SafetyPublished Lead storyThat day's edition
How SynthID watermarks AI content and what limits it
This explainer covers how Google DeepMind's SynthID hides a signal in AI-generated images, video, audio and text, how C2PA records fit alongside it, and where watermarks are weak.
Check our sources · 6 sources, 14 claims
Video: Google DeepMind on YouTube
Key points
- Google says SynthID embeds watermarks into AI-generated images, audio, text or video that humans cannot perceive and that SynthID's technology can detect.
- For text, Google says SynthID adjusts token probability scores; the Nature paper says it modifies only the sampling procedure and detects the mark without the underlying model.
- The paper lists limits: generative watermarks are vulnerable to stealing, spoofing and scrubbing, and are weakened by edits such as paraphrasing by a language model.
What happened
SynthID is a tool from Google DeepMind to watermark and identify content generated through AI. SynthID embeds digital watermarks into AI-generated images, audio, text or video, and the watermarks are imperceptible to humans but can be detected by SynthID’s technology.
For images, Google says SynthID adds an invisible watermark that is designed to stand up to modifications like cropping, adding filters, changing frame rates or lossy compression.
For text, Google explains that a language model generates text one token at a time, each token has a probability score, and SynthID adjusts these probability scores to generate a watermark.
The Nature paper on SynthID-Text says the scheme does not affect model training, modifies only the sampling procedure, and detects the watermark without using the underlying language model. The paper says SynthID-Text uses a sampling algorithm called Tournament sampling.
In a live experiment the authors assessed feedback from nearly 20 million Gemini responses, which they say confirmed that text quality was preserved.
Google DeepMind’s Pushmeet Kohli said in a DeepMind podcast published 1 October 2026 that the watermarks Google builds are designed for "imperceptibility, robustness and scalability" (04:13).
The paper lists limits: generative watermarks are vulnerable to stealing, spoofing and scrubbing attacks, and are weakened by edits to the text such as paraphrasing by a language model. It also says that enforcing watermarking on open-source models deployed in a decentralized manner is difficult.
A watermark is one of two ways to tie content to its origin: the C2PA specification describes a signed manifest of provenance information, which it also calls Content Credentials.
In that specification a hard binding is one or more cryptographic hashes that identify an asset or part of it, and a soft binding can be a content identifier embedded as an invisible watermark.
Google launched the SynthID Detector, a verification portal, on 20 May 2025, and said then that over 10 billion pieces of content had been watermarked with SynthID. On 30 September 2026 Google introduced SynthID Bio, which watermarks AI-designed proteins, and says watermarked designs matched the performance and natural diversity of unwatermarked ones in laboratory tests.
What it means for you
Our viewSynthID and C2PA are built differently. Google says the image and video watermark is designed to stand up to cropping, filters, changed frame rates and lossy compression.
A C2PA manifest carries a claim signature, and the C2PA specification allows an invisible watermark as a soft binding inside it, so the two can be used together. The Nature paper says text watermarks weaken when a language model paraphrases the text and that enforcing watermarking on open-source models is difficult.
If your team relies on marks to identify AI content, ask each vendor which mark it applies to each content type, and test whether the mark survives your own editing steps.
This part is our reading of the facts above. It adds no fact of its own.
Your reaction
One press adds one. We count a number for each notice and day, never who pressed it. The counts help us decide what goes in the monthly issue. If you are signed in to My notis, your own page counts yours too.
Check our sources
6 sources, 14 claims. We opened each source and checked every sentence above against it.
1 SynthID
Open the source-
SynthID is a tool from Google DeepMind to watermark and identify content generated through AI.
SynthID A tool to watermark and identify content generated through AI
-
SynthID embeds digital watermarks into AI-generated images, audio, text or video, and the watermarks are imperceptible to humans but can be detected by SynthID’s technology.
SynthID embeds digital watermarks directly into AI-generated images, audio, text or video. The watermarks are embedded across Google’s generative AI consumer products, and are imperceptible to humans – but can be detected by SynthID's technology.
-
For images and video, Google says SynthID adds an invisible watermark that is designed to stand up to modifications like cropping, adding filters, changing frame rates or lossy compression.
Narrowed to what the source supportsSynthID adds an invisible digital watermark to an AI-generated image (or video segment). The watermark doesn’t change the image or video quality. It’s added the moment content is created, and designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression.
-
For text, Google explains that a language model generates text one token at a time, each token has a probability score, and SynthID adjusts these probability scores to generate a watermark.
Large language models generate text one word (token) at a time. Each word is assigned a probability score, based on how likely it is to be generated next. ... SynthID adjusts these probability scores to generate a watermark.
2 Scalable watermarking for identifying large language model outputs
Open the source-
The Nature paper on SynthID-Text says the scheme does not affect model training, modifies only the sampling procedure, and detects the watermark without using the underlying language model.
SynthID-Text does not affect LLM training and modifies only the sampling procedure; watermark detection is computationally efficient, without using the underlying LLM.
-
The paper says SynthID-Text uses a sampling algorithm called Tournament sampling.
In the SynthID-Text generative watermarking scheme, we use the Tournament sampling algorithm.
-
In a live experiment the authors assessed feedback from nearly 20 million Gemini responses, which they say confirmed that text quality was preserved.
we conducted a live experiment that assessed feedback from nearly 20 million Gemini responses, again confirming the preservation of text quality.
-
The paper lists limits: generative watermarks are vulnerable to stealing, spoofing and scrubbing attacks, and are weakened by edits to the text such as paraphrasing by a language model.
Another limitation of generative watermarks is their vulnerability to stealing, spoofing and scrubbing attacks, which is an area of ongoing research. In particular, generative watermarks are weakened by edits to the text, such as through LLM paraphrasing
-
It also says that enforcing watermarking on open-source models deployed in a decentralized manner is difficult.
Furthermore, the rise of open-source models presents a challenge, as enforcing watermarking on these models deployed in a decentralized manner is difficult.
3 From deepfakes to DNA: the science of watermarking AI
Open the source-
Google DeepMind’s Pushmeet Kohli said in a DeepMind podcast published 1 October 2026 that the watermarks Google builds are designed for "imperceptibility, robustness and scalability" (04:13).
4 C2PA Technical Specification 2.2
Open the source-
The C2PA specification defines a C2PA Manifest as the set of information about the provenance of an asset, including a claim signature, and calls it a Content Credential.
Narrowed to what the source supports2.3.4. C2PA Manifest The set of information about the provenance of an asset based on the combination of one or more assertions (including content bindings), a single claim, and a claim signature. ... 2.3.6. Content Credential This is the preferred non-technical term for a C2PA Manifest.
-
In that specification a hard binding is one or more cryptographic hashes that identify an asset or part of it, and a soft binding can be a content identifier embedded as an invisible watermark.
2.3.12. Hard binding One or more cryptographic hashes that uniquely identifies either the entire asset or a portion thereof. 2.3.13. Soft binding A content identifier that is either (a) not statistically unique, such as a fingerprint, or (b) embedded as an invisible watermark in the identified digital content.
5 Google SynthID Detector
Open the source-
Google launched the SynthID Detector, a verification portal, on 20 May 2025, and said then that over 10 billion pieces of content had been watermarked with SynthID.
6 We're introducing SynthID Bio, bringing our watermarking technology to synthetic biology
Open the source-
On 30 September 2026 Google introduced SynthID Bio, which watermarks AI-designed proteins, and says watermarked designs matched the performance and natural diversity of unwatermarked ones in laboratory tests.
Nothing appears on this site that we have not opened and linked.