LLMs never are limited to "exact words", because their output is inherently probabilistic. The method Anthropic (along with Gemini, who has been using the exact same watermark for at least a year) uses doesn't bias the output token distribution, just reseeds the PRNG in a way that can be detected after the fact: https://www.anthropic.com/news/claude-text-watermark#which-s...