Silicon Valleys Journal
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
  • Contact Us
No Result
View All Result
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
  • Contact Us
No Result
View All Result
Silicon Valleys Journal
No Result
View All Result
Home Technology & Industry AI

AI Watermarking: Who Really Wins and Who Gets Hurt

By Mike Hakob, Andava Digital

SVJ Thought Leader by SVJ Thought Leader
September 5, 2026
in AI, Case Studies, Cybersecurity, Enterprise Tech, Innovation Spotlight, Leadership & Perspective, Policy & Regulation, Technology & Industry
0

Most AI watermarking discussions focus on the technology details of watermarking, such as hidden characters, metadata, or subtle semantic variations. That approach explains the plumbing but skips the problems your team actually faces.

The interesting problem is who this technology helps or hurts, and what a watermark can actually establish when someone is confronted with one. Regulators are moving, and vendors are starting to ship marks. Since 2 August 2026, most provisions of the EU AI Act have applied, including the transparency requirements.

The number of adoptions of this technology increases in unison with the efforts to regulate it. The Salesforce Tenth Edition State of Marketing report presents results from a survey conducted in late 2025 of about 4,500 marketing decision-makers worldwide; it states that 75% of marketing organizations worldwide already use some form of AI.

This brings us to the most pressing question: what does an AI watermark actually illustrate about the person behind the text?

What AI Watermarking Is — and Isn’t

One word is used to describe two very different things, and it ends up causing damage.

The first type sits outside the actual words. This includes metadata, provenance manifests, and maybe even Unicode characters that are unseen and are included between words. This type of data travels with the document and not the language.

The second type is found in the language itself. SynthID by Google nudges a model’s word choices in the direction of a statistical pattern that a detector can later pick up. This is done entirely invisibly. The signal lies in the phrasing, and the researchers on this project are clear that creating a reliable text watermark is genuinely hard.

The most important part: both types of data can hint at which systems came into contact with the content. Neither of these can tell us how much of the work was done by a human, what changes an editor made, or who was responsible for the final work.

Provenance answers where this came from. Authorship answers who made this. A watermark talks about the first question, and the second is where most of the arguments in the workplace begin.

Who Does AI Watermarking Help?

With watermarking, three groups stand to benefit. The first is the vendors of AI models. The second are the regulators. Lastly, organizations that need to trace content to provide sources also benefit.

AI companies, large and small, will want to watermark their models to demonstrate accountability to policymakers. A simple change to the model means the companies can claim they have engaged with policymakers, even if they’ve done little to nothing. This is not cynicism. This is a plain incentive.

Watermarking output is the most valuable to regulators. A machine-readable mark empowers auditors by enabling regulators to enforce a broad principle. Published compliance data in the Article 50 guidance indicate that, for approximately 33% of respondents, transparency is the second most prevalent compliance trigger, behind trust.

For genuine needs, watermarking is valuable to publishing houses, advertising agencies, insurance companies, and banks for verifying content, submissions, and disclosures. A signal of origin serves a real operational need.

Notice what these three have in common. Each wants to know where content came from at scale. None of them needs to prove that a specific person did or did not write a specific paragraph. That distinction is where the benefits stop, and the harm begins.

Who Does It Hurt?

The people most exposed are not the ones generating content wholesale. They are the ones who write their own work and use AI to tidy it up.

Consider an agency copywriter who drafts a case study from scratch, then runs it through a model to fix comma splices and shorten three bloated sentences. The ideas are hers. The reporting is hers. A statistical mark may still survive in the final phrasing, and a client running a detector sees a red bar with no context.

That pattern scales badly. When three in four marketing organizations already use AI somewhere in their process, the flag stops distinguishing anyone. It simply catches whoever edits with a tool.

The second group has it worse. Non-native English speakers and people with disabilities often reach for AI precisely because it closes a gap. A Stanford study found that detectors falsely flagged 61% of TOEFL essays written by non-native English speakers, while performing near-perfectly on essays by native English writers. Of the 91 essays tested, 97% drew a flag from at least one of the seven tools.

The Center for Democracy and Technology (CDT) argues that those error rates are not merely a technical shortcoming. In schools, they can produce disparate discipline against a protected group, which raises civil rights questions rather than IT questions.

The third group cannot fight back. A student facing an academic panel, a freelance journalist whose byline gets questioned, a self-represented litigant whose filing draws doubt. Each faces an accusation dressed up as a score, with no expert witness and no budget for appeal.

Note the shape of the harm. It falls hardest on people with the least institutional power and the strongest legitimate reason to use assistive tools. Heavy AI users, meanwhile, learn to route around the problem.

There is a quieter cost too. Once writers understand that polish invites suspicion, some stop polishing. Clean prose becomes a liability, and the tool that helped a careful writer sound clear now marks her as a suspect.

A Flag Is a Hint, Not Proof

A “hit” means AI use is more likely. A “miss” means it’s less likely. Neither one proves anything, and neither tells you who wrote the text.

These systems err in both directions. They flag people who wrote every word themselves, and they miss the content a model produced end-to-end. A confident-looking percentage hides that uncertainty behind a number, which is exactly why the number travels so well.

The damage happens at the moment of interpretation. A professor treats the score as a verdict. A manager forwards it to HR. Opposing counsel attaches it to a motion.

At that point, a probabilistic hint has quietly become an accusation. The person on the receiving end must now prove a negative.

Watermarks and third-party detectors are not the same technology, yet audiences conflate them into a single idea. Both produce a signal about likelihood. Both get read as a confession.

CDT’s recommendation is worth borrowing well outside education: detector output belongs in a broader inquiry, never as a substitute for professional judgment.

How Easily Does It Come Off?

Removing an AI watermark is often easier than people assume. That’s the difficult part for people planning to rely on marks as evidence.

Metadata and characters disappear in seconds. Days after Anthropic added invisible watermarks to Claude’s output, developer Guillaume Meyer released an MIT-licensed tool to remove invisible Unicode characters, C2PA manifests, and metadata in PNG, JPEG, SVG, PDF, DOCX, HTML, and Markdown files.

ANOTHER News reported that it reached over 6,000 GitHub stars in a few days. The same trend can be observed for any AI watermark remover searches.

Statistical watermarks are harder to remove. The tool’s creator explicitly states that. Since these watermarks are incorporated into the text itself, removing them requires editing the text and rephrasing.

Here is the twist that undermines the enforcement fantasy. Rewriting text and even translating into other languages are normal editorial practices. A copy editor making the text more concise, a localization team creating the German version, or a writer editing the length down to 400 words are all examples of reducing the value of the watermark.

The signal, therefore, weakens under normal conditions and vanishes under deliberate effort. As that report framed it, an arms race, rather than a policy announcement, will determine watermarking’s practical value.

What the New EU Rules Say

Article 50 of the EU AI Act requires generative system providers to develop a machine-readable method for tagging and detecting synthetically generated outputs.

These obligations took effect on 2 August 2026. The AI Omnibus provisional agreement of May 2026  grants generative systems already on the market a deadline of 2 December 2026 to meet the requirement for machine-readable markings. They reach any system used in the covered situations, not only high-risk situations.

One exception is worth mentioning. The marking requirement does not apply to systems that perform an assistive function limited to grammar correction or other minor changes to the input. It is not yet clear how this would affect the “polish-your-own-draft” example.

The main concern is the time limit. The technical standards for marking were finalized by the Code of Practice on 10 June 2026, and the technology may still be catching up.

So What Can a Watermark Actually Prove?

A watermark shows that text was written in a certain way, which can be attributed to a particular system. It does not do much, and people incorrectly generalize its implications.

It doesn’t name names. It can’t say someone contributed 5% versus 95%. It can’t distinguish between a heavily processed memo and a drafted essay that went through multiple levels of grammar checking before publication.

As isolated evidence, it doesn’t stand strong in either case. It doesn’t survive most editing techniques and gets completely removed by simple scripts. Additionally, the cases in which it does produce a result are often those involving people least able to dispute it.

One line to keep: a watermark points at a tool, not at a person.

In almost every circumstance, everything else logically follows from this statement. Provenance is a valuable signal for content routing, auditing, and disclosure. It is weak evidence for accusations, discipline, and lawsuits, and will remain so as watermark technology improves.

What Businesses Should Do Now

Begin by addressing the interpretation issue, since that is where the cost falls. State in your own policy that a detector flag or a missing watermark should not be considered evidence of anything.

Decide internally as a team how you will disclose AI use and apply this consistently. Taking the time to include a brief statement in a document explaining how it was generated is better than any technical marker. This is the version that clients or regulators can actually act upon.

Maintain a record of your drafting process. The history of all versions of a document is better evidence than any argument on detection accuracy.

Prepare for Article 50 while understanding watermarking is not the answer. Take stock of where AI-generated content flows through your organization and see if the human review and editorial responsibility carve-out encompasses the content that you published. Consider watermarks as one of several compliance requirements.

FAQs

Can AI watermarks be removed?

Yes, but there are different levels of difficulty. Certain markers and special symbols are easily removed with free software. Marks embedded in word choices take way more effort to address, often requiring a lot of rewriting. Much of that can even be weakened during routine editing or translation.

Do AI watermarks prove who wrote something?

No. A watermark does not provide information about the degree of AI versus human text production. It doesn’t reveal what portions of a text have been edited or who is accountable for the final product.

Does the EU AI Act require AI watermarking?

Watermarking can be used as one technique to create machine-readable markings required for AI-generated content. Systems already on the market before 2 August 2026 had until 2 December 2026 to include markings. Article 50 obligations took effect on 2 August 2026. Technical standards were finalized through the Code of Practice, published on 10 June 2026.

Previous Post

Counting the Wrong Bullet Holes: Banking’s Shadow AI Blind Spot

SVJ Thought Leader

SVJ Thought Leader

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

December 27, 2025
The AI Cold War and How to Prepare for It

The AI Cold War and How to Prepare for It

May 1, 2026
AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

November 24, 2025
The UK’s Seed-to-Series A gap is growing. Should we fix it?

The UK’s Seed-to-Series A gap is growing. Should we fix it?

November 25, 2025
The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

1

50 Key Stats on Finance Startups in 2025: Funding, Valuation Multiples, Naming Trends & Domain Patterns

0
CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

0
Clarity Is the New Cyber Superpower

Clarity Is the New Cyber Superpower

0

AI Watermarking: Who Really Wins and Who Gets Hurt

September 5, 2026
Counting the Wrong Bullet Holes: Banking’s Shadow AI Blind Spot

Counting the Wrong Bullet Holes: Banking’s Shadow AI Blind Spot

September 5, 2026

Bloom Energy, Illumina, and Everpure Set to Join S&P 500; Others to Join S&P 100, S&P MidCap 400, and S&P SmallCap 600

September 5, 2026

Amwell Receives Frost & Sullivan’s 2026 United States Technology Innovation Leadership Recognition for Technology-Enabled Care Platforms

September 5, 2026

Recent News

AI Watermarking: Who Really Wins and Who Gets Hurt

September 5, 2026
Counting the Wrong Bullet Holes: Banking’s Shadow AI Blind Spot

Counting the Wrong Bullet Holes: Banking’s Shadow AI Blind Spot

September 5, 2026

Bloom Energy, Illumina, and Everpure Set to Join S&P 500; Others to Join S&P 100, S&P MidCap 400, and S&P SmallCap 600

September 5, 2026

Amwell Receives Frost & Sullivan’s 2026 United States Technology Innovation Leadership Recognition for Technology-Enabled Care Platforms

September 5, 2026

About & Contact

  • About Us
  • Branding Style Guide
  • Contact Us
  • Help Centre
  • Media Kit
  • Site Map

Explore Content

  • Events
  • Newsletter
  • Press Releases
  • Reports & Guides
  • Topics

Legal & Privacy

  • Advertiser & Partner Policy
  • Communications & Newsletter Policy
  • Contributor Agreement
  • Copyright Policy
  • Privacy Policy
  • Prohibited Content Policy
  • Terms of Service

Tiny Media Brands

  • Silicon Valleys Journal
  • The AI Journal
  • The City Banker
  • The Wall Street Banker
  • World Lifestyler
  • About
  • Privacy & Policy
  • Contact

© 2025 Silicon Valleys Journal.

No Result
View All Result

© 2025 Silicon Valleys Journal.