Skip to main content
AI Watermark Removal

AI Watermarking

Is DeepSeek Watermarked?

Yes, but only half of what the law behind it asks for. DeepSeek's Open Platform Terms of Service require developers building on its API to label AI-generated content, an obligation tracing to China's Measures for Labeling of AI-Generated Content and mandatory standard GB 45438-2025, both effective September 1, 2025. On chat.deepseek.com that shows up as a reminder on the welcome page and a label appended to the end of generated text, exactly what DeepSeek's own disclosure page describes. The part most coverage misses is that China's rule asks for two things, an explicit visible label and implicit machine-readable metadata including "watermarks where feasible," and DeepSeek's public documentation accounts for the first while saying nothing about the second.

Published 2026-08-11Updated 2026-08-11Confirmed

Key takeaways

  • DeepSeek's Open Platform Terms of Service require developers, classified as "network information service providers" under Chinese law, to label AI-generated content, a duty tracing to China's Measures for Labeling of AI-Generated Content and mandatory standard GB 45438-2025, both effective September 1, 2025.
  • On chat.deepseek.com that obligation shows up as a visible reminder on the welcome page plus a label appended to the end of generated text, exactly what DeepSeek's own model and algorithm disclosure page describes, and nothing more.
  • China's regulation asks for two layers, not one: explicit visible labels and implicit machine-readable metadata (provider name, a content reference number, and "watermarks where feasible"). DeepSeek's public documentation only accounts for the visible half.
  • A September 2025 report from phandroid.com claimed DeepSeek combines its visible label with an "implicit" hidden digital fingerprint. That description doesn't appear in DeepSeek's own Terms of Service or disclosure pages.
  • A sibling Chinese chatbot, Alibaba's Tongyi Qianwen, has at least one dated, uncorroborated 2023 report describing an actual invisible watermarking technology called "Orange Shield." DeepSeek has no comparable claim on file, stale or otherwise.
  • There's no confirmation of any watermark, visible or invisible, in output from DeepSeek's Janus-Pro image generator, and no DeepSeek statement addresses EU AI Act Article 50 at all.

Provider map

Text watermark status by provider

Detector guide
How to read this map

Confirmed means an official or primary source documents text watermarking. Contested means official sources disagree with each other. Watchlist means regulation, research, or provider behavior makes the topic worth tracking closely.

Yes, and you can see it without any tools

Confirmed

Here's the exact mark DeepSeek documents, where it appears, and which named law put it there.

DeepSeek's Open Platform Terms of Service spell out a labeling obligation for anyone building on its API. Chinese law classifies those developers as "network information service providers," and that status brings a duty to label AI-generated content before it reaches end users.

Note where that duty sits. DeepSeek's terms place it on the developer integrating the API, not only on DeepSeek itself.

The rule behind it is specific. China's Cyberspace Administration finalized the Measures for Labeling of AI-Generated Content, alongside mandatory technical standard GB 45438-2025, on March 14, 2025, both effective September 1, 2025.

On DeepSeek's own consumer product, the company's model and algorithm disclosure page describes what that looks like in practice:

  • A reminder shown on the welcome page when a chat starts
  • A label appended to the end of generated text

Both are visible to whoever reads the output, so the detector Google's autocomplete nudges people toward has nothing to look for. The disclosure page describes nothing sitting underneath that tag, just the plain-text label itself.

DeepSeek issued its own announcement around September 1, 2025 confirming the rollout. It isn't findable self-hosted on a deepseek.com or deepseek.cn domain, but it was reproduced verbatim across multiple independent outlets, including Sina, 快科技 (mydrivers), and cctime.

The half of the law DeepSeek doesn't describe

Confirmed

You'll see the second labeling layer China requires, plus the two-word escape hatch that might explain DeepSeek's silence about it.

China's rule doesn't stop at a visible tag. GB 45438-2025 requires explicit labeling, meaning on-screen text, audio, or graphics a person can see or hear, and implicit labeling, meaning machine-readable metadata embedded in file headers.

The implicit half has named fields:

  • The provider's name or code
  • A content reference number
  • In the regulation's own words, "watermarks where feasible"

It applies across text, images, audio, video, and virtual scenes. It also binds both the platforms that host content and the creators who generate it.

DeepSeek's disclosure page, the one document that actually describes chat.deepseek.com's behavior, accounts for the explicit half and stops. It says nothing about embedding provider codes, reference numbers, or a watermark into file metadata.

So there's a real open question here that DeepSeek hasn't answered publicly. Does the company consider implicit metadata labeling infeasible for its chat product, or has it built that layer without documenting it?

Both are plausible. Neither has been confirmed.

No confirmed invisible watermark, despite the headlines

Community discussion

Here's the single report behind the hidden-fingerprint claim, and what a genuinely specific claim looks like by comparison.

Nothing in DeepSeek's own documentation describes an invisible watermark. No statistical signal embedded in token choices, no hidden pattern a detector could pull back out of the text later.

A report from phandroid.com published around September 3, 2025 complicates that slightly. It describes DeepSeek's approach as combining the visible label with "implicit" hidden digital fingerprints baked into the content itself.

That claim doesn't appear in DeepSeek's Terms of Service or disclosure page. It reads much more like a paraphrase of the Chinese standard's general implicit-labeling requirement than a DeepSeek-specific technical disclosure.

A useful contrast sits one company over. Alibaba's Tongyi Qianwen, the chat product built on the Qwen model family, was reported by Chinese tech outlets in 2023 to use "Orange Shield" technology for screenshot-resistant invisible watermarking, tied to an early draft of the same national labeling push.

That's what makes "DeepSeek has an invisible watermark" look less like a documented feature and more like a borrowed description of what the regulation generally asks of everyone.

Two related gaps stay open. There's no confirmation of any watermark, visible or invisible, in output from DeepSeek's Janus-Pro image generator, and no DeepSeek statement addresses EU AI Act Article 50 compliance at all.

FAQ

How does DeepSeek's labeling compare to Claude's or Gemini's watermarking?

It depends on what you mean by watermark. DeepSeek's only confirmed mechanism is a visible label, text a reader can see, not a hidden signal buried in the output. Google has published details of SynthID, an invisible watermarking system applied to Gemini's text and image output, with a public detector tool available to check afterward. Anthropic has separately confirmed that supported Claude models weave an invisible watermark directly into generated text, though without naming a mechanism or shipping a public detector yet. That puts DeepSeek in a different category from both: the only one of the three with no confirmed invisible signal at all, and the only one whose labeling is driven by a domestic regulation rather than a voluntary international commitment.

Does the Chinese regulation apply only to DeepSeek?

No. The obligation traces to China's Measures for Labeling of AI-Generated Content and its companion standard GB 45438-2025, which target any developer classified as a "network information service provider" under Chinese law, a category the regulation defines broadly. DeepSeek's Terms of Service simply pass that obligation on to developers building on its API, alongside DeepSeek's own labeling on chat.deepseek.com.

Does China's regulation actually require an invisible watermark?

In part, yes, at least on paper. GB 45438-2025 asks for implicit, machine-readable metadata including provider identifiers, a content reference number, and "watermarks where feasible," alongside the visible label most people notice. DeepSeek's documentation only describes the visible half, so whether the company treats embedded metadata as infeasible for chat.deepseek.com or has simply not documented it is a real open question nobody has answered publicly.

Has any Chinese AI chatbot been reported to use an actual invisible watermark?

Alibaba's Tongyi Qianwen, marketed under the Qwen brand, was reported by Chinese tech outlets in 2023 to use "Orange Shield" technology for invisible, screenshot-resistant watermarking, tied to an early draft of China's labeling rules. That report is now nearly three years old and comes from Chinese tech press rather than an Alibaba statement, so treat it as dated community reporting rather than a confirmed current mechanism. It also says nothing about DeepSeek.

Next steps

  • Get the full picture of the law that forces the label, including why its two-layer structure keeps producing bad headlines about DeepSeek. DeepSeek watermark tracker
  • Understand why a watermark detector and an AI detector answer different questions, which is the confusion behind most "deepseek watermark detector" searches. AI watermark vs AI detector
  • Check a saved DeepSeek reply for invisible Unicode characters in your browser, so you're testing rather than trusting a headline. Invisible character checker

Sources and citation status