claude has several perfectly acceptable ways to phrase a sentence. It might choose one word instead of another, or one grammatical construction instead of another, according to a statistical pattern.
Individually, those choices look completely normal.
Across a sufficiently long passage, however, they can form a recognizable signal.
Anthropic says its system will use the SynthID-Text approach developed by Google DeepMind, creating a pattern that is effectively invisible to ordinary readers but can potentially be detected using the appropriate key.
That distinction is crucial.
An AI watermark is not supposed to make AI writing look strange.
It is designed to make its origin verifiable.
The Important Difference Between Watermarking and AI Detection
For years, schools, employers and publishers have relied on AI detectors that attempt to determine whether a piece of writing "sounds like AI."
That approach has obvious weaknesses.
AI detectors generally look for statistical or stylistic characteristics associated with machine-generated writing. Certain sentence structures, predictable vocabulary and repetitive patterns can become signals.
But writing styles change.
Humans can write in ways that resemble AI.
AI can also be instructed to write in ways that resemble humans.
Watermarking approaches the problem from a completely different direction.
Instead of asking:
"Does this text look like AI?"
the system asks:
"Does this text contain the cryptographic or statistical signal associated with this AI model?"
That could potentially make provenance much more reliable.
But it does not make it impossible to disguise AI-generated material.
Can You Remove an AI Watermark?
Yes—at least under some circumstances.
Anthropic acknowledges that extensive rewriting can eliminate the watermark.
If someone takes an AI-generated article and completely rewrites every sentence and word, there may no longer be enough of the original generated material for the watermark to survive.
But that creates an interesting philosophical question.
At what point does AI-assisted writing become human-authored writing?
Consider two scenarios.
A journalist asks Claude to produce a 1,500-word article and publishes it almost unchanged.
A second journalist uses Claude to brainstorm ideas, conducts interviews independently, writes the article herself and then asks Claude to correct several grammatical errors.
These are radically different forms of AI involvement.
Anthropic says watermark detectability will depend partly on how much text Claude generates or changes. Light proofreading may leave little material for a watermark to attach to because most of the final text was written by the human.
This suggests that future debates about AI authorship may become considerably more complicated than simply asking:
"Was AI used?"
The more important question may be:
"How was AI used?"
And Then There Is Code
The most interesting part of Anthropic's explanation may be its discussion of programming code.
AI-generated software is not the same as AI-generated prose.
When Claude writes an essay, it has enormous freedom. There are countless ways to express an idea.
Code is different.
A programmer may need to use a specific programming language, library, function, syntax or API. The program must satisfy technical constraints and, ideally, actually work.
That dramatically reduces the number of arbitrary choices available to the model.
Consequently, Anthropic says AI-generated code should generally contain less watermarking than ordinary text.
The watermark could still appear where the model has freedom to make arbitrary linguistic choices—for example, comments, descriptions or certain naming decisions.
But the actual functional code should be affected much less.
That is an important distinction.
A watermark that substantially changed executable code could potentially introduce bugs.
The purpose of the system is therefore not to sacrifice functionality simply to make software identifiable as AI-generated.
The Future of AI-Assisted Programming
This raises a larger question about software development.
AI coding tools are rapidly becoming part of the programming workflow.
Developers increasingly use AI to:
- generate functions;
- explain unfamiliar code;
- identify bugs;
- write tests;
- refactor applications;
- document software;
- generate boilerplate;
- translate code between programming languages.
If watermarking becomes widespread, the industry could eventually develop systems capable of determining which portions of a codebase originated from AI models.
That could have consequences for software auditing, intellectual property, cybersecurity and compliance.
Imagine a company purchasing a critical software system and asking:
How much of this code was generated by an AI system?
Today, there is no universal answer.
Tomorrow, provenance technologies could make that question easier to investigate.
Watermarking Could Become a New Layer of Digital Provenance
The biggest significance of Anthropic's announcement may therefore have little to do with students trying to evade plagiarism detection.
It could be about digital provenance.
The internet is entering an era in which synthetic media can be produced at enormous scale.
Text, images, audio, video and software can all be generated or substantially modified by AI.
That creates a fundamental problem.
If the cost of producing convincing synthetic content approaches zero, determining where something came from becomes increasingly valuable.
Watermarks could become one part of the answer.
Instead of relying entirely on visual or linguistic clues, platforms could eventually ask whether a piece of content contains a machine-readable provenance signal.
That could be useful for news organizations, governments, educational institutions, software companies and online platforms.
But there is an important limitation.
A watermark can potentially tell you that content originated from a particular AI system.
It cannot automatically tell you whether the content is true.
A watermarked article can contain misinformation.
A human-written article can contain misinformation.
A watermark establishes provenance, not accuracy.
That distinction will become increasingly important.
The EU Is Helping Push the Industry in This Direction
Anthropic says its watermarking initiative is connected to the European Union's AI transparency requirements.
This matters because regulation can turn an optional technical feature into an industry standard.
Once major AI companies begin implementing provenance technologies, smaller companies may eventually be expected to follow.
Anthropic also indicates that Claude will not be the only system implementing watermarking. Other major AI developers that have committed to the relevant European AI Code of Practice are expected to introduce their own approaches.
That could lead to an ecosystem in which different AI models have different invisible signatures.
The long-term possibility is fascinating.
A document could potentially carry evidence of having passed through multiple AI systems.
One model generates the draft.
Another rewrites it.
A third summarizes it.
A fourth translates it.
The resulting document might contain traces of several different AI systems—or none, depending on how extensively it was transformed.
The technology could therefore become a new kind of digital fingerprinting system.
But Watermarks Will Not Solve the AI Problem
There is a temptation to see watermarking as the final answer to AI-generated content.
It is not.
Watermarks can be attacked, weakened or removed.
Heavy rewriting can destroy the original signal.
Short texts may not contain enough material for reliable detection.
Human editing can complicate attribution.
And different AI systems may implement different standards.
There is also the possibility of adversarial techniques specifically designed to disrupt watermark detection.
So watermarking should be understood as a provenance mechanism, not an infallible lie detector.
That distinction matters enormously in education and employment.
A watermark should not automatically become evidence of academic dishonesty or professional misconduct without context.
The Bigger Question: Who Owns the Digital Fingerprint?
There is an even deeper issue hiding underneath the technology.
If AI systems place invisible signatures into everything they generate, AI companies are effectively creating a new layer of metadata around human communication.
That raises questions about privacy, ownership and control.
Who can detect the watermark?
Who holds the detection key?
Can governments access it?
Can universities use it?
Can employers use it?
Can online platforms automatically scan every piece of content?
And what happens when AI-generated text becomes so common that the distinction between human and machine authorship is no longer binary?
These questions will become more important as AI moves from being a novelty into basic digital infrastructure.
The Coming Internet May Need an "Origin Layer"
For most of the history of the internet, the central question was whether information could be accessed.
The next era may be about determining where information came from.
Was it written by a person?
Generated by Claude?
Created with another AI model?
Edited by several systems?
Completely rewritten by a human?
Or produced through a mixture of all of the above?
AI watermarking is one attempt to answer those questions.
It will not be perfect.
It will not prevent deception.
And it will not eliminate the need for human judgment.
But it represents an important shift.
The AI industry is moving from simply generating content to embedding information about the provenance of that content.
For text, that could change how we think about authorship.
For code, it could change how companies audit software.
And for the internet as a whole, it could mark the beginning of a new era in which digital content carries an invisible history of how it was created.
The most important question may no longer be whether AI can generate convincing content.
We already know it can.
The question now is whether the internet can develop a reliable way to tell us where that content came from—and whether we should trust it.
- Get link
- X
- Other Apps

Comments
Post a Comment