The watermark is not hidden ink.It is a trail of choices.

The EU now requires providers serving its market to mark AI-generated content. Claude and Gemini watermark the words. ChatGPT marks pictures and supported audio, not the text. Copilot, Llama and Mistral signed the same code; they have not published a text method. Anthropic published how Claude’s version works. Google invented the method. When the mark is in the words, it lives in word choice. Nothing is added to the text.

Reviewed by

Published

01

One prompt can take many valid paths

A language model writes one token at a time. When several next words are equally good, a random number chooses among them. An early choice changes the context for every choice that follows.

promptWrite one moody opening line.

Generated path

The rain before anyone thought to run.

At this fork, the model’s shortlist was:

42%
arrived without warning,
34%
started before dawn,
24%
came in from the sea,
02

The watermark changes the dice, not the vocabulary

SynthID-Text, the method Google published and the labs now use, derives each random number from a secret key and the words written so far. The shortlist can stay the same while the sequence of choices leaves a pattern the key holder can test.

Ordinary generation
numbers from
fresh random numbers
numbers used
0.18 · 0.71 · 0.43
Keyed generation
numbers from
key + words so far
numbers used
0.18 · 0.71 · 0.43
To disturb that sequence, choose a new path

Rewrite depth

More new phrasing usually means more new token choices — and more risk of changing tone.

Watermarked path

The rain arrived without warning, turning the avenue silver before anyone thought to run.

New path

Without warning, rain glazed the road in a sheet of silver and caught the pedestrians still walking.

Wording changed57%
Illustrative keyed match31%
Lower is better for this illustrative measure.

Illustrative only. A real score depends on the vendor’s key, detector, text length and implementation. Gifi cannot see or certify any of those.

03

Deleting characters does not touch a statistical text mark

A statistical text watermark adds nothing you can select and delete. C2PA is what labs attach to images and documents — a signed note in metadata, a different job. A statistical mark is a property of the choices across the text.

Deterministic

Hidden characters and C2PA

U+200B · U+E0067 · EXIF · C2PA

We can name the exact carrier, remove it, and show a precise before-and-after report. The visible sentence can stay unchanged. This is not a statistical text watermark.

CleanFree in your browser

Probabilistic

Token-choice pattern

SynthID-Text · key + words so far

There is no stray character to delete. Rewriting samples a new sequence, but every edit carries some risk of meaning or tone drift.

RewriteModel call · paid

Detection needs room for chance

More high-entropy choices give a detector more evidence.

Open prose
strong
Summary
moderate
Code
weak
Exact quote
none

Very short text, exact quotations and constrained outputs may not contain enough choices for reliable attribution in the first place. A watermark check is evidence, not an identity test.

What the mark does

What the watermark does, and does not, mean

Is this only Claude?
No. Gemini already watermarks text with SynthID-Text. Claude does too, on models from August 2026. ChatGPT does not watermark text as of August 2026 — it marks images and supported audio. Copilot, Llama and Mistral signed the same EU code and have not published a text method. Each lab uses a different key.
Will a light edit remove it?
Usually not. The published method says light editing probably keeps the signal. Replacing every word does not — though at that point the text is no longer the original generation.
What about short text?
Fewer forks mean less evidence. Detection is weak on short samples and grows more confident as the passage lengthens.
What about code?
Code has fewer equally-good next tokens, so the mark is sparser. Comments and other arbitrary wording can still carry it; a required identifier cannot.
What if the model only proofread?
The watermark only attaches to words the model chose. Light grammar edits may be too few to register. Heavier rewriting leaves more of a trail.
Do translations carry it?
Yes. A translation produced by the model is a sequence of words it chose, so the watermark has a full passage to live in.
Can it identify me?
No. Nothing in the watermark or its key points to a person, organisation, or chat. It tests whether a given model was involved, not who asked.
What does a hit prove?
That a specific model — ChatGPT, Claude, Gemini, or another — was likely involved at some point. It cannot tell “the model wrote this” from “the model heavily edited this,” and it does not prove human authorship.
What about images and files?
Those get a C2PA content credential in metadata — a signed note, not SynthID-Text. The file cleaner can strip that label. Soft binding can survive and re-link to a remote manifest.

Choose the right tool

Statistical signal? Rewrite the prose. Hidden characters or C2PA? Clean the file.

Gifi keeps those jobs separate because they have different costs, different risks, and different standards of proof.

By model

Use rewriting only on content you own or are authorised to process. A changed statistical signal does not prove human authorship, and no third-party tool can guarantee the result of a private detector. Read Anthropic’s explanation.