Imagine you're a building inspector. You know no building is earthquake-proof — but you don't need it to be. You need to certify that the building meets a specific code at a specific confidence level, re-inspect periodically, and document what was tested. This paper does the same thing for AI text watermarking: it stops chasing the impossible goal of unbreakable marks and builds an inspection regime instead. The core claim is that strong watermarking — a mark that survives any adaptive adversary — is provably impossible for free-form text. The authors don't just assert this; they formalize a description-length robustness profile showing that detectable statistical bias decays as text is edited, and that the sample size required for detection grows with the inverse square of that decay rate. The key move is replacing an unidentified Shannon-entropy constant with collision entropy, which gives you an actual computable bound rather than a theoretical placeholder. From there, the paper constructs a detection framework using label-conditional conformal prediction sets. Instead of a binary watermarked/not-watermarked output, the detector produces three verdicts: 'watermark supported,' 'not supported,' or 'inconclusive.' Crucially, the false-attribution rate and false-exclusion rate are controlled separately, and coverage guarantees hold as finite-sample results under exchangeability — not asymptotic promises. This is the statistical backbone that makes the legal compliance story work. The validation is a small reproducible simulation of a tournament watermark scheme. The simulation confirms both theoretical claims — bias decay matches the predicted profile, and the conformal sets maintain coverage. One practical finding stands out: the surviving-token rule, a common heuristic for estimating how much editing a watermark can tolerate, overstates the actual tolerable edit rate by roughly twofold. If you're building a watermark detector and using that rule, you're twice as optimistic as you should be. The paper's contribution is architectural, not algorithmic. It doesn't propose a new watermarking method. It proposes a compliance stack: a premarket certificate (what the watermark can and cannot do), a signed detector report (what was found in this specific sample), and a postmarket recalibration protocol (how to update as the state of the art shifts). This maps directly onto Article 50(2) of the EU AI Act and the Commission's 2026 Code of Practice, including the qualifiers about technical feasibility, cost, and content-specific limits. The intellectual honesty is notable. The authors explicitly do not claim universal robustness. They treat the impossibility of strong watermarking not as a problem to solve but as a boundary condition to design around. The framework's value is proportional to how seriously regulators take the distinction between 'unbreakable detection' and 'auditable compliance with known limitations' — a distinction the AI Act's text already makes but that most technical work ignores. What's missing is scale. The simulation is small and reproducible, but there's no deployment on a production LLM, no adversarial red-teaming beyond the theoretical model, and no comparison to existing commercial watermarking systems like those from OpenAI or Google DeepMind. The theory is clean; the empirical gap between theory and practice remains open.