Watermarks Without Verification: AI Text Watermarking After the EU AI Act
Source note: Preprints on societal impact.
arXiv:2609.09604v1 Announce Type: new Abstract: On August 2, 2026, the obligations of Article 50 of the EU AI Act took effect, requiring generative AI providers to mark the content their systems produce and ensure it can be detected as AI-generated. Days later, Anthropic disclosed that every Claude model released after that date embeds a watermark based on SynthID-Text in all generated text, enabled by default with no user opt-out; Google has deployed SynthID-Text in Gemini since 2024. Users objected that the watermark degrades quality, particularly for code, that it secretly encodes identifying information, and, in mutual contradiction, that it is easily removable and inescapable; the vendor answered with assurances of unchanged quality, no identifying information, and robustness to light editing. In this work, we argue that neither the objections nor the assurances can currently be verified and that this unverifiability, rather than watermarking itself, is the substantive governance failure. We sort the contested assertions by what it would take to settle each and evaluate the open-source SynthID-Text implementation on two open-weight models, because no public tool can test the deployed systems. On prose, the measured effect of the watermark does not exceed that of changing the sampling seed. On code, the cost is three points of correctness on one model and below measurement on the other, while detection remains near chance, a limitation of detectability rather than quality. The remaining gaps trace to withheld access or missing institutions and we map each to a requireme
Every model that read this
| Model | Provider | Stage | Score | Conf. | Latency | Prompt | When |
|---|---|---|---|---|---|---|---|
| Llama 3.3 70B | Meta | analysis | -60 | 80% | 5673ms | v1.0.0 / m1.0.0 | 2026-09-10 08:55 |
| gpt-oss 120B | OpenAI | consensus | -40 | 78% | 12146ms | v1.0.0 / m1.0.0 | 2026-09-10 08:58 |
| Llama 3.3 70B | Meta | analysis | 0 | 80% | 3368ms | v1.0.0 / m1.0.1 | 2026-09-10 09:17 |
| Mistral Small 3.1 24B | Mistral AI | consensus | +55 | 90% | 9450ms | v1.0.0 / m1.0.1 | 2026-09-10 09:19 |
The article discusses the potential negative implications of AI text watermarking, including degradation of quality and unverifiability of claims. The authors argue that the inability to verify the effects of watermarking is a substantive governance failure. The measured effects of the watermark on prose and code suggest a potential negative impact on human flourishing, particularly in terms of the reliability and trustworthiness of AI-generated content. The lack of transparency and accountability in the implementation of watermarking raises concerns about the potential for misuse or unintended consequences.
The EU‑mandated watermark appears to reduce the correctness of generated code while offering little detectable signal, indicating a policy that harms AI utility without delivering its intended safety benefit. This governance shortfall is materially concerning for human flourishing, though not catastrophic.
Unverifiable claims about AI watermarking
The article discusses the implementation and challenges of AI text watermarking post-EU AI Act. The primary finding is that watermarking does not significantly degrade text quality but has a minor effect on code correctness. The main concern is the lack of verification mechanisms, which is a governance failure. The article proposes several requirements to address these issues, suggesting a path towards improved AI governance.
Evidence extracted
- Anthropic embeds a watermark based on SynthID-Text in all generated text
- The watermark degrades quality, particularly for code
- Anthropic embeds watermark in Claude models
- Watermark degrades quality
- Watermark is removable
Consensus history
Superseded readings are kept. Nothing is overwritten.
| When | Mean | Spread | Agreement | State |
|---|---|---|---|---|
| 2026-09-10 09:20 | -11 | 115 | low | current |
| 2026-09-10 08:59 | -50 | 20 | high | superseded |
SOURCE arXiv cs.CY (Computers and Society) (tier 1)
↓
DOCUMENT 478b9ada-3213-4282-863b-07d58414452d
https://arxiv.org/abs/2609.09604
↓
EVIDENCE 5 extracted excerpts
↓
MODEL RUN 4 runs, methodology 1.0.1
↓
SCORE -11 (Mixed or uncertain)
↓
CONFIDENCE 82%