Breaking
September 2, 2026

Here’s How AI Watermarks Work (and How to Properly Check for One) Eric Ravenscraft | usagoldmines.com

Recently, Anthropic announced that its Claude models will soon begin marking its text output with invisible watermarks. At the same time, Google revealed that its own visible Gemini watermark on generated images will now be optional. These are just two contradictory examples of the wildly varied methods of watermarking AI output. So, let’s break down how AI watermarks work, and how you can detect them even when they’re “invisible.”

How does AI watermarking work?

The exact method for watermarking AI output will depend on the type of media being generated, but the principle is generally the same: The generated media is embedded with data that is undetectable (or occasionally detectable) to the human eye or ear, but which identifies it as AI-produced. Watermark-detecting tools can then be used to identify if something was made with AI, without guessing or using an unreliable AI “detector”. Here are some examples of how watermarks may be implemented for various media types.

  • For images: Since the pixels of an image are mathematical values, they can be slightly modified to embed a digital signature, without perceptible changes to the image itself. Google’s SynthID, for example, distributes an invisible signature across any generated image, so even a cropped version will still contain detectable portions of the watermark. Note: This is distinct from the visible gray symbol in the corner of Gemini images. Even if you turn off the visible Gemini watermark, the invisible one remains.

  • For audio: Embedding a watermark in audio files can be even easier, placing signature sounds outside the range of human hearing (typically below 20Hz or above 20,000Hz). SynthID has an audio component that can be heard by watermark detectors, but remains imperceptible to the ear.

  • For video: Naturally, generated video tends to use a combination of both of the above watermarking methods, though it’s worth keeping in mind that someone making fake content could, for example, generate AI audio to accompany real video, meaning the watermark might appear in one piece of the content, but not another.

  • For text: Every next word an LLM generates comes with a probability score. The sentence “The cat is” could end with “fluffy,” “cute,” or “small.” Each one of those words is given a percentage likelihood that it will appear. Text watermarks work by inflating the chances that certain sets of random words will appear. This can make it possible to detect LLM-generated text without changing its semantic meaning. However, this tends to work better for longer pieces of text, which provides more chances to detect the presence of less-likely words.

  • For metadata: While not strictly a watermark, C2PA is a framework for adding metadata that can help verify the origin of a piece of media. Some camera manufacturers, for example, have implemented C2PA to give photographers a traceable record of where an image came from. This can also include noting whether an image was generated with AI tools.

While SynthID originated with Google’s DeepMind, the company open-sourced the protocol, and now it’s also used by other AI companies, including OpenAI. Some companies. conversely, do not use a watermark at all—and among those that do, the implementation can be inconsistent between tools. In other words, the presence of an AI watermark can confirm something was made or modified with AI, but the absence of one can’t prove it wasn’t.

How can you detect AI watermarks?

Despite SynthID and C2PA being relatively common, it’s still kind of a crapshoot to properly detect the presence of watermarks or metadata that will confirm if a piece of media was generated with AI. OpenAI has a standalone tool to check for SynthID or C2PA in a file, and Google lets you access its verification tools via Gemini or, with the right prompting, directly via Google itself.

However, these tools have limitations. OpenAI’s detector, for some reason, only seems to detect media generated by OpenAI itself. During my testing, I tried uploading images generated via Gemini—which could detect its own SynthID watermark—and OpenAI’s tool did not find it.

Meanwhile, Google created a SynthID Detector portal, but it’s currently available on an invite-only basis, specifically for journalists and verification professionals. You can still access some SynthID detection functions via Gemini or Google, though in some cases, you’ll need the right prompts to do so. In my testing, when asking “is this real” for a known AI-generated image via Gemini, the tool invoked a verification tool to check for SynthID. However, when doing the same process via Google, the LLM’s output resembled a visual analysis instead. It only invoked a SynthID check when specifically asked to do so.

Even if you do your diligence to check for every version of a SynthID watermark or C2PA metadata, it’s still possible that a piece of media could have some other form of watermark that requires a different detector. Unfortunately, unless you have a strong indicator of which tool was used to create a piece of generated media, it can still be difficult to thoroughly check for every kind of watermark.

When it comes to text-based watermarks like the kind Claude or even Gemini use, detecting them can still be very difficult. For starters, neither offers a public way to check for the text watermark just yet (Google’s SynthID Detector portal can do so, but it’s not generally available).

Can AI watermarking be circumvented?

With enough work, any watermark can technically be removed, though SynthID specifically is pretty resistant to most typical forms of modification. An AI-generated image with a SynthID watermark that has been cropped, filtered, or modified can still retain enough of its original watermark to be detectable. It’s not impossible to remove, but it’s generally hard to do so accidentally.

Removing metadata like C2PA, on the other hand, is considerably easier. For images, that’s as simple as taking a screenshot. A screenshot of an image essentially creates a new image file based on the pixels visible on the screen. This means that any watermark that affects those pixels can remain, but an entirely new set of metadata is created, wiping any C2PA data along with it.

That means that if you want to maintain a metadata chain that lets you prove the authenticity of an image, it’s important to download or upload the specific original files and make sure any editing tools you use support maintaining that metadata.

Text watermarks are among the easiest to get around. Since they work by simply altering the probability that certain words will appear, running text through another AI tool that rephrases the words without using a watermark, or even manually rewriting a block of text, can potentially remove the watermark.

Does a watermark always mean a piece of media was AI-generated?

It’s important to keep in mind that a watermark can be added to an authentic piece of media. If someone uploads an authentic photo to a tool like Gemini to perform simple edits, the output image will have a SynthID watermark, too. This doesn’t mean the whole image is inauthentic, but it will still be flagged by watermark detectors.

Similarly, it’s possible to generate an image of a subject, cut the subject out, and add it to an image using traditional manipulation techniques like Photoshop to create an inauthentic image that’s mostly made from an authentic image. Whether or not the watermark will remain on the portion of an image that was AI-generated can only be determined on a case-by-case basis.

As mentioned before, the absence of a watermark cannot prove that an image is authentic. Even the presence of a watermark can’t prove that the substance of an image isn’t real. Watermarks and metadata are simply tools to help you figure out where a piece of media likely came from and how it might’ve been modified. Ultimately, it’s still up to you to verify the things you see and hear online.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.