Statement from Digimarc CEO, Riley McCormack, on Executive Order on Artificial Intelligence

October 30, 2023

The following commentary was quoted in an official statement from the White House that can be read in full here.

We support the bold action taken today by the Biden Administration as it works to balance protecting the rights of Americans without impeding the tremendous potential of Artificial Intelligence (AI).

First, we are encouraged by the Order’s mandate to the Secretary of Commerce to create standardizations around authenticity and labeling synthetic content through the use of tools like watermarking. We additionally believe it is critical that standards for the tools themselves are developed, as only in so doing can these tools be relied upon to create a digital ecosystem of greater trust, fairness, and safety. Through the embedding and detection of digital watermarks, critical information can be reliably communicated to content consumers, including information on content provenance and authenticity, copyright ownership, the use of synthetic content creation tools, and if content has been manipulated. Creating standards around technologies like digital watermarking, coupled with adherence by industry to those standards, is imperative.

Second, we applaud the administration for recognizing the benefits of establishing the authenticity and provenance of all digital content, both synthetic and non-synthetic. Having almost thirty years of experience in building systems of trust and authenticity, Digimarc agrees that the best way to create an ecosystem of trust is when all authentic content is identified as such, which cannot be achieved if only synthetic content is watermarked. In addition, digitally watermarking human-created content provides an easy way for creators to claim their copyrights, thereby affording them protection and thus accomplishing another commendable goal of the Order. To this end, the tools to digitally watermark non-synthetic content must be made easily accessible at all points of content creation and distribution, such as on the devices used to create, modify, and publish digital assets.

Third, consideration must be given for how all content authenticity, provenance, and ownership will be conveyed. The Order discusses detection of synthetic content, but is silent on detection for non-synthetic content, despite recognizing the importance of establishing the authenticity and copyright ownership of this content. To have value, any form of communication must be received, not just sent. The most encompassing and quickest way to achieve the conveyance of authenticity and provenance is through ubiquitous detection of digital watermarks on the devices where digital content is consumed. The only way to achieve conveyance of copyright ownership, and thus creator protection, is through ubiquitous detection ahead of content ingestion by AI engines.

Given the growing conversation around digital watermarking as a tool to deliver a safe and fair internet, and some recent confusion around the technology, we believe it is important to detail what we believe constitutes digital watermarking technology and what does not.

What is a Digital Watermark?

Digital watermarking is the science of hiding information about an item in the item itself. Images, audio, video, and documents are among the types of digital assets that are currently digitally watermarked at global scale. Embedding is the act of hiding the information in an asset and the process of discovering that information is referred to as detection. Often, this embedded information consists of a unique identifier, and that identifier is used to communicate content provenance, authenticity, and copyright information about a digital asset in a way that is both secure and inextricably linked to the asset itself.

The Order defines “watermarking” as “the act of embedding information which is typically difficult to remove (…)”. As the pioneer and widely recognized leader in digital watermarking, Digimarc believes a digital watermark must have five specific characteristics, all of which are necessary to fulfill the definition set out in the Order:

  1. Covert and Machine Readable: A digital watermark is meant to be read by machines, not humans. As such, in addition to the requirement of indeed being detectable and readable by machines, it can also be (and almost always is) invisible and inaudible.
  2. Immutable: Once a digital watermark is applied to a digital asset, it becomes part of the digital asset itself, and thus the information cannot be changed. This also enables a digital watermark to transit all formats and distribution channels, ensuring its utility regardless of workflow.
  3. Ubiquitous: Because a digital watermark is covert, it can cover the totality of a digital asset, thereby making it more difficult to damage, manipulate, or remove the information.
  4. Redundant: Since a digital watermark can cover the totality of a digital asset, in addition to how the watermark itself is constructed, the digital asset can suffer significant damage or manipulation without impacting the digital watermark’s ability to be detected.
  5. Secure: The information contained in a digital watermark should only be shared in encrypted form which, when combined with other properties listed above, results in a robust data carrier that cannot be trivially severed from an asset. This also means digital watermarks should not be created using open-source technology as this introduces system risk caused by bad actors.

Variances in Digital Watermarks

Like any other technology, not all digital watermarks are created equal. Some are much better, more secure, and more technically complex than others—just like the locks to a home. For example, the lock to a screen door is much less secure than a multi-pronged deadbolt attached to a steel door. They are both locks, yes, and given the right tools they could both be broken, but one is markedly more secure than the other.

At Digimarc, we are focused on building the deadbolt, steel-door version of watermarks for both the physical and digital worlds, ensuring that the locks provide the security needed for a given application. That’s why our technology has been deployed at a significantly larger scale and for a much longer duration than other digital watermarking technology. It is for this reason that our technology has been trusted by the world’s central banks for over 25 years.

We are also adding other layers of security to our technology in addition to digital watermarks because the true security of any system isn’t defined by the security of any single layer, but how all those layers work in tandem to accomplish the goal. Just like choosing a secure lock for your door helps protect your home, adding additional security features like motion-activated floodlights, a home alarm system, and a video doorbell makes it safer.

Metadata and Manifests are Not Digital Watermarks

Information about a digital asset, such as provenance and ownership, is referred to as metadata. Sometimes this metadata is stored in a format called a manifest. This information is critical to determining the ownership or authenticity of digital content.

The term “digital watermarking” is sometimes erroneously used when discussing metadata, and this confusion has significant implications for system security. As an example, metadata attached to an image file differs from digital watermarking in that the image file is not immutable and the metadata contained therein is not ubiquitous or redundant. Moreover, metadata is noticeably insecure as it can be (and often is) easily removed from files, severing it from the content it was originally tied to. Then, new (and incorrect or nefarious) metadata can be inserted instead. The ease with which metadata can be removed or replaced is not lessened by any cryptographic techniques used to sign the metadata, and thus metadata does not meet the definition provided in the Order of being difficult to remove.

Digital watermarks are not only different than metadata, they are also necessary in a system that is built upon the accuracy of that metadata, because digital watermarks give metadata enduring value. A digital watermark can act as a tether to retrieve a digital asset’s correct and unaltered manifest, and hence its correct and unaltered metadata. A system built on metadata alone, without the enduring tethering of that metadata to a digital asset via a digital watermark, provides false certainty.

Final Thoughts and Commitment to Partnership

Addressing the issues of content authenticity and creator protection in our modern age is a huge and ever-growing problem. There is no silver bullet that will make our digital ecosystem fully trustworthy, fair, and safe. However, there are tools, especially when combined, that will allow us to make incredible progress towards this universally desired goal.

At Digimarc, we believe that tools like digital watermarking can help change our digital ecosystem from one of uncertainty, unfairness, and suspicion to one of greater authenticity, fairness, and trust. For this to happen, however, digital watermarking and similar tools must be held to the highest technological security standards, and companies must agree to adhere to those standards. Moreover, the tools to digitally watermark all content (synthetic or not) must be easily accessible, as must the tools to detect digital watermarks.

We applaud the diligent and thoughtful work of the Biden Administration and the leadership demonstrated by the Executive Order on AI, and we look forward to doing our part to achieve the ideals and goals set forth in this important and historic order. 

Riley McCormack
CEO, Digimarc

You May Also Like

Learn more

Why Automated Product Inspection Needs a Digital Makeover

Learn more

Piloting Digital Product Passport for Plastic Recycling