Stay Ahead, Stay ONMINE

Hallucinations, Watermarks, Removers, and a Squeezed Balloon

AI safety has a friendly-fire problem. The technology that proves where AI text came from is weakening the technology that checks whether it is true. Watermarking, or embedding a hidden signature in generated text so that its origin can be proven later, is used to increase transparency on AI applications (Europe’s EU AI Act Article 50 [1] ; China’s AI labeling regulation by the Cyberspace Administration of China [2]). Besides, hallucination detection tries to flag the parts of an answer that the model made up. We use it to check if model outputs are reasonably predictable. Regulators are pushing both edges. But there is a hidden collision inside AI models between both transparency and liability. The collision is hidden in the model’s internals but can have real consequences in AI systems’ safety.How watermarking worksAn LLM does not write sentences. It computes, at every step, a probability distribution over the next token. Sometimes that distribution is sharp. After “The capital of France is”, the token “Paris” carries almost all the probability mass, and there is no real choice to make. Sometimes it is flat. After “She left the party because”, multiple continuations are equally plausible, and the model flips a weighted coin. The technical name for the flatness of that distribution is entropy or semantic entropy to be more specific [1]. High entropy means the model is choosing among many comparable options. Low entropy means the next token is essentially forced. Keep this distinction in mind, because both technologies in this story live at the high-entropy positions.A text watermark biases the coin flips using a secret key. The best known scheme for watermarking comes from the work of Kirchenbauer and colleagues in 2023 [4]. This approach splits the vocabulary at each step into a pseudorandom “green” and “red” list derived from the key and the recent context, then adds a small bonus to the green tokens (Figure 1). The text still reads naturally, but it contains statistically more green tokens than chance would produce. A detector holding the key reconstructs the lists, counts the green tokens, and computes how improbable that count would be in unwatermarked text.Figure 1: The same prompt answered twice: without a watermark (top) and with one (bottom). Green marks the words the secret key favors. Human text of this length would contain about 9 green words without any watermark at work. The watermarked answer contains 28. The odds of that happening naturally are about 1 in 10 trillion, so the detector concludes the text is machine-made. Adapted from Kirchenbauer et al., 2023 [4]Google DeepMind’s SynthID-Text [5], deployed in all its Gemini family models, refines the idea with a mechanism called tournament sampling (the model drafts several candidate words and the secret key referees a knockout between them; the champion gets written), applied as a processor on the model’s output probabilities. The scheme is open sourced in the Hugging Face Transformers library.A third family, the distortion-free schemes inspired by Aaronson’s Gumbel trick, arranges the bias so that the output distribution of a single generation is provably unchanged on average, while the text remains correlated with the key [6].A watermark can only push where there is room to push. At a low-entropy position, biasing the choice would mean writing the wrong word, and quality would visibly collapse. Take an invoice summary. In the sentence “The total due is 4,320 dollars,” everything after “is” is constrained. There is only one correct continuation, and a watermark that nudged the model toward any other number would not be hiding a signature, it would be corrupting the document. Now take the sentence “Payment was received immediately” The model could have written “quickly”, “swiftly”, or “without delay”, and the reader could never say which word it would have picked on its own. That second slot is where the watermark lives. A signature can only hide inside choices that make no difference, which is exactly why it is invisible, and exactly why it cannot exist where the choice matters. So every scheme concentrates its signal at high-entropy positions, the moments of doubt. This signature is statistical and average-case. Detection is reliable “given enough text”, which is not the same as a per-output certificate.Currently Google marks all their Gemini family models. OpenAI built a scheme and chose not to deploy it. Anthropic has just announced they are going to add watermarks to their Claude family models. Open-weight models leave decoding in the user’s hands, so their text is unmarked whenever the user prefers.How hallucination detectors workA hallucination is a fluent statement that happens to be wrong: an invented statistic, a fabricated citation, a number that appears in no source document. Current detectors can be divided into two mechanistically different families.Grounding-based detectors read the answer against a trusted source and ask whether each claim is supported. Token-support models such as LettuceDetect classify which spans of the answer lack backing in the context. Entailment models such as MiniCheck ask whether the source logically implies the claim. LLM judges do the same with a prompted model. What is common in these approaches is the input: the output text and the evidence, nothing else.Uncertainty-based detectors exploit a behavioral signature instead: a model that knows the answer produces it consistently, while a model that is guessing drifts across resamples. Semantic entropy[1] formalizes this by sampling several answers, clustering them by meaning, and measuring the entropy over clusters. SelfCheckGPT and the logprob-calibration methods are variations on the the same idea. In this family of detectors also the input is a common feature. the model’s uncertainty, read either from repeated sampling or from the probabilities directly.The collisionThe watermark operates at high-entropy positions because those are the only positions where the choice can be steered invisibly. Uncertainty-based detectors reads those positions because hesitation is its “here” ignal. The watermark steps in at the moment of doubt, and resolves it with the secret key (a private number that fixes how every doubtful choice tips). The detector’s trick depends on the resamples being fresh, independent tries. The watermark schema breaks that. Every retry uses the same secret key, so the coin flips inside the model land the same biased way each time, and in the strictest watermark schemes a fixed key produces exactly the same answer, word for word (Figure 2). If we ask a guessing model the same question five times we should see five slightly different guesses. That variation is the warning sign. With the watermark the five tries agree, not because the model stopped guessing, but because the same loaded coin decided all five. The steadiness we observe belongs to the sampler, not to the model’s knowledge.Figure 2: The watermark removes the variation the detector was reading. Image by author.As a consequence, consistency-based hallucination detectors overestimate agreement and underestimate uncertainty on watermarked text.Not every confidence check works by asking the question again. A second family skips the retries and reads the model’s internal probability numbers directly, the running record of how sure it was about each word. But the watermark has already edited those numbers before any check gets to read them, so this family inherits the distortion as well. A 2025 study across seven instruction-tuned models [7] found that watermarking measurably changes how models behave on downstream tasks, and that the changes remain after accounting for the loss in text quality. So, for any check that reads retries or probability numbers, the interference follows necessarily from how the watermark works.Figure 3. One moment of doubt, one distribution over the next word. The check on the left is reading the model. The check on the right is reading the key. Image by author.Grounding-based detectors sit on the other side. They read only the output text against the evidence (for example in RAG systems), and the watermark selects among semantically equivalent continuations. So, in principle, they are not affected by watermarks as much as operate in a different space. If we need to run reliability checks on watermarked text, this is the family to run.The watermark removersThe removal tools arrived on schedule, and nearly all of them are paraphrasers: a second model reads the watermarked text and says it again in different words. We are currently seing three approaches:Watermark stealing [8] showed that for under fifty dollars of API queries an attacker can learn enough of a scheme’s hidden green-list rule to strip the mark from schemes previously considered safe, with success rates above 80 percent, and also to forge it.BIRA [9] (September 2025) rewrites text while steering the rewriter away from the words the watermark favored, and reports over 99 percent evasion without knowing which scheme was used.WASH [10] (May 2026) does not even rewrite: it averages the outputs of three ordinary models, the independent watermark biases cancel out, and detection scores fall from far above the alarm threshold to below it.The question is, do they work? The response is yes, and this is settled and it has a theoretical explanation. There is a mathematical proof of this with a fitting title: “Watermarks in the sand: Impossibility of strong watermarking for generative models” [11]. The argument is simple (Figure 4). Suppose the attacker can do two things: tell whether a small edit made the text worse, and keep making small edits that don’t. Then they can wander step by step through thousands of rewrites that are all equally good, and somewhere along that walk the watermark’s pattern gets left behind, because the pattern lived in the specific word choices and the words are no longer the ones the model chose. No current watermark scheme can survive that, whatever key it uses. Google, in its own description of SynthID-Text presents it as a marker for good-faith use, not as protection against someone determined to remove it.Figure 4. A walk through equally good rewrites leaves the pattern behind. Image by authorSqueezing a balloonRemember which detectors the watermark could not hurt: the ones that never ask how confident the model felt. They take the output answer and hold it up against your source documents, checking word by word and phrase by phrase whether each claim is grounded in the provided context. The watermark changed which words got picked, but the claims still matched the sources, so these checks kept working. But the washing watermark-removal approach breaks exactly that safety. A washed text says the same thing in different words. Different words no longer line up with the source documents, so the matching scores fall, and a correct answer starts to look unsupported.Moreover, the washing tool is itself an “AI rewriting the text”, and nobody is checking its output. Rewriting is known to change things at the edges: a number shifts, a “probably” disappears, a name gets swapped. The cleanup step can create the very mistakes the safety checks were built to catch. And since washing happens after the text is finished, it cannot bring back the natural variation the watermark removed. Conclusion: the confidence-based checks stay broken.The distortion only movesFigure 5: The distortion never disappears. Image by author.The distortion produced by the watermark and its removal process never disappears. It moves, like squeezing a balloon. The watermark presses on one side at writing time and distorts the checks that read doubt. The remover presses on the other side at cleanup time and distorts the checks that read evidence. Text that has been through both steps has weakened both kinds of hallucination-detection approaches. As far as I know, nobody has measured that second effect directly yet. The experiment is sitting there waiting for someone to run it.Forgery closes the loop from the other side. The same tricks that strip a watermark off can stamp one onto text the model never wrote. So the label “watermarked” can fail both ways: missing from machine text that was laundered, present on false text that was faked.💬 Comments and suggestions are wellcome.✉️ You can contact me javier@jmarin.infoReferences[1] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance) [https://eur-lex.europa.eu/eli/reg/2024/1689/oj][2] Measures for Labeling of AI-Generated Synthetic Content Document. State Information Office Tongzi [2025] №2. Cybersecurity Administration, Ministry of Industry and Information Technology, Ministry of Public Security, State Administration of Radio and Television [https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm][3] Farquhar, S., Kossen, J., Kuhn, L. et al. Detecting hallucinations in large language models using semantic entropy. Nature 630, 625–630 (2024). https://doi.org/10.1038/s41586-024-07421-0[4] Kirchenbauer, J., Geiping, J., Wen, Y., Katz, J., Miers, I., & Goldstein, T. (2023, July). A watermark for large language models. In International conference on machine learning (pp. 17061–17084). PMLR.[5] Google DeepMind, SynthID documentation and the Hugging Face Transformers integration (SynthIDTextWatermarkLogitsProcessor, BayesianDetectorModel). https://deepmind.google/technologies/synthid/ and https://huggingface.co/docs/transformers[6] Fu, J., Zhao, X., Yang, R., Zhang, Y., Chen, J., & Xiao, Y. (2024, August). Gumbelsoft: Diversified language model watermarking via the gumbelmax-trick. In Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (pp. 5791–5808).[7] Verma, A., Phan, N., & Trivedi, S. (2025). Watermarking degrades alignment in language models: Analysis and mitigation. arXiv preprint arXiv:2506.04462.[8] Jovanović, N., Staab, R., & Vechev, M. (2024). Watermark stealing in large language models. arXiv preprint arXiv:2402.19361.[9] Hwang, J., Park, S., & Ok, J. (2025). LLM Watermark Evasion via Bias Inversion. arXiv preprint arXiv:2509.23019.[10] Wu, Z., Gong, G., Zhu, Q., Chen, Y., & Zhao, R. (2026). Linear Ensembles Wash Away Watermarks: On the Fragility of Distributional Perturbations in LLMs. arXiv preprint arXiv:2605.30501.[11] Zhang, H., Edelman, B. L., Francati, D., Venturi, D., Ateniese, G., & Barak, B. (2023). Watermarks in the sand: Impossibility of strong watermarking for generative models. arXiv preprint arXiv:2311.04378.

AI safety has a friendly-fire problem. The technology that proves where AI text came from is weakening the technology that checks whether it is true. Watermarking, or embedding a hidden signature in generated text so that its origin can be proven later, is used to increase transparency on AI applications (Europe’s EU AI Act Article 50 [1] ; China’s AI labeling regulation by the Cyberspace Administration of China [2]). Besides, hallucination detection tries to flag the parts of an answer that the model made up. We use it to check if model outputs are reasonably predictable. Regulators are pushing both edges. But there is a hidden collision inside AI models between both transparency and liability. The collision is hidden in the model’s internals but can have real consequences in AI systems’ safety.

How watermarking works

An LLM does not write sentences. It computes, at every step, a probability distribution over the next token. Sometimes that distribution is sharp. After “The capital of France is”, the token “Paris” carries almost all the probability mass, and there is no real choice to make. Sometimes it is flat. After “She left the party because”, multiple continuations are equally plausible, and the model flips a weighted coin. The technical name for the flatness of that distribution is entropy or semantic entropy to be more specific [1]. High entropy means the model is choosing among many comparable options. Low entropy means the next token is essentially forced. Keep this distinction in mind, because both technologies in this story live at the high-entropy positions.

A text watermark biases the coin flips using a secret key. The best known scheme for watermarking comes from the work of Kirchenbauer and colleagues in 2023 [4]. This approach splits the vocabulary at each step into a pseudorandom “green” and “red” list derived from the key and the recent context, then adds a small bonus to the green tokens (Figure 1). The text still reads naturally, but it contains statistically more green tokens than chance would produce. A detector holding the key reconstructs the lists, counts the green tokens, and computes how improbable that count would be in unwatermarked text.

Figure 1: The same prompt answered twice: without a watermark (top) and with one (bottom). Green marks the words the secret key favors. Human text of this length would contain about 9 green words without any watermark at work. The watermarked answer contains 28. The odds of that happening naturally are about 1 in 10 trillion, so the detector concludes the text is machine-made. Adapted from Kirchenbauer et al., 2023 [4]

Google DeepMind’s SynthID-Text [5], deployed in all its Gemini family models, refines the idea with a mechanism called tournament sampling (the model drafts several candidate words and the secret key referees a knockout between them; the champion gets written), applied as a processor on the model’s output probabilities. The scheme is open sourced in the Hugging Face Transformers library.

A third family, the distortion-free schemes inspired by Aaronson’s Gumbel trick, arranges the bias so that the output distribution of a single generation is provably unchanged on average, while the text remains correlated with the key [6].

A watermark can only push where there is room to push. At a low-entropy position, biasing the choice would mean writing the wrong word, and quality would visibly collapse. Take an invoice summary. In the sentence “The total due is 4,320 dollars,” everything after “is” is constrained. There is only one correct continuation, and a watermark that nudged the model toward any other number would not be hiding a signature, it would be corrupting the document. Now take the sentence “Payment was received immediately” The model could have written “quickly”, “swiftly”, or “without delay”, and the reader could never say which word it would have picked on its own. That second slot is where the watermark lives. A signature can only hide inside choices that make no difference, which is exactly why it is invisible, and exactly why it cannot exist where the choice matters. So every scheme concentrates its signal at high-entropy positions, the moments of doubt. This signature is statistical and average-case. Detection is reliable “given enough text”, which is not the same as a per-output certificate.

Currently Google marks all their Gemini family models. OpenAI built a scheme and chose not to deploy it. Anthropic has just announced they are going to add watermarks to their Claude family models. Open-weight models leave decoding in the user’s hands, so their text is unmarked whenever the user prefers.

How hallucination detectors work

A hallucination is a fluent statement that happens to be wrong: an invented statistic, a fabricated citation, a number that appears in no source document. Current detectors can be divided into two mechanistically different families.

  • Grounding-based detectors read the answer against a trusted source and ask whether each claim is supported. Token-support models such as LettuceDetect classify which spans of the answer lack backing in the context. Entailment models such as MiniCheck ask whether the source logically implies the claim. LLM judges do the same with a prompted model. What is common in these approaches is the input: the output text and the evidence, nothing else.

  • Uncertainty-based detectors exploit a behavioral signature instead: a model that knows the answer produces it consistently, while a model that is guessing drifts across resamples. Semantic entropy[1] formalizes this by sampling several answers, clustering them by meaning, and measuring the entropy over clusters. SelfCheckGPT and the logprob-calibration methods are variations on the the same idea. In this family of detectors also the input is a common feature. the model’s uncertainty, read either from repeated sampling or from the probabilities directly.

The collision

The watermark operates at high-entropy positions because those are the only positions where the choice can be steered invisibly. Uncertainty-based detectors reads those positions because hesitation is its “here” ignal. The watermark steps in at the moment of doubt, and resolves it with the secret key (a private number that fixes how every doubtful choice tips). The detector’s trick depends on the resamples being fresh, independent tries. The watermark schema breaks that. Every retry uses the same secret key, so the coin flips inside the model land the same biased way each time, and in the strictest watermark schemes a fixed key produces exactly the same answer, word for word (Figure 2). If we ask a guessing model the same question five times we should see five slightly different guesses. That variation is the warning sign. With the watermark the five tries agree, not because the model stopped guessing, but because the same loaded coin decided all five. The steadiness we observe belongs to the sampler, not to the model’s knowledge.

Figure 2: The watermark removes the variation the detector was reading. Image by author.

As a consequence, consistency-based hallucination detectors overestimate agreement and underestimate uncertainty on watermarked text.

Not every confidence check works by asking the question again. A second family skips the retries and reads the model’s internal probability numbers directly, the running record of how sure it was about each word. But the watermark has already edited those numbers before any check gets to read them, so this family inherits the distortion as well. A 2025 study across seven instruction-tuned models [7] found that watermarking measurably changes how models behave on downstream tasks, and that the changes remain after accounting for the loss in text quality. So, for any check that reads retries or probability numbers, the interference follows necessarily from how the watermark works.

Figure 3. One moment of doubt, one distribution over the next word. The check on the left is reading the model. The check on the right is reading the key. Image by author.

Grounding-based detectors sit on the other side. They read only the output text against the evidence (for example in RAG systems), and the watermark selects among semantically equivalent continuations. So, in principle, they are not affected by watermarks as much as operate in a different space. If we need to run reliability checks on watermarked text, this is the family to run.

The watermark removers

The removal tools arrived on schedule, and nearly all of them are paraphrasers: a second model reads the watermarked text and says it again in different words. We are currently seing three approaches:

  • Watermark stealing [8] showed that for under fifty dollars of API queries an attacker can learn enough of a scheme’s hidden green-list rule to strip the mark from schemes previously considered safe, with success rates above 80 percent, and also to forge it.

  • BIRA [9] (September 2025) rewrites text while steering the rewriter away from the words the watermark favored, and reports over 99 percent evasion without knowing which scheme was used.

  • WASH [10] (May 2026) does not even rewrite: it averages the outputs of three ordinary models, the independent watermark biases cancel out, and detection scores fall from far above the alarm threshold to below it.

The question is, do they work? The response is yes, and this is settled and it has a theoretical explanation. There is a mathematical proof of this with a fitting title: “Watermarks in the sand: Impossibility of strong watermarking for generative models” [11]. The argument is simple (Figure 4). Suppose the attacker can do two things: tell whether a small edit made the text worse, and keep making small edits that don’t. Then they can wander step by step through thousands of rewrites that are all equally good, and somewhere along that walk the watermark’s pattern gets left behind, because the pattern lived in the specific word choices and the words are no longer the ones the model chose. No current watermark scheme can survive that, whatever key it uses. Google, in its own description of SynthID-Text presents it as a marker for good-faith use, not as protection against someone determined to remove it.

Figure 4. A walk through equally good rewrites leaves the pattern behind. Image by author

Squeezing a balloon

Remember which detectors the watermark could not hurt: the ones that never ask how confident the model felt. They take the output answer and hold it up against your source documents, checking word by word and phrase by phrase whether each claim is grounded in the provided context. The watermark changed which words got picked, but the claims still matched the sources, so these checks kept working. But the washing watermark-removal approach breaks exactly that safety. A washed text says the same thing in different words. Different words no longer line up with the source documents, so the matching scores fall, and a correct answer starts to look unsupported.

Moreover, the washing tool is itself an “AI rewriting the text”, and nobody is checking its output. Rewriting is known to change things at the edges: a number shifts, a “probably” disappears, a name gets swapped. The cleanup step can create the very mistakes the safety checks were built to catch. And since washing happens after the text is finished, it cannot bring back the natural variation the watermark removed. Conclusion: the confidence-based checks stay broken.

The distortion only moves

Figure 5: The distortion never disappears. Image by author.

The distortion produced by the watermark and its removal process never disappears. It moves, like squeezing a balloon. The watermark presses on one side at writing time and distorts the checks that read doubt. The remover presses on the other side at cleanup time and distorts the checks that read evidence. Text that has been through both steps has weakened both kinds of hallucination-detection approaches. As far as I know, nobody has measured that second effect directly yet. The experiment is sitting there waiting for someone to run it.

Forgery closes the loop from the other side. The same tricks that strip a watermark off can stamp one onto text the model never wrote. So the label “watermarked” can fail both ways: missing from machine text that was laundered, present on false text that was faked.


💬 Comments and suggestions are wellcome.
✉️ You can contact me javier@jmarin.info

References

[1] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance) [https://eur-lex.europa.eu/eli/reg/2024/1689/oj]

[2] Measures for Labeling of AI-Generated Synthetic Content Document. State Information Office Tongzi [2025] №2. Cybersecurity Administration, Ministry of Industry and Information Technology, Ministry of Public Security, State Administration of Radio and Television [https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm]

[3] Farquhar, S., Kossen, J., Kuhn, L. et al. Detecting hallucinations in large language models using semantic entropy. Nature 630, 625–630 (2024). https://doi.org/10.1038/s41586-024-07421-0

[4] Kirchenbauer, J., Geiping, J., Wen, Y., Katz, J., Miers, I., & Goldstein, T. (2023, July). A watermark for large language models. In International conference on machine learning (pp. 17061–17084). PMLR.

[5] Google DeepMind, SynthID documentation and the Hugging Face Transformers integration (SynthIDTextWatermarkLogitsProcessor, BayesianDetectorModel). https://deepmind.google/technologies/synthid/ and https://huggingface.co/docs/transformers

[6] Fu, J., Zhao, X., Yang, R., Zhang, Y., Chen, J., & Xiao, Y. (2024, August). Gumbelsoft: Diversified language model watermarking via the gumbelmax-trick. In Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (pp. 5791–5808).

[7] Verma, A., Phan, N., & Trivedi, S. (2025). Watermarking degrades alignment in language models: Analysis and mitigation. arXiv preprint arXiv:2506.04462.

[8] Jovanović, N., Staab, R., & Vechev, M. (2024). Watermark stealing in large language models. arXiv preprint arXiv:2402.19361.

[9] Hwang, J., Park, S., & Ok, J. (2025). LLM Watermark Evasion via Bias Inversion. arXiv preprint arXiv:2509.23019.

[10] Wu, Z., Gong, G., Zhu, Q., Chen, Y., & Zhao, R. (2026). Linear Ensembles Wash Away Watermarks: On the Fragility of Distributional Perturbations in LLMs. arXiv preprint arXiv:2605.30501.

[11] Zhang, H., Edelman, B. L., Francati, D., Venturi, D., Ateniese, G., & Barak, B. (2023). Watermarks in the sand: Impossibility of strong watermarking for generative models. arXiv preprint arXiv:2311.04378.

Shape
Shape
Stay Ahead

Explore More Insights

Stay ahead with more perspectives on cutting-edge power, infrastructure, energy,  bitcoin and AI solutions. Explore these articles to uncover strategies and insights shaping the future of industries.

Shape

Cisco taps Teleport for infrastructure identity management tech

Cisco is continuing to embed identity management capabilities deeper into its product portfolio by teaming with Teleport, a security vendor headquartered in Oakland, Calif., that’s focused on identity-based infrastructure access management. Cisco is investing in and partnering with Teleport as part of its efforts to bring infrastructure identity everywhere, Matt Caulfield,

Read More »

DOE and SBA Launch SBIC-E Initiative to Unleash Private Capital for American Innovation and Small Businesses

WASHINGTON—The U.S. Department of Energy (DOE) and the U.S. Small Business Administration (SBA) today signed a Memorandum of Agreement establishing the Small Business Investment Company-Energy (SBIC-E) Initiative, a new strategic partnership advancing President Trump’s commitment to supporting America’s small businesses, strengthening domestic manufacturing and supply chains, and ensuring the United States leads in the technologies critical to our national and economic security. The new SBIC-E Initiative brings together DOE’s scientific and technical expertise with SBA’s proven Small Business Investment Company (SBIC) Program, which currently has $58 billion in combined portfolio value. Since 1958, the SBIC Program has invested $147 billion in American small businesses, and since 1995, SBIC-backed businesses have created or supported 10.6 million jobs. “America’s small businesses drive American innovation and affordable, reliable energy access,” said U.S. Secretary of Energy Chris Wright. “By partnering with the Small Business Administration, the Energy Department is committing to invest its resources in American small businesses that will create jobs, strengthen our domestic manufacturing base, and unleash American energy production.” Through DOE’s Office of Technology Commercialization (OTC), the Department will identify strategic technology priorities, provide technical and commercialization expertise, and help engage the investment community. SBA, through its Office of Investment and Innovation, will administer the initiative and encourage the formation and growth of investment funds focused on those priorities. SBIC-E adds another tool to that effort by connecting innovators with private capital to help promising technologies grow, scale, and build here at home. “President Trump is establishing American energy dominance, ending the Green New Scam, and putting our nations’ producers and innovators back in control at the dawn of a new era of energy reliability and abundance,” said SBA Administrator Kelly Loeffler. “Through this partnership, the SBA and Department of Energy are strengthening access to capital in the private sector to

Read More »

Energy Department Announces $500 Million Award to Revitalize American Steelmaking

WASHINGTON—The U.S. Department of Energy (DOE) today announced a $500 million award to support a $1 billion investment at Cleveland-Cliffs’ Middletown Works facility in Middletown, Ohio. Vice President JD Vance and U.S. Energy Secretary Chris Wright visited Middletown Works today to highlight the Trump Administration’s commitment to American steelworkers and the resurgence of American manufacturing. The investment will modernize American steelmaking, protect 2,300 American jobs, and strengthen the domestic steel supply chain. The project advances President Trump’s commitment to put American workers first, bring investment back to American communities, and strengthen the industries critical to America’s economic and national security. Cleveland-Cliffs determined that the business case for the original project scope no longer made sense given customers’ unwillingness to pay a “green premium” for steel. Working with DOE, Cleveland-Cliffs identified a viable alternative that will upgrade and improve the efficiency of the existing coal-fired blast furnace while also capturing and commercializing co-product blast furnace gas (BFG). “President Trump is rebuilding America’s industrial base,” said Secretary Wright. “This investment puts American workers and American manufacturing first. It will modernize one of our nation’s critical steelmaking facilities, protect thousands of jobs, and strengthen our domestic steel production—keeping Ohio at the heart of American manufacturing and strengthening our national security.” The investment will modernize critical steelmaking operations at Middletown Works by rebuilding and upgrading the plant’s main coal-fired ironmaking furnace, deploying AI to optimize furnace operations and improve energy efficiency, and building an on-site facility to convert steel mill process gases into electricity. Follow-on investments will turn industrial byproducts into materials for concrete used in regional infrastructure. “This landmark investment at Middletown Works will secure a reliable domestic supply of high-purity steel while protecting thousands of quality jobs in Ohio,” said Assistant Secretary of Energy Audrey Robertson. “DOE is proud to partner with Cleveland-Cliffs to reduce America’s dependence on foreign products

Read More »

Energy Secretary Keeps Critical Generation Available in Mid-Atlantic

WASHINGTON—U.S. Secretary of Energy Chris Wright today issued an emergency order to address critical grid reliability issues facing the Mid-Atlantic region of the United States. The emergency order directs PJM Interconnection L.L.C. (PJM), in coordination with Constellation Energy Corporation, to ensure Units 3 and 4 of the Eddystone Generating Station in Pennsylvania remain available to operate and to employ economic dispatch to minimize costs for the American people. The units were originally slated to shut down on May 31, 2025. “The energy sources that perform when you need them most are the most valuable,” Secretary Wright said. “During recent Mid-Atlantic heat waves, coal, natural gas, and nuclear kept the lights and air conditioners on. President Trump and the Energy Department are committed to keeping critical generation available when demand is highest, reducing the risk of blackouts and ensuring Americans have affordable, reliable, and secure power—regardless of whether the wind is blowing or the sun is shining.” As outlined in DOE’s Resource Adequacy Report, power outages could increase by 100 times in 2030 if the U.S. continues to take reliable power offline. This order is in effect beginning on August 23, 2026, through November 20, 2026.                                                                                             ###

Read More »

Energy Department Announces $500 Million to Secure America’s Critical Mineral and Battery Supply Chains

WASHINGTON—The U.S. Department of Energy’s (DOE) Office of Critical Minerals and Energy Innovation (CMEI) today announced $500 million for seven selected projects to expand critical mineral and material processing, battery manufacturing, and recycling capacity in the United States. In accordance with President Trump’s Executive Order, Unleashing American Energy, the selected projects advance the President’s agenda to strengthen America’s domestic critical minerals and materials supply chains, reduce reliance on foreign sources, bolster national security, and advance American energy dominance. “For too long, America has depended on foreign actors for critical materials essential to modern life that underpin our economy, energy security, and national security,” said U.S. Secretary of Energy Chris Wright. “President Trump is reversing that dependence by securing our critical supply chains, unleashing American industry, and bringing critical materials production and processing back to the United States.” “DOE is taking decisive action to secure the critical supply chains necessary to power our nation,” said Assistant Secretary of Energy Audrey Robertson. “These projects underscore DOE’s commitment to driving innovation, reducing reliance on foreign sources, and promoting American energy dominance.” This is the third round of funding from DOE’s Battery Materials Processing and Battery Manufacturing and Recycling programs, which support battery materials processing, recycling, and manufacturing projects. These include demonstration projects, construction of commercial-scale facilities, and retrofitting or retooling existing facilities.  Critical minerals and materials are essential to American industry, energy production, and national security. Expanding domestic capacity will help ensure the resources America needs are processed, manufactured, and recycled in the United States.  Information on the selected projects is available here and here.

Read More »

bp lets Shah Deniz compression automation contract

bp has let a contract to Emerson to deliver automation technologies for the Shah Deniz Compression project offshore Azerbaijan. Emerson will provide integrated control and safety systems aimed at enhancing production, safety, and reliability on the new offshore compression platform. The contract includes systems to provide process control, safety shutdown, fire and gas detection, and power management. Together, these systems deliver real-time visibility and remote control of critical operations, Emerson said. The $2.9 billion Shah Deniz Compression project, which includes an electrically powered, normally unattended offshore production platform, is a next stage development of the Caspian Sea Shah Deniz field. Designed to access low-pressure gas reserves and maximize overall recovery, the platform will be equipped with four 11 Mw compressors and serve as the central compression hub for gas from the Shah Deniz Alpha and Bravo platforms. The platform will operate remotely from bp’s onshore Sangachal terminal 55 km south of Baku. The project is expected to enable about 50 billion cu m of additional gas and about 25 million bbl of condensate production and export. Construction is scheduled to be completed in 2029, with first gas compression expected from the Shah Deniz Alpha platform in 2029 and from the Shah Deniz Bravo platform in 2030. The agreement follows a previous automation contract bp signed with Emerson for the Azeri Central East and Shah Deniz Stage 2 developments. bp is operator at Shah Deniz (29.99%) with partners Lukoil (19.99%), TPAO (19%), Cenub Qaz Dehlizi (16.02%), NICO (10%), and MVM (5%).

Read More »

Federal court voids Texas GulfLink license over agency’s ‘serious procedural errors’

The ruling voids the license, halting all construction or progress. Sentinel Midstream declined comment on the ruling and would not answer questions about the status of construction. GulfLink, sited about 30 miles offshore Freeport, Tex., is designed to export up to 1 million b/d via Very Large Crude Carriers (VLCCs) to the government of Japan and Freeport Commodities. The project involves a 44-mile, 42-in. OD pipeline and was scheduled to begin operations around 2028. The estimated $2.1 billion investment was funded as part of a broader trade agreement between the US and Japan. The legal battle stems from a specific rule in the Deepwater Port Act of 1974 that dictates that the federal government can only permit one crude oil deepwater port, including any supporting infrastructure, within a single designated “application area.” Because the competing SPOT project’s pipeline route physically overlaps and intersects GulfLink’s lines, the plaintiff—Citizens for Clean Air & Clean Water in Brazoria County (Better Brazoria), represented by Earthjustice—successfully argued that MARAD violated the “one port” rule when issuing GulfLink’s license in February. The three-judge panel found that MARAD “improperly drew” the map designing the project’s official boundaries to exclude the pipelines and approved two overlapping projects in the same zone instead of only licensing one. The court wrote that the scope of the error made vacatur, not the less serious remand without vacatur, the appropriate remedy. Vacatur deems the license invalid and is used when the court finds “serious procedural errors” that cannot be easily explained or fixed with minor changes. Remand without vacatur sends the decision back to the agency for corrections but leaves the current license in place in the meantime. SPOT project status The $2.5-3-billion SPOT project, developed by Enterprise Products Partners in partnership with Enbridge Inc., also lies about 30 miles from Freeport. Designed to handle VLCCs,

Read More »

IBM unveils dual-architecture processor to run Arm-native apps on Z mainframes

“These caches have enormously low latency, and that is one of the key reasons and key engineering choices to support the performance and scalability of enterprise workloads, very data-intensive workloads like databases and transactions,” Jacobi said. “In addition, we have an on-chip data processing unit for IO acceleration and dedicated AI accelerators as well as accelerators for data compression, cryptography and data sorting.” One of the biggest takeaways from this processor announcement is that the enormous catalog of software already built for Arm becomes accessible on a mainframe without anyone having to port it first, notes Matt Kimball, senior datacenter analyst at Moor Insights & Strategy, in a research note about the news. Still, “this is a 2027 conversation, and with no date, supported software list, or Arm licensing treatment, the work now is inventory and scenario planning rather than financial modeling,” Kimball wrote.

Read More »

PJM’s New Data Center Power Equation

PJM Interconnection has now filed one of the most consequential proposed changes yet in the relationship between data centers and the electric grid. Rather than simply treating a new hyperscale or AI facility like any other customer whose demand will be backed through regional capacity procurement, PJM is proposing a framework under which the largest new loads would need to be supported by new capacity, have their needs covered through the Reliability Backstop Procurement, or face potential curtailment when the regional power system is short of supply. The approach has been developing since PJM launched its Critical Issue Fast Path process for large loads in 2025, but it became substantially more concrete in late July and August 2026. PJM filed its proposed Reliability Backstop Procurement with FERC on July 31 and began accepting applications that day for its FERC-approved Expedited Interconnection Track. On Aug. 13, PJM filed its proposed Interim Resource Adequacy Service, or IRAS, along with the Large Load Registry that would support it. The immediate numbers explain the urgency. PJM’s July 2026 capacity auction for the 2028/2029 delivery year procured 138,318 MW of unforced capacity through the centralized auction. Even after including Fixed Resource Requirement resources, however, PJM came up 6,831 MW short of its reliability requirement. The auction cleared at the FERC-approved $325/MW-day price cap. It was the second consecutive auction in which the PJM region failed to procure its full reliability requirement, something that had not happened before these two auctions. That gap is occurring while demand continues to accelerate. PJM’s 2026 long-term forecast projects summer peak demand growing at an average 3.6% annually over the next decade, compared with just 0.3% in the comparable forecast issued in 2021. Summer peak demand is projected to rise by nearly 66 GW over 10 years. Data centers are

Read More »

Zayo, NVIDIA Build the Long-Haul Backbone for Distributed AI

The data center industry’s increasingly power-first approach to site selection has created a follow-on question: Once the megawatts are found, is there enough network infrastructure to make the site useful at AI scale? Zayo and NVIDIA are putting real infrastructure behind that question. Zayo said it is working with NVIDIA to expand network capacity supporting AI factories across North America, including an 8,000-route-mile program targeting some of the fastest-growing AI corridors in the United States. The project encompasses six new long-haul routes along with overbuilds of existing network across 10 high-demand corridors. The announcement arrives as AI data center development moves beyond the largest established hubs toward markets where power and land may be more readily available, but fiber capacity cannot necessarily be taken for granted. That geography is increasingly important. NVIDIA has separately developed “scale-across” networking technology designed to allow AI infrastructure distributed among different buildings — or even data centers separated by hundreds of kilometers — to operate as a more unified computing environment. Put together, the developments suggest that networking is becoming inseparable from the AI factory buildout itself. Power may determine where the next generation of AI infrastructure can be built. Fiber will increasingly determine how effectively those sites can participate in the larger AI ecosystem. Fiber Follows the Power Zayo CEO Steve Smith said AI demand is changing both where network infrastructure is needed and how aggressively capacity must be deployed ahead of development. “AI is fundamentally reshaping where and how network infrastructure needs to be built across the U.S.,” Smith said. The company’s 8,000-mile program is more nuanced than that top-line number might suggest. Zayo disclosed in April that the expansion includes approximately 3,000 route miles across six new long-haul routes, plus more than 5,000 route miles of overbuilds across 10 existing corridors. Zayo

Read More »

Southern’s 17 GW Pipeline Puts AI Power Demand Into Utility Math

The headline number from Southern Company’s latest earnings report is hard to miss: electricity use by data centers across the utility’s system increased 55% in the second quarter compared with a year earlier. But the more consequential numbers may be the ones sitting behind it. Southern now has more than 1.2 GW of operating data center load, up by more than 500 MW from a year ago. At the same time, its electric utilities have signed contracts and large-load agreements totaling more than 17 GW by the mid-2030s, with another 8 GW in late-stage development and a prospective pipeline of large industrial and data center projects exceeding 75 GW. That leaves an enormous gap between the data center megawatts consuming electricity today and the load Southern has contractually positioned itself to serve during the next decade. For the data center industry, that gap may be the most important part of Southern’s second-quarter story. It offers a look at how utilities are beginning to convert the AI infrastructure boom from forecasts and campus announcements into contracts, generation procurement, transmission investment and eventually energized capacity. From Contracts to Megawatts Southern added roughly 6 GW of contracted large load during the quarter alone. Alabama Power signed three projects representing about 3 GW, while Georgia Power reached a 25-year agreement to serve OpenAI’s planned project in Effingham County near Savannah. That facility is expected to require approximately 3.2 GW and begin taking electric service in phases in 2028. The numbers nevertheless require an important distinction. Seventeen gigawatts contracted does not mean 17 GW will suddenly appear on Southern’s grid. Large data center campuses ramp gradually, often over several years, and Southern executives acknowledged that actual customer ramp schedules do not always match the assumptions made when projects are first approved. CEO Chris Womack said

Read More »

PORTS-Pike Takes Shape as an 8-GW AI Infrastructure Model

Back on March 31, 2026, we discussed we discussed SoftBank and SB Energy’s plans to redevelop the former Portsmouth Gaseous Diffusion Plant site near Piketon as a 10-GW artificial intelligence data center campus supported by almost an equal amount of new power generation. At the time, the plan called for as much as 10 GW of new generation, including 9.2 GW of natural gas capacity, along with approximately $4.2 billion of high-voltage transmission infrastructure developed with AEP Ohio. An initial 800-MW data center phase was targeted for service in 2028. The March story was notable because Pike County appeared to offer a preview of a new model for building hyperscale infrastructure: develop the generation, transmission and data center simultaneously rather than wait for an increasingly congested regional grid to deliver multiple gigawatts of capacity. Not to mention the reuse of a brownfield site with the encouragement of the federal government. Since then, almost every important part of the project has moved forward, and on August 17, the most consequential missing pieces fell into place. NVIDIA announced that it will become the exclusive AI compute infrastructure provider for the PORTS-Pike Technology Campus. OpenAI will be the data center customer, signing a 20-year lease with SB Energy for approximately 8 GW of IT capacity. NVIDIA will invest another $1.5 billion in SB Energy and provide credit support for the land, power and shell infrastructure behind an initial 4.25 GW of IT load, with an option covering approximately another 3.75 GW. The Securities and Exchange Commission filing accompanying the announcement makes the financial commitment even more significant. NVIDIA disclosed that its aggregate payment obligation associated with its initial commitment is capped at $105 billion. That is not a conventional capital commitment to spend $105 billion building the campus, nor is it simply a

Read More »

Nvidia scales back financing guarantee for OpenAI data center

Nvidia is scaling back a proposed financial guarantee tied to a massive OpenAI data center project in Ohio, reducing its initial commitment from as much as $250 billion to less than $120 billion, according to report in the Wall Street Journal. Earlier this month, Nvidia announced partnerships with major financial firms including Apollo Global Management, BlackRock, Blackstone, Brookfield Asset Management, Goldman Sachs and KKR, aimed at mobilizing more than $500 billion in capital for AI computing infrastructure. The change represents a significant restructuring of Nvidia’s role in financing the planned facility, which is being developed by SB Energy, a subsidiary of SoftBank. Under the revised arrangement, Nvidia would guarantee financing for the project’s first phase, representing roughly 5 gigawatts of capacity, or half of the total proposed capacity. Financing for the remaining capacity would be considered separately at a later stage.

Read More »

Microsoft will invest $80B in AI data centers in fiscal 2025

And Microsoft isn’t the only one that is ramping up its investments into AI-enabled data centers. Rival cloud service providers are all investing in either upgrading or opening new data centers to capture a larger chunk of business from developers and users of large language models (LLMs).  In a report published in October 2024, Bloomberg Intelligence estimated that demand for generative AI would push Microsoft, AWS, Google, Oracle, Meta, and Apple would between them devote $200 billion to capex in 2025, up from $110 billion in 2023. Microsoft is one of the biggest spenders, followed closely by Google and AWS, Bloomberg Intelligence said. Its estimate of Microsoft’s capital spending on AI, at $62.4 billion for calendar 2025, is lower than Smith’s claim that the company will invest $80 billion in the fiscal year to June 30, 2025. Both figures, though, are way higher than Microsoft’s 2020 capital expenditure of “just” $17.6 billion. The majority of the increased spending is tied to cloud services and the expansion of AI infrastructure needed to provide compute capacity for OpenAI workloads. Separately, last October Amazon CEO Andy Jassy said his company planned total capex spend of $75 billion in 2024 and even more in 2025, with much of it going to AWS, its cloud computing division.

Read More »

John Deere unveils more autonomous farm machines to address skill labor shortage

Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More Self-driving tractors might be the path to self-driving cars. John Deere has revealed a new line of autonomous machines and tech across agriculture, construction and commercial landscaping. The Moline, Illinois-based John Deere has been in business for 187 years, yet it’s been a regular as a non-tech company showing off technology at the big tech trade show in Las Vegas and is back at CES 2025 with more autonomous tractors and other vehicles. This is not something we usually cover, but John Deere has a lot of data that is interesting in the big picture of tech. The message from the company is that there aren’t enough skilled farm laborers to do the work that its customers need. It’s been a challenge for most of the last two decades, said Jahmy Hindman, CTO at John Deere, in a briefing. Much of the tech will come this fall and after that. He noted that the average farmer in the U.S. is over 58 and works 12 to 18 hours a day to grow food for us. And he said the American Farm Bureau Federation estimates there are roughly 2.4 million farm jobs that need to be filled annually; and the agricultural work force continues to shrink. (This is my hint to the anti-immigration crowd). John Deere’s autonomous 9RX Tractor. Farmers can oversee it using an app. While each of these industries experiences their own set of challenges, a commonality across all is skilled labor availability. In construction, about 80% percent of contractors struggle to find skilled labor. And in commercial landscaping, 86% of landscaping business owners can’t find labor to fill open positions, he said. “They have to figure out how to do

Read More »

2025 playbook for enterprise AI success, from agents to evals

Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More 2025 is poised to be a pivotal year for enterprise AI. The past year has seen rapid innovation, and this year will see the same. This has made it more critical than ever to revisit your AI strategy to stay competitive and create value for your customers. From scaling AI agents to optimizing costs, here are the five critical areas enterprises should prioritize for their AI strategy this year. 1. Agents: the next generation of automation AI agents are no longer theoretical. In 2025, they’re indispensable tools for enterprises looking to streamline operations and enhance customer interactions. Unlike traditional software, agents powered by large language models (LLMs) can make nuanced decisions, navigate complex multi-step tasks, and integrate seamlessly with tools and APIs. At the start of 2024, agents were not ready for prime time, making frustrating mistakes like hallucinating URLs. They started getting better as frontier large language models themselves improved. “Let me put it this way,” said Sam Witteveen, cofounder of Red Dragon, a company that develops agents for companies, and that recently reviewed the 48 agents it built last year. “Interestingly, the ones that we built at the start of the year, a lot of those worked way better at the end of the year just because the models got better.” Witteveen shared this in the video podcast we filmed to discuss these five big trends in detail. Models are getting better and hallucinating less, and they’re also being trained to do agentic tasks. Another feature that the model providers are researching is a way to use the LLM as a judge, and as models get cheaper (something we’ll cover below), companies can use three or more models to

Read More »

OpenAI’s red teaming innovations define new essentials for security leaders in the AI era

Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More OpenAI has taken a more aggressive approach to red teaming than its AI competitors, demonstrating its security teams’ advanced capabilities in two areas: multi-step reinforcement and external red teaming. OpenAI recently released two papers that set a new competitive standard for improving the quality, reliability and safety of AI models in these two techniques and more. The first paper, “OpenAI’s Approach to External Red Teaming for AI Models and Systems,” reports that specialized teams outside the company have proven effective in uncovering vulnerabilities that might otherwise have made it into a released model because in-house testing techniques may have missed them. In the second paper, “Diverse and Effective Red Teaming with Auto-Generated Rewards and Multi-Step Reinforcement Learning,” OpenAI introduces an automated framework that relies on iterative reinforcement learning to generate a broad spectrum of novel, wide-ranging attacks. Going all-in on red teaming pays practical, competitive dividends It’s encouraging to see competitive intensity in red teaming growing among AI companies. When Anthropic released its AI red team guidelines in June of last year, it joined AI providers including Google, Microsoft, Nvidia, OpenAI, and even the U.S.’s National Institute of Standards and Technology (NIST), which all had released red teaming frameworks. Investing heavily in red teaming yields tangible benefits for security leaders in any organization. OpenAI’s paper on external red teaming provides a detailed analysis of how the company strives to create specialized external teams that include cybersecurity and subject matter experts. The goal is to see if knowledgeable external teams can defeat models’ security perimeters and find gaps in their security, biases and controls that prompt-based testing couldn’t find. What makes OpenAI’s recent papers noteworthy is how well they define using human-in-the-middle

Read More »