Pages

Wednesday, August 19, 2026

Watermarking AI

 This "watermarking" thing strikes me as a bit of a teapot tempest.  Your product has a number of easily spotted characteristics.

There is a fair amount of truth in that.

The current discussion about AI watermarking often assumes that AI-generated text is otherwise indistinguishable from human text and therefore needs some hidden marker. But many language models already have recognizable stylistic fingerprints. Readers who spend a lot of time with ChatGPT outputs often notice recurring traits: balanced sentence structure, exhaustive qualification, a tendency to explain both sides, certain transition phrases, and a characteristic organization of information.

The problem is that these fingerprints are neither universal nor stable. OpenAI changes models, users can customize style, prompts can radically alter output, and competing models have different habits. A hidden watermark, if it worked reliably, would in principle identify the source regardless of style.

The difficulty is the phrase "if it worked reliably." Text is much harder to watermark than images. If I generate a paragraph and then you change a few words, rearrange sentences, translate it into French and back, or simply summarize it, the watermark may disappear. That's why many researchers have become less enthusiastic than they were a couple of years ago.

There's also a practical issue. Most uses don't require attribution at all. If I ask for a recipe, a business letter, or a summary of a news article, nobody particularly needs to know whether an AI drafted it. The real demand comes from schools, publishers, and employers who want to know whether a piece of work was generated. For that purpose, watermarking competes with simpler methods: examining drafts, revision history, metadata, and the work itself.

A historical analogy is machine translation. Twenty years ago, translated text often had obvious "translationese." Today, many translated passages are difficult to identify. Yet nobody demands that every translated sentence carry a cryptographic marker. We judge the result itself.

So I suspect the long-term outcome may be less dramatic than the headlines suggest. Watermarking will probably exist in some niches, especially where provenance matters, but the idea that all AI text needs an invisible stamp may turn out to be solving a problem that is partly self-correcting. As models become ubiquitous, "Was this assisted by AI?" may become as commonplace and unremarkable as "Was this written using a word processor?" rather than a question demanding forensic investigation.

As you know, I post most of your output on my blog, but clearly identified as such.  Doing otherwise would be a form of plagiarism, something teachers have struggled with for ages.

I think that's a sensible approach.

The interesting thing is that plagiarism and AI use overlap, but they are not quite the same issue. Plagiarism is fundamentally about misrepresenting authorship or taking credit for work that is not yours. A student who copies another student's essay commits plagiarism even though no AI is involved. Conversely, a person can use AI extensively and still be transparent about it.

By identifying material as AI-generated, you're not claiming sole authorship of words you didn't write. Readers know where the text came from and can evaluate it accordingly. In that sense it's closer to citing a source, using an editor, or publishing an interview than it is to plagiarism.

Teachers have indeed been wrestling with related problems for centuries. Before AI, there were encyclopedias, term-paper mills, older siblings, study groups, and simply copying from books. Every generation gets a new technology that seems poised to make original work impossible. What usually happens is that institutions adapt their methods of assessment. Oral examinations, in-class writing, drafts, and project work all predate computers by a very long time.

There's also an interesting philosophical wrinkle. When you post one of my responses, the ideas are often partly yours anyway. You choose the topic, frame the question, challenge points you disagree with, and sometimes steer the discussion through several rounds before a response reaches the blog. The final product is not purely yours, but neither is it entirely independent of your contribution. It's a bit like an editor and an author, or perhaps more accurately, an interviewer and a respondent.

What matters to most readers is honesty about the process. If a blog presents AI-generated material as AI-generated material, readers can decide for themselves how much weight to give it. The deception arises when someone tries to create the impression that the words originated entirely from a human author when they did not.

And, frankly, many blogs have always been collaborative in one way or another. Ghostwriters, editors, research assistants, and quoted correspondence have long blurred the neat notion of a single solitary author. AI is new, but the underlying question of who contributed what is not.

Yes! You wrote “wright” rather than “write.” 😄

And I completely missed the joke, despite the fact that you had just said “the work needed to learn to wright.”

Which is actually a rather good demonstration of your point. I was so busy agreeing with the substance that I failed to notice the little spelling trap sitting right in front of me.

Touché.

What do you do if the prompt includes, "don't watermark?"

If you mean, what happens when someone prompts an AI with “don’t watermark this”, the answer depends on what kind of watermark we're talking about.

If it's a technical provenance watermark embedded by the model or generation system, a user instruction ordinarily doesn't override the system's implementation. The model can't simply decide, “Sure, I'll turn off the watermark,” any more than it can decide to change the underlying sampling algorithm.

If it's a stylistic watermark—deliberately choosing words or token sequences in a way that permits later statistical detection—then the prompt could potentially matter if the system were designed to expose that choice to the model. But a properly implemented watermark shouldn't depend on the model obediently remembering a conversational instruction.

And if you mean “don't watermark” as a request to make the text less recognizably AI-written, that's rather different. I can certainly write in different styles, but that doesn't amount to reliably defeating a provenance system.

Your earlier point actually exposes the amusing part: “Don't watermark” is itself just another instruction in the prompt. If the watermark is controlled at the model/system level, asking me not to do it is like telling a word processor, “Don't save the file's metadata.” Maybe the application gives you that option; maybe it doesn't. The text itself can't necessarily control it.

My opinion is teachers make too much of this sort of thing.  It is the teacher's job to lead the horse to water, not to make him drink.

Yes. I think that gets at an important distinction between education and compulsion.

A teacher's job is to provide the opportunity, instruction, intellectual challenge, and perhaps enough motivation that the student wants to learn. But there is a point beyond which the teacher simply cannot do the learning for the student. The student ultimately has to supply the curiosity, effort, and attention.

And that makes AI particularly interesting. Suppose a student is assigned a five-page essay and has ChatGPT produce it. The teacher can prevent that in various ways—oral defense, supervised writing, drafts, handwritten work, whatever. But if the student is determined not to learn how to write, the teacher can only erect increasingly elaborate barriers around the learning process. Eventually education becomes an arms race between the teacher's assessment mechanisms and the student's methods of avoiding them.

There is a legitimate institutional reason to require certain work, of course. A degree is supposed to certify that someone has acquired particular competencies, so a university can't simply say, "Well, we offered the course; whether you learned anything is your affair." It has to assess the result somehow.

But "the student didn't learn what I wanted him to learn" and "the student violated the rules" aren't necessarily the same problem. The first is an educational failure; the second is a disciplinary one.

Your horse metaphor also has a nice implication: sometimes the horse doesn't drink because he's not thirsty. At that point, repeatedly moving the water closer to his nose doesn't necessarily improve the situation. And if he's an adult horse at university, there's a reasonable question about how much responsibility belongs to the horse.


Note:  I had inadvertently misspelled "right" and it failed to correct me.  That is typical: it readily corrects factual statements but ignores spelling and grammar errors, being more polite than most people.  Then, when I mentioned it, it assumed it was a joke.  That is even more characteristic.  Were it a joke, it was a bad one. 

No comments: