cs.CROct 5, 2026

Watermarking: from Impossibility to Auditable Compliance

Authors: Fernando Delbianco, Fernando Tohmé, Hugo Acciarri

Organizations: Departamento de Economía, Universidad Nacional del Sur (UNS), Bahía Blanca, Argentina · Instituto de Matemática de Bahía Blanca (INMABB), CONICET–UNS, Bahía Blanca, Argentina · Departamento de Derecho, Universidad Nacional del Sur (UNS), Bahía Blanca, Argentina

Abstract

Article 50 (2) of the EU Artificial Intelligence Act requires providers of generative systems to make synthetic outputs machine-readable and detectable, while qualifying the effectiveness, interoperability, robustness, and reliability by technical feasibility, cost, content-specific limits, and the state of the art. For free-form text, one important implementation route is the implementation of a generative watermarking procedure, which poses a compliance problem that is hard to address. Strong watermarking is impossible against adaptive removal, while ordinary edits attenuate statistical evidence, and unmarked human text may overlap distributionally with machine output. This article develops an auditable alternative. First, it defines a description-length robustness profile. A finite-sample bound shows that detectable bias decays and that the required sample size grows with the inverse square of the decay rate. This replaces an unidentified Shannon-entropy constant with collision entropy. Second, it constructs label-conditional conformal prediction sets with separate false-attribution and false-exclusion levels, reporting watermark supported,'' not supported,'' or ``inconclusive''. Coverage is obtained as a finite-sample result and is class-conditional under exchangeability. A small reproducible simulation of a tournament watermark confirms both claims and shows that the surviving-token rule overstates the tolerable edit rate roughly twofold. The resulting premarket certificate, signed detector report, and postmarket recalibration protocol operationalize the Commission's 2026 Code of Practice without claiming universal robustness.

Figures & tables

Explore similar work

CardsList
  1. Watermarks Without Verification: AI Text Watermarking After the EU AI Act

    Sep 10, 2026Alexander Nemecek, Vipin Chaudhary, Erman AydayAi-Generated Content DetectionWatermarks

  2. Attribute-based Undetectable Watermarking for Generative AI Models

    Aug 4, 2026Miryam Mi-Ying Huang, Chung-Wei Lee, Max Raffel +1WatermarksAi-Generated Content Detection