AI RESEARCH
Watermarking Should Be Treated as a Monitoring Primitive
arXiv CS.AI
•
ArXi:2605.13095v1 Announce Type: cross Watermarking is widely proposed for provenance, attribution, and safety monitoring in generative models, yet is typically evaluated only under adversaries who attempt to evade detection or induce false positives at the level of individual samples. We argue that watermarking should be treated as a monitoring primitive, and that internal monitoring is unavoidable given per-entity attribution keys and messages, as well as detector access. We