Insights · AI & law

AI watermarks in text: what they can do, and what they cannot

Since 2 August 2026 the EU AI Act has required providers of generative AI systems to mark their output machine-readably. What that means in practice, who can actually read such a marking, and whether removing one is even worth the effort — sorted out without the usual imprecision.

Not legal advice
This piece summarises the state of the debate as of August 2026 and is not legal advice. Article 50 of the AI Act has only recently become applicable and there is no settled case law. If your business depends on the question, settle it with a lawyer specialising in IT law. A first draft of this text was written with AI assistance and then edited by hand.
In one sentence: AI watermarks are invisible statistical markings in AI-generated text that let you prove its origin — technically proven, but so far used by only a few vendors and barely verifiable from the outside.

What this is about — and what it is not

AI watermarks are digital markings embedded not only in images but also in text, in order to identify its origin. They allow later identification and verification without affecting readability.

The SEO industry is currently debating whether such provenance signals will influence rankings and citations in AI answers. That debate is the actual occasion for this piece — not the technology itself, which has been well documented since 2024.

How a watermark gets into text

Modern watermarks leave no visible trace. Instead they create statistical patterns in word choice that stay invisible to readers but can be recognised by dedicated checking procedures. The text reads entirely normally.

The idea: while generating, the language model picks certain words somewhat more or less often than it otherwise would. Individually those deviations mean nothing, but across a longer text they can be evaluated statistically.

A well-known example is SynthID Text from Google DeepMind. The method was published in Nature in 2024 and is designed to make AI-generated text identifiable through statistical signatures without noticeably changing quality or readability.

Which systems use watermarks?

As of August 2026 the picture is thinner than the debate suggests:

  • Google SynthID Text — publicly documented, published in Nature and available as an open-source tool. The best-evidenced method.
  • Other vendors — several major labs have published or announced research on text watermarking. Which model actually marks its output in production is generally not verifiable from outside.

That is exactly the point most coverage misses: a watermark only helps whoever holds the right key to read it. Without the vendor, usually nothing can be proven.

The SEO question: can Google detect other vendors’ watermarks?

There is no publicly confirmed information on this.

Google says so far that AI-generated text is not a ranking disadvantage in itself — what counts is quality, not origin. I have my doubts, but I cannot back them with sources, and that belongs in the open.

Technically the question is narrower than it sounds anyway: one vendor’s watermark can only be read by another if they hold the key. Cross-system detection therefore requires cooperation or a shared standard. Neither exists today.

The detection technology exists. What is open is who may read the signals — and whether they ever become a ranking or citation factor.

What the EU actually requires

Precision pays here, because a lot of imprecise material circulates on this point.

The relevant instrument is the EU AI Act, Article 50, whose transparency obligations have applied since 2 August 2026. It contains two distinct duties that are frequently conflated:

  • Providers of AI systems generating text, images, audio or video must mark the outputs in a machine-readable format so that they are detectable as artificially generated. This duty falls on the model providers — not on you as a website operator.
  • Deployers publishing AI-generated text in order to inform the public on matters of public interest must disclose that the content was artificially generated — unless a human has editorially reviewed it and someone holds editorial responsibility.

What does not follow: there is no obligation to watermark every text on your own website. Anyone who edits and takes responsibility for an AI draft generally does not fall under the deployer disclosure duty.

This page is not legal advice. If your business depends on the question, settle it with a lawyer specialising in IT law.

Can a watermark be removed again?

In theory yes, in practice with effort — and the question is what for.

A statistical watermark lives on the distribution of words across a longer text. The more someone rewrites, cuts, reorders and adds their own passages, the weaker the signal becomes. Studies on the reliability of such methods show they are robust against light paraphrasing and markedly less so against thorough editing.

That leads to an unspectacular conclusion: anyone who edits an AI text thoroughly enough for the watermark to disappear has generally written their own text. The effort of removal roughly equals the effort of proper editorial work — only with a worse result if done purely to cover tracks.

What this means in practice

For most websites, little changes in the short term. Three things still seem sensible:

  • Clarify responsibility. Whoever reviews a text and puts their name to it is on safe ground regarding the deployer duty — and writes better text along the way.
  • Do not build on obscuring. A strategy that relies on hiding origin is unprotected against any future rule change.
  • Watch the debate rather than chase it. As long as no search system publicly confirms that it evaluates provenance signals, any measure built on that is a bet.

Verdict and outlook

AI watermarks are technically real and scientifically documented. What is missing is the infrastructure around them: a shared standard, generally accessible checking tools, and a statement from search providers on whether they evaluate these signals at all.

Honestly, I am still undecided how I would handle it if I were building a search engine:

  • Devalue AI-generated content across the board?
  • Devalue editorially reworked AI text that carries no disclosure?
  • Or make purely human-written content more visible?

Each of those three answers has uncomfortable side effects. While that stays unresolved, I regard disclosure as a question of integrity, not of search engine optimisation. We are staying on it.

Sources

Quick quiz: have you got the picture?

1. How does a reader spot an AI watermark in text?

2. Who does Article 50 of the EU AI Act oblige to mark output machine-readably?

3. Can Google read another vendor’s watermark?

4. What happens when you thoroughly edit an AI text?

Frequently asked questions

What are AI watermarks and why do they matter?

AI watermarks are digital markings embedded into AI-generated text to evidence its origin. They are invisible to readers and sit in the statistical distribution of word choice. They matter because the EU AI Act obliges providers of generative AI systems to mark their output machine-readably, and because the SEO industry is debating whether such provenance signals will one day influence rankings or citations.

How does a watermark get into text?

While generating, the language model picks certain words somewhat more or less often than it otherwise would. Individually those deviations mean nothing; across a longer text they can be evaluated statistically. Google DeepMind published this approach as SynthID Text in Nature in 2024.

Can you detect an AI watermark yourself?

Generally not. A watermark only helps whoever holds the matching key. There is no shared standard and no universally accessible checking tool, so one vendor cannot read another vendor’s marking without cooperation.

What does the EU AI Act actually require?

Article 50, applicable since 2 August 2026, contains two distinct duties. Providers of AI systems that generate text, images, audio or video must mark the output in a machine-readable format. Deployers publishing AI-generated text to inform the public on matters of public interest must disclose it — unless a human has editorially reviewed it and holds responsibility. There is no obligation to watermark every text on your own website.

Can an AI watermark be removed?

In theory yes, in practice with effort. The signal weakens as you rewrite, cut, reorder and add your own passages. Studies show these methods are robust against light paraphrasing and markedly less so against thorough editing. The unspectacular conclusion: anyone editing an AI text thoroughly enough for the watermark to disappear has essentially written their own text.

Does Google devalue AI-generated text?

Google says so far that AI-generated text is not a ranking disadvantage in itself — what counts is quality, not origin. There is no publicly confirmed information on whether search systems read provenance signals at all. Any measure built on the assumption that they do is currently a bet.

Free SEO & GEO Check

SEO score, AI visibility and citability of your website in 30 seconds — no registration required.

Check for free now

Ready to optimize your website?

Register for free, get 10 credits and start right away.

Register now

Related glossary terms

KI-Wasserzeichen KI-Sichtbarkeit (AI Visibility) GEO (Generative Engine Optimization) Content Creator