AI4SWITZERLAND
Research

OpenAI Taps ETH Zurich’s Martin Vechev to Test Its AI Text Watermark

October 8, 2026 · 6 min read · Research

OpenAI Taps ETH Zurich’s Martin Vechev to Test Its AI Text Watermark

ETH Zurich computer scientist Martin Vechev has been chosen by OpenAI to test and evaluate the company’s new watermarking technique for AI-generated text, the university’s Department of Computer Science announced on October 7. He joins a select group of leading researchers worldwide who have been asked to investigate what the method can do, where its limits lie and how it might develop.

Vechev heads ETH’s Secure, Reliable, and Intelligent Systems Lab, known as SRI Lab, and is also scientific director of INSAIT, the AI institute in Sofia, Bulgaria. His group has previously published research on attacks against watermarks for large language models, including a 2024 study on “watermark stealing”, in which an outsider learns enough about a watermark to spoof or remove it.

The technique takes a different route from today’s AI detectors. Conventional tools judge from a passage’s style whether it was machine-written. OpenAI’s approach instead embeds an invisible statistical signal in the model’s word choices, and a detector then looks for that signal to decide whether a section of text carries an OpenAI watermark. According to ETH, OpenAI says the approach may be expanded as the technology develops and more is known about its reliability.

What it means in practice

OpenAI Taps ETH Zurich’s Martin Vechev to Test Its AI Text Watermark — contextual photo

The work is driven by the European Union’s AI Act, which imposes transparency requirements on existing AI systems that must be met by 2 December 2026, ETH noted. Switzerland is not an EU member, but Swiss companies that offer AI services in the EU fall under those rules, and Bern is still preparing its own approach, with a consultation draft for an AI law expected in early 2027.

Independent scrutiny of AI security is a recurring theme at ETH. An ETH lab recently showed that LLM honeypots can triple attacker dwell time, and the university has hosted policy debates such as the AI Policy Summit held under Council of Europe auspices.

Watermarks are not a complete answer. Signals carried in word choice can weaken when text is heavily edited, paraphrased or translated, which is exactly the kind of limitation outside testers are meant to measure. What to watch: whether OpenAI publishes the evaluators’ findings, how well the watermark survives editing and translation, and whether other model makers adopt comparable signals before the December deadline.

← Back to AI4Switzerland