Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.
Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.

Code Bear · @thecodebear
Words
2,215
Runtime
12:15
Speaking pace
181wpm
Reading time
9min
181 words per minute, the same as the 181 median of 349 measured videos. That distribution comes from the 349-video hook study.
Opening (first 30 seconds)
Claude is getting a hidden watermark. And no, Anthropic is not adding invisible characters to your text or attaching metadata to it or secretly writing made by Claude somewhere you can't see. The watermark is actually hidden inside the choices Claude makes while generating the text itself. Anthropic has now announced that future Claude models will generate watermark text with older models getting the technology over the coming months. And this isn't just an Anthropic thing. Google has already developed text watermarking with SynthID. And as AI-generated text becomes harder and
91 words, the words spoken in the first 30 seconds at 181 words per minute.
Free, no signup. See how the first 30 seconds hold attention, with rewrites.
Sentence shape
| Measure | This transcript |
|---|---|
| Sentences | 187 |
| Average words per sentence | 11.8 |
| Longest sentence | 32 words |
| Questions asked | 6 |
| Sentences containing a number | 13 |
Most used terms
Filler phrases
12 in total: actually 6 · like 4 · basically 2.
A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.
Run the check on the words above: where attention is likely to drop, with a rewrite for each weak line. The free check shows the scores and the one issue costing the most.
What this transcript is
Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, generated automatically by YouTube, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.
No Script X-ray for this video: YouTube shows a Most replayed graph only once a video has enough views.
Claude is getting a hidden watermark. And no, Anthropic is not adding invisible characters to your text or attaching metadata to it or secretly writing made by Claude somewhere you can't see. The watermark is actually hidden inside the choices Claude makes while generating the text itself. Anthropic has now announced that future Claude models will generate watermark text with older models getting the technology over the coming months.
And this isn't just an Anthropic thing. Google has already developed text watermarking with SynthID. And as AI-generated text becomes harder and harder to distinguish from human writing, AI companies are looking for ways to make their own output detectable. But watermarking text is difficult. With an image, you have millions of pixels where you can hide tiny changes that nobody will notice. But text is different. Change a single word and you might change the meaning of an entire sentence.
If the AI wants to say, for example, "The capital of France is Paris," you obviously can't watermark it by changing Paris to London. So, how do you hide a watermark inside an ordinary text without adding anything to the text or without changing its meaning and while still being able to detect that watermark later? That's what we are going to understand in this video, and luckily, we don't have to guess how it works. Anthropic says Claude's watermarking method is based on SynthID text, the technique originally published by Google's DeepMind.
So, we are going to simplify the publicly available SynthID method, build it up from the very beginning, and then slowly introduce the real technical terms behind every step. And to understand the watermark, we first need to understand one extremely important thing. How does an AI model actually choose its next word? When an AI model generates text, it does not write the whole sentence at once. It generates one token at a time.
A token can be a word, part of a word, punctuation, or sometimes even just a few characters. So, imagine the model has generated this, "The movie was really." Now, it needs to decide what comes next. Internally, the model gives every possible next token a score. For example, "good" might get a high score. "Great" might get slightly lower score than "good." "Interesting" might get a different score. And something that makes very little sense might get an extremely low score.
These raw scores are called logits. The logits are then passed through a function, for example, softmax, which converts them into probabilities. So, after softmax, we might have something like this. Good with probability of 50%, great 30%, interesting Now, here is something important. The model does not necessarily just choose the token with the highest probability. It can sample from this probability distribution. So, good has the best chance of being selected, but great can also be selected.
If you generated the same response many times, you could get slightly different wording each time. And this randomness is where SynthID gets an opportunity to insert a watermark. SynthID does not generate the text first and then secretly attach something to it. There are no invisible characters saying, "This was written by Gemini." Instead, SynthID changes the process of selecting the next token. It works inside what is called decoding or sampling stage of generation.
So, we have the neural network produces logits, softmax turns them into probabilities, and before the final token is selected, SynthID gets involved. Now, we need one more thing, which is a secret key. Think of secret key as a secret number known to the watermarking system. The user does not know it. Now, SynthID takes that secret key and combines it with some of the tokens that were generated just before the current position.
For example, maybe the recent text is, "The movie was really" Internally, those words are represented by token IDs, basically numbers. So, maybe the recent token IDs look something like 48291764231. SynthID combines those recent token IDs with its secret key and runs them through a mathematical function. The result is another number. We can call this number a seed. Now, when I say seed, don't think of anything mysterious.
A seed is simply a value used to produce results that look random, but are actually repeatable. If you give the system the same previous tokens and the same secret key again, it will produce the same result. This is called deterministic pseudo randomness. Pseudo random means it looks random. Deterministic means the same input always produces the same output. This is extremely important because later during detection Google needs to recreate the exact same hidden pattern.
Now SynthID has the recent tokens, the secret key, and the seed created from them. Using these, it gives possible next tokens hidden watermark scores. In Google's paper, they are called G values. And the functions that generate them are called G functions. For simplicity, imagine the G value is either zero or one. So, we might have the word good with model's probability 50% G value zero. Word great with model's probability 30% G value one.
The word interesting with model's probability 15% and G value one. And the word terrible model's probability 5% and G value zero. And this distinction is extremely important. The probability and G value mean completely different things. Probability comes from the language model. It tells us how plausible is this token as the next token. The G value comes from watermarking system. It tells us does this token fit the secret watermark pattern at the particular position.
The G value does not mean the great is better word than good. It also does not mean that every time the word great appears, it is one. Because the score also depends on the recent context. In one sentence, great might get G value of one. In another sentence, the exact same token might get zero. Now, you might be thinking if good has 50% probability and great has only 30%, but SynthID gives great a one, does SynthID simply force the model to choose great?
The answer is no. And this is where the tournament sampling comes in. Instead of taking all possible tokens and simply choosing whichever one has the best watermark score, SynthID first samples candidates using the model's original probability. Let's say it samples eight candidates. Because good has a 50% probability, we might get good, great, good, good, interesting, great, good, good. Notice that good appears many times.
That's because the language model thought it was the most likely answer. And a very low probability token might not appear in the candidate list at all. So, the model's original probabilities are still controlling which tokens even get a chance. Now, SynthID takes these candidates and puts them into a tournament. Imagine the first pair is good versus great. If the secret G function gives good a zero and great a one, then great wins that match.
Now, imagine another match, good versus good. Both have same watermark score. That's a tie. So, one of them can be selected randomly. After the first tournament round, eight candidates become four, then four become two, then two become one final token. Different tournament rounds can use different G functions. So, a token that wins one round is not guaranteed to win the entire tournament. This is an important detail.
SynthID is not saying any token with a G value of one automatically wins. Instead, the G value biases the competition. A token may be favored in one round and still lose later. Eventually, one token wins. That becomes the next generated token. Now, that token gets added to the text and the whole process starts again. Because the text has changed, the recent token context has changed. That produces a new seed and the new seed produces new G values.
Then another tournament happens, then another token is selected. And this continues token-by-token through the entire response. Now, this also explains why SynthID does not necessarily destroy the quality of the answer. Imagine the model is answering "The capital of France is". Its probability distribution might look something like this: Paris 99.9% because that's the correct answer. Everything else, almost zero. If SynthID samples eight candidates from this distribution, it will probably get Paris, Paris, Paris, Paris, Paris, Paris.
There is nothing meaningful for the watermark to change, so Paris wins. Now, compare that with this approach is the my the model might think useful is 20 The model might think useful is 27% effective is 24% practical is 21% helpful is 18%. Now, there are several reasonable options. So, SynthID has much more freedom to influence which one is selected without making the sentence obviously worse. There is a technical term for this idea called entropy.
You can think entropy here as how uncertain the model is about the next token. If one token has nearly 100% probability, entropy is low. There is almost no freedom. If many different tokens have similar probabilities, entropy is higher. There is more room for watermark to influence the selection. Now, we have watermarked text, but how does Google detect it later? Imagine all Google has is the final sentence. There are no hidden characters.
There is no metadata, just the text. The clever part is that Google still has the same secret key. So, the detector tokenizes the text again. Then, it moves through the text one position at a time. For every token, it takes the preceding token. It combines them with the same secret key. Because the process is deterministic, it gets the same seed. And using that seed, it can recreate same G values for the token that actually appeared.
So, the detector might reconstruct something like token one G value one, token two zero, token three one, token four one, token five zero, and so on. The detector does not need to know which candidates were sampled during generation. It does not need to recreate every tournament match. It only needs to ask, "Did the tokens that actually appeared align with our secret watermark scores more often than they should appear by chance?" Imagine normal human-written text because the humans does not know Google's secret key.
There should be no special relationship between their word choices and Google's secret G value. So, in our simplified zero or one example, you might get something roughly balanced. Maybe 51% ones, 49% zeros. But, SynthID deliberately biased generation towards favorable G values. So, maybe a long watermark response has noticeably more ones. For example, 64% favorable G values, 36% unfavorable. Those percentages are just examples.
The real detector is more sophisticated, but the core idea is the same. It looks for the statistical biases. Not every token needs to have a one. That would actually make the watermark far too obvious. Instead, across hundreds of tokens, the detector looks for an unusual correlation between the generated text and the Google's secret scoring system. Technically, this becomes a form of statistical hypothesis testing. The detector starts with something called the null hypothesis.
Basically, assume the text was not watermarked. Then it asks, "If this really was ordinary text, how likely would it be for it to match our secret pattern this strongly purely by accident?" If the pattern is weak, there is not enough evidence. If the pattern is extremely strong, the detector can say that the text contains evidence of the SynthID watermark. And yes, a human-written text can accidentally match the pattern as well.
This is called a false positive. The opposite can also happen. A genuinely watermarked text might be edited, shortened, or changed enough that the detector fails to recognize it. This is called a false negative. So, SynthID detection is not the same thing as finding a hidden label that deliberately says Gemini wrote it. It is statistical evidence. And now, we can put the whole system together. During generation, the model reads the previous token, it produces logits, softmax converts those logits into token probabilities, then SynthID takes the recent context and its secret watermark key.
That produces a repeatable pseudo-random seed. The seed is used by G functions to create a secret G value for candidate tokens. The candidate tokens are sampled using the model's original probability distribution. Those candidates compete through tournament sampling. The G value biases which candidates survive. One token wins. That token is appended to the text, and the process repeats. And then during detection, the finished text is tokenized for every position.
The detector takes the preceding token and the same secret key. It recreates the same seed. It recreates the G values. Then it checks whether the actual tokens in the text matches favorable watermark scores unusually often. If the statistical pattern is strong enough, the text is considered likely to contain the SynthID watermark. So, SynthID is not really hiding something inside the characters. It is hiding something inside the probability decisions that created those characters in the first place.
So, yeah, this was a very simplified explanation of how we can watermark a text. I hope you learned something new from this video. You enjoyed this video. I'll see you in the next one. Till then, peace out.
The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.
Free tools for your own script: paste a draft and see where it stands before you record it.
Paste your draft and see where viewers are likely to drop off, with a rewrite for each weak line.
Paste the first 30 seconds of your own draft for a hook score and rewrites.
Check your draft against YouTube's advertiser-friendly guidelines before you record it.
Read this channel's public videos and transcripts, and download a writing brief for it.