// GLOSSARY · AI WATERMARK DETECTION

AI watermark detection

Checking whether a file carries a watermark that marks it as AI-made — reading a planted signal like Google SynthID or C2PA, not guessing from style.

Last verified · 2026-10-08 · by Moe Ameen

What it is

AI watermark detection is the act of checking a file to see whether it carries a watermark that identifies it as AI-generated. The defining feature is that it reads a signal the generating model deliberately planted — an invisible [SynthID](/glossary/ai-content-watermark) mark woven into the pixels, frames, or waveform, or a [C2PA](/glossary/c2pa) Content Credentials record in the file's metadata — rather than guessing an origin from style. That makes a positive result close to decisive for content the participating tool actually marked, which is the property that separates watermark detection from the probabilistic AI "detectors" that scan an essay for statistical tells.

The most visible example is Google's SynthID Detector, which on October 7, 2026 opened to the public globally at synthid.com after roughly a year and a half gated to journalists, media professionals, and researchers since its announcement at Google I/O in May 2025. You upload an image, video, or audio file and it reports whether Google DeepMind's SynthID watermark is present — and, as of that release, it reads not only Google's own output but partner content from OpenAI, NVIDIA, and Kakao, with Apple named as coming soon. C2PA verification runs on a parallel track: a Content Credentials inspector reads the signed provenance record attached to a file's metadata, reporting the issuer, the generating tool, and the edits logged along the way.

The single most important thing to understand about watermark detection is what a negative result does and does not mean. Google states plainly that SynthID Detector "is not a general AI detector": it can only identify media from tools that adopted the scheme, and heavy editing can degrade a mark below the detection threshold. So "watermark not detected" means no participating watermark was found — not that the content is human-made. Detection confirms presence far more reliably than it confirms absence, and that asymmetry governs every correct use of the tool.

The history

Watermark detection as a public capability is young. The underlying marks came first: the Coalition for Content Provenance and Authenticity (C2PA) defined Content Credentials as a cryptographic provenance record, and Google DeepMind productionized SynthID across images, audio, video, and text from 2023 onward, with SynthID-Text published in Nature in 2024 and open-sourced. For most of that period, reading those signals at scale required either specialist tooling or vendor access — detection existed, but not as something an ordinary creator or viewer could run.

That gate came down over 2025 and 2026. Google announced the SynthID Detector portal at I/O in May 2025 and offered early access through a waitlist aimed at journalists and researchers, then opened it to everyone on October 7, 2026. In parallel, OpenAI began previewing a public verification tool that reads both Content Credentials and SynthID-style signals to check whether an image came from its models, and Google folded provenance checks into Search, the Gemini app, and Chrome. Regulation pushed in the same direction: the EU AI Act's Article 50 transparency rules, effective August 2, 2026, require providers of generative systems to mark synthetic media in a machine-readable, detectable format — which only matters if the marks can actually be read, making public detection the other half of the mandate.

How it behaves across platforms

PlatformBehavior
Google SynthID DetectorPublic since October 7, 2026 at synthid.com, globally in English. Reads the invisible SynthID watermark in images, video, and audio from Google plus partners OpenAI, NVIDIA, and Kakao (Apple coming soon), and highlights the regions most likely watermarked. Explicitly "not a general AI detector" — it only sees participating models.
C2PA Content Credentials inspectorReads the signed provenance record in a file's metadata — issuer, generating tool, and logged edits. Rich detail when present, but the record is lost the moment a tool strips it: a screenshot, a careless re-export, or a CMS that discards metadata on upload. Best paired with an in-content watermark check, not relied on alone.
OpenAI verification toolPreviewed as a public checker that looks for both C2PA Content Credentials and a SynthID-style watermark to determine whether an image came from OpenAI models. Reading two signals at once gives a fuller answer than either alone, since they survive different kinds of handling.
Platform auto-detection (Meta / TikTok / YouTube)Platforms run their own detection on upload, reading provenance signals like C2PA to apply "AI info" / AI-generated labels automatically — so a file can be labeled at the platform layer even when a creator sets nothing. This is detection operating at scale and outside the creator's control.
Text (the blind spot)There is no drag-and-drop detector for AI text. The only durable signal is a statistical token-choice watermark read by a key-based test, and most text models embed none. An AI image is far more likely to be detectable than an AI paragraph.

Concrete examples

  • A newsroom editor drags a suspicious viral image into SynthID Detector; it flags a SynthID watermark and highlights the marked regions, confirming a participating AI tool made it — a one-upload check that a year earlier needed researcher access.
  • A brand's legal team runs an agency-supplied product video through a C2PA Content Credentials inspector and reads the generating tool and edit history off the metadata — until someone screenshots a frame, which strips the record and leaves only the in-content signal to read.
  • A creator uploads their own heavily-edited AI image to the detector expecting a clear "AI" verdict and instead gets "not detected," because the compression and filtering degraded the SynthID mark below threshold — a reminder that absence is not proof.
  • A teacher assumes SynthID Detector will catch an AI-written essay, uploads the text, and finds there is no text option at all — watermark detection covers image, video, and audio, and AI prose needs a different, far less reliable approach.

Common mistakes

  • Reading "not detected" as "human-made." The tool only sees participating models and only reads marks that survived editing, so a clean result is the absence of one specific signal, never a verdict on origin.
  • Confusing watermark detection with an AI detector. One reads a planted, key-verifiable signal (close to decisive); the other guesses from style (probabilistic, prone to false positives on human work). They answer different questions and are not interchangeable.
  • Expecting it to detect AI text. Public watermark detection covers image, video, and audio; text has no imperceptible layer to hide a durable signal in, and most models embed nothing.
  • Treating a positive result as proof the content is fake or false. Detection reads how a file was made, not whether what it depicts is true — provenance and veracity are separate questions.
  • Assuming a watermark-free export is untraceable. Stripping a visible badge removes only the human-facing mark; an invisible SynthID signal or a C2PA credential can remain and be read.

The honest take

The public launch of SynthID Detector is quietly one of the more consequential moments in the AI-content debate, because it collapses a hypothetical into a fact. "Can anyone actually tell this is AI?" used to be a shrug — technically yes, practically no, not without access most people lacked. Now it is a one-upload answer for images, video, and audio from a growing set of tools. The right reaction is neither relief nor panic. It is to internalize the asymmetry: the tool is strong evidence of presence and weak evidence of absence, so use a positive result as close to proof and never use a negative as an alibi.

For a working creator the consequence lands at publish time, not at generation time. Once provenance is checkable by a viewer or a platform in seconds, the energy some people still spend trying to scrub or outrun a watermark is wasted — and it is exactly the concealment platforms are built to catch. The durable posture is to assume your visual AI output is detectable, disclose where a platform or the law asks, and compete on quality. A publishing engine like [Kompozy](/) matters here only in that it puts that disclosure decision in one governed place — set per platform at a human review step — so the honest label is applied as part of shipping rather than remembered afterward. The lesson outlasts any one portal: detection is becoming ambient, and the creators who do well are the ones who stopped treating it as a threat to evade.

Frequently asked questions

What is AI watermark detection?

It is checking a file to see whether it carries a watermark that identifies it as AI-generated. Unlike a style-based AI detector that guesses from writing or visual cues, watermark detection reads a signal the model deliberately planted — an invisible SynthID mark in the content, or a C2PA Content Credentials record in the metadata — which makes a positive result close to decisive for content that participating tool actually marked.

Is Google SynthID Detector free and public?

Yes. Google opened SynthID Detector to everyone globally, in English, on October 7, 2026, at synthid.com. It had been limited to journalists, media professionals, and researchers via a waitlist since it was announced at Google I/O in May 2025. You upload an image, video, or audio file and it reports whether a SynthID watermark is present, covering Google's models plus partners OpenAI, NVIDIA, and Kakao.

Does a clean result mean the content is not AI-generated?

No. Google states the tool "is not a general AI detector." It only identifies media from companies that adopted SynthID, so content from a non-participating model returns clean even if fully AI-made, and heavy editing can weaken a real watermark below the detection threshold. A "not detected" result means no participating watermark was found — not that a human made it.

Can you detect AI-written text with a watermark detector?

Not with a public drag-and-drop tool. Watermark detection portals cover image, video, and audio, where a signal can be hidden perceptually. Text has no such headroom; the only durable mark is a statistical bias in the model's word choices, read by a key-based test, and most text models embed none — so AI prose is far harder to detect than an AI image.

What is the difference between SynthID detection and C2PA verification?

SynthID detection reads an invisible watermark embedded in the content itself, which survives cropping, screenshots, and re-encoding. C2PA verification reads a cryptographic provenance record in the file's metadata, which carries rich detail but is lost the moment a tool strips it. They are complementary, and the better verifiers now check for both because each survives different handling.

Related terms

  • AI content watermark — An umbrella term for any signal that marks content as AI-generated: a visible badge, an invisible SynthID mark, a C2PA metadata record, or a text watermark.
  • Visible AI watermark — An on-file badge — like Gemini's corner sparkle or a 'Made with AI' label — that shows a viewer content is AI-generated, unlike an invisible SynthID mark.
  • AI text watermarking — A hidden statistical signal embedded in an AI model’s word choices as it writes, letting a detector later confirm the text was machine-generated.
  • C2PA — The open standard behind Content Credentials — a signed, tamper-evident record of a file's origin and edit history, embedded in its metadata.
  • Likeness detection — Platform technology that scans uploads for a specific enrolled person’s face or voice and flags AI-generated content using their identity, so they can review it or request removal.
Related deep guides

← All terms · Get started →