
Briefing Chat: Anthropic rolls out new AI watermark — will it make a difference?
August 14, 202616 min · 3,423 words
Show notes
In this episode: 00:29 What does Anthropic’s new watermark mean for research? Nature: Can Anthropic’s invisible watermarks curb ‘AI slop’? Researchers remain sceptical 10:57 Ticklishness is a distinct, specialized body sensation, research finds Nature: Where are you ticklish? Researchers map the sensation across cultures
Highlighted moments
So Anthropic, which of course makes the model Claude, that many people use, has announced that for future versions of the model that come out after the 2nd of August, they will have an invisibly embedded watermark.
“And in essence, they use an algorithm that will tweak the selection of the words in such a way that some words are going to, for that particular sequence, be more likely to be picked than others.”
“How useful a watermark will be to tackle that problem is not clear. Partly because as I say, like, what are people using Claude for? You know, maybe they have done something very original, very human, but it's a bit long. And so they get Claude to rewrite it in a shorter format.”
“now, this article is talking about gargalesis. Okay, now this is the type of tickling that's associated with play, like being tickled.”
Transcript
Watermarking AI text
0:00Hi listeners, Benjamin here. Welcome to the Friday show where we talk about a couple of stories that have been in the Nature Briefing, which is of course Nature's daily email roundup of the latest science news. Here with me today is Lizzie Gibney. Lizzie, how are you doing? Hello, Ben. I'm good. Thank you. We've just been yabbering about how much we enjoyed the eclipse. Oh, I enjoyed the eclipse so much. My colander got a lot of action, I tell you what. Right. Well, you've got a story that couldn't be more different today to start off with, and it's about AI and AI-generated text. Now, we live in a world, of course, where
0:34this is becoming a lot more prevalent, certainly in academia as well. Evidence suggests that it's getting used more and more. And there's often a question that people have like, oh, is this just AI-generated? And it can be quite hard to tell, but there may be ways to do so, and that's what you've been looking at. Yes, absolutely. So Anthropic, which of course makes the model Claude, that many people use, has announced that for future versions of the model that come out after the 2nd of August, they will have an invisibly embedded watermark. So that is
1:05something that doesn't affect the actual quality of the text, like the user will not notice this at all. But it's effectively constructed in such a way that, at least for now, Anthropic, and potentially in the future, anybody can tell if that was made by Claude or not. Right. So an invisible watermark, I'm going to guess, given our discussions on AI in the past, this is going to be statistics-based. Absolutely. So we don't know the exact details of how they did this, but we do know the details of how Google created its synth ID. They actually published a paper about it and made it open for
1:37anyone to use. And I am almost certain this is something very similar. So, I mean, with text, you don't have that many variables anyway. You can change, right? So it all comes down to word choice. And in essence, they use an algorithm that will tweak the selection of the words in such a way that some words are going to, for that particular sequence, be more likely to be picked than others. You can then reverse engineer that from the text and see if there's this statistically observable kind of trace of that algorithm left in the word choice. And it is pretty reliable in terms of it can
2:08tell you, OK, this was generated by Claude. But I suppose there are lots of things that we'll talk about where it's not reliable in terms of, well, what does that mean? You know, what exactly did you use Claude for? That it can't say. Well, you've read my mind. We certainly will talk about that. But let's talk about why this is being done. So Anthropic and Claude then, and you mentioned Google too, there are reasons that they're introducing these things. Absolutely. So this is quite a hard and fast reason, which is that the European Union demands it. So the EU AI Act, which was drafted two years ago, but has become enforceable now. So fines can be
2:38enforced from the 2nd of August. They say that it should be possible for people to know if something was generated by AI. And when it comes to text, that means a watermark like this. So the companies are all trying to comply with the EU, basically. Google, as I say, have this synth ID, and they've actually been using it for a few years now. But no one would necessarily know or bat an eyelid because there's no way of the general public to be able to detect it. So Google themselves will know. But as anybody else, you know, the general public or user, you would not know. They have
3:09means to do that for images and audio. And OpenAI actually uses synth ID from Google as well. So for video images and audio, that is possible. But for text, it's not yet. Okay. So the difference then is that they can know if it's been made by a robot, but with the Claude version that you potentially, as a user, could identify if something's AI. Yes, they have not yet created that, but they said they are working on it. So they've signaled their intention to do that, to make some kind of tool, which again, is what the law asks for. So presumably, the others will have to follow suit. And let's talk about, I guess, why this is important. I think I said at the start there,
3:42it's getting harder to know what is AI and what isn't in many cases. And I'm guessing that is ultimately the reason why. Yeah, there's a simple question of transparency. There are some circumstances where AI use has caused problems in science in particular. You know, it is now so incredibly easy to get an AI model to write you a paper from scratch that we know that journals, conferences, preprint repositories are all absolutely flooded with papers, many of them written by single authors. And that is a weight that the system is really, really straining under. How useful a watermark
4:17will be to tackle that problem is not clear. Partly because as I say, like, what are people using Claude for? You know, maybe they have done something very original, very human, but it's a bit long. And so they get Claude to rewrite it in a shorter format. Maybe they're using Claude for translation. And maybe, again, it's completely original ideas in one language, but when it gets translated, it gets left with this watermark. Those things are coming to be something that, as a community, we generally think are okay. I mean, as a news reporter, literally none of my words can ever be written by AI.
4:48Same here, of course. But there are many, many areas of work where it is acceptable. And here it just kind of slightly muddies things, really, because, as I say, you know, it might be that Claude wrote something from scratch and it's not your original idea, but we don't know that either. Yeah. So there are potentially shades of grey, but hypothetically speaking, if one were to try and circumvent this, I would imagine that if I got my AI to write something from start to finish, I then put it through another AI to say, change this enough, but keep kind of the meaning
5:21the same, that would potentially erase said watermark? Well, this is the other big issue. Yes. How motivated are you to not be detected? Because it's all down to word choice, you change the exact words that are there and the watermark goes away. So Anthropic has said it will survive, like, you know, copy and paste is absolutely fine because the word choice is the same. It will survive some editing, but I would say a heavy editing paraphrasing, certainly using another model that doesn't have a watermark to rewrite it, then your watermark just completely evaporates. And then the question is there again, like,
5:54maybe if some people are just churning out papers, maybe they won't care about that. Maybe they'll leave the watermark. I cite in the story, the case of a conference, the International Conference on Machine Learning, ICML this year, that had a stream of peer review that was strictly no AI use. So they had two options. You can use AI in some ways, or there's one that people have requested where reviews must absolutely not use AI. And they put their own kind of version of a watermark into the papers that they gave out for review so that if people then did do what
6:26they weren't supposed to do and use AI, it would come up with these telltale phrases they could detect on the other side. Even though this was like really well advertised, they were going to do it. The papers about the methods were all out there. Like it was quite broadly known that this was something they were going to do. More than 500 people still were found to have cheated this system, because they just didn't see the, I don't know, laziness or what, but they didn't get rid of this watermark that would have been very easy to get rid of. And so they were shown that they had used AI where they were not supposed to. So I guess that shows two things. One is that maybe watermarks will be useful in these quite strict scenarios where the rule
7:00is literally no AI allowed, which I would say is becoming a lot smaller, that category. And that even though, yes, it's very easy to get rid of the watermark, that doesn't mean people are always going to do it. What do we think about where this might go? We now have two companies who either have text watermarking or are introducing text watermarking. Obviously, there is some laws now that say companies have to do this. Do we expect the other AI producers to follow suit? It's very difficult to know. The onus on compliance is going to be on those big companies. So that's
7:31probably who the EU would go after first. But it could create this kind of standard, I suppose, where everybody is expected to do it. It is quite onerous to do also like to add that layer. If you think about it, every time it generates some text, it not only has to do the job of like, okay, what's it going to say? And then it then has to add in this quite complex algorithmic element about precise word choice. Compute more. Absolutely. And for some people, that is not going to be worth their while. Open models. Also,
8:02people can make their own versions of, you can distill a model and in your version, add no watermark. They're always going to be available. I'm sure for people to use, maybe they're not going to be absolutely at the frontier, but they will be available. But you know, even in a world where just the most used models have a watermark, even if that watermark can be gotten rid of, I think it feels like a broadly positive measure towards transparency. One thing we have covered on the podcast is the future of education, which obviously is a huge topic, but how students are engaging with this brave new world of AI and content creation and
8:39essay writing, this sort of thing. I guess educators might be interested in this. Absolutely. So I spoke to a few people for the story and the broad feeling was that given the limitations of the watermark, exactly as we talked about, you don't really know how that person engaged with AI and what ways they used it. There's a big worry that the very fact that there is a watermark out there might end up being used as some kind of automated measure or binary measure of like, this is good, this is bad by universities. And that's probably not a good
9:10idea, not least because the ones who are probably most motivated to cheat might also be the ones most likely to get rid of the watermark, right? If they're going to do that in the first place, they might go the extra way and raise the signs of it. And so the feedback that I had was like a kind of real like begging of universities really like to not use the fact that this tool exists as their gauge by which to judge cheating in university or inappropriate use of AI, because it really just does not tell you that. It's all about nuance. It's hugely about nuance. One thing that I guess I wonder, a few times we've talked about how AI is doing research or is moving towards doing original
9:46research. It may not be there yet. In that instance, knowing that an AI has done something, maybe is one of these situations where having a watermark kind of doesn't matter, right? Totally. So Paul Ginsberg, who was one of the founders of the archive, the big famous preprint repository, he said to me like, watermarking is kind of fighting last year's battle. So last year's battle was we had all this AI slop that was being generated, no one knew what to do with it. And okay, maybe that still exists. But increasingly, AI is being used in cutting edge research, you know, as you say, not necessarily on its own, but as part of the process, especially in some fields like
10:19mathematics, where you are able to verify results. We had a step towards solving the Ryman hypothesis last week. And so it may become just de rigueur that papers involve AI and almost expected in some fields that you're going to have used AI. So the idea that you have a watermark that says so just is very kind of meaningless. So the value of the watermark will also be shaped by this idea of just how accepted it is, even expected it is that you will have used AI to some extent in your research. Well, I have a feeling this isn't the last we're going to hear about this topic. And
The universal science of tickling
10:52you and I are going to talk about this topic. But we'll link to your story in the show notes. Of course, let's move on to our second story this week. Lizzie, are you ticklish? There's no need to call HR. This is a legit question. I most certainly am. Me too. Do you know, it's my feet for me to think it's so ticklish. Anyway, there is a reason for this. And this is a story in Nature that I read about. And it's based on a paper in Nature Human Behaviour. And it's all about how certain types of ticklishness, I suppose, seem to be a consistent thing around the world. Okay, amazing. And what are we talking about in terms of types, like places that you're tickled
11:26or methods of tickling or? I have learned from reading this article, there are different types of tickling. Okay, now, this article is talking about gargalesis. Okay, now this is the type of tickling that's associated with play, like being tickled. If someone comes and tickles you, that's gargalesis, right? So that elicits laughter and sometimes squirming, all the rest of it. This is not knismesis. Now that's like if someone brushes a feather against you, you know, that kind of you feel like a ticklish in your skin, but it doesn't make you laugh. Now the latter has attracted a lot of research attention because it's similar to itching. And you can think of a lot of diseases
12:01and skin conditions that result in itching. And so researchers have looked at that. Gargalesis then. The fun one. The fun one is not well understood. And folk have written about it since antiquity. What is it? What is it for? And we know that humans aren't the only ticklish animal. Other great apes tickle each other. Rats and meerkats apparently respond to human tickling, which suggests that this sensation has been preserved across evolution. And there's a link in the article to a video of a gorilla being tickled. This gorilla is having the timeless life, I'll tell you what. But
12:35what is going on is a question that researchers have had. And that's what they're trying to move towards solving with this research. Well, I mean, it does feel like something quite instinctive. I mean, the fact that we're talking about, you know, kids and play, like, my children are incredibly ticklish, love being tickled, love tickling. Like, it feels like something that humans just do. Yeah. And there have been a few ideas as to why it exists, which we'll get to in a bit. Right. But to test what might be going on, some researchers recruited 448 participants from three distinct cultural backgrounds. We've got Dutch, Greek and Chinese. Now, each
13:07person then completed a survey about their experiences and perceptions of tickling. And then they went onto a computer and they coloured in areas of a body model to create maps of where they were ticklish, repeating this exercise for other body sensations like pain or pleasurable touch. So what they've made in this research, these two researchers, is a high-resolution tickle map.
13:30OK. So we're talking feet. Yep. Like tummy. Yeah, belly. Under your arms. Yep. And neck is the other one. Neck. Yeah. OK, yeah, yeah. And almost all the participants, so 98.4% of them, in fact, reported having experienced tickling and 95.8% reported having tickled somebody else. Wait, so two-ish percent... Have never tickled or felt being tickled. Right. Now, this might not sound too surprising that most people have done one or the other. But studies suggest that how people interpret
14:04touch that is sort of processed emotionally, such as hugging, for example, that can differ by cultural background. But tickling maybe seems kind of across the board. And as we say, these ticklish areas were highly consistent between cultures and individuals. So yeah, neck, armpit, belly, soles of feet. And this is different to the comparisons and maps of the other sensations, like pain or pleasure, suggesting that the sensation of tickling is distinct and unique. And as I say, nobody really knows why it exists. And in this research,
14:38the researchers kind of tested five theories. Some of these were ancient, some of these were new. Aristotle attributed ticklishness to different areas of the skin being more delicate, thinking that maybe you'd be more ticklish where the skin is thinner. Like where it's thinner or something, yeah. Charles Darwin, though, his idea was that areas that are touched the least are most ticklish. And it turns out that the factor that showed significant association with ticklishness was this idea by Darwin. So it doesn't explain all of it, but the evidence is that that seems to be at least
15:12a part of it. And the authors say that perhaps there's kind of a surprise-based mechanism going on here because areas that are rarely touched, maybe without your feet, you're more surprised if someone does. And so it feels ticklish. And that tallies with the fact that you can't tickle yourself because it's never a surprise. And that's right, because two parts of your brain are working at once. You know the feeling of touch and also the act of you going to do it. But they also say that maybe there's kind of a self-reinforcing mechanism here. Some areas are ticklish because they're rarely touched and they're rarely touched because they're ticklish.
15:42Yes, that also makes sense. I mean, it does make sense, but I have to say this is not a cut and dried thing. I mean, they've only tested three cultural groups here. They didn't test situational context. But as you say there, people often enjoy tickling kind of innately. And it does seem like it is this conserved thing. So whether it plays a role in social bonding or protection, like your armpits, you know, there's a lot of blood vessels there that could be damaged, for example. Hard to know. But it's an interesting story because it does shine a light on this phenomenon, this activity that is so
16:17potentially so universal, but quite poorly understood. I love the idea that you might, you know, go to Amazonia and find a tribe that's never met anybody else from outside. And, you know, one thing you could share is that you're all
Closing thoughts and briefing signoff
16:30ticklish.
Closing thoughts and briefing signoff
16:31This is something that would have to be uncovered, I suppose. Well, if that story has tickled your fancy, sorry, we'll put a link to that one in the show notes as well, as well as a link on where you can sign up to The Nature Briefing to get even more stories like this delivered directly to your inbox. But for this week, all that's left to be said is I've been Benjamin Thompson, Lizzie Gibney. Thank you so much for being here. Thank you so much for having me.
More from Nature Podcast

Briefing Chat: How 1,000 pairs of buried underpants helped measure soil health
Sep 4, 202612 min

Audio long read: Could mending damaged DNA prolong life?
Sep 2, 202618 min

Briefing Chat: How Dolly Parton left her mark on science
Aug 28, 202614 min

Highest-ever ocean temperatures recorded as El Niño intensifies
Aug 26, 202619 min

Briefing Chat: New narcolepsy drug could unlock host of novel brain therapies
Aug 21, 202612 min