Watermark (AI models)

Watermark (AI models)

A watermark is a hidden identifying feature that a computer program embeds into texts, images, or sounds so that one can later prove: a machine produced this. It is invisible to humans, but detectable with the right verification tool.

Programs that write texts or paint images at the push of a button deliver results that can hardly be distinguished from human work anymore. A watermark is the attempt to artificially restore this distinguishability. In doing so, the generating program embeds a hidden pattern into its result, a kind of invisible stamp. Anyone who reads or looks at the result notices nothing of it. Anyone who, on the other hand, possesses the appropriate verification program can detect the pattern. The name comes from the watermark on banknotes: it only stands out once you specifically look for it.

What’s at stake: the burden of proof in forgeries

Fake photos and videos of real people can now be made in minutes. Such forgeries are called deepfakes. They can influence elections, move stock prices, or ruin people. A watermark is meant to make verification easier: editorial teams, courts, and platforms could recognize machine-generated content faster.

Politics is also interested in this. The European Union’s AI regulation, often called the AI Act, requires providers to label machine-generated content in a machine-readable way. Watermarks are one possible way of implementing this obligation. For companies, this is no longer a purely technical topic, but a legal requirement.

A second reason concerns AI itself. Models learn from texts and images found on the internet. If more and more machine-generated material ends up there, new models learn from the outputs of old models. Experts fear this leads to a loss of quality. Watermarks help to filter out such content when collecting training data.

The hidden stamp in detail

With images, individual pixels are minimally altered according to a fixed, secret scheme. These changes lie below the eye’s perception threshold. The verification program knows the scheme and calculates whether it is present in the image. With sounds, it works similarly, there the pattern sits in frequencies that cannot be heard.

With text, it is more sophisticated. A language model selects each word from many similarly suitable possibilities. For watermarking, the vocabulary is secretly divided beforehand into two groups, often called “green” and “red.” The model then slightly favors the green words. A single sentence reveals nothing, because green words also occur by chance. Over a hundred words or more, however, the surplus becomes statistically noticeable.

The catch lies in durability. Anyone who rephrases a text or runs it through a translation program often destroys the pattern. With images, sometimes heavy compression, cropping, or a screenshot is enough. And models that anyone can freely download and modify can be rebuilt so that they no longer set any watermark at all. A watermark is therefore an indication, not a proof.

Watermarks in search engines, schools, and cameras

Google labels images from its own systems using a method called SynthID and indicates in search results whether an image was machine-generated. Platforms like YouTube, TikTok, and Instagram require labeling for realistic-looking content. In some cases, they detect such content themselves and add the label automatically.

A related approach works not with hidden patterns but with provenance data. In the industry standard C2PA, a cryptographically secured history is attached to a file: how it was created, what was edited. Some cameras already record this at the moment of capture. Watermarks and provenance data complement each other, because provenance data is easily lost when copying.

In schools and universities, the topic is often confused with AI detectors. These tools guess based on stylistic features whether a text originates from a machine, and they are frequently wrong. A watermark is something different: it must have been deliberately embedded during generation. If it is absent, that proves nothing.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.