Part of the legislation requires them to make a public AI text detector (ala GPTZero I assume).

Wouldn’t having that be enough to eventually reverse engineer the key?

Not if they designed the algorithm right.

Probably not to get the key, but you could certainly use it adversarially to remove the watermark.

Removal may come down to changing every third token to a different one.