Doing this manually would be very time consuming - you'd basically need to rewrite the entire text. What they are doing is altering the statistical properties of the entire generated text, essentially on a word by word basis - they are not just hiding a watermark pattern in there someplace.
Yes this is what im trying to figure out. It means you cant be confident a negative is true. It sounds like this is the spirit of the law but it makes no sense. It would work better if only the model provider knows and the government can ask.
the government can ask .... who? If the claimed text is genuine, then the government is responsible for submitting the text to ...? all frontier labs? surely not every model within a lab is going to watermark in the same fashion?
I'm so very confused on this implementation and would want to see an expected use case.