fingerprinting
The number of times over decades that companies have been found to be fingerprinting documents is very high. Never did the fingerprints remain.
The concerns were certainly that it was done without consent, but the problem is inherently controlling use of fingerprinting, the map from fingerprint to user, and expansion of the fingerprint itself and what data it carries. Can you know which user? What the prompt was? The date? The location? It turns out they know all that and once there is a fingerprint all of that is part of the record.
Putting aside the constitutionality of this (and the vendor favoritism), have to imagine Anthropic’s output watermarking would be verrrry concerning for certifications like this
Claude’s watermark probably doesn’t work how you think. As the CTO of GPTZero, I’ll explain how Anthropic, Google and OpenAI are building text watermarking in this brief explainer and whether it can be defeated.
Almost all forms of watermarking that are fast and cheap enough for a frontier lab have the same formula, following the KGW method:
In generation: