Statistical versus character watermarks
Almost every confused claim about AI watermarking comes from treating these two as the same thing. They share a name and nothing else: not the mechanism, not the survivability, not who can detect them.
Character-level marking
The idea is straightforward: insert invisible characters into the output in a pattern that encodes information. Zero-width spaces and zero-width non-joiners give you a binary alphabet; tag characters give you a full invisible ASCII. A hidden identifier can be encoded in a few dozen characters that render as absolutely nothing.
It has one decisive property: it does not survive contact with reality. A single regular expression removes every zero-width character in a document. Pasting through a plain text field strips them. Retyping strips them. So does any normalisation step in any pipeline the text passes through.
This is why no serious provider uses character-level marking as a watermark, and why the belief that they do is so persistent, invisible characters really are present in text people copy out of chat interfaces. They are just there for an entirely different reason.
Where the characters actually come from. Rendered typography. A chat interface lays out its answer with non-breaking spaces, thin spaces and occasional zero-width break opportunities, exactly as any well-typeset web page does. Copying the rendered text copies the typography. The hidden characters guide covers every source.
Statistical marking
The other approach never adds anything. It changes which of several acceptable words the model picks.
At each position, a language model produces a probability distribution over the next token and samples from it. Usually several continuations are all perfectly good. A statistical watermark uses a secret key to derive a pseudorandom score for each candidate, then biases sampling toward higher-scoring candidates, by a margin small enough that output quality does not visibly change, because every word chosen was already a word the model was willing to choose.
No single word is evidence of anything. Across a few hundred tokens, though, the average score of the words actually selected sits measurably above chance. A detector with the key computes that average and returns a confidence.
Side by side
| Character-level | Statistical | |
|---|---|---|
| What carries the mark | Extra characters added to the text | Which words were chosen |
| Visible to inspection | Yes, with any hex dump or checker | No, not even in principle without the key |
| Survives copy and paste | Sometimes | Yes |
| Survives cleaning | No | Yes, completely unaffected |
| Survives paraphrasing | Not applicable | Degrades gradually as words change |
| Who can detect it | Anyone | Only the key holder |
| Works on short text | Yes | Poorly; needs enough token decisions |
| Deployed by major providers | No | Yes, Google's SynthID for Gemini, and Anthropic's confirmed mark for newer Claude models |
Three consequences worth internalising
A clean checker result says nothing about watermarking. Running text through the checker and finding no hidden characters tells you the text has no hidden characters. Statistical marks are invisible to that check by construction, and always will be.
Nobody can offer you third-party detection. Statistical detection requires the key, and the key stays with the provider. Any site claiming to detect Google's SynthID or Claude's watermark in your browser is doing something else, usually a style-based classifier, which produces false positives on ordinary human writing at rates that make it unsafe for consequential decisions.
Cleaning and rewriting are different operations. A cleaner removes characters and leaves every word in place; that is precisely why it cannot affect a statistical mark. Only changing the words changes the token choices. This site does not rewrite text and is not built to.
Why entropy is the real constraint
Statistical watermarking needs choice to work with. Where the model has essentially no freedom, a direct quotation, a mathematical expression, a well-known list, a very short answer, there is nothing to bias, and those spans carry little or no signal.
This is not an implementation weakness; it falls straight out of the mechanism. It explains why detection confidence is reported as a score over a passage rather than a yes or no over a sentence, and why a one-line reply is effectively unmarkable no matter how carefully the scheme is designed.
Where to go next
- Claude's confirmed watermark - what Anthropic announced in August 2026 and which models it covers.
- Gemini and SynthID - the same class, across four modalities.
- C2PA explained - the third mechanism, which is metadata rather than either of these.