Text AI Watermarks Will Always Be Trivial to Remove

The EU AI Act's Article 50, enforceable from August 2026, requires LLM providers to watermark AI-generated text. But text watermarking is a fundamentally different beast from image watermarking — and removing it remains trivial. Here's the technical breakdown.
Why Text Watermarking Is Hard
Images have noise you can hide watermarks in; text doesn't. You can't tweak a sentence without a human noticing. That makes it a steganography problem where the plaintext can't be arbitrarily manipulated. A naive approach like "every fifth letter is 'e'" would compromise output quality.
Could the model itself juggle the watermark? Strong models can, but it burns reasoning tokens and degrades output quality — a poor trade-off.
Why Detection Via Model Re-Run Fails
Running the text through the model to check token probabilities doesn't work: the space of human text that reads like AI output is huge, false positives abound, and it's prohibitively expensive for every EU citizen to get free verification.
How SynthID Works
Google's SynthID is the only public text watermark. It assigns each token a score based on previous tokens — e.g., sum token IDs mod 5. When sampling, the model picks the highest-scoring token from the top five likely options. Detection aggregates the score across a text block; a suspiciously high aggregate flags AI generation.
This is like the em-dash heuristic, but based on subtle mathematical patterns humans can't spot.
The Catch
But any watermark that preserves lexical diversity is removable by simple paraphrasing, token substitution, or even translation. As long as the text must read naturally, you can strip the signal with minimal effort. SynthID's robustness is limited — it's designed for mass detection, not for resisting deliberate removal.
Expect the EU to enforce a requirement that's technically unsatisfiable. Labs will comply with the letter, but anyone who cares can bypass it in seconds.
📖 Read the full source: HN AI Agents
👀 See Also

AI Detection Tools Push Students to Use AI Defensively, Study Finds
AI detection tools in education are causing students to intentionally write worse to avoid false positives, with some students turning to AI tools defensively to check if their own writing will be flagged.
Stripe to Acquire AI Gateway OpenRouter for $7B+
Stripe has reportedly finalized a deal to acquire AI gateway startup OpenRouter for over $7 billion, giving it a single access point to 400+ AI models and 8 million users.

Qwen 3.6 27B at 52.8 tps TG on AMD MI50s: Full Precision, No MTP, No Quant
A Reddit user benchmarks Qwen3.6-27B on eight AMD MI50s (2018 cards) using a vllm fork with ROCm 7.2.1, achieving 52.8 tps TG and 1569 tps PP with full precision and no MTP.

Nvidia RTX Spark: 1-Petaflop Superchip Brings Local AI Agents to Windows PCs
Nvidia unveils RTX Spark, a 1-petaflop superchip for Windows PCs, enabling local AI agents with up to 128GB unified memory and full CUDA/RTX stack. Ships this fall in laptops and desktops from ASUS, Dell, HP, Lenovo, Microsoft Surface, and MSI.