Actually they're working on embedding a verifiable, steganographic signature into GPT responses that would let them detect it's outputs later. It would basically bias common word choices in a subtle way that requires a private key to verify.
That sounds like it would be simple to work around by automatically replacing words with sensible synonyms, changing punctuation, or even translating between languages. I wonder if there's a way to encode the "signature" such that it would survive these lossy transformations.
Maybe. I believe it's probably deeper than just the choice of synonyms, the choice of "next token" as a whole. For more information see Aaronson's description of his work in the section titled "My Projects at OpenAI":
Easily defeated by another something good at statistical analysis... say an LLM.
LLMs can't so easily defeat cryptography which is used in the encoding. If you have one powerful enough to mess with GPT's output to make it pass a watermark test, you probably have one powerful enough to generate the output you're looking for to begin with, so why bother with GPT at all?