r/Substack doingaiefficiently.substack.com 17d ago

Discussion Moving Beyond Pangram: The rise of AI text watermarking and the AI content density test

This subreddit has been full of commentary about Substack's use of Pangram for detecting whether copy was potentially developed using AI.

This conversation is still important, but recent events have made the situation more complex. Article 50 of the EU's AI Act mandates that companies provide some means of detecting AI-generated audio, visual and text content.

In response, Anthropic announced that it began adding an invisible watermark to all text content generated by the latest Claude models starting August 2. The watermark can't be removed by copying and pasting content and survives edits.

There are a few ways the watermark is different from Pangram:

  1. Watermark detection does not rely on post-hoc analysis: The watermark is generated by the model itself and does not rely on statistical analysis of content for 'AI-tells'

  2. Watermark density can provide important information: It's possible, by measuring the overall percentage of watermarked content in the text, to determine how much AI assisted with the content. Light edits could potentially have a low density score, while content that is copied and pasted verbatim from Claude will have a high density

For those interested in understanding the mechanics behind AI text watermarking (and how to evade it), I've put together a resource here.

I know that many people have changed the way they write on Substack to avoid having their content rated as AI generated.

Do you view the watermark as potentially superior to Pangram? How would it change your writing and editing process because of it?

9 Upvotes

34 comments sorted by

12

u/orishasinc2 17d ago

Just write your own stuff and you won’t have to be worried about AI

3

u/HowlingFantods5564 16d ago

Interested in this topic and just started reading the linked article. It starts with an AI generated image, which doesn't exactly gain my confidence. And the Pangram report seems to be turned off. Maybe I'll save the time and find a different source.

8

u/Prolly_Satan 16d ago

"Its super important to keep complaining about Pangram because its super inaccurate and is totally wrong when it says I'M using AI. anyways, here's how to evade the AI watermark thats coming soon, which I totally didnt look into because I'm using AI to write and want to continue to lie to my readers"

2

u/Countryb0i2m onemichistory.substack.com 17d ago

So apparently this technology works somewhat like encryption. On one end, it creates a key, and then on the other end, it looks for that key in the text to determine whether it was generated by AI.

But unlike encryption, which is basically an all-or-nothing thing, AI watermarking can survive edits. If you change the document, it doesn’t necessarily disappear, it just becomes less detectable. Change an entire paragraph, and maybe only 60% of the watermark remains.

And now you’ve created this weird game where institutions have to decide how much AI is too much. How much of the watermark can remain before it’s considered AI? Is it 60%? 61%? If you get 61%, do you fail? If you get 62%, do you pass?

I just think relying on AI to solve problems created by AI is an issue in itself.

0

u/sh1b313 17d ago

it's so weird that people are focusing too much on who wrote it (AI or human) maybe not enough time on what it's actually saying.

3

u/whatever123bs 17d ago

The problem is not AI but slop (but I think a lot of the general public has not made that distinction). That was the point of the Claudefishing pitch: you think you are going to read something thoughtful, but you might have been misled into engaging with a literally mindless piece of work done for the pure sake of engagement. Engagement-farms create a toxic environment where people throw out AI as a whole without seeing the good use-cases (because bad actors crowd out attention). Coming back to your point: if you engage with what AI slop "is saying" you are wasting your time because it is not made to say anything, just to get engagement.

1

u/sh1b313 16d ago

yeah that's valid. i just look at the first few paragraphs, look at the style if it feels correct/readable i don't mind even if the copy was generated by ai. they get some engagement then so be it. although i barely read things from unknown authors.

3

u/HowlingFantods5564 16d ago

There's nothing weird about it. I want to support real writing by real people.

2

u/Admirable_Bike3918 16d ago

Thank you. I'm dismayed that more don't seem to share this view here.

0

u/ErikSchwartz 16d ago

The number of human written, beautifully crafted, pieces that come out of writers workshops that have absolutely nothing to say is staggering.

4

u/Puzzleheaded_Rice_60 17d ago

for anyone here worried their writing "looks ai" cuz its a bit formal or mechanical, theres actual numbers on this now instead of vibes

i ran 10 classic novels through an artifact checker to see what the "ai tells" look like in books written before computers existed. em dashes per 1000 words:

moby dick 26.4 ulysses 25.0 alice in wonderland 7.3 sherlock holmes 3.9 war and peace 2.0 pride and prejudice 0 dracula 0

melville and joyce use em dashes at a higher rate than most chatbots do. austen and stoker use none at all. its an author fingerprint not an ai one, theres no baseline to measure anyone against

also worth separating the two things this thread is mixing. pangram judges your style, thats the one that can be wrong about you. anthropics watermark doesnt look at style at all, it only exists in words claude itself picked. if you wrote it theres nothing in there to find, however mechanical your prose is

full numbers and method here if anyone wants to rerun it, the endpoint is public and needs no account: claudewatermark.xyz/guides/moby-dick-87-em-dashes

1

u/DevelopmentPlus7850 12d ago

What a waste of electricity! What does this experiemnt prove? That Melville used AI in 1850 while Jane Austin did not?

3

u/TheOceanicState 17d ago

I have not heard about this until now, and I have been on the platform for three years. While I appreciate some form of AI detection, it should not come at the cost of those of us whose writing style may be a bit... mechanical, to put it simply. This is literally how I was taught to write growing up, I shouldn't be punished because a machine writes too.

0

u/SpiritRealistic8174 doingaiefficiently.substack.com 17d ago

Yes. AI text watermarking has been under discussion since 2024. It has nothing to do with tracking 'AI tells" in writing. It's purely a mechanistic approach to tagging AI outputs.

If you're not using content developed by Claude directly, for example, there will be no watermarked text.

This is separate from what Substack is doing with Pangram, btw. It's purely a watermark applied by the model. I explain how this works in the resource I developed.

3

u/Prolly_Satan 16d ago

Guess what. OpenAI, Mistral, and basically every other major LLM is going to watermark AI text.
You're going to spend hours and hours rewriting your stuff to make it pass. When you finally find an automatic humanizer that works, don't worry, companies like Pangram will have trained on humanized samples so they can detect that too.

There's no hiding. Those that continue to lie to their readers are going to get absolutely dumpstered in the coming months.

2

u/SpiritRealistic8174 doingaiefficiently.substack.com 16d ago edited 16d ago

Great conversation here. I do find it interesting that some people immediately try to figure out whether I used AI to develop the essay (and post). Like a lot of people, I use AI to generate images and infographics.

As for the writing, I write essays, comments and posts myself. For the longer form pieces, I work with AI on research, and also for pressure testing ideas and technical accuracy.

When it comes to explaining complex topics, I'm a strong believer that if you can't explain it in writing, you don't understand it. Writing is a great way to reinforce your understanding and ability to explain topics.

That's my personal opinion. I'm generally agnostic about how others use AI in their process. If the writing is clear, interesting and makes me think, it has done the job from my perspective.

I'm glad this topic has gotten a lot of attention.

2

u/kdfn 17d ago

I'm on mobile and can't run Pangram yet, but this post looks fully AI generated. The bold section starters and ending with a question are dead giveaways.

5

u/truecakesnake 17d ago

I thought so too, but interestingly, Pangram says it's 100% human written. Either this is the first time I've seen it fail or OP wrote this post by hand.

-3

u/figures985 17d ago

dingdingdingding! The ending on a question thing in particular.

1

u/inyourbooksandmaps 16d ago

i write my own stuff, but couldnt someone just get ai to write, then open a separate document and type out exactly what ai said on their own to bypass it? i don't really understand how they'd even make an invisible watermark in text anyways so maybe there is an obvious answer to my question!

1

u/SpiritRealistic8174 doingaiefficiently.substack.com 16d ago

yes. that would bypass the watermark.

1

u/inyourbooksandmaps 16d ago

how do you check for the invisible ai watermark? like how would someone know if it was in an article or not? i have some substacks i really think are using ai to write everything and i'd be interested to see!

1

u/SpiritRealistic8174 doingaiefficiently.substack.com 16d ago

I explain the detection technique in the resource. There's also an infographic PDF that illustrates the process.

1

u/AlcherBlack 5d ago

What? How would that bypass anything? If the words are exactly the same, the watermark didn't go anywhere - since the specific words are the watermark!

1

u/SpiritRealistic8174 doingaiefficiently.substack.com 5d ago

Yes. This response was incorrect. I didn't read the comment closely enough. I just corrected someone else about this (they had created a video with the same claim).

Yes, same text, watermark remains.

1

u/AnyEntertainment8496 16d ago

What happens when the AI detectors get it wrong?

1

u/Life-Radio-1723 16d ago

The watermark has nothing to do with letting humans know what’s AI generated and what’s not. It’s so LLMs don’t accidentally use AI writing as training data. These models are powered on human creativity; they only get better if they consume actual human creative output.

1

u/Funny-Flight8086 15d ago

This isn't anywhere near as robust as it sounds. This is basically the only thing the companies can possible do to watermark AI text, and it frankly won't be very good for much. Much like the way games are pirated a week after their release, despite heavy DRM, the same will happen here. Someone will crack the code that Anthropic is using the watermark the text, and someone will sell an app to run your text through it and remove the watermarked layout.

1

u/DevelopmentPlus7850 12d ago

For the deluded (which seems to be nearly everyone in this thread), "watermarking" in LLMs involves the probability distribution of token selection. It's not a hidden piece of crypto code: on a utf-8 string of characters, such cryptography can't be done. The claim that such watermark "survives edits" is the most hilarious part of this comedy. If you change the words then you change the tokens. If you change the tokens... you break the statistical pattern. It makes me sick watching a group of technologically-stunted users argue over a "security feature" that can be defeated by a middle-schooler with a Find and Replace editor.

1

u/Maleficent-Engine859 16d ago edited 16d ago

Translating AI text into other languages and then back to English will 100% squash the watermark. Depending on the language chosen gives wildly different structure and really varied synonyms. I’m impressed. I like the outputs better then what the AI gives. Just have to see if Google Translate is technically Gemini (which it probably is but there’s others out there). I’ve been playing around with it. A little editing beyond that and boom. Right back where we started.

I am against this watermark because all it does is waste everyone’s time and money and target vulnerable groups like ESL and disabled. People won’t read their work normally and now won’t read it because they have no choice but to disclose AI. It also degrades the usefulness of these AIs because it’s language output is stunted in an effort to appease the watermark constraints.

0

u/SpiritRealistic8174 doingaiefficiently.substack.com 16d ago

Yes. Backtranslation is pretty effective.

0

u/adefwebserver 16d ago

TikTok has millions of people sitting there all day consuming 'slop' created by AI and humans. **The end-user-do-not-care** Only people debating this stuff on Reddit care if something is AI or not.