Watermarking Should Be Treated as a Monitoring Primitive
Watermarking is widely proposed for provenance, attribution, and safety monitoring in generative models. We argue that it should be evaluated and governed as a monitoring primitive through two complementary observer models. Internal observers use detector or decoder access and entity mappings for attribution; external observers learn entity-specific signals from labeled outputs without keys or detectors. With persistent entity bindings and reliable inference, either pathway can support monitoring. We show that even zero-bit watermarking supports internal attribution under per-entity multi-key deployments without explicitly encoding identity, and demonstrate external identification in selected text and image configurations. External exposure depends on persistent, learnable watermark structure and is not universal, while internal attribution also remains conditional on reliability and access. These findings motivate governance of attribution access and deployment choices alongside evaluation of design-dependent entity linkability, de-anonymization or re-identification, beyond per-sample robustness.