It's presumably so they can rate-limit people who are trying to reverse-engineer or otherwise strip it (e.g. iteratively tweaking until it stops getting detected)
I wonder how relevant this really is.
How hard can it be to download a set of real images and generated ones in order to train a model to detect and strip the watermark with minimal perceptual difference?
> iteratively tweaking until it stops getting detected
I don't think that dodgy folks have any issue with registering thousands of IDs. I know that I used to regularly get approached by these Chinese companies that were selling good reviews of my free apps. They did this by having thousands of legit AppleID accounts that would download and rate the app.
I haven't been approached by one of these in a long time. I guess Apple figured out how to put the kibosh on them.