Research · curated 18 Sep 2026
The Provenance Tax: Understanding the Impact of LLM Watermarking on AI Agent Behavior
First reported lasso.security
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Watermarking mandated for provenance can subtly shift an agent's refusal decisions and tool-calling arguments, meaning a compliance-driven safety mechanism may inadvertently weaken resistance to prompt injection in deployed AI agents.
Lasso Security's research "The Provenance Tax" empirically studies how LLM text watermarking (SynthID-Text, as adopted by Anthropic's Claude to comply with the EU AI Act) alters the token-sampling process and thereby changes model behavior. The authors find measurable "sampling drift" affecting both model refusal behavior and agent tool calling, noting the effect is model- and key-dependent and that a weakened refusal becomes more consequential under prompt injection when the model can act through tools.