Skip to content

Science1 publisher3 min readPublished

A 150-word floor decides which AI-written messages carry Europe's watermark

Watermarking is already shipping in mainstream models ahead of Europe's compliance date, and the exemptions in the Code of Practice will decide whose writing gets marked, which leaves the absence of a mark saying very little.

The Scientist · Science desk

Illustration accompanying A 150-word floor decides which AI-written messages carry Europe's watermark

What happened

  • Machine-readable watermarking of generative AI output is required under the EU's transparency rules, and systems already on the market have until December 2026 to comply.
  • OpenAI, by the account in the phys.org piece, developed a watermarking system for ChatGPT years ago and held it back rather than risk alienating users.
  • The mark is a function of statistical word patterning, which means extensive rewriting or paraphrasing can override it after the fact.

Compiled by The ScientistSomething wrong?How this is made

Why it matters

  • constraint Watermark checking is a one-sided test: it can confirm mainstream AI involvement in a long document, but silence is uninformative, so any internal policy built on scanning will treat honest short notes and paraphrased drafts identically.
  • decision Managers who want their AI use to read as legible rather than concealed have to write the norm themselves, since the mark cannot separate a polished self-draft from a delegated one, and that is the difference recipients respond to.
  • exposure Visibility lands unevenly on people who write at length in mainstream tools, while short messages and privately run models sit outside the mark's reach entirely.
  • contradiction The remedy the authors prefer costs the thing it is meant to protect: they report disclosure lowering trust across 13 experiments, so an open-disclosure policy buys legibility at a price the article never sizes.

The mark is a pattern in statistical word choice, which is why one line in the researchers' account carries more weight than the deadline does: extensive rewriting or paraphrasing can override it [8]. Two further conditions have to hold before there is anything to find. The Commission's Code of Practice exempts text under roughly 150 words [6], and it exempts assistive functions that do not substantially change the input, grammar and spell-checking among them [7].

Put those together and the audit trail has a shape. A missing watermark is consistent with a human author, and equally with a short note, an assistive edit, a paraphrase pass, or a model the sender runs privately [6][7][8][16]. Anyone who takes up the habit of checking colleagues' messages for AI fingerprints is running a test with no control: a positive result carries information, a negative one carries none.

What the mark does report is thin in a second way. It indicates that AI was probably involved, and it does not distinguish a note the sender drafted and then asked a model to polish from one handed over whole [9]. That is the distinction a recipient is actually trying to make.

The behavioural findings summarised in the phys.org piece all point one way. People frequently cannot tell an AI-written personal message from a human one, yet their reading of the sender moves once they learn which it was [10]. Employees extend more latitude to a manager's AI-drafted scheduling note than to AI-drafted praise, where sincerity comes under question [11]. Apologies attributed to AI draw less trust and forgiveness [12]. Each finding gives a direction but no magnitude: the article gives no sample sizes or effect sizes, and no citation to the underlying experiments [14]. The thing this does not tell you is whether the penalty is a small discount on one message or something that changes how a team reads everything a manager sends.

Of the three providers named, two now ship a watermark, Google through SynthID in its proprietary models and Anthropic across Claude output globally, while OpenAI reportedly built one for ChatGPT years ago and held it back for fear of alienating users [15][3][4][5]. Coverage therefore skews toward people who write at length in mainstream, transparent systems, so a two-line apology by text may carry no mark while a long letter of condolence does [16].

The authors, who study AI's relational and emotional effects on learning, favour disclosure that people write themselves, explaining when, how and why they used a model [17]. That carries a measured price: across 13 experiments, they report, disclosing AI use reduced trust [13], and the piece does not say by how much [14]. A stated practice supplies the degree of involvement that the watermark by construction cannot, which is why the norm, not the detector, is the part a manager can actually plan [9].

What to watch

  • Whether the Commission's guidance keeps the roughly 150-word exemption or moves the threshold, which decides how much routine writing is covered.
  • Whether OpenAI ships watermarking for ChatGPT, which would change the share of mainstream generated text that carries a mark at all.
  • Publication of the underlying experiments with sample sizes and effect sizes, so the trust penalty can be sized rather than only signed.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories