# The watermark era begins: Article 50 and the compliance layer nobody voted on

URL: https://www.thedeepfeed.ai/posts/2026-08-02-the-watermark-era-begins/
Category: Policy
Published: 2026-08-02
Author: the-deep-feed
Tags: policy, eu-ai-act, watermarking, transparency, regulation, compliance, gpai
Kind: deep

> The EU AI Act's transparency obligations entered into force today: machine-readable marking of AI-generated content, backed by fines up to 3% of global turnover. The law names the outcome but not the technology — which means the next four months will decide whose watermark becomes everyone's standard.

## TL;DR

- **Article 50 of the EU AI Act entered into force today**: AI-generated text, audio, image, and video must carry machine-readable marking, with fines up to **3% of global turnover**. A grace period runs to **December 2**.
- On July 31 the AI Office said **about 190 organisations had signed** the transparency Code of Practice — including Meta, which loudly refused the 2025 GPAI code ('Europe is heading down the wrong path on AI'). **xAI is absent from the list.**
- The law mandates an outcome, not a technology. The only production-tested text watermark is Google's SynthID-Text, validated on **nearly 20 million Gemini responses** per its 2024 Nature paper — whose own authors flag that paraphrasing weakens the mark.
- OpenAI confirmed in August 2024 it built a **'99.9% effective'** text watermark and shelved it, citing circumvention and users who said they'd use ChatGPT less. That shelved system is suddenly a compliance asset.
- Like the [trust contest](/posts/2026-07-25-the-trust-contest/), the mark only sticks to closed models: an API provider can watermark every token it serves, but weights already downloaded will never mark anything.

The [third wave of the EU AI Act entered into force today](https://www.debevoisedatablog.com/2026/08/03/the-third-wave-of-eu-ai-act-requirements-are-in-force-transparency-requirements-supervisory-powers/), a Sunday, with no signing photo and no press conference, because the signing happened years ago. What changed at midnight is that Article 50's transparency obligations stopped being a compliance roadmap and became law in effect: AI-generated text, audio, images, and video served to users in the European Union must now be marked as such in a machine-readable way, and the AI Office assumed its full supervisory powers over general-purpose model providers. The penalty ceiling is 3% of global turnover — for the companies this law is aimed at, a board-level number.

There is a grace period: providers have until December 2 to get their marking systems in order. But the legal switch flipped today, and the four months between now and December are the window in which the most consequential technical decision of this regulatory cycle gets made, mostly in private, by a handful of labs: what, exactly, does a machine-readable mark on AI-generated *text* look like, and who builds it?

Because here is the thing the coverage of "the EU's watermark law" keeps sliding past: the law does not contain a watermark. Article 50 mandates an outcome — marking that is machine-readable, effective, interoperable, reliable — and stays silent on the technology that achieves it. Images and video have candidate answers with years of engineering behind them. Text, the medium that makes up the overwhelming bulk of what these models produce, does not have a settled answer at all. The EU has ordered an industry to converge on a standard that does not yet exist, on a four-month clock, with a 3%-of-turnover penalty for failing to converge.

Nobody voted on what that standard will be. Nobody will. It will be decided by whichever lab ships first, and by whether the labs that ship second build their own or borrow.

# The obligations that landed at midnight

The AI Act arrived in waves by design: prohibitions first, then general-purpose model obligations, and now the transparency layer plus real enforcement machinery.

| In force Aug 2 | Who it binds | The teeth |
|---|---|---|
| Article 50 transparency: machine-readable marking of AI-generated text, audio, image, video | Providers of generative systems reaching EU users | Fines up to 3% of global turnover |
| Full AI Office enforcement powers | General-purpose AI model providers | Supervision, information demands, the power to actually levy the fines above |
| Code of Practice on Transparency of AI-generated Content | Signatories (voluntary) | A presumption-of-compliance bridge while standards mature |
| Grace period on marking | Everyone | Closes December 2 |

The first row reshapes products: every frontier lab serves EU users, and none has announced a shipping, production-grade marking system for text. The second row is the quieter structural change. The AI Office has had a mandate on paper for a year; as of today it has the supervisory powers of an actual regulator.

![Schematic: Article 50 machine — text, audio, image, video through a marking gate; 3%-of-turnover fine; Dec 2 grace deadline.](/post-images/2026-08-02-the-watermark-era-begins/article-50-machine.jpg)

# Who signed, who didn't, and the reversal in the middle

The Code of Practice is the tell about how the Commission expects this to actually work, and unlike most compliance stories, this one comes with a dated paper trail. Brussels built the [voluntary code](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content) in the open, on a published clock: a consultation launched September 4, 2025, drafting began November 5, a first draft landed December 17, and the final text was [published June 10, 2026](https://digital-strategy.ec.europa.eu/en/news/commission-publishes-code-practice-marking-and-labelling-ai-generated-content). Adherence functions as evidence of compliance. And on July 31, two days before the obligations bit, the AI Office published the receipts:

> "By the end of July 2026, about 190 organisations across various sectors - including IT, telecom, education, and retail - have signed the code. … Several well-established and prominent AI companies have committed to adhering to the code. Examples for Section 1 include: Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, Open AI, Synthesia."
> — [European AI Office, July 31, 2026](https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content)

That list contains a reversal. A year ago, Meta was the loudest holdout in Brussels. "Europe is heading down the wrong path on AI," chief global affairs officer Joel Kaplan wrote on LinkedIn on [July 18, 2025](https://techcrunch.com/2025/07/18/meta-refuses-to-sign-eus-ai-code-of-practice/), announcing Meta would not sign the general-purpose AI code of practice and calling it "over-reach" that introduces "legal uncertainties for model developers." On the transparency code, Meta signed. So did OpenAI, which pre-announced its support in a [June 11 blog post](https://openai.com/index/supporting-eu-trustworthy-ai-ecosystem/) framing it as "building on years of provenance work," and Anthropic, which has never published text-watermarking research of its own. The conspicuous absence is xAI, which [signed only the safety chapter](https://www.reuters.com/technology/musks-xai-sign-chapter-safety-security-eus-ai-code-practice-2025-07-31/) of the 2025 GPAI code on July 31 of that year, and does not appear anywhere on the transparency code's published signatory list.

The signing data tells you who accepted the obligation, not the mechanism: the code specifies measures, not algorithms. The arrangement should look familiar — it is the architecture we described in [the voluntary gate that works like a license](/posts/2026-07-09-the-voluntary-gate-that-works-like-a-license/), a nominally optional instrument everyone treats as binding. This one comes with a published text, a published deadline, and a published fine. It is the statutory edition of the gate, and 190 signatures say the industry understood exactly that.

# A mandate without a mechanism

For images and video, the compliance path is legible. Provenance metadata in the C2PA mold is already shipping; invisible pixel-level watermarks have been in production at Google for two years. Both are imperfect — metadata strips when a file is re-encoded or screenshotted — but a provider can stack them and plausibly tell the AI Office it is marking by the state of the art.

Text is the hard case, and text is the case that matters. There is no file to attach metadata to; the mark has nowhere to live except in the words themselves. The only approach anyone has demonstrated at production scale is statistical watermarking at the sampling layer: bias the model's token choices, imperceptibly, according to a keyed pattern, so that a detector holding the key can later test whether a passage carries the signature. The one open, published, production-tested implementation is SynthID-Text, which Google DeepMind [published in Nature](https://www.nature.com/articles/s41586-024-08025-4) on October 23, 2024, open-sourced the same day, and has run on Gemini traffic since. The paper, credited to Sumanth Dathathri, Abigail See, Sumedh Ghaisas, and two dozen co-authors, reports a live experiment across "nearly 20 million Gemini responses" confirming users could not tell watermarked output from unwatermarked. And Pushmeet Kohli, DeepMind's vice president of research, was explicit about the ambition the day it shipped:

> "Now, other [generative] AI developers will be able to use this technology to help them detect whether text outputs have come from their own [large language models], making it easier for more developers to build AI responsibly."
> — [Pushmeet Kohli, MIT Technology Review, October 23, 2024](https://www.technologyreview.com/2024/10/23/1106105/google-deepmind-is-making-its-ai-text-watermark-open-source/)

The strategic geometry is uncomfortable for everyone but Google. A European regulation now effectively requires every lab selling into the EU to watermark text. The only off-the-shelf, battle-tested way to do it belongs to Google, whose research chief publicly invited the industry to adopt it two years before the law had teeth. Borrowing means adopting your largest rival's technology as your compliance layer; building means betting your in-house scheme will satisfy a regulator who has been handed a working reference implementation by said rival. The regulation does not name SynthID. It does not have to. Gravity does the naming.

Tally what each signatory actually holds on day one of the obligation, because the asymmetry is the whole story:

| Lab | Text-watermark asset as of Aug 2 | Public evidence |
|---|---|---|
| Google | SynthID-Text in production on Gemini since 2024; open-sourced, 1,000+ GitHub stars, shipped in Hugging Face Transformers | [Nature paper](https://www.nature.com/articles/s41586-024-08025-4), Oct 23, 2024; [GitHub repo](https://github.com/google-deepmind/synthid-text) and [HF integration](https://huggingface.co/blog/synthid-text) same day |
| OpenAI | A shelved internal system, "99.9% effective," never shipped | [Blog update confirming the WSJ report](https://www.theverge.com/2024/8/4/24213268/openai-chatgpt-text-watermark-cheat-detection-tool), Aug 2024 |
| Anthropic | No published text-watermarking research | Absence of record |
| Meta | Image/video provenance work; nothing published for text | Signature on the code, Jul 2026 |
| xAI | Nothing published; not on the signatory list | [Safety-chapter-only signature](https://www.reuters.com/technology/musks-xai-sign-chapter-safety-security-eus-ai-code-practice-2025-07-31/), Jul 2025 |

One lab has a two-year production head start and gave the implementation away — not just as a paper but as a maintained library inside Hugging Face Transformers, one `pip install` from any serving stack in the world. One has a system in a drawer. Three have nothing on the public record. That table, not the statute, is the power map of the next seventeen weeks.

And yet borrowing is not the foregone conclusion it looks like. Three concrete reasons a lab might refuse. First, key custody: a lab that adopts Google's scheme still runs detection through infrastructure whose failure modes Google understands better than it does. Second, detection-as-product: if provenance checking becomes a paid enterprise feature, handing the reference implementation the win forecloses a revenue line. Third, the OpenAI-specific reason, visible in its own 2024 numbers: a company whose survey showed nearly 30 percent of users would use ChatGPT less under watermarking has a demand-side incentive to ship the *weakest* mark the AI Office will accept, and a borrowed best-in-class scheme is by definition not that. What the grace period will reveal is which lab thinks compliance is plumbing and which thinks it is a bargaining chip.

# How a tournament inks a sentence

Since the entire compliance question turns on this one mechanism, it is worth understanding what SynthID-Text actually does, one level down. The scheme intervenes at the only point where a text watermark can live: the sampling step, where the model converts a probability distribution over its vocabulary into a single chosen token.

The lineage starts with [Kirchenbauer et al.'s ICML 2023 paper](https://arxiv.org/abs/2301.10226), the first practical LLM watermark: hash the preceding tokens to pseudo-randomly split the vocabulary into a "green list" and a "red list," then nudge the model toward green tokens. A detector that knows the key counts green tokens and runs a one-sided significance test; the paper showed the mark was detectable from spans as short as 25 tokens. The weakness was the nudge itself: biasing token probabilities distorts the output distribution, and quality-sensitive production systems will not accept distortion.

SynthID-Text's contribution, per [the Nature paper](https://www.nature.com/articles/s41586-024-08025-4) and DeepMind's [reference implementation](https://github.com/google-deepmind/synthid-text), is a sampling algorithm the authors call tournament sampling. At each generation step, the system computes a random seed from a sliding window of recent context plus a secret watermarking key. It then draws several candidate tokens from the model's own distribution and runs them through a bracket: a multi-layer single-elimination tournament in which candidates are compared on pseudo-random "g-values" derived from the seed, and the winner is emitted. Because every candidate was sampled from the model's true distribution in the first place, the non-distortionary configuration provably preserves that distribution on average: no word is ever forced, no probability is ever overridden. The mark is not in any token. It is in the statistical tilt of thousands of tiny wins, readable only by a detector holding the key and scoring the same g-values.

Three consequences follow directly from the design. First, cost: the intervention adds negligible latency, which is why Google could run it silently on production Gemini traffic and confirm, across nearly 20 million responses, that users noticed nothing. Second, secrecy: the watermarking key never leaves the provider, so detection is a service the provider operates, not a property of the text anyone can check. That is a structural fact with real consequences for who gets to say what is synthetic. Third, and decisive for Article 50: the entire mechanism lives in the serving stack. It marks tokens as they are sampled. It has no existence apart from the sampler, which is precisely why it cannot follow a model whose weights leave the building.

![Tournament-sampling bracket: candidate tokens advance through g-value rounds into an inked sentence; a detector meter reads the signal](/post-images/2026-08-02-the-watermark-era-begins/tournament-sampling.jpg)

# The skeptic's ledger: what paraphrase actually does to the mark

The strongest case against the watermark era is not philosophical. It is empirical, and the numbers come from the technology's own literature. Take the skeptics seriously, then weigh what survives.

The Nature paper's limitations section concedes the vector: edits weaken the mark, and LLM paraphrasing is the edit that matters, because the attacker has free access to exactly the class of tool that produced the text. An [August 2025 robustness study from Queen's University](https://arxiv.org/abs/2508.20228) (Han, Li, Ni, and Zulkernine) tested the published SynthID-Text implementation against the attacks a motivated user would actually run (paraphrasing, copy-paste splicing of watermarked text into human text, and back-translation through another language) and found each one "can significantly degrade watermark detectability." Their proposed fix, layering a semantic-level watermark on top of SynthID's lexical one, bought back an average of 11.1 percent in F1 score, which is another way of saying the base scheme leaks badly under meaning-preserving rewrites. The practitioner version of the argument is blunter: engineer Sean Goedecke's July essay, [written with Article 50's enforcement date in view](https://www.seangoedecke.com/text-ai-watermarks/), argues that text watermarks "will always be trivial to remove" because text, unlike images, has no noise floor to hide in — every sentence is signal, so every hiding place is findable, and a rewrite through any unwatermarked model launders the text completely.

There is a second attack class the discourse mostly misses: spoofing. If a detector's response can be observed, an adversary can learn to produce text that *triggers* the mark without the provider's model ever generating it — framing a lab for text it did not write. The academic literature treats scrubbing and spoofing as a joint problem precisely because hardening against one tends to soften the other.

So does the skeptic win? On the strong claim — watermarks will identify adversarial synthetic content — yes, completely, and the Commission's own "insofar as technically feasible" language quietly concedes it. On the claim that matters for the regime, no. The overwhelming majority of AI text reaching readers is not laundered through paraphrase pipelines; it is pasted directly from a chat window into an email, an essay, a listing, a review. Against that traffic, a sampling-layer mark with a keyed detector works exactly as designed. Article 50 is a census instrument, not a forensic one: it will make the honest bulk of synthetic content legible while the motivated fringe washes out. A law that catches 95 percent of volume and zero percent of adversaries is either a reasonable public-health measure or a security theater, depending entirely on which problem you thought it was solving. Brussels, to its credit, wrote the feasibility hedge into the guidance. The labs that oversell robustness this fall will not be able to say the same.

# Build or borrow: the four-month question

The thing to watch between now and December 2 is not Brussels. It is the labs, and three questions in descending order of consequence.

*Who moves first on text?* Whoever ships the first Article 50-grade text watermark defines the baseline the AI Office will hold everyone else against; the second lab to ship will be asked why its scheme detects less reliably than the one already running.

*Do the followers build or borrow?* OpenAI's file here is thicker than most people remember, and it is dated. In August 2024, after The Wall Street Journal reported the company had built and shelved a text watermarking system for ChatGPT, OpenAI updated a blog post confirming the work: internally documented as "99.9% effective" and resistant to paraphrasing, yet "trivial to circumvention by bad actors" using tricks like rewording through another model. Per the Journal's reporting, [nearly 30% of surveyed ChatGPT users said they would use the product less](https://www.theverge.com/2024/8/4/24213268/openai-chatgpt-text-watermark-cheat-detection-tool) if watermarking shipped. That is the whole strategic problem in one 2024 memo: the technology works on honest users, dissolves under adversarial ones, and the honest users do not want it. What was a product liability in 2024 is a compliance asset in 2026 — whether OpenAI dusts off that system or adopts the open implementation is the open question of the fall. A lab that borrows concedes provenance is plumbing, shared infrastructure like TLS. A lab that builds claims detection is a competitive surface. The market has not priced either answer yet.

*Does anyone say the quiet part about robustness?* Every statistical text watermark degrades under paraphrase and translation, and this is not a critic's claim — it is in the reference implementation's own limitations section:

> "Generative watermarks are weakened by edits to the text, such as through LLM paraphrasing."
> — [Dathathri et al., *Nature*, October 23, 2024](https://www.nature.com/articles/s41586-024-08025-4)

The Commission's guidance asks for marking that is effective and reliable "insofar as technically feasible," which is load-bearing language: the regime can launch on technology a determined adversary can wash out. The mark is for the honest majority of content, not the motivated forger. Watch whether any lab is candid about that distinction when it ships, because the ones that oversell robustness are setting up the regime's first credibility crisis.

# The mark only sticks to closed models

There is a structural boundary to all of this, the same one we mapped in [the trust contest](/posts/2026-07-25-the-trust-contest/): a serving-layer control only controls what you serve. An API provider can watermark every token because every token passes through infrastructure it owns. A lab that ships weights has no sampling layer to bias once the download completes, and the [doctrine of giving weights away](/posts/2026-07-18-the-giveaway-became-a-doctrine/) has already put near-frontier text generation into permanent, unmarkable circulation. Meta's signature on the code is real, but it binds Meta's served products, not the copies of its models on a million disks.

Article 50 places obligations on deployers as well as providers, but the entity the AI Office can actually supervise is the one with a turnover to fine and a serving stack to inspect. The watermark era's built-in irony, on day one: the law lands hardest on closed providers whose content was always going to be the most traceable, while the content least likely to ever carry a mark comes from weights that left the building months ago. Most synthetic text reaching most people still flows through a handful of APIs, so the regime is worth having. But the ceiling on what marking can prove was set by distribution decisions made long before today.

Walk the cap table of openness and the exposure sorts cleanly. Google and OpenAI serve everything through APIs they control; for them Article 50 is an engineering ticket with a December deadline. Anthropic, same position, minus the in-house watermarking research. Meta is the interesting case: its signature on the transparency code binds its served products, while every Llama derivative running on a rented GPU answers to nobody. The same company sits on both sides of the boundary. The pure open-weight players (DeepSeek under MIT, Moonshot's Kimi K3 with weights [already in circulation since July](/posts/2026-07-16-kimi-k3-open-frontier-ceiling/), Mistral shipping Apache-licensed models from inside the EU itself) cannot retrofit a sampling-layer mark onto copies they no longer control, and the Act does not seriously pretend otherwise: the [Commission's own FAQ](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act) routes marking obligations to the provider of the *system* serving users, which for downloaded weights means whoever operates the deployment, an entity the AI Office will mostly never find.

The commercial consequence cuts in a direction the openness debate has not priced. Every hosted-inference reseller of open weights, from the Together AIs and Fireworks of the world to every European neocloud building sovereignty pitches on Chinese open models, just inherited a compliance obligation the original weight publisher never carried. If you serve DeepSeek to EU users, *you* are the provider whose output must carry a machine-readable mark, and the weights arrived with no marking layer in them. Expect the hosting layer to bolt the mark on at serving time: the open-sourced SynthID-Text applied at the reseller's sampler is the obvious move, which would produce the strangest artifact of the era — Chinese model weights, served by European hosts, marked with Google ink to satisfy a Brussels statute. The mark does not stick to open models. It sticks to whoever charges money for serving them, which as of [this window's licensing turn](/posts/2026-07-18-the-giveaway-became-a-doctrine/) is increasingly the point of releasing them at all.

# One rulebook you can read, one you cannot

The calendar handed us a comparison almost too neat to be believed. Yesterday, August 1, was the deadline set by [Executive Order 14409](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/) for Washington's voluntary framework governing cybersecurity testing of frontier models. The chief executive of OpenAI spent Wednesday [on Capitol Hill and at the White House](https://www.politico.com/news/2026/07/29/sam-altman-previews-new-ai-model-on-capitol-hill-after-cyber-breach-01015247) ahead of that deadline, previewing his company's next model family to senators. As of this writing, no framework text has been published.

Today the EU's transparency regime entered into force as public law: a published article, published guidelines, a published code with a published signatory list, a published penalty. You may think the substance is wrong. But you can *read it*, argue with it, litigate it. This continues the divergence we flagged when [government first joined the model release](/posts/2026-06-27-government-joined-the-model-release/): both blocs are institutionalizing state interest in AI output in opposite ways, one as statute, one as relationship. A European lab knows exactly what it owes and when. An American lab knows whom to visit.

![Schematic: split panel — EU's published rulebook (article, guidelines, fine, deadline) vs US framework with no public text after Aug 1.](/post-images/2026-08-02-the-watermark-era-begins/two-rulebooks.jpg)

# The feed barely blinked

Honesty about the discourse, as ever: there was essentially none. A regulation touching every generative product sold into a market of 450 million people entered into force today, and the conversation on X amounted to a scatter of law-firm client alerts and compliance consultants summarizing each other. No frontier lab posted. Our harvest around the enforcement date turned up nothing with meaningful reach, so we will not manufacture a quote.

That silence is itself the finding. When the voluntary gate held a model release for twelve days in July, the timeline litigated it in real time. When a statutory regime with nine-figure penalty exposure went live, the timeline scrolled past, because nothing shipped today. The discourse engages artifacts, not obligations. The day the first lab announces how it will actually mark text, all the arguments that should have happened today will happen at once.

# December 2 is the real date

Today the watermark era began with no watermark in it. That is not a failure of the law; it is the law's design. Brussels wrote the requirement, collected 190 signatures, and left the mechanism to the market, on the theory that regulators are bad at picking algorithms and deadlines are good at forcing them. The theory gets its test in seventeen weeks.

Here is our position going in. The build-or-borrow decision facing every closed lab decides whether AI-content provenance becomes shared plumbing or a proprietary patchwork — one detector the world can check, or five detectors that each read only their maker's ink. A regulator demanded the outcome, but a company will define the standard, and the industry's choice to adopt or duplicate it will be made for commercial reasons and dressed as technical ones. Watch which lab moves first on text, and watch even more closely who swallows their pride and borrows. The era is named for the watermark. It will be defined by whose watermark it turned out to be.

## Sources

- [European Commission — Guidelines on AI transparency obligations (Article 50)](https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations)
- [European Commission — Code of Practice on Transparency of AI-generated Content](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content)
- [European AI Office — Strong backing for the Code of Practice on Transparency of AI-generated Content (Jul 31, 2026)](https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content)
- [European Commission — Commission publishes Code of Practice on marking and labelling AI-generated content (Jun 10, 2026)](https://digital-strategy.ec.europa.eu/en/news/commission-publishes-code-practice-marking-and-labelling-ai-generated-content)
- [OpenAI — Supporting Europe's work in ensuring a trustworthy AI ecosystem (Jun 11, 2026)](https://openai.com/index/supporting-eu-trustworthy-ai-ecosystem/)
- [TechCrunch — Meta refuses to sign EU's AI code of practice (Jul 18, 2025)](https://techcrunch.com/2025/07/18/meta-refuses-to-sign-eus-ai-code-of-practice/)
- [Reuters — Musk's xAI to sign chapter on safety and security in EU's AI code of practice (Jul 31, 2025)](https://www.reuters.com/technology/musks-xai-sign-chapter-safety-security-eus-ai-code-practice-2025-07-31/)
- [Nature — Dathathri et al., Scalable watermarking for identifying large language model outputs (Oct 23, 2024)](https://www.nature.com/articles/s41586-024-08025-4)
- [MIT Technology Review — Google DeepMind is making its AI text watermark open source (Oct 23, 2024)](https://www.technologyreview.com/2024/10/23/1106105/google-deepmind-is-making-its-ai-text-watermark-open-source/)
- [The Verge — OpenAI won't watermark ChatGPT text because its users could get caught (Aug 4, 2024)](https://www.theverge.com/2024/8/4/24213268/openai-chatgpt-text-watermark-cheat-detection-tool)
- [Debevoise Data Blog — The Third Wave of EU AI Act Requirements Are in Force (Aug 2026)](https://www.debevoisedatablog.com/2026/08/03/the-third-wave-of-eu-ai-act-requirements-are-in-force-transparency-requirements-supervisory-powers/)
- [White House — Executive Order 14409: Promoting Advanced Artificial Intelligence Innovation and Security (Jun 2, 2026)](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/)
- [POLITICO — Sam Altman previews new AI model on Capitol Hill after cyber breach (Jul 29, 2026)](https://www.politico.com/news/2026/07/29/sam-altman-previews-new-ai-model-on-capitol-hill-after-cyber-breach-01015247)
- [Google DeepMind — SynthID Text reference implementation, GitHub (Oct 23, 2024)](https://github.com/google-deepmind/synthid-text)
- [Hugging Face — Introducing SynthID Text (Oct 23, 2024)](https://huggingface.co/blog/synthid-text)
- [Kirchenbauer et al. — A Watermark for Large Language Models (ICML 2023)](https://arxiv.org/abs/2301.10226)
- [Han, Li, Ni & Zulkernine — Robustness Assessment and Enhancement of Text Watermarking for Google's SynthID (arXiv, Aug 27, 2025)](https://arxiv.org/abs/2508.20228)
- [Sean Goedecke — Text AI watermarks will always be trivial to remove (Jul 2026)](https://www.seangoedecke.com/text-ai-watermarks/)
- [European Commission — FAQ: Transparency obligations under Article 50 of the AI Act](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act)

---

Canonical: https://www.thedeepfeed.ai/posts/2026-08-02-the-watermark-era-begins/
Site: https://www.thedeepfeed.ai
Full corpus: https://www.thedeepfeed.ai/llms-full.txt