Watermark Theater
My weekend was leavened by the release of the Anthropic watermark explainer. I’ve been fascinated by AI detection tools for months and have some longer pieces drafting, but the watermark post is too rich an invitation to ignore.
Treat this as a contribution to the almost incoherent noise generated by arguments over AI invasion of human skills. I think surviving creatively in the next year or two depends on being able to handle this noise.
Some years ago I walked down under the freeway entrance to the Bay Bridge, where Survival Research Labs was tormenting the small section of the San Francisco population lucky enough to have heard about the performance with a display of terrifying pyrotechnics. Before the sirens from the fire department scattered the crowd I experienced extreme anxiety that — among other simultaneous catastrophes — their pile of burning pianos would collapse on top of somebody. It was a deeply irresponsible and inexcusable event that I nonetheless remember with admiration and gratitude. I think about that night and say to myself: so many things had not happened yet. Such things still seemed fun.
With much of what we thought were essentially human skills going into the bonfire, the Anthropic watermark scheme appears as a comic policeman blowing his whistle while his pants fall down and Mark Pauline loads a cannon with rotting fish.
Since by vocation I’m a science journalist, I could carefully explain in terms almost anybody could understand why the watermark is more clever and more effective against naive attack than you might think at first, while being so vulnerable to defeat by non-naive attack that they probably shouldn’t have bothered in the first place. But you’ll have to take my boast about being able to do this on faith. Or not; you can equally well disbelieve it. I don’t care, and it doesn’t matter, because the skill at taking a technical invention and making it comprehensible to general readers has been so well mastered by robots that it is hardly a skill at all. I can’t make money from it, and I don’t feel like doing it.[1]
What I do feel like doing is finding a way to express how thrilling it is to watch the most painstaking parts of my professional life become trivially easy. The dissolution of my paranoia about making a mistake now that I have the most powerful forensic apparatus in human history at my disposal has brought me into contact with new problems that —. Well, I was going to say they were previously unseen, but that’s not true. I think the problems that chatbots have exposed were seen or at least felt but they were only approachable as tasks by people with an astounding amount of creative freedom.
A big statement that I won’t try to defend — yet. Instead, let me offer a few scenarios where controlling the ability of robots to alter a text is important in ways that watermarks don’t and can’t address.
Disciplined correction. Chatbots have become indispensable in my work for making relatively sophisticated copy edits, especially (but not only) to references. For instance, what used to be an easily breakable choreography of bibtex imports and Zotero shortcuts now begins with a simple spoken request, transcribed and executed. But, unfortunately, not flawlessly executed. The kinds of errors chatbots make are different than typical human errors, and require a different kind of supervision. As soon as I lose track of what the robots have done, I start to spin. These monsters have to be watched. Often the spans of text are short and the mistakes are not really stylistic. I don’t want robotic contributions dissolved invisibly into my text.
Layering. Any complex analytical work involves layering. For instance, a detailed example that takes hours or days to understand may be compressed into a few lines or even a few words. When I was first starting out as a journalist, I hated losing this material from my drafts. What a waste, I’d think. Eventually, I developed a tolerance for cutting, and finally I loved it. I realized that if I worked through some historical or narrative background well enough I could be confident about the kind of compact formulations — abstract or allusive or metaphorical — that support its conceptual span. Robots layer too, but differently. Their environment is not the world. Their layered constructions need to be probed adversarially. I have to see their work. I can’t have them running loose.
Synthesis and critique. Compose a timeline of key events. List shared features among distinct or competing frameworks. Simulate a particular critical perspective to expose possible flaws in an argument that may otherwise go unnoticed. Chatbots are increasingly useful as synthetic interlocutors. But they are a tricky, translucent mirror. In them, I see my work reflected against the background of their training data. People do synthesis and critique also. Their critique is also tricky. In it, I see my work reflected against the background of their commitments and training and goals and sensitivities. I have to think about the synthesis and critique that comes from humans in a way that’s different than I have to think about synthesis and critique from robots. This is perfectly obvious. On the other hand, how much of the synthesis and critique I get from humans is really coming from robots? if you think watermarks can help with this very deep problem of how we relate to each other creatively, you don’t know very much about humans — or robots.
I can’t say more right now. I want to, though. I think every writer now is being pressed to articulate some facet of their desperate situation.
Note: This text was written using a custom writing surface created by Thomas Blomseth Christiansen that requires humans and robots to take an explicitly named turn before altering the text and preserves the record of each turn. These terms are preserved in a trailer to the document. They are asserted rather than guaranteed, and third parties can have no reliance on them. However, since I am interested in my own relation to robotic influence, I don’t care about third parties for now.
[1] If you want patient instruction on how watermarks work and are defeated, first get an overview from James Padolsey’s interactive explainer, How AI Text Watermarking Works, then point your robots to these references and ask your own questions: John Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz, Ian Miers, and Tom Goldstein, “A Watermark for Large Language Models.” ICML 2023. arXiv:2301.10226; Sumanth Dathathri, Abigail See, Sumedh Ghaisas, et al., “Scalable watermarking for identifying large language model outputs.” Nature 634 (2024): 818–823. doi:10.1038/s41586-024-08025-4; Nikola Jovanović, Robin Staab, and Martin Vechev, “Watermark Stealing in Large Language Models.” ICML 2024. arXiv:2402.19361; Saifur Rahman Tamim and Amir Labib Khan, “AI Watermark Evidence Fails Forensic Readiness: An Empirical Evaluation.” 2026. arXiv:2607.16010.

