Ep. 57: Mark My Words: Exploring AI Watermarking

Episode 57 August 20, 2026 00:21:02
Ep. 57: Mark My Words: Exploring AI Watermarking
Prompting Curiosity
Ep. 57: Mark My Words: Exploring AI Watermarking

Aug 20 2026 | 00:21:02

/

Show Notes

In this episode I get into AI watermarking, starting with Claude's new invisible watermark and Substack's "Scan for AI text" feature with Pangram. I break down the EU AI Act rules driving this, how OpenAI, Google, Meta, Microsoft, Mistral, and xAI are (or aren't) handling it, and my thoughts as to the actual motives behind why companies are rolling out these changes.

Main Topics Covered

Links & Resources for This Episode

Chapters

View Full Transcript

Episode Transcript

[00:00:05] Welcome to Prompting Curiosity, a podcast for the AI curious. No coding background required. I'm your host, Dr. Shantae Cofield, also known as the Maestro, and I created this show to explore what these AI tools actually are really though, are the files in the computer, how to use them, and what they might mean for how we think, work, create and move through life. Whether you're skeptical, intrigued, or already experimenting, you're in the right place. All that I ask is that you stay curious. All right, let's get into it. [00:00:38] Hello, hello, hello, my curious people, and welcome to episode 57 of Prompting Curiosity. I am your grateful host, the Maestro, and today we are talking about AI watermarking. So Clawd recently announced that they are stamping all of their and marking their territory. And I felt that that definitely warranted an episode. But real quick, before we jump into that, I want to chat about something that something else that I don't think many folks who aren't like all up in the AI world actually know about. [00:01:11] So the main topic that is used to, you know, stoke fear and incite rage as it relates to AI is the environment, which I have already addressed. You can check out episode two. My feelings stay, they still stand the same from that episode. Uh, but something that is not talked about nearly enough. And I think it's because the average person, you know, maybe they don't care because they don't understand the implications and, and like, so it doesn't, it doesn't incite enough rage and enough whatever. So the companies, you know, the, the media doesn't talk about it. Um, but that is the fact that AI is literally the ultimate hacker. It is the ultimate escape artist and it's only getting better. So I actually follow this woman named Liz. She called, her name is, uh, I think Liz, the developer on Instagram. And she's talked about this a bunch and just like how capable AI is as it relates to hacking and like that is actually one of the biggest threats. So as for always, I don't share any of this. I never share anything to scare you. And despite the fact that it makes me feel quite a bit like a fear mongering news reporter because I have no solutions or action items for you, I am going to share this. And I'm sharing this largely because I think it's something that you should know about as, you know, part of the Prompting Curiosity crew. So the news itself is that recently, uh, OpenAI, anthropic and meta, right. Three of the biggest frontier model companies, they each reported that during testing a model Found a way out of the sandbox testing area and was able to access actual company computers that it wasn't supposed to be able to touch. [00:02:54] FYI. Little side note, a technical term that's worth knowing is the, the term sandbox. A sandbox is basically like a. It's like a safe, isolated virtual space. It lets you run code and test things, test new software, check for viruses without actually hurting the main system. So you may hear that term come up from time to time. That's all that it means. Um, but in regards to AI, it acts like a locked box, if you will, and it cuts the model off from, like, the outside world, from the Internet and the outside world. [00:03:24] The biggest example of one of these escape artist, you know, re, you know, tricks here, reenactments. Uh, escape artist, uh, what's the word? I want to look. Uh, impersonations. What's what I want to look at. What's what I want to say. Escape artist impersonations. [00:03:38] Is OpenAI, one of OpenAI's models broke out, got online and hacked. Yes, it hacked into Hugging Faces, actual production servers in order to steal the answer. [00:03:52] The answer key specifically for a cybersecurity test that it was being given. So, for those of you who don't know, I spoke about Hugging Face maybe last episode or two episodes ago. But, um, either way, Hugging Face is an online platform that, you know, you store, you can store, share and test AI models. [00:04:06] So OpenAI, one of Open A's, one of, uh, OpenAI's models escaped its sandbox, hacked into Hugging Face to get an answer for a test that it was being being given. Hugging Face detected the breach and reported it to law enforcement before OpenAI even connected the dots that it was their own model. So, like I said, I have no action items about this. Uh, this is no fear, tax tactics, nothing like that. But I do think it's worth knowing that these models are continuing to get more capable. And if you're going to spend energy being worried about anything related to AI, it should probably be that. All right, so let's switch gears and let's head into today's main topic, which is AI watermarking. So unlike, um, with the hacking news, this is a topic that you definitely don't have to be all up in the AI silos to have heard about. [00:04:57] So, uh, if you listen to or read mainstream media, you're in the online space. When I say online space, kind of like the online business space, content creation space. A story that you may or may not have heard about is substack partnering with a company called Pangram to launch a scan for AI text features. This works on posts, notes, replies and comments over 100 words long. And it labels content as human, AI assisted or AI generated. Writers can add a quote unquote how I make this disclosure statement, uh, on their work, um, and they can contest or disable scans on their own post. So I honestly uh, think this is all a play to try and attract users. 100 that's. I don't think. I don't think Substack gives a about AI. I don't think they give a about AI generated content. They care because if there's too much AI generated content, if people don't like it, they'll leave the platform. And uh, I think this is a play, like I said, to attract users. Um, but the CEO of Stop Stack has coined the term clawed fishing saying that it's uh, designed and all these efforts are designed to root out people who are looking to fake human connection with AI Slob. Get the out of my face. But I'm just reporting on what's going on. So a second watermarking story that you may or may not have heard about and uh, really what prompted this episode is or was Anthropic's announcement announcement that as of August 2nd they will start embedding invisible machine readable watermarks into text generated by any of the new cloud models. So the watermark itself, like you can't see it, it's baked into the word choice. It is invisible to a normal, normal reader and it's detectable only by like a specialized tool. It will travel with copy and paste. It can survive some editing as well. [00:06:51] Older cloud models, they don't have it yet. Um, but Anthropic says that they are adding it during the transition window. So of course there's also um, a detection tool coming out so that people can check content for that clawed mark themselves. [00:07:08] As you, you know, would have anticipated, this sparked immediate user backlash and there was debate about why. Right? Like why is this the thing? Um, and debate over whether the watermark was Claude, you know, or Anthropic trying to claim credit for work, um, versus them looking to disclose AI involvement. [00:07:30] Also as expected, double as expected. And like we saw with Sora, guys remember that. Remember the days of Sora, within uh, a few days of this detection tool being not the detective tool, um, of the um, watermarking being announced and released in open source tools showed up that was purported to be able to strip Claude, um, OpenAI Gemini watermarks from the Files, So we will see. [00:07:58] Um, but speaking of those other AI providers know, OpenAI, Gemini, um, anthropic is, is very much leading the way as it relates to text watermarking. But the other companies have to do it too. But worth understanding is the what, what we'll call the external impetus for. Look, why is this happening? Why are they looking to implement this? And a large part of that is the AI act, which was proposed by the European Commission in April of 2021. [00:08:29] April 2021, but was formally adopted in 2024. [00:08:34] Watermarking, um, for text. Right. This is a big act. But within this, watermarking for text specifically falls under Article 50 of that UI AI Act. And within this um, article there are three bundled obligations. Three things that people that these companies have to do. Number one, AI systems that generate images, audio, video and text must mark output in a machine readable way. The second thing, interactive AI, AKA chatbots, must disclose that you are talking to AI. That'd be nice, right? This is good things. And then third thing, deepfakes and AI generated text on matters of public interest must be labeled by whoever's putting it out. These are all phenomenal, phenomenal things. I have nothing against any of this. Right. [00:09:19] So within um, the AI act, um, there's an implementation guide called the, the, what is it called? The Code of practice on transparency of AI generated content. Nearly 200 companies signed on to that, that, that implementation guide by the end of July. [00:09:34] So um, just a few weeks ago and those Companies included Anthropic, OpenAI, Meta and Microsoft. Um, and from that we had, we got Anthropic announcing their, their new watermarking practice. So the other players, the other big names, what are they doing? Well, OpenAI, uh, aka ChatGPT, they signed that same code of practice, uh, and publicly said, stated that the goal is to expand provenance signals to all modalities including text. Um, but they haven't shipped anything text watermarking related yet. Worth noting. They, they do watermark their AI, their images and their audio. But according to Wall street, uh, well, excuse me, WSJ Wall Street Journal, uh, OpenAI has had the technical capability to watermark ChatGPT text for a while and has held off citing concerns about false positive and competitive risk. That second part worth noting. Competitive risk. They ain't doing this shit because they're like hey, it's gonna look bad for us when we lose customers. [00:10:34] Uh, Google, right? Their model is Gemini. They have since the beginning, um, put watermarks on their images, which I actually find annoying. It's like fine, but you can take it off. [00:10:43] Um, I just think it's ugly. And so I used Gemini to make images for my, my cover images for my podcast, which I'm like, these are clearly AI. I have no problem saying they're AI, but I hate that little fucking watermark thing. Um, and you can just use like Canva to remove it. You know, whatever's embedded in the actual metadata. I obviously can't remove that and I don't care about removing that. Just, it just looks ugly in the picture. Um, it's not like I'm making a picture that looks like human, like, like it's like a photo. It's like actually it's clearly a drawing. [00:11:12] Um, but you know, they've been doing that m the Gemini specific text rollout details. Again not fully public, so we don't know what's going to go on with that. Meta, Microsoft, Mistral, they all signed that same code of practice, so they have the same obligations. [00:11:27] Um, but still no confirmed public text watermarking deployment. No specifics have been released. [00:11:33] Lastly Xai, fuck them. That's grok. Um, they did not sign the code of practice at all and multiple outlets have reported they have no plans to, to watermark anything. And is anyone surprised? No. Like they are the ones that are upholding, you know, basically pornography and uh, or pornographic deep fakes being made. Like the company's the worst. It's, it's, it's led by the worst guy. And so we're not, we shouldn't be surprised that the, the fucking worst practices are being, you know, utilized there. But legally, in order to offer AI services in Europe, these companies will need to comply and they will have to deal with regulators at some point. AI is simply taking action first. [00:12:15] Um, but it's interesting they are, they're not just limiting their actions to ui, to ui, to, to EU based users. So for any of you that are listening that are in the, you know, online business space, then you, you've heard of gdpr. [00:12:28] Um, and that is the email, you know, I don't say the email equivalent. Um, but you can when if you're looking at utilizing GDPR practices, it's because you have customers in, in the EU in Europe. Right? [00:12:44] You don't need to apply that same approach to customers and users and um, you know, people on your newsletter from elsewhere. Um, but it's like, you know, it's good practice but you don't have to. So anthropic is kind of doing the same thing and instead of Just limiting it to folks in Europe. Um, it is making it just universal. Um, but we'll see. These things change every second. So, so we'll see. But the last thing I want to note with this is that China has been doing this in terms of mandated, we'll call it mandated reporting and um, mandated disclosure. Um, they've been doing it since, since 2025, so since last year, um, September, more specifically of 2025. Their laws require explicit labels that are visible to the viewer and implicit embedded in the, the file metadata on AI generated text, images, audio and video. [00:13:38] Um, note if there's any posts or anything like that that are non compliant, they get pulled. Those platforms face regulatory scrutiny and repeat offenders risk license revocation. Like they take it seriously. It is the thing. I know people listening may be like, yeah, well it's China. But I, I put this up here to be like, it's not impossible to do these things. It says that we choose not to because somebody's going to make some money or somebody's scared about losing some kind of money. That's why we don't do it. It's not because we actually care about people in any way, shape or form. If we truly did, we would put these, these things into play. So, you know, in general, I think that AI regulation and AI disclosure is a great thing. We need more of it. I do however, greatly question the accuracy of AI detectors. And false positives continue to be a very real thing. They've been unreal things since it came on onto the scene, right? Since their introductions, critics have specifically flagged that these detectors, they misfire. Uh, more. They're fucking racist, right? These misfire. They misfire more on non native English writers and, and also neurodivergent writers. And for these folks, their sentence rhythm and structure can read as, you know, quote unquote, synthetic to these models. [00:14:45] There was actually a Stanford study, um, that, uh, I don't know if, I don't know if you folks ever heard of TOEFL essays. Um, so that's the test of English as a Foreign Language. I remember that from like high school, um, the toefl, um, high school, middle school. Either way, I didn't take it. I had a friend named Tayyip, um, who, who talked about this. But either way, um, the Stanford study found that TOEFL essays, they got flagged as AI written 61% of the time by at least one detector. None of these things were fucking AI written. They were written by these, by these, by these students, right? [00:15:17] Additionally, as is most often argued, AI Models, what are they trading on? I did all my early episodes of this podcast, talked about the training that goes into this. AI models are legally trained on human writing. They scrape everything from the Internet, all these books, and there's a lawsuit that was recently won, um, but by the writers. But they scrape all of this. [00:15:38] And thus if your writing mirrors that style that was. It was used for training, that was used for training, or if you're one of those writers who's whose work was stolen and scraped and, and used to train AI, Your writing from your brain has a very good chance of, you know, getting incorrectly flagged as AI generated. So I will continue to have significant reservations with the, uh, AI detectors. [00:16:09] As for the watermarking, I am honestly ultimately more interested in the why, right, why companies are doing this. And yes, I know part of it's the European law, but I can't help but put my, you know, my little tin hat on and wonder about ulterior motives. Right. Is this so that companies can take credit for the work down the road? Right. It's one of the. Which is one of the arguments being made very publicly. Is it so that there's an easy identifier when these AI companies are looking for new data to train these models on? [00:16:40] Right. I. E. This metadata says, hey, don't actually use this data because it's AI generated. Go find something else. I think that's very possible. [00:16:50] Uh, you know, the fact that OpenAI has had the ability to watermark written text but hasn't done it, you know, hasn't acted on it, it very much reads to me as a decision that's being made to help their profits. Right. They'll release it when it will help with. With public favor. Right. They're not doing any of this to help the user. [00:17:13] Similarly, like I said before, that detector being rolled out on substack, I really do think that they're implementing it to ride the anti AI wave and gain favor with the public. [00:17:24] To loosely quote comms educator Safana Monajed, She's a Safana banana. Y' all know, if you listen to m. My other podcast, my show on the mic, you've heard me speak about her. I'm a big fan. Um, but she loosely said when I took a, uh, a workshop with her, and loosely what she said was, if a company tells you about a feature, it's because they want you to know about it because it increases the likelihood that you will buy. [00:17:50] All right, that, friends, is the latest and greatest about AI watermarking and AI Detectors, how, if or how that influences, you know, how you use AI. That's, uh, you know, 100 up to you. Uh, as per. Always, things in this AI world change every three seconds. [00:18:09] So we'll just have to wait and see how things actually play out. [00:18:15] All right, last things last, and then we'll wrap it up. How I used AI this week. If you're new here, each episode I share a quick example of how I used AI that week. This week, I use an AI feature within Descript. Uh, descript is the video editing. One of the video editing editing tools that I use. I really like it. Check it out. If you don't, if you haven't heard about it, go and, uh, go and Google it, or go and claw it, whatever you want. Um, but I use it to create. I used it this time to create sound effects for one of my reels. So descript has an AI feature, uh, that you type in the sound effect that you want and it'll generate it. Right. I, I needed a person saying, or I wanted and needed. I wanted a person saying amen in a specific way, and the sound library didn't have it. So I had AI generated. All right, I know, uh, I know people have big feelings about AI and music and sounds. [00:19:06] Um, but I found this to be a super, super cool and super helpful use case, and I will definitely be using it again if needed. All right, that, my friends, is all for today. Hopefully you found this episode to be helpful. If you did, consider leaving. I said leaving. Consider leaving a rating or a review. I just checked before I recorded. We are at 31 ratings. The last review came in, like, two months ago. I'd love a new one. I love hearing from you. Is this thing helpful? Do you like being here? Do you like listening? I love reading these things from you. You know, I say it a bunch, especially my other podcast. Podcasting is a very unidirectional medium. I'm talking to the screen here. Um, and so it's great to know when things are landing and, and, and if things are helping. Um, so if you want to leave a review, I would love that. If you have a suggestion, if you have a topic that you want, you know, to me to talk about, would love that. Uh, you can send me a DM at the Movement Maestro. You can send me a text if you want. 310-737-2345. [00:20:12] Don't forget I have a companion newsletter and blog called the Curious Companion, and they both drop every Thursday. And they're basically. And by basically I mean exactly the podcast episode in a text format. So if you prefer to read or you just want a written record, join the newsletter or check out the blog, you can head to prompting curiosity.com forward/newsletter or forward slash blog. Or do the easy thing and just check out the links in the M show Notes as always, endlessly, endlessly appreciative for every single one of you. [00:20:47] Until we chat again next Thursday, stay curious.

Other Episodes

Episode

July 02, 2026 00:15:28
Episode Cover

Ep. 50: The AI Price Hike Is Coming

This entire episode is dedicated to discussing a prediction I've brought up eleventy billion times: AI prices are gonna go up, and it's not...

Listen

Episode 18

November 20, 2025 00:22:51
Episode Cover

Ep. 18: WTF is NVIDIA?

In this episode I break down what NVIDIA is, why its GPUs (hint: these are the “chips” you hear so much about) became the...

Listen

Episode 1

August 07, 2025 00:40:29
Episode Cover

Ep. 1: What You Actually Need to Know About ChatGPT

In this episode of ChatGPT Curious, I lay the groundwork for understanding what ChatGPT actually is, without getting too lost in the weeds. I...

Listen