Anthropic's 'Watermark' Text Adulteration in Claude Is a Perversion of Writing

Aug 17, 2026 04:53 AM - 2 hours ago 1
Sunday, 16 August 2026

When I wrote this week astir Anthropic’s announcement that each Claude models, worldwide, would soon statesman “watermarking” everything they generate, including text, to comply pinch this EU regulation, we were near to estimate how this was going to work, because Anthropic offered not moreover a vague explanation of really it would work — despite the truth that the title of the announcement was, absurdly and insultingly, “How Claude Marks AI-Generated Content”.

My first speculation was that possibly they’d hide invisible non-printing Unicode characters successful the text. Just spitballing. Turns retired that’s not what they’re going to do. What they’re going to do is use a shape of steganography, wherever the prime of words (or different token output) astatine conclusion clip will time off fingerprints that tin later, maybe, beryllium detected probabilistically.

I initially guessed “invisible characters” not because I didn’t deliberation of the semantic word-choice technique, but because I was a fool who took Anthropic astatine its connection successful their explanation of what they would do. Their original support archive claims:

When a supported Claude exemplary generates text, it weaves an imperceptible watermark straight into the matter itself. You won’t see it, and it doesn’t alteration the meaning, quality, aliases readability of Claude’s response.

They opportunity “imperceptible” and “doesn’t alteration the meaning, quality, aliases readability”. Their words. Not almost imperceptible. Not slightly changes the meaning, quality, aliases readability. That made consciousness to me, because that’s perfectly what I want — nay, demand — from immoderate devices I usage personally. It’s unacceptable for a instrumentality to sacrifice an iota of clarity, coherence, meaning, quality, etc. for the intent of embedding hidden clues wrong the matter to propose its provenance. That’s what I would and will demand. And Anthropic’s (original) support archive unambiguously claims that’s what their strategy will enable. So if that were true, I couldn’t spot what was near different than hiding invisible characters wrong the text.

My correction was believing Anthropic that their strategy wouldn’t adulterate and corrupt the semantics of the matter their models generate. That is successful truth precisely what they scheme to do. I should person my caput examined for believing a azygous connection of a archive titled “How Claude Marks AI-Generated Content” that doesn’t explain, astatine all, really Claude marks (or will mark) AI-generated content.

How It’s Actually Going to Work

Yesterday, connected an wholly different website than the original “How Claude marks AI-generated content” article (the 1 that didn’t explicate thing astatine each astir it works), Anthropic published “How Claude’s Text Watermark Works”, which does really explicate successful layman-accessible position really it’s going to work. I will return to Anthropic’s caller highly euphemistic and somewhat misleading explanation below.

There’s a bunch of investigation connected this topic, immoderate of which I person besides linked to below. But the very champion explanation of the wide thought down the method is an interactive effort by James Padolsey, “How AI Text Watermarking Works”. It’s a wonderfully cogent read, and the interactive elements splendidly exemplify the main concepts. A+ work. If you person immoderate liking successful this astatine all, I situation opportunity you must read — and play with — Padolsey’s piece.

But here’s my stab astatine a layman’s high-level summary. If you flip a coin N times and statement the results, you tin find pinch a grade of certainty whether the coin is adjacent aliases biased. LLMs are, successful their celebrated incarnations, non-deterministic. Ask the aforesaid mobility of the aforesaid exemplary and you often get astatine slightest somewhat different answers. Maybe the aforesaid meaning, but different phrasing. At each determination constituent for generating the adjacent token, the exemplary makes a choice. With these semantic watermarking techniques, they make different choices for immoderate tokens based connected connection lists that could beryllium called “green” and “red”. At each determination point, they’re a small much apt to prime a connection from the greenish database than the reddish list. That doesn’t mean they ne'er take words from the reddish list. Just that they’re little apt to than they would if the adulterated marking method weren’t successful place. (Same measurement that a crooked 51-49 coin will still onshore “wrong” broadside up 49 times retired of 100 connected average.)

Words aliases connection phrases are sorted into the greenish and reddish lists deterministically connected the fly, astatine each “next token” procreation point. So sometimes a circumstantial connection will beryllium connected the greenish list, and different times it will beryllium connected the reddish list. Someone pinch the concealed cardinal tin find which database a connection will beryllium connected astatine each token procreation constituent (which is really the watermarking is detected); those without the concealed cardinal cannot. This intends location will ne'er beryllium a database of words that Claude prefers aliases eschews.

With coin flipping, the higher N is — the much times you flip — the much assured you tin beryllium that the coin is adjacent aliases biased. So excessively pinch this semantic watermarking. The much words successful the text, the much meticulous the study will beryllium that the matter was generated by a circumstantial AI exemplary aliases not. With excessively fewer coin flips, you can’t execute immoderate assurance astatine each regarding a coin’s fairness. With excessively fewer words (or tokens), there’s nary measurement to execute immoderate assurance whether a drawstring of matter was AI-generated aliases not.

Given a drawstring of matter to analyse for signs of a circumstantial watermarking system, if location are much words tagged arsenic greenish and less tagged arsenic reddish than would different beryllium expected, the matter tin beryllium flagged — with immoderate grade of confidence — as having been generated, aliases simply modified, by the AI strategy that applies the circumstantial secret-key watermarking system. The magnitude of assurance successful the determination will evidently vary, significantly, based connected the size of the matter drawstring and randomized weights fixed to words connected the greenish and reddish lists. But only Anthropic will beryllium capable to find if matter was seemingly generated by Claude, and Anthropic will only beryllium capable to observe the watermarks that are applied by Claude. Claude can’t observe the hidden watermark signals generated by, say, Gemini, and Gemini can’t observe the hidden watermark signals created by Claude, because each implementation is predicated connected concealed keys held only by the LLM provider.

Objections to the Technical Premise

One of my basal problem pinch this is that nary 2 synonyms transportation the exact aforesaid meaning. “He leaped astatine the chance” and “He jumped astatine the opportunity” are very akin sentences expressing the aforesaid wide sentiment, but they are not the same. The nonstop words we take erstwhile penning matter. I want immoderate LLM I usage to take the very best, astir precise words astatine each azygous determination point. An evident constraint that I judge is clip and computation. Within the constraint of executing conclusion quickly, and astatine a definite costs per token, I want the champion words. This constraint matches quality writing. I could surely constitute a amended file by taking longer to constitute it. I constitute pinch a consciousness of really overmuch attraction I should put into each connection and punctuation prime I make. I return much clip pinch definite paragraphs, sentences, aliases moreover individual connection choices erstwhile my gut emotion says I should.

In different words, these are necessary trade-offs. These factors are each successful my interest: speed, cost, quality. Ideally I would for illustration cleanable writing, astatine instantaneous procreation speed, astatine zero cost. None of those things are possible. Computation is not free of complaint (and cloud-based LLM conclusion pinch starring models is really expensive). Inference is not instantaneous. And awesome writing, whether earthy aliases artificial, tin only approach perfection.

The thought that thing different than my needs should facet into the procreation of matter for me is patently offensive.

This isn’t conscionable astir matter 1 mightiness make pinch the volition of passing it disconnected arsenic their ain earthy work. This isn’t moreover astir LLM proofreading of activity written by hand. Anthropic is saying that all caller Claude models are going to adulterate each azygous spot of matter longer than 200 tokens (~150 words) they generate, including everything it presents to its users to read. So moreover successful a backstage speech betwixt a personification and Claude, which will ne'er beryllium publication by anyone different than the user, Claude will statesman making connection choices successful the sanction of marking its output successful statistically predictable ways alternatively than maximizing clarity and precision.

Even today’s alleged frontier models are already decidedly lacking successful lucidity. Claude, ChatGPT, Grok, et al. are “better writers” than astir humans and nutrient amended prose than the median human. But: nary shit. Most group are unspeakable writers. The “average person” is beautiful stupid and half of each group are stupider than that. And location are galore smart, absorbing group who are miserable writers. So arsenic awesome arsenic LLMs are, the barroom is low. The champion penning I spot travel retired of these models is worse than thing I would take to publication for pleasure. And now Anthropic is saying they’re going to make it worse, connected purpose, for purposes that do not use maine successful immoderate way? Even if only somewhat worse?

Get fucked.

Objections to the EU Regulation

Speaking of objections, the applicable EU regularisation motivating each of this, “Code of Practice connected Transparency of AI-Generated Content”, is red-tape nanny-state pipe-dream nonsense. Here’s Ben Thompson’s summary from a paywalled Stratechery update this week:

  • The regularisation applies to matter longer than 200 tokens.
  • The supplier must instruction successful their terms-of-service that users not region the watermarking.
  • The solution should beryllium robust successful position of evading “typical processing solutions” for illustration surface shots, scanning and OCR, copy-and-pasting, translations, etc.

Taken literally, compliant LLM position of work must forbid users from rephrasing the output from models that comply pinch this regulation, because the connection choices are the marks. But it’s not the European Union that is trying to enforce their absurd, impractical, witch-hunt-fueling regularisation connected the full world. That falls connected Anthropic.

Complying pinch this, peculiarly pinch respect to text, is only going to create problems for honorable users. Dishonest users attempting to walk disconnected AI-generated matter arsenic their ain penning (students, employees, whoever) will simply circumvent discovery done non-compliant AI paraphrasing tools.

James Padolsey — whose interactive ocular mentation of really these schemes activity I linked to above — explains this successful a station titled “Anthropic’s Weak Watermarks Appease a Weak Law” (which, if it rings a bell, I linked to in a standalone post earlier today):

The aforesaid thought that led to this rule could person applied to calculators astatine the clip of their inception, had their outputs revealed themselves done artefacts. Thankfully, a sum borne of the encephalon is treated nary otherwise from 1 produced by a calculator. Likewise pinch spellcheckers. To make assistance suspect only erstwhile the instrumentality becomes tin capable to constitute a whole condemnation is not a opinionated boundary. It is simply a civilized premium placed connected trouble itself.

Anthropic has nevertheless chosen a blanket, model-level implementation that appears broader than the law’s minimum requirement. That whitethorn beryllium convenient compliance engineering, but it discards distinctions the rule expressly attempted to preserve. The result is simply a awesome wide capable to implicate harmless and assistive use, yet vulnerable capable to beryllium removed by a motivated person done important recomposition. It risks concentrating suspicion connected mean and assistive users while remaining weakest against deliberate deception.

Padolsey is the creator of Declaude, a delightfully elemental web app that allows you to “Paste successful AI-flavored matter and get the aforesaid contented backmost arsenic plain prose”. Declaude’s original intent is cleaning the saccharine Claude characteristic stink from matter (whether it was created by Claude aliases immoderate different LLM), but, if Anthropic persists successful its stated scheme to statesman adulterating each matter Claude generates, Declaude will besides service arsenic a copy-paste single-extra-step measurement to eliminates those marks. Declaude is absorbing and useful already, but it exemplifies really ill-considered and futile this EU regularisation is erstwhile it comes to prose.

Google SynthID

Google has a watermarking strategy successful spot that they telephone SynthID, which they use to AI-generated images, video, audio, and text. I’m concerned successful this article only pinch text. With multimedia, embedded watermarks tin beryllium metadata wrong files, and genuinely not impact the experiential value of the activity erstwhile viewed aliases listened to. With text, we are talking astir the existent words that are chosen. From the “AI-generated text” conception of Google DeepMind’s ain explanation of SynthID:

We’ve expanded SynthID to watermarking and identifying text generated by the Gemini app and web experience. Large language models make matter 1 connection (token) astatine a time. Each connection is assigned a probability score, based connected really apt it is to be generated next. So for a condemnation for illustration “My favourite tropical fruits are mango and…”, the connection “bananas” would person a higher probability people than the connection “airplanes”. SynthID adjusts these probability scores to make a watermark. It’s not noticeable to the quality eye, and doesn’t impact the value of the output.

In a group chat, a friend of excavation quoted the above, and I responded that if a chatbot wrote “My favourite tropical fruits are mango and airplanes”, I’m beautiful judge I’d fucking notice. Another friend past responded pinch this:

AI-generated image of an airplane carved retired of a pineapple aliases something, connected a tropical beach.

Days later, that still cracks maine up.

But Google’s absurd explanation puts the dishonesty to their ain declare that it isn’t noticeable, and it serves to show conscionable really small respect the group down these generated-text fingerprinting schemes person for the existent trade of writing. Of people bananas has a higher probability people than airplanes, because airplanes aren’t fruit. But what astir pineapple? Should the condemnation complete to “mango and bananas” aliases “mango and pineapple”? That’s a bully question, and the only acceptable reply for why an LLM should take bananas alternatively of pineapple (or coconut, aliases guava, aliases papaya...) is that it has wished that it’s the champion fresh for the intended meaning, tone, and sentiment of the text. Not because bananas is connected the watermarking “green” database and pineapple is connected the “red” list, moreover though pineapple mightiness beryllium the amended fit. Google’s ain supposedly jocular explanation of really SynthID useful successful truth captures really the strategy perverts the matter it generates.

They’re saying you won’t announcement because if it only chooses bananas complete pineapple for these fingerprinting purposes, well, they’re some tropical fruits and who cares. But it’s utter delirium that the quality is “not noticeable to the quality eye”. The semantic quality betwixt banana and pineapple is conscionable arsenic noticeable to the quality oculus arsenic the arsenic the sensation of the 2 are to the quality tongue.

If it did nutrient “My favourite tropical fruits are mango and airplanes”, it’d beryllium incredibly stupid, but it wouldn’t beryllium offensive because we’d each admit that thing wholly off-key happened. What’s violative is that pinch a strategy for illustration SynthId successful place, wherever the fingerprinting decisions are motivated by a concealed key, we person nary thought whether it completed to “mangos and bananas” because bananas was wished to beryllium the champion adjacent token, aliases because bananas is successful the “green” bucket of words. It calls each azygous connection prime into question.

Here’s a insubstantial published successful Nature wherever Google’s squad down SynthID published their work, aft putting it into accumulation pinch Gemini (née Bard):

We analysed astir 20 cardinal watermarked and unwatermarked responses and computed the thumbs-up and thumbs-down rates (both as a fraction of the full number of thumbs-up and thumbs-down feedback received). We recovered that the thumbs-up complaint for the two models differed by 0.01% (with the watermarked exemplary being higher); and the thumbs-down complaint differed by 0.02% (with the watermarked exemplary being lower). We recovered some of these differences to beryllium statistically insignificant, and good wrong the 95% confidence intervals.

From this experiment, we reason that complete a wide assortment of real chatbot interactions, the quality successful consequence value and utility, arsenic judged by humans, is negligible. Subsequently, non-distortionary SynthID-Text has been productionized and is currently watermarking responses successful Gemini and Gemini Advanced. To the champion of our knowledge, this information represents the first systematic watermarking investigation of its benignant wrong a large-scale accumulation system.

To this I say:

  • Gemini/Bard’s thumbs-up/thumbs-down buttons are not a bully research for evaluating the effect connected quality. If a chatbot tells maine “My favourite tropical fruits are mango and bananas” alternatively of “mango and pineapple”, I’m not going to springiness the consequence a thumbs down because of the consequence it chose. I’d springiness it a thumbs down if said “airplanes”, yes, but that’s a strawman. (The insubstantial successful Nature moreover uses the “My favourite tropical fruits are mango and ...” illustration arsenic an illustration, but successful the paper, the only 4 adjacent tokens considered are, successful bid of probability distribution, mango, lychee, papaya, and durian. No airplanes. And, conveniently, successful the paper’s example, the “winner” of the watermarking “tournament” conscionable happens to beryllium mango, the 1 that would person been selected arsenic the champion if the watermarking weren’t successful place.)

  • A “difference successful consequence value and utility, arsenic judged by humans” that is “negligible” does not mean imperceptible. What they really mean is that it’s only somewhat worse and that everyone is either excessively stupid to announcement aliases excessively indifferent to care.

  • It’s wide considered that Gemini is down ChatGPT and Claude successful quality. Perhaps the truth that they’ve put SynthID-text into accumulation is 1 of galore reasons why. I personally work together that Gemini’s prose is inferior. Maybe the usage of SynthID has thing to do pinch the truth that I, on pinch the wide nationalist consensus, see Gemini to beryllium a second-rate chatbot — but successful that case, possibly it’s the truth that Gemini is simply a second-rate chatbot that makes the quality “negligible” erstwhile Google started mixing successful SynthID-motivated tokens successful its results. It’s a batch much apt that your edifice customers won’t announcement that you replaced your regular java with Folgers Crystals if your regular java is second-rate to commencement with.

Anthropic

Now, finally, backmost to Anthropic’s caller “How Claude’s Text Watermark Works” published yesterday. I person immoderate comments.

To summarize:

  • We usage a method of watermarking that does not person immoderate practical impact connected the value aliases contented of Claude’s outputs;

  • The quality betwixt watermarked and un-watermarked matter will not beryllium distinguishable to readers;

Translation: Specific words do not matter and we don’t deliberation anyone sounds thing closely.

  • Nothing is added to the matter and location are nary hidden characters;

This would person been worthy clarifying astatine the outset.

  • Watermarking won’t beryllium circumstantial to Claude. As of August 2, the EU requires AI providers serving its marketplace to people AI-generated content. Other awesome exemplary developers person signed the aforesaid Code of Practice and will beryllium implementing their ain watermarks.

No different AI supplier has stated that they will use specified marking, adulterating each generated text, extracurricular the EU.

Take the condemnation “The upwind coming was acold and…”. The adjacent word is very improbable to beryllium “sugary.” But it is rather apt to be “overcast” aliases “grey.” Under astir circumstances, it doesn’t matter much to the scholar which of these second 2 words the model ultimately chooses — the meaning of the condemnation is mostly the same either way. In cases for illustration this, the prime is settled by a random number.

Arguing that grey vs. overcast “doesn’t matter overmuch to the reader” is the crux of my statement that this full endeavor is simply a perverse adulteration of what it intends to write — or to read. That it’s subtle successful immoderate ways makes it more perverse, because it’s sneaky.

In soul testing, we’ve seen nary effect of watermarking connected the content, level of creativity, aliases readability of Claude’s text. In the SynthID-Text paper, which introduced the method we use, Google DeepMind tested this effect by serving a exemplary that used watermarking to a information of their Gemini postulation and comparing thumbs-up and thumbs-down ratings. They recovered no statistically important differences from the unwatermarked model. And successful a controlled study, quality raters comparing watermarked and unwatermarked answers side-by-side saw no difference successful quality.

See supra for my statement that this thumbs-up/thumbs-down information is perfectly worthless successful evaluating whether the SynthID-style word-bias watermarking makes matter worse. By meaning it must make matter worse, unless the underlying LLM model’s scoring is wrong, because the quality of the watermarking algorithm requires it to sometimes summation the probability of selecting a worse connection prime and alteration the probability of selecting the model’s best choice. It’s only a mobility of really overmuch worse. What Google’s thumb-counting information shows is only that it isn’t truthful overmuch worse arsenic to make Gemini users click the thumbs-down button.

Watermarking doesn’t alteration the meaning aliases acquisition for the person reference it, but if you wanted to cheque aft the fact whether the matter was apt generated by Claude, the watermark allows you to do so.

No, it does not. Because the full strategy is tied to concealed keys held only by the AI provider, it only allows Anthropic, not “you”, to cheque anything.

When Claude proofreads matter written by a person, what it gives back has mostly only been lightly edited; because astir all the words are the person’s, there’s very small (if anything) for the watermark to connect to. Depending connected the magnitude of the text and really heavy Claude has edited it, those changes mightiness not be enough to make Claude’s engagement detectable. The much Claude writes, the much decisions it has to make, and the much space there is for a watermark.

Translation: No 1 tin ever again usage Claude for proofreading their ain prose unless they’re consenting to consequence that the full point mightiness beryllium flagged arsenic having been generated by Claude.

For example, erstwhile the exemplary has written “2 + 2 =”, location is simply a very clear champion prime for the adjacent token (if the exemplary is completing the sum, location isn’t an reply that’s arsenic as bully arsenic “4”; if it’s talking astir George Orwell’s Nineteen Eighty-Four, there isn’t an reply that’s arsenic as bully arsenic “5”). The “nudge” of the watermark wouldn’t beryllium applied here. For the aforesaid reason, code — which successful very galore cases has to beryllium exact — has mostly less watermarking than immoderate different forms of text.

Having said that, successful areas wherever location is an arbitrary choice between peculiar words aliases position wrong the code, the watermark can beryllium used, specified arsenic comments wrong code. But by definition, it will person a negligible effect connected the existent codification produced.

Translation: We worth precision successful programming code; we do not successful prose.

And it is exceedingly rich | to mention George Orwell’s Nineteen Eighty-Four, approvingly, successful the discourse of justifying a matter adulteration strategy premised connected the conception that circumstantial words do not matter. I mean what the existent fuck? Orwell!

Lastly, arsenic to why they’re doing this:

We’re implementing watermarking to comply pinch the EU AI Act. Anthropic, on pinch respective different awesome AI exemplary providers and around 190 full signatories, signed the EU Code of Practice connected Transparency of AI-Generated Content successful July 2026. This requires AI strategy providers to usage methods of “marking” AI-generated text. We’re applying watermarking globally astatine launch because we don’t yet person a durable measurement to scope it by region.

This, from a institution that the Financial Times conscionable reported is weeks distant from an IPO pinch an intended valuation of $2 trillion, which would make it 1 of the 10 highest-valued companies successful the world — as of today, placing it astatine #7, betwixt TSMC ($2.2T) and Broadcom ($1.9T).

This leaves america to judge that 1 of the pursuing must beryllium true:

  • It’s perfectly reasonable that a exertion institution weighted connected par pinch Amazon and TSMC is technically incapable of complying pinch an EU location rule only wrong the EU itself.1 Not a origin for interest astatine all.

  • Anthropic is successful complete their heads, wields shockingly small power complete their ain tech stack, and their imminent IPO is apt to beryllium remembered only arsenic a caller high-water people successful the manic world AI bubble.

Also, what happens if different awesome world marketplace makes it unlawful for AI to secretly watermark generated text?

OpenAI

From an OpenAI support archive titled “Provenance Signals (Content Credentials, SynthID) successful OpenAI-Generated Content”:

Consistent pinch our commitments nether the European Commission’s Code of Practice connected Transparency of AI-generated content, our extremity is to grow provenance signals to all modalities including text, truthful customers and developers have clear ways to meet their ain transparency obligations as standards and tooling proceed to mature.

There’s a batch of wiggle room successful this little statement, and it could conscionable arsenic good mean that OpenAI models will only adulterate matter pinch fingerprint markers erstwhile users aliases developers inquire for it. Or that it will only beryllium mandatory for users successful the EU. If I were astatine OpenAI I’d spell difficult connected this and publically opportunity that ChatGPT will ne'er watermark matter it generates unless you inquire it to, and that if you want devices that secretly activity down your backmost without telling you really they activity to emblem your words successful ways you can’t see, spell up and usage Claude.

Further Reading

Three papers connected ArXiv:

  • “A Watermark for Large Language Models”, past revised May 2024.
  • “Watermarks successful the Sand: Impossibility of Strong Watermarking for Generative Models”, past revised May 2025.
  • “Robust Text Watermarking for Large Language Models via Dual Semantic Embeddings”, past revised June 2026.

I will admit that while I’m profoundly offended by the thought of personally utilizing devices that effort to time off specified watermarks successful matter they nutrient aliases touch, the mathematics down it are fascinating.

Michael Lopp, astatine Rands successful Repose, “RIP Claude”:

As a quality who has had to wrangle pinch EU regulations successful the past, I americium abundantly clear what’s progressive successful the laborious bureaucratic process. I tin conjecture what threats Anthropic is facing. However, this is simply a tone-deaf, clumsy, and alarming opening salvo successful their watermark strategy. [...]

My penning is my work, and Anthropic’s existent strategy is aggressively writer-hostile.

Jeff Gamet, “Anthropic’s Claude Watermark Is Akin to an AI Poison Pill”:

To beryllium clear, the watermarking is embedded successful beautiful overmuch immoderate text Claude touches. Along pinch matter Claude generates, it besides applies to matter it processes, specified arsenic proofreading and summarizing. I expect we’ll spot excessively galore inaccurate accusations of utilizing Claude to constitute documents wherever the contented was human-written, but AI-proofread.

The watermarking sticks pinch documents done copy-and-paste, too. Imagine copying matter from a blog station aliases email only to have what you wrote tagged arsenic perchance AI-generated. In fact, that could very good hap pinch this post. I personally constitute each of my contented without AI tools, but I copied the quote astatine the apical of this portion straight from Anthropic’s website. Does that mean what I wrote present will show arsenic AI-generated? If they utilized their own models to make aliases edit what I quoted, past the reply is very likely “yes.”

One of the papers published astatine ArXiv I cited supra claims that specified watermarking moreover persists erstwhile an article of matter primitively generated successful English is translated into German.

Secrets are the poison here. When only Anthropic holds the concealed keys that some nutrient the watermarking and execute the probabilistic discovery of those marks, we’re each near to wonder. To wonderment if what we’re reference is secretly watermarked, what we’re quoting is secretly watermarked, and whether what we ourselves are penning will beryllium unjustly accused of being AI-generated based connected secrets we don’t cognize and can’t see. Poisonous is precisely the correct word.

Or should I opportunity toxic? Or airplanes?

More