Why AI Watermarking Isn’t The Answer

OpenAI logo

Earlier this week, Shreeharsh Kelkar, a lecturer at the University of California at Berkeley, published an excellent essay in the Chronicle of Higher Education calling for governments and universities to push for AI watermarking.

The argument is pretty simple. Kelkar argues that the technology exists for AI companies to insert watermarks in text, images, and video that it generates. These marks would be invisible to users but could be detected by tools designed to see them. 

In a classroom setting, this would make it easy for instructors to know if students used AI. Instructors would then be free to set their own tolerances for AI for a particular assignment and ensure that their instructions were followed.

This also could have a major impact outside of academia. Social media platforms, for example, could highlight what content was AI-generated. This could reduce the impact of deepfakes, prevent the sale of low-quality books on sites like Amazon, and address many other AI-related issues.

Kelkar points to research that highlights how this could align with the interests of AI companies. After all, preventing misuse could increase the legitimacy of AI and actually aid the long-term goals of AI companies.

To be clear, all of this is true. However, AI watermarking is not a silver bullet for the problems that AI has created. That includes both inside and outside the classroom.

The Problem with AI Watermarking

To be clear, I fully agree with Kelkar that AI companies could and should be watermarking their output. It’s a basic step that can reduce the harms of AI without impacting regular users. 

And several AI companies do use watermarks. Google, for example, uses SynthID to embed watermarks in AI-generated images, audio, text, and video. Meta uses Stable Signature for images. 

However, as Kelkar pointed out, OpenAI, the makers of ChatGPT, have been reluctant to do so. That’s because a survey of users found that nearly 30 percent said they would stop using it if the output was watermarked.

In the current AI race, that is simply not an acceptable loss. Even if that 30% represents the ones misusing the technology.

According to Kelkar, “The classic answer to this problem, from the point of view of economics and public policy, is regulation that forces all companies to take action so that no single company suffers a competitive disadvantage.”

However, there are two problems with this approach. First is simply that there is no interest or willpower. In October 2023, then-President Joe Biden signed an executive order calling on AI watermarking. But the order didn’t have any teeth and didn’t even apply to any of the existing AI systems.

But even if there were the willpower to do it, we’ve already seen the problems with enforcing it.

The DeepSeek Problem

In January 2025, DeepSeek launched its R1 and V3 models. It caused a 16% drop in NVIDIA stock and a 3% drop in the Nasdaq 100. 

The reason was that not only was a Chinese company able to create a model that rivaled the stalwarts, but that the model was cheaper to run and cheaper to train.  

And that was just the first salvo. Shortly after DeepSeek’s launch, OpenThinker-32B pushed the envelope even further. It created an open-source model that used only 14% of the data of what an already slimmed-down DeepSeek did. 

Generative AI is no longer solely the space of large companies like OpenAI, Google, Microsoft, and Meta. It’s possible, even simple, for others to put forward their own models that require much less in resources. So even most of the world gets on board with AI watermarking, there will always be somewhere that isn’t.

To be clear, this isn’t an issue unique to AI. Once per year, the United States Trade Representative releases a list of “Notorious Markets” for counterfeiting and piracy. This includes countries, sites, and other markets that it feels are not taking adequate steps to reduce intellectual property infringement. This list has been released every year since 2006. 

AI watermarking would face the exact same issue. However, there is yet another problem. Even if these models were not as good as the major (watermarked) ones, they would still likely be “good enough” for most purposes. 

This includes generating essays for classrooms and AI slop for social media. But, even then, there’s a potentially bigger problem. The future of AI may not be in the cloud at all.

The Local Problem

As models may be getting bigger and more advanced on the cutting edge, there’s been an equal push to make models that can do more with less. Currently, you can find open-source AI models that will run on just about any computer, even low-end MacBooks. 

Though some of these models, such as Gemma 3, may have watermarking capabilities. It’s the user who ultimately decides how they are implemented. Once again, these models may not be as powerful as high-end ones from AI companies, but they will likely be “good enough” for most tasks.

And that danger of “good enough” is something I’ve been warning about for over three years. Cell phone cameras didn’t supplant standalone ones for most uses by being better. They did it by being “good enough” for most uses.

That was the same danger with AI. But now it isn’t that a ChatGPT essay will be good enough for a student, it’s whether a model they run on their laptop will be good enough. If we aren’t at that point, we likely will be soon.

In short, there’s no way to enforce watermarking, at least not with current technology and the current legal situation. While I am deeply skeptical that AI will live up to the promises the industry has made, the truth is that it’s reaching or has reached a point where you don’t need to query ChatGPT to get intelligible text that can pass for an essay.

You can do that relatively well on a five-year-old laptop that can be bought for less than $300.

Bottom Line

To be clear, I do think that AI companies can and should watermark their output. Not only would that help curb the misuse of their systems, but it would give AI companies a greater argument for legitimacy.

Simply put, if you truly believe that AI writing or AI art is equally valid to work created by humans, then there is no reason not to watermark it. Let the public judge what value AI-created work has and make a knowing decision if they want to view it.

However, enforcing that is going to be impossible. As someone who has been on the internet for over 30 years and watched as the law has struggled to keep up with it at every turn, I’m not an optimist that this can be done. 

But, even if it can, the prevalence of smaller and smaller models with greater and greater capabilities means that there will always be a way to generate non-watermarked AI content. Whether it’s an essay, an image, or even a video, there will always be a way to do it locally given enough time and equipment.

So yes, AI companies can and should watermark their content. But we as instructors or even just readers can’t rely on such watermarks. At best, they can be a tool. But we will always need more tools to separate man from machine. 

Want to Reuse or Republish this Content?

If you want to feature this article in your site, classroom or elsewhere, just let us know! We usually grant permission within 24 hours.

Click Here to Get Permission for Free