虎嗅

A Brief History of Tracking AI Traces

原文:AI痕迹追踪简史

Summary of Key Points

This article focuses on the "identity recognition" of AI-generated content, starting from Shannon's communication theory to explain that any information source (including AI) leaves statistical "fingerprints." It then discusses the technical approaches from passive detection (such as guessing authors based on word frequency) to active watermarking (both overseas invisible watermarks and domestic metadata). The article analyzes the vulnerabilities of watermarking technologies, such as their susceptibility to modification and false positives. Finally, it outlines the industrial opportunities surrounding AI watermarks in areas like compliance, copyright, and finance, as well as the legal and ethical challenges beyond the technical aspects.

Detailed Breakdown

1. How can AI content be identified? — The "invisible fingerprints" hidden in statistics

Shannon stated 77 years ago that any information source will leave statistical traces. For example, when a person writes an article, the frequency of using certain words like "de," "le," and "he" is fixed—just like everyone's handwriting, which cannot be changed. The same applies to AI: each word selection in generated content comes from a probability distribution, and different models (such as GPT and Gemini) have distinct preferences for words (for instance, GPT tends to use "reshape" more often, while Gemini prefers "influence"). These subtle differences accumulate to form an AI's "fingerprint."

For example, in 1964, statisticians used word frequency to determine that the author of 12 controversial articles from The Federalist Papers was Madison; the FBI used a similar method to catch the "mail bomber"—the usage of "you" and "yours" in his manifesto matched those in his personal letters. Today, AI content follows the same principle. DetectGPT works on this basis: it identifies content that seems most likely generated by an AI, as altered content appears less plausible.

2. Active watermarking: Overseas "invisible watermarks" vs domestic "metadata"

Passive detection methods are too inaccurate, so manufacturers have started to add watermarks actively, using two approaches:

  • Overseas: Generation-level invisible watermarks (e.g., Google's SynthID): During content generation, key parameters are adjusted to change the probability of word selection. For example, the probability of using "change" might be slightly increased, while "influence" is decreased. Humans may not notice, but specific tools can detect these changes; even if a screenshot is OCR-ed, the watermark remains if the vocabulary sequence remains unchanged. However, if the content is rewritten (e.g., "changing the world" becomes "reshaping the future"), the watermark disappears.
  • Domestic: Metadata labeling (required by the "Identification Methods for Artificially Generated Synthetic Content"): Information about the creator, content ID, and generation attributes is directly included in the file (for example, videos generated by Douyin will have a "AI-generated" label). The advantage is easier regulation and traceability; the downside is that metadata can be lost easily (e.g., during screenshots or sharing).

These two approaches differ in their basis: overseas watermarks are technically driven, while domestic ones are policy-driven.

3. Watermarks are not omnipotent:

Watermarking technologies have several limitations:

  • Invalidation by modification: A single AI rewriting tool can reduce the detection rate of all major watermarks to below 30%; experiments in 2026 showed that the SynthID watermark was removed in over 98% of cases.
  • False positives: SynthID misclassifies 5.4% of human-written articles as AI-generated and reports uncertainty for 80% of watermarked content.
  • Inability to apply to simple content: For example, when a model is asked to respond to "The Oriental Pearl Tower is in Shanghai," it can only choose "Shanghai" without enough options to add a watermark.
  • Lack of originality verification: If AI is used to edit a human-written article, the output will still have a watermark, but this does not prove that the content is AI-generated (Anthropic has warned about this flaw).

Therefore, watermarks are primarily effective against bulk copying and pasting of AI content by automated accounts; carefully rewritten content is difficult to detect.

4. Industrial opportunities:

Despite the limitations, the demand for watermarking technologies is growing:

  • Compliance auditing tools: Nearly a thousand registered large models in China need tools to ensure their metadata meets national standards.
  • Copyright verification services: With increasing AI-related disputes, tools are needed to prove that content is not AI-generated and thus original, serving as evidence in copyright lawsuits.
  • Financial information differentiation: Financial institutions need to distinguish between AI-generated reports and those written by analysts (which differ significantly in quality), but there are currently no specialized tools for this.
  • Cross-border interoperability middleware: Since Chinese metadata standards do not align with overseas watermarking practices, content platforms facing European markets need tools to convert formats. This represents a strategic opportunity during the policy transition period.

The market is valued at $600–800 million in 2026, with an annual growth rate of 25%. These demands exist even without perfect technology.

5. Legal and ethical considerations:

Even if AI-generated content can be detected, many issues remain unresolved:

  • Copyright ownership: Who owns the copyright to an AI-written novel—human or AI?
  • Academic integrity: Does using AI to write a paper count as plagiarism?
  • News ethics: Should AI-generated news be labeled, and will readers believe it?
  • Responsibility allocation: Who is responsible for false content generated by AI—the platform or the user?

There is no consensus on these issues, and legal and ethical frameworks have not kept up with technological developments. These are more challenging problems than technical ones.

Conclusion

While AI content recognition technology is advancing, the real challenge lies in defining the responsibilities and rights associated with AI-generated content using legal and ethical frameworks. This is not just a technical issue but also a social one.