We can remove the first of these layers completely, disrupt the second on the images we have tested, and do nothing at all about the third. That split is the whole difference between C2PA, SynthID and a platform’s AI label. C2PA is a signed note stored beside the picture. SynthID is a pattern woven into the picture. A platform label is a decision someone else makes about the picture after you post it, with or without either of the other two.
Three layers, three owners
The metadata layer is the file’s paperwork: text fields such as EXIF and XMP, including the IPTC digital source type trainedAlgorithmicMedia, plus the C2PA manifest. The generator writes it, anyone holding the file can delete it, and it goes the moment an app saves a new file without copying it across.
The watermark layer lives in the pixel values. Google DeepMind says SynthID is “designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression,” and OpenAI said in May 2026 that its images now carry SynthID too. Google’s own SynthID Detector portal is being tested with journalists and media professionals, and everyone else can only join a waitlist, so the public route is to ask Gemini, which checks for SynthID and adds its own reasoning.
The platform layer belongs to whoever hosts the post. Meta has said it labels images when it finds C2PA or IPTC markers from Google, OpenAI, Microsoft, Adobe, Midjourney and Shutterstock, and that it is building classifiers for content that carries no marker at all.
What a screenshot, a re-save, a clean and a regeneration each do
| Action | Metadata and C2PA | Pixel watermark (SynthID) | Platform classifier |
|---|---|---|---|
| Screenshot | Gone. The screenshot is a new file. | Can survive. It sits in the pixels the screenshot copies. | Unaffected. It judges the picture, which looks the same. |
| Re-save or export from an editor | Usually gone. A macOS re-save dropped a Google manifest in our test. | Designed to survive lossy compression, by Google’s account. | Unaffected. |
| Metadata-only cleaning (ExifTool, or the first step of our wipe) | Gone, with the image data unchanged byte for byte. | Untouched. No pixel changes. | Unaffected, though labels triggered by metadata have nothing left to trigger on. |
| Regeneration (our Maximum disruption) | Gone. Cleaned first, and the output is a new file. | Disrupted: passed Gemini’s check on all three of our test images. Not guaranteed. | Unknown. We have not tested any platform’s classifier. |
The first three rows all hit the same layer. A screenshot of a Gemini image can lose its manifest and keep its watermark, so the part you can see in a file inspector is gone while the part Google’s own check reads may still be there.
The SynthID paper tests the mark against 30 basic transformations, and its own results show lower detection when several are stacked than for any one alone.
Regeneration goes further than stacking. Our Maximum disruption mode redraws the image lightly with an AI image model, keeping as much of the original as it can. On a portrait with a small face, a text-heavy profile image and a close-up gym photo with a heavy mark, the output passed Gemini’s provenance check. That check is a classifier judgment from Gemini, not Google’s production detector, which nobody outside Google can run. A lighter redraw failed on the heavily marked image, and steering the model harder visibly changed the person, so what works sits in a narrow band. It costs some detail: small printed text can garble, and fine knit texture shifts a little. The tool warns you before this mode uploads your image to our servers. The full recipe and its dead ends are in the SynthID removal research notes.
We also can’t tell you whether Google’s production detector would agree with Gemini on those three images. There is no public way to ask it.
How the layers point at each other
They were built as separate layers, but they refer to each other. A Google manifest we read in our test set records, as an action, “Applied imperceptible SynthID watermark.” An OpenAI manifest in the same set records the action c2pa.watermarked.unbound. So layer one announces layer two, and deleting the manifest deletes the announcement, not the mark. C2PA’s durable Content Credentials run the other way: an invisible watermark plus a fingerprint of the image is used to find a stored copy of a manifest that has been stripped. Adoption of that is limited so far.
Platforms use both. Meta reads the metadata markers and adds classifiers on top. When a real photo picks up an AI label, one of those two is the reason, and the Instagram AI info guide goes through which.
Where we stop
No tool controls the third layer, ours included, and we think any product that promises to remove a platform’s AI label is describing the first two layers and hoping about the third. Our stance is narrower: clean the files you made, keep the metadata out of places it shouldn’t travel, and study how well the watermarks hold up. What the metadata layer contains in the first place is covered in what C2PA records.
Sources
- Google DeepMind: SynthID
- SynthID-Image paper (arXiv 2510.09263)
- Google: AI image verification in the Gemini app
- Meta: labeling AI-generated images on Facebook, Instagram and Threads
- Content Authenticity Initiative: Durable Content Credentials
- PetaPixel: OpenAI adds SynthID to its images (20 May 2026)
- WAVES watermark benchmark (arXiv 2401.08573)