AI Rounds by the Cumming School of Medicine
Sep 23, 2026 · 21 min · 11 segments
Since August, much of what the major AI systems produce carries an invisible watermark. In this episode I explain what that mark is, how it gets built into text and images, and why new European rules…
The word watermarking is being used for four different things, and most of the confusion in the coverage comes from mixing them up.
The AI system builds a hidden statistical pattern into what it produces while it produces it.
You cannot hear it, you cannot see it, but a detection tool holding the company's secret key can find it.
You may hear it called C2PA, after the industry group that wrote the standard or content credentials.
It is a digitally signed record attached to a file saying what made the file and what edits happened afterward.
A screenshot does not copy it and most social media platforms strip it on upload.
When the Washington Post uploaded a video carrying these credentials to eight different major platforms last year, none of the eight actually kept the Providence metadata.
The third is a detector, and this is the one maybe most educators have already heard about.
It looks at text or an image after the fact and estimates, from style and statistics, whether AI produced it.
It gets no help from the company that made the content, and what it gives you is a probability.
The fourth is a visible label, a caption, an icon, a small logo in the corner, and we all know these are easy to crop out.
Companies tend to ship several of these at once, and the free checking tools look much the same whether they are reading a watermark or running a classifier.
The distinction I would most like you to keep is between the first and the third.
A watermark is deliberately placed by the system that made the content, and it is read with a key.
When a colleague tells you a submission was flagged, ask which of the two they mean, because the evidence behind each is very different.
The word watermarking is being used for four different things, and most of the confusion in the coverage comes from mixing them up.
The AI system builds a hidden statistical pattern into what it produces while it produces it.
You cannot hear it, you cannot see it, but a detection tool holding the company's secret key can find it.
You may hear it called C2PA, after the industry group that wrote the standard or content credentials.
It is a digitally signed record attached to a file saying what made the file and what edits happened afterward.
A screenshot does not copy it and most social media platforms strip it on upload.
When the Washington Post uploaded a video carrying these credentials to eight different major platforms last year, none of the eight actually kept the Providence metadata.
The third is a detector, and this is the one maybe most educators have already heard about.
It looks at text or an image after the fact and estimates, from style and statistics, whether AI produced it.
It gets no help from the company that made the content, and what it gives you is a probability.
The fourth is a visible label, a caption, an icon, a small logo in the corner, and we all know these are easy to crop out.
Companies tend to ship several of these at once, and the free checking tools look much the same whether they are reading a watermark or running a classifier.
The distinction I would most like you to keep is between the first and the third.
A watermark is deliberately placed by the system that made the content, and it is read with a key.
When a colleague tells you a submission was flagged, ask which of the two they mean, because the evidence behind each is very different.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.