Text AI Watermarks Will Always Be Trivial to Remove

The EU AI Act's Article 50, enforceable from August 2026, requires LLM providers to watermark AI-generated text. But text watermarking is a fundamentally different beast from image watermarking — and removing it remains trivial. Here's the technical breakdown.
Why Text Watermarking Is Hard
Images have noise you can hide watermarks in; text doesn't. You can't tweak a sentence without a human noticing. That makes it a steganography problem where the plaintext can't be arbitrarily manipulated. A naive approach like "every fifth letter is 'e'" would compromise output quality.
Could the model itself juggle the watermark? Strong models can, but it burns reasoning tokens and degrades output quality — a poor trade-off.
Why Detection Via Model Re-Run Fails
Running the text through the model to check token probabilities doesn't work: the space of human text that reads like AI output is huge, false positives abound, and it's prohibitively expensive for every EU citizen to get free verification.
How SynthID Works
Google's SynthID is the only public text watermark. It assigns each token a score based on previous tokens — e.g., sum token IDs mod 5. When sampling, the model picks the highest-scoring token from the top five likely options. Detection aggregates the score across a text block; a suspiciously high aggregate flags AI generation.
This is like the em-dash heuristic, but based on subtle mathematical patterns humans can't spot.
The Catch
But any watermark that preserves lexical diversity is removable by simple paraphrasing, token substitution, or even translation. As long as the text must read naturally, you can strip the signal with minimal effort. SynthID's robustness is limited — it's designed for mass detection, not for resisting deliberate removal.
Expect the EU to enforce a requirement that's technically unsatisfiable. Labs will comply with the letter, but anyone who cares can bypass it in seconds.
📖 Read the full source: HN AI Agents
👀 See Also

ACP Bug Investigation: Protocol Mismatch Causes 'metadata is missing' Error with Local Ollama
A confirmed bug in the ACP/OpenClaw integration prevents acpx spawn commands from working with local Ollama models due to a protocol mismatch where acpx expects JSON but receives text output.

Leaked Claude Code Reveals KAIROS System and the Verification Gap in AI Agents
A leaked Claude Code source map revealed 512K lines of TypeScript, 44 feature flags, and KAIROS—a background agent that consolidates memory during idle time. An independent developer built a similar daemon to chain sessions for multi-day campaigns, but discovered that successful compilation doesn't guarantee functional code.

Weekly Multimodal AI Roundup: Holotron-12B, Nemotron Omni, GlyphPrinter, and More
This week's multimodal AI highlights include Holotron-12B for computer-use tasks, NVIDIA's Nemotron Omni models integrating language+vision+voice, GlyphPrinter for accurate text rendering in image generation, and several open-source projects for video enhancement, 3D segmentation, and multi-agent systems.

Cognitive Debt: When AI Output Outpaces Understanding
A Reddit post discusses 'cognitive debt' — the gap between AI-generated output and the team's understanding of it — and argues that creative control means knowing what you shipped. The post itself was written with Claude's help, meta-commenting on the irony.