Watermarking large language models in Europe: interpreting the AI act in light of technology

{"Abstract":[0],"To":[1],"foster":[2],"trustworthy":[3],"Artificial":[4],"Intelligence":[5],"(AI)":[6],"within":[7,226],"the":[8,11,20,45,81,87,117,120,145,162,168,199,227],"European":[9,84,201],"Union,":[10],"AI":[12,147],"Act":[13],"requires":[14],"providers":[15],"to":[16,61,116,184],"mark":[17],"and":[18,29,42,48,72,94,134,159,164,203],"detect":[19],"outputs":[21],"of":[22,51,83,89,112,119,161,165,167,230],"their":[23],"general-purpose":[24],"models.":[25],"The":[26],"Article":[27],"50":[28],"Recital":[30],"133":[31],"call":[32],"for":[33,53,196],"marking":[34],"methods":[35,114,195],"that":[36,205],"are":[37,126],"\\"sufficiently":[38],"reliable,":[39],"interoperable,":[40],"effective":[41],"robust\\".":[43],"Yet,":[44],"rapidly":[46],"evolving":[47],"heterogeneous":[49],"landscape":[50],"watermarks":[52],"Large":[54],"Language":[55],"Models":[56],"(LLMs)":[57],"makes":[58],"it":[59],"difficult":[60],"determine":[62],"how":[63],"these":[64],"four":[65,211],"standards":[66],"can":[67],"be":[68],"translated":[69],"into":[70,222],"concrete":[71],"measurable":[73],"evaluations.":[74],"Our":[75],"paper":[76],"addresses":[77],"this":[78],"challenge,":[79],"anchoring":[80],"normativity":[82],"requirements":[85,149],"in":[86,175],"multiplicity":[88],"watermarking":[90,113,177,194,223],"techniques.":[91],"Introducing":[92],"clear":[93],"distinct":[95],"concepts":[96],"on":[97,157],"LLM":[98,121,176],"watermarking,":[99],"our":[100],"contribution":[101],"is":[102],"threefold:":[103],"(i)":[104],"Watermarking":[105,141,189],"Categorisation:":[106],"We":[107,143,191],"propose":[108,180],"an":[109],"accessible":[110],"taxonomy":[111],"according":[115],"stage":[118],"lifecycle":[122],"at":[123],"which":[124],"they":[125],"applied":[127],"—":[128],"before,":[129],"during,":[130],"or":[131,138],"after":[132],"training,":[133],"during":[135],"next-token":[136],"distribution":[137],"sampling.":[139],"(ii)":[140],"Evaluation:":[142],"interpret":[144],"EU":[146],"Act’s":[148],"by":[150,214],"mapping":[151],"each":[152],"criterion":[153],"with":[154],"state-of-the-art":[155],"evaluations":[156],"robustness":[158],"detectability":[160],"watermark,":[163],"quality":[166],"LLM.":[169],"Since":[170],"interoperability":[171],"remains":[172],"largely":[173],"untheorised":[174],"research,":[178],"we":[179,218],"three":[181],"normative":[182],"dimensions":[183],"frame":[185],"its":[186],"assessment.":[187],"(iii)":[188],"Comparison:":[190],"compare":[192],"current":[193],"LLMs":[197],"against":[198],"operationalised":[200],"criteria":[202],"show":[204],"no":[206],"approach":[207],"yet":[208],"satisfies":[209],"all":[210],"standards.":[212],"Encouraged":[213],"emerging":[215],"empirical":[216],"tests,":[217],"recommend":[219],"further":[220],"research":[221],"directly":[224],"embedded":[225],"low-level":[228],"architecture":[229],"LLMs.":[231]}

Authors

Publication Details

Journal
Ethics and Information Technology
Published
2026-09-17
DOI
https://doi.org/10.1007/s10676-026-09918-w
Primary Topic
Adversarial Robustness in Machine Learning
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Watermarking large language models in Europe: interpreting the AI act in light of technology

Thomas Souverain
Ethics and Information Technology
Adversarial Robustness in Machine Learning
article

Watermarking large language models in Europe: interpreting the AI act in light of technology

Thomas Souverain
article en

Abstract

Abstract To foster trustworthy Artificial Intelligence (AI) within the European Union, the AI Act requires providers to mark and detect the outputs of their general-purpose models. The Article 50 and Recital 133 call for marking methods that are "sufficiently reliable, interoperable, effective and robust". Yet, the rapidly evolving and heterogeneous landscape of watermarks for Large Language Models (LLMs) makes it difficult to determine how these four standards can be translated into concrete and measurable evaluations. Our paper addresses this challenge, anchoring the normativity of European requirements in the multiplicity of watermarking techniques. Introducing clear and distinct concepts on LLM watermarking, our contribution is threefold: (i) Watermarking Categorisation: We propose an accessible taxonomy of watermarking methods according to the stage of the LLM lifecycle at which they are applied — before, during, or after training, and during next-token distribution or sampling. (ii) Watermarking Evaluation: We interpret the EU AI Act’s requirements by mapping each criterion with state-of-the-art evaluations on robustness and detectability of the watermark, and of quality of the LLM. Since interoperability remains largely untheorised in LLM watermarking research, we propose three normative dimensions to frame its assessment. (iii) Watermarking Comparison: We compare current watermarking methods for LLMs against the operationalised European criteria and show that no approach yet satisfies all four standards. Encouraged by emerging empirical tests, we recommend further research into watermarking directly embedded within the low-level architecture of LLMs.

Ethics and Information TechnologyVol. 28(4)
Openalex Percentile: Top 99%
Adversarial Robustness in Machine Learning
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.