AI text watermarks: what can be measured, and what cannot

Guide · 18 August 2026

In one sentence. Three unrelated mechanisms are all called AI text watermarks — extra characters inserted into the text, statistical patterns in the choice of words, and signed provenance records — and they differ in the one way that matters: whether anyone outside the company that made them can measure them.

Three different things share one name

When a tool, an article or a vendor mentions a watermark in AI-generated text, it can mean any of three mechanisms with almost nothing in common:

  • Inserted characters: zero width code points, unusual spaces, letters borrowed from another alphabet. They live in the text as data — each one is present, or it is not.
  • Statistical marks: nothing is added to the text at all. The signal lives in which words the model picked while writing.
  • Signed provenance: a Content Credential — a cryptographically signed record bound to a file, designed to be read rather than hidden.

The three behave so differently that a sentence about AI watermarks in general is usually a sentence about nothing. What can be measured, and by whom, depends entirely on which family is in front of you.

Family one: characters in the text

The first family is arithmetic. A zero width space is at position 214 of your text or it is not; no judgement is involved. This is the only family a third party can fully measure — list, count, and take out — and the only one where the result can be verified by anyone.

QuietMeta's text cleaner works from an inventory of 1,326 exact code points in six classes: invisible characters, exotic spaces, bidirectional controls, letters from another alphabet drawn exactly like Latin ones, typographic punctuation, and styled letters that look bold or italic but are entirely different characters. Everything it finds is reported one entry at a time, with its code point, its Unicode name, how many times it occurs and where. No heuristics and no statistics: what is in the table is reported, and nothing else is guessed at.

Some listed code points are kept on purpose — a zero width joiner between two emoji is what makes them a single picture, and the same character is grammatically required in Persian and several Indic scripts. When the cleaner keeps one, it names it and counts it, rather than deciding in silence.

The check is the point. Paste the cleaned result back into the box and every class you switched on reads zero. The cleaner runs inside the page, in your browser, and sends nothing anywhere.

Family two: marks in the choice of words

The second family works on a completely different principle. Rather than adding anything to the text, the model is nudged while it writes: at each step it has several words that would do, and the choice between them is skewed by a secret key. No single word looks unusual. Across a few hundred words, the pattern of choices becomes measurable — by whoever holds the key. Google published this approach for text as SynthID-Text in Nature in 2024; Anthropic announced in August 2026 that Claude marks its text output, without publishing the method.

The consequence for cleaning is absolute: there is no character to remove. Deleting every zero width space in a marked text leaves the mark exactly as it was, because it never lived in characters. A character cleaner does nothing to this family, and cannot — a tool claiming otherwise is describing something it has not measured. Because the signal is spread thinly across the word choices themselves, only choosing different words touches it: the published research on SynthID-Text reports that paraphrasing, translation and heavy editing degrade detection substantially, while light editing does not.

Family three: signed provenance

The third family is not hidden at all. A Content Credential is a provenance manifest, cryptographically signed and bound to the asset it describes, under the C2PA standard. It can carry a signed statement that AI took part in a version of the content, or in an ingredient of it. It is the only mechanism of the three that a third party can validate offline against a public specification — and today it travels with images, documents, audio and video rather than with raw text. It has its own guide.

What no third party can measure

Neither of the two statistical schemes deployed at scale can be verified by anyone outside the company running it:

  • Anthropic's text mark, announced for models launched in the EU from 2 August 2026. No algorithm, threshold, corpus or API is public; Anthropic says documentation enabling third-party detection will follow, with no date and no known access conditions.
  • Google's SynthID, deployed at very large scale and adopted beyond Google, notably by OpenAI. Detection has no public specification comparable to C2PA: it goes through Google's own SynthID Detector portal, first opened to journalists and researchers, with an API announced on registration.

QuietMeta says this instead of implying coverage it does not have. In its reports, a mechanism with no public detector produces detector unavailable — never not detected. The difference is the whole point: an absence of signal is not evidence of human authorship, and no status in the product is allowed to present it as such. Each report lists what could not be tested next to what was found.

Style-based detectors are a different question

Separate from all three families, a market of tools estimates whether a text was machine-written from its style and structure. They look at the writing itself, not at hidden characters, and independent testing puts their accuracy well below what their marketing claims. This guide does not name or rank them. What matters here is narrower: removing invisible characters changes the characters in your text and says nothing about who or what wrote it — it is not a way to change how any classifier judges a text, and no honest tool will tell you what a third-party detector will conclude, because that is not something it measures.

What rewriting does, and what it does not promise

Because the statistical family lives in which words were picked, the only operation that reaches it is choosing different words. QuietMeta's text page carries that option, deliberately separated from the character cleaning: it asks a hosted language model to choose different words, which cannot happen on your machine. It is the only option on the page that sends your text anywhere, and it is off until you switch it on. Our server keeps no copy of the text, no fragment, no hash and no result — only a count of words.

The trial rewrites your first 100 words free, with no account. A subscription rewrites up to 100,000 words per month — 2.99 EUR a month or 29.99 EUR a year — and adds .txt and .md file rewriting. The desktop application is a separate one-off purchase of 19 EUR (less with an active subscription) with 50,000 words of rewriting included, and no subscription.

What is promised is the operation, not a verdict: your words are chosen again by the model named in our privacy policy. We make no claim about what any detector or platform will conclude from the result, because no third party can measure those marks — including us.

Clean text See the subscription

Related