25 comments

  • levocardia 45 minutes ago
    Crazy how a smart person like this fails to understand the gumbel softmax technique. It does not affect writing quality at all, provably. The very fact that there is generally no "best next token" with 100% certainty is precisely why the trick works (you cannot watermark a response to "respond with the To be or not to be soliloquy from the first folio Hamlet", for precisely this reason).
    • tapland 8 minutes ago
      Making blog posts about AI that make it apparent that the tech is going whoosh is a choice.
    • reader9274 15 minutes ago
      "Smart"? Have you read his writings in the last decade? It's all nonsense, which is why I stopped reading circa 2018
    • docjay 1 minute ago
      [dead]
    • selectively 6 minutes ago
      [dead]
    • RegardDetector 9 minutes ago
      >It does not affect writing quality at all

      >provably

      You cannot make this sh1t up n1gga

  • syrrim 1 hour ago
    > I want any LLM I use to choose the very best, most precise words at every single decision point.

    Then bad news: LLMs already use randomness in a fundamental way. Each time they go to generate a token, they first generate a probability distribution of possible tokens. Then they pick one randomly according to this distribution. The technique described can be thought of as making the random number generator pseudo random. The output it generates is one of the possible outputs it would have generated before, just now it's deterministic and will generate the same thing every time.

    • npilk 53 minutes ago
      I think this is a key reason why humans write better prose than LLMs - we can try to choose the best word every time, and go back and restructure sentences and paragraphs if we want.

      On the other hand, LLMs are forced into picking some likely-ish word, and then have to build the rest of their response to retcon that choice into making sense.

      Even good human writers would probably struggle with this constraint. It would be like someone interrupting your writing to tell you the next word MUST be such-and-such, and then you have to try and make it work as best you can first try, without going back to edit. The result would probably be a little clunky. (Maybe it’s impressive LLMs write as well as they do.)

      • mholm 27 minutes ago
        This was true in the ChatGPT era. Now we're in a world with reasoning tokens, where a model can thoroughly plan out the response it wants to make. If anything, it makes the style worse.
        • tomrod 9 minutes ago
          Isn't this just chain-of-thought though, doing the same thing multiple times without necessarily defining one path?
      • cush 20 minutes ago
        Models can easily do multiple passes
      • hyusap 30 minutes ago
        autoregressive generation doesn’t mean the model is myopic. the next-token distribution can already reflect a longer horizon plan for the output sequence.
      • scuppernong 42 minutes ago
        auto-oulipo
        • Alive-in-2025 30 minutes ago
          Today I learned a new word, "Oulipo". Interesting.

          But what about the general idea that they can watermark results to tell where they came from. The next step is tracking down which user got a result. I hate both of these things. Must everything we do be tracked? Next altering wikipedia results so they can tell who looked at the page or something?

          I'd like "the best answer" from an llm and don't want to be tracked, but this isn't for me, it is for them. I understand llm results are already using a varying statistical input so they aren't always the same. But I really hate watermarking and likely tracking too.

    • dragonwriter 1 hour ago
      That's inaccurate in two ways:

      (1) The behavior that is approximately what you describe is not "fundamental" (though it may not be something you can disable on some hosted providers), it is an option that is not fundamental (and with runtimes where you have full control can be either disabled or tuned in a large number of manners), and

      (2) The actual behavior that is approximately what you describe already usually involves use of PRNG (with a user or harness supplied seed), not a true RNG; the change to do watermarking isn't going from RNG to PRNG, it involves adding an additional set of constraints on token generation on top of the existing ones, which inherently compromises quality.

      • reliablereason 40 minutes ago
        (1) LLMs collapse and start outputting garbage after a number of tokens if you do not sample and just pick the "best token" each time. This is a consequence of how they are trained.
    • colmmacc 24 minutes ago
      I think the article is wrong on this but it's more subtle than that. Probability distributions have a peak; there is still a token with a peak probability. What's interesting about these techniques is that token by token it can actually make the peak token even more probable. A distribution doesn't have to be "flattened" to leave a watermark - it can be "amplified" and made "more peaky".
    • avaer 14 minutes ago
      That's missing the point. It's the distribution that's the "best", not the tokens. Then Anthropic comes in and makes the distribution something other than the best. The only saving grace is that Anthropic says it's not that bad.

      Even so, I don't think it will stop here. Once this is in place, the next step is to put more and more identification into the AI generated content; might as well pack it in, it's not that bad, and if it is they won't admit it. There's no way for anyone to check. And your argument will still be technically correct but missing the point.

  • Imnimo 11 minutes ago
    >I want any LLM I use to choose the very best, most precise words at every single decision point.

    Does the author think he is currently getting T=0 output from Claude? Is he under the impression that T=0 produces the "best" writing?

    This entire article just seems so detached from the basics of how LLMs work.

  • smallerize 1 hour ago
    Translation: No one can ever again use Claude for proofreading their own prose unless they’re willing to risk that the whole thing might be flagged as having been generated by Claude.

    I think that was intended, yes.

    • epihelix 12 minutes ago
      You know, back in the era when proofreaders were human, I never one met a proofreader who rewrote my text afresh, rather than annotating the text with a pen.

      It's still possible to use Claude to proofread - highlight grammatical, flow, structure, logic errors and make simple suggestions for you to pick and choose or adapt as you wish. No watermarking will flag your text. No flaw accusations of LLM authorship will haunt you. All will be fine.

      But if you want an LLM to rewrite your text, that's (a) not proofreading, and (b) should be flagged as LLM generated ... because it is.

    • demetrius 54 minutes ago
      I'm not sure the quoted statement is true. Proofreading like "point to problems in the text", if you fix the problems yourself and don't copy-paste the solutions given to you, should still be safe, shouldn't it? So, human-written text should not be falsely flagged if you use LLM for proofreading.

      And if you copy-paste the answers from LLM, I think it's only fair the end result gets flagged. You're not writing it yourself.

    • skew-aberration 24 minutes ago
      Can't the LLM just generate e.g diffs? Or some other intermediate language. Then the watermark is lost when the translation step is applied.
    • jleyank 45 minutes ago
      Rands made this point a few days ago as I recall. Worries about having his tool corrupt his writing during editing, etc.
    • ButlerianJihad 1 hour ago
      It is quite just, if you think about it. Human works are copyrighted and protected at the moment of creation. All rights reserved. Yet, LLM outputs are uncopyrightable. Therefore, if Claude or any AI has processed my copyrighted work, the end result is uncopyrightable and in the Public Domain. The public has a right to know: is this a human copyrighted work, an LLM PD work, or is the human falsely claiming authorship in order to retain copyright?

      A point of confusion for me, however: is every watermark unique? Is every algorithm for watermarking going to vary amongst models and amongst model versions? Will each model publisher keep this watermarking as a trade secret, that they alone can detect? If so, this can't scale! How do you detect "JoeBob 4.3 LLM" output? By querying every single model's watermark-detector? And if they all work by re-running the model and using tokens anew? That is extraordinarily wasteful.

      If a watermark is not self-evident, or universally detectable, then it is no good. Take, for example, US currency. The security measures are published and well known. Any count-out room in retail has a big poster indicating how you can detect authentic US bills. Nobody has to accept non-US currency in the US, and so the only authenticity you need to worry about is your US bills alone. LLM watermarking has none of this in common. Currently sounding like a shitshow, if you ask me.

      • dare944 37 minutes ago
        As I understand it, the current watermarking methods rely on a secret key, making the detection schemes a black box to anyone not in possession of the key. This means organizations like Anthropic are free to make any claim about authorship they want, true or not, and no one can call them on it.
      • fwipsy 1 hour ago
        Perhaps LLM outputs are uncopyrightable, but derivative works of copyrighted works are not automatically in the public domain.
        • ButlerianJihad 48 minutes ago
          That's an intriguing twist, isn't it? It could lead to a tug-of-war.

          Working backwards: if it is possible to confirm 100% confidence that a chunk of text is LLM output, then it is "PD until proven otherwise". How can a human reliably assert human authorship of their source text? When all watermark tests fail? Is that proof of humanity now?

          If a human proves human authorship, and LLM watermarking tests positive, then is that going to be considered a "derivative work" or not? What if there is an applicable license for the source work, such as "CC-BY-ND" that prohibits derivative works?

          This has not been court-tested, and I expect that it will need testing at that level before we can have any assurances.

  • pibaker 3 minutes ago
    I think it's pretty dishonest of Anthropic to frame their watermark as EU regulation compliance. The EU regulation, from my understanding, requires AI content to be labeled for human viewers. In the meanwhile the Anthropic new release on the watermark says this.

    > The difference between watermarked and un-watermarked text will not be distinguishable to readers

    https://www.anthropic.com/news/claude-text-watermark

    Which is to say, it does not actually meet the EU AI act requirements which require transparency to humans. Not to mention that if the detection requires access to the base models, it makes anthropic the only entity who gets the say on if a piece of text comes out of Claude. Anthropic is both the player and the referee here.

    If there is one takeaway you should have from this fiasco it is that you should be wary of using tools that doesn't serve your needs and your needs only.

  • aselimov3 1 hour ago
    This article feels slightly incoherent. You want high quality precise writing and to use an LLM to generate it? Feels like those are diametrically opposed
  • Planktonne 4 minutes ago
    There is no coherent position in which the watermarking is a perversion of writing but AI writing as a whole is not a worse one.
  • bushido 1 hour ago
    This is not meant to be snarky, But almost any writing done by Claude is a perversion of writing.

    I honestly can't stand the way Claude writes. This watermark change just makes it scarier.

    • _kulang 35 minutes ago
      I moved to Sol for my writing and it is so so much better. But it makes more mistakes. I think they have different ideas of product but it seems OpenAI is going to follow Anthropic’s lead over the next year. I think I am going to put more effort into my writing skills to remove myself from this awful situation
  • codedokode 3 minutes ago
    Watermarks are garbage because they may embed account id, IP address and deanonimize you. That's why we should be using open-weights LLM whenever possible.
  • arjie 48 minutes ago
    It seems fine. I use an LLM to argue with me prior to posting blog posts so that I don't post obvious incorrectness, but the UX element to it is that it constructs notes about various sections of the text and we talk about those. There's no way for the generated text to enter the blog unless I copy-paste it and I'm not going to do that because the entire point is for me to write it.

    At the point that you're generating entire volumes of text from Claude you're not really trying to be a sophisticated writer. I don't see how it's going to hurt for it to choose random related words.

  • capitalsigma 37 minutes ago
    > I chose to depend on a private company to express my own thoughts and now I'm mad that I'm not in control of the output

    Who could have seen this coming???

  • walrus01 1 hour ago
    > I want any LLM I use to choose the very best, most precise words at every single decision point.

    Try running an llm like qwen 3.8 27B in Q8 locally with an intentionally very low temperature setting, it will write like a caveman crossed with a robot. You may find that an extremely literal output does not look pleasant to read for humans.

    • LoganDark 24 minutes ago
      That is not what that means. Generally, precise word choice requires more than autocomplete. Larger models simulate this with hidden layers.
      • walrus01 21 minutes ago
        Excessively precise word choice does not result in something that looks like content written by, or palatable to humans. It looks like you gave a high school 12 grade student a science paper and told them to apply a thesaurus to at least one word in every sentence and replace it with something else.
        • LoganDark 1 minute ago
          There is a difference between precise word choice and concise word choice. You can be precisely accessible the same as you can be concisely terse.
  • nomel 1 hour ago
    > The provider must mandate in their terms-of-service that users not remove the watermarking.

    So, you don't own the generated text, and can't use it freely then. What if I copy paste a section, or rewrite a section of text to my liking? What if I rewrite some lines of code that contains the mark?

    Security theater, and vague enough to be used as a weapon against who the government wishes.

    I hope it's left off for non-EU customers.

  • stabbles 52 minutes ago
    Claude's writing was already easy to recognize. The fact that Anthropic complied without complaint makes me wonder if they already watermark their outputs and used the opportunity to create goodwill. Presumably they want to avoid training their new model on text generated by the previous model, so they have reasons to be able to recognize AI-generated text.
  • lemarchr 37 minutes ago
    Some here are arguing that mechanisms used by LLM providers already derail the goal of "the very best, most precise words at every single decision point", therefore the author is misguided.

    The author has expressed a preference. Assume that there is a sequence of tokens, such that it is considered the absolute best by the author. This particular method of watermarking makes it less likely to generate that sequence, by definition.

    I feel their argument would have been clearer and stronger if they had spent more time exploring the alternatives, and whether these alternatives would be just as effective. It is trivially easy to remove invisible tokens.

    Like it or not, there is a public good to being able to identify AI generated content, and a small degredation in quality is tolerable in my opinion.

    I don't think anybody has to worry about this issue though. Manual writing, coding, and proof reading continues to be an option. Where AI output is nothing to be ashamed of, the tools are available. For everyone else, there will be LLM providers that ignore EU law.

    • capitalsigma 35 minutes ago
      If the author has preferences on their "own writing" that conflict with Anthropic's, then they should actually write it themselves rather than paying Anthropic to do it. Private companies don't owe you anything, even less so when they're beholden to laws in foreign jurisdictions.
    • Barrin92 29 minutes ago
      >Assume that there is a sequence of tokens, such that it is considered the absolute best by the author

      You can't assume that because if that was the case he'd already know what sentence to write, because that's what that means.

      The notion of a best sentence requires a final cause, an end to write to. By their very nature that's not how LLMs work, so you can't 'degrade' them on that front. They can't lose a property they didn't have.

  • DarkmSparks 24 minutes ago
    I dont see how there would be remotely enough entropy in most model outputs for this to be close to feasible with any kind of accuracy.

    Either they false positve on pretty much everything ever written, or the chances of catching a true positive is so low as to be useless.

    Basically Cinavia for text, and that often falls over and is easy to remove even when there is megabytes of data streaming over a long period of time rather than 2 or 3 bits per wall of text, let alone what most people use claude for, when there is a strict dictionary and other tight output constraints.

  • etchalon 2 minutes ago
    The objection seems to be that Claude will always write worse prose than a human writer, even if the writing Claude generates is understandable.

    Yeah, John. We're all OK with that.

  • 4d4m 34 minutes ago
    Reminder: your favorite distilled model does not treat you, the customer, as an adversary and mess with your output.... May the free market win.
  • chrisjj 1 hour ago
    > the only acceptable answer for why an LLM should choose bananas instead of pineapple (or coconut, or guava, or papaya...) is that it has determined that it’s the best fit for the intended meaning, tone, and sentiment of the text.

    It already fails. It randomly picks between close candidates. To help fool people into believing in intelligence claim, I guess.

  • andy99 1 hour ago
    I don’t understand how this works for anything but prose. Is that the point? In any code or structured output, there just isn’t the flexibility, and depending on how the user requests the output be constrained there is even less (“answer only True or False”). So is it just chat responses? If I ask the API to tell me a story about Alice and Bob then it watermarks it, but when I ask it some implausibly constrained thing like write a story about Alice and Bob with each word starting in rotation with the letters alicebob, does it try to do so and hope there are roughly équiprobable tokens regularly?
    • smallerize 1 hour ago
      • andy99 1 hour ago
        I should have read that, it’s actually quite reasonable and I don’t really understand the objections in TFA having read it.

        > One of my fundamental problem with this is that no two synonyms carry the exact same meaning. “He leaped at the chance” and “He jumped at the opportunity” are very similar sentences expressing the same general sentiment, but they are not the same. The exact words we choose when writing matter.

        Doesn’t make sense at all in light of the actual approach, they’re just choosing a different RNG. It’s not like they’re corrupting it by flipping words.

        Should add I don’t support the watermarking and requiring it is idiotic.

        • krackers 1 hour ago
          I don't understand Gruber's points either, I wonder if there is some fundamental technical misunderstanding. Does he think that the logits should be sampled from in a "pure" manner without introducing any other bias? Does he know that there's already a sampling temperature, and that most providers have probably moved on to sampling strategies other than top-k? Does he know that the word choices have already been altered irreversibly during RLHF which is how you get the obvious Claudism like "load bearing" and "seams"?

          Perhaps it would be useful to publish examples of samples with/without watermark. I'd suspect that the variability from simply sampling repeated times would dwarf any semantic differences you'd detect with the watermark.

        • smallerize 45 minutes ago
          I think Anthropic should have put all the info into one blog post. Splitting it up is really confusing people.
    • chrisjj 1 hour ago
      > In any code or structured output, there just isn’t the flexibility

      Variable name perversion incoming...

  • LoganDark 22 minutes ago
    I keep seeing an irritating misconception in this space, which is that the alternatives chosen by these algorithms are supposed to mean the same things as what they're displacing. That's not true, and not how LLM generation works. Complaints that two different choices don't mean the same thing miss the entire point.
  • Finnucane 45 minutes ago
    "Anthropic's . . . Claude is a Perversion of Writing."

    FITFY.

    I have no sympathy for writers whining about what the AI is doing to 'their' writing. It's only your writing when you write it. There's any easy way to avoid this: don't fucking use it. Use you own brain.

  • nian2326076 59 minutes ago
    [flagged]
  • herf 28 minutes ago
    Not telling someone you used AI is a perversion of writing. Also agree that an AI proofreader should not claim authorship, but in most other cases, the AI is not reading your mind, it's only watermarking its own usage, and we kind of need more of that.
  • jeffgreco 22 minutes ago
    Gruber has a ridiculous knee-jerk response to anything the EU does, so hardly a surprise he didn't come to the table with a sober facts-based response.