Do Not Write Between My Lines

Text watermarks confuse AI assistance with authorship, intrude on word choice, and burden honest writers while doing little to deter deliberate deception.

John Gruber is right to be furious about text watermarking, even if one need not accept every technical step of his argument. A system such as SynthID-Text is more sophisticated than a thesaurus mechanically replacing one synonym with another. It modifies the model’s token-sampling process so that a statistical signal emerges across a sufficiently long passage. Its developers claim this can be done without measurably reducing average output quality. That is an interesting engineering claim. It is not a satisfactory answer to the objection.

The objection is simpler: a secret key held by an AI company should have no vote in my choice of words.

Words are not interchangeable packing material. “Kingly” is not “regal”; “ghost” is not “spirit”; “grey” is not “overcast.” Each word brings its ancestry, register, rhythm and emotional temperature. Anyone acquainted with serious literature knows that a sentence can remain factually equivalent while becoming aesthetically false. If a tool is helping me find the right English expression, its only loyalty should be to meaning, precision and voice—not to a hidden statistical pattern inserted for the convenience of a regulator or vendor.

This matters particularly to those of us who are not native English speakers. I do not ask AI to supply opinions for me. I use it to inspect translations, expose awkward constructions and suggest alternatives that my working vocabulary may not immediately offer. The argument remains mine. The original text remains mine. Most importantly, the final decision remains mine.

Yet a watermark detector cannot explain that history. It may detect model involvement, but involvement is not authorship. It cannot distinguish a machine-written essay from a human essay whose author accepted six useful corrections. It cannot distinguish intellectual substitution from linguistic assistance. Calling both “AI-generated” is not transparency. It is bureaucratic graffiti.

Anthropic says its watermark has no practical effect on content or readability and acknowledges that light proofreading may leave too little signal to detect, depending on the length and extent of editing. That caveat is crucial: detection is probabilistic and its meaning is ambiguous. The company’s own explanation makes clear that the more text Claude contributes, the stronger the possible signal becomes. Anthropic’s description therefore supports a narrower conclusion than the public is likely to draw: a signal may indicate that Claude influenced a passage. It does not establish who conceived, researched or authored the work.

The underlying European policy has a legitimate target. Synthetic photographs, cloned voices and fabricated video can impersonate reality. Marking an altered photograph—especially one purporting to document an actual person or event—is sensible. The viewer deserves to know that the apparent evidence was manufactured or materially changed.

Prose is different. It does not claim to be an optical record of a physical moment. Its substance consists of the very words the watermarking mechanism must operate upon. Metadata can accompany a photograph without rewriting the objects depicted. A semantic text marker participates in the act it is supposed merely to describe.

The EU’s transparency framework at least recognizes human review and editorial responsibility when discussing public-interest publications. That distinction should be central, not buried beneath an indiscriminate model-level signal. Responsibility is the relevant test. Who makes and defends the claims? Who checks the facts? Who approves the final wording? A hidden statistical mark answers none of these questions.

Nor will it reliably catch determined fraud. Someone intent on concealing machine authorship can use an unmarked model, substantially rewrite the output or move it through another system. Honest users, meanwhile, keep the uncertainty, the stigma and the obligation to explain themselves. It is a familiar regulatory achievement: inconvenience for the conscientious, a minor detour for the dishonest.

The responsible countermeasures are not clandestine “watermark removers.” Those would surrender the moral argument and might breach a provider’s terms. Writers should instead protect authorship openly:

  • Keep the original-language draft, revision history and tracked changes.
  • Ask AI for comments or alternative phrases rather than indiscriminate full-text rewriting.
  • Review every proposed change and preserve your own cadence, including the occasional non-native turn of phrase when it is expressive rather than erroneous.
  • Use tools or modes that do not semantically watermark prose, where contractually available, and demand a clear opt-out.
  • Require providers to publish meaningful information about detection limits, allow independent audits and offer a way to challenge adverse findings.
  • Never let a school, publisher or employer treat detection as proof. A signal should begin a conversation, not conclude a prosecution.
  • Disclose material assistance in a precise sentence instead of accepting the crude label “AI-generated.”

The research behind SynthID-Text is substantial; its authors report no detected quality loss in benchmarks, side-by-side ratings and a large Gemini experiment. But the same published paper also says no detection method is foolproof and describes trade-offs among quality, detectability and complexity. “We did not measure a quality loss” is evidence worth considering. It is not permission to make a secret corporate key an invisible co-editor.

I use AI. That is not an embarrassment, and it is not a contradiction. Spellcheckers, dictionaries, editors and translation tools have always mediated language. The honest boundary is neither purity nor technological abstinence. It is responsibility.

My thoughts are my own. My sources are open to inspection. My use of assistance can be stated plainly. And the words that finally appear under my name must answer to me—not to a watermark hidden between them.

Disclosure: This commentary was conceived and directed by the author. AI was used to review the English, test phrasing and suggest revisions. The author selected the final wording and accepts responsibility for every claim.

No comments yet