SynthID is Google DeepMind’s invisible watermark for AI-generated media: a signal written into the pixels of an image (or the frames of a video) that a matching decoder can read back later. Nothing about it shows on screen, and nothing about it lives in the file’s metadata, which is why deleting EXIF data or Content Credentials leaves it exactly where it was.
The name also covers a text watermark that works on completely different principles. Most confusion about SynthID comes from treating the two as one thing.
How the image watermark gets in
Google’s 2025 paper on SynthID-Image describes it as a post-hoc scheme: a pair of neural networks, an encoder that adds the mark to a finished image and a decoder that looks for it. The generator draws the picture first. Then the encoder nudges its pixels. You can’t see the change. Because the watermark is added after generation rather than baked into one model, the same system can mark output from any of Google’s image and video models, and the paper says that independence was a deliberate design choice.
Where in the image the signal sits is less settled than most explainers suggest. The paper does not say whether the deployed system works in the frequency domain or directly on pixel values. Google keeps that private. The claim that SynthID is “spread across the frequency spectrum” comes mostly from attack research, where the UnMarker authors argue that any watermark robust enough to survive ordinary edits has to live in the image’s overall spectral amplitudes. That is a strong argument about watermarks in general. It is not a description Google has confirmed for SynthID, and we would treat any page that states it as fact with some caution.
What is clear is that the mark is image-wide, not a patch in one corner. Cropping a region out doesn’t carry the watermark away with it, and the Gemini app’s help page says it can read the mark from screenshots, as long as they are cropped tightly around one picture.
What it is built to survive
DeepMind’s product page lists cropping, filters, frame-rate changes and lossy compression. The paper goes further: it tests 30 “basic” transformations in six groups, including small rotations, flips, noise, brightness and contrast shifts, resizing, JPEG compression and Instagram-style filters. It also reports that combinations of edits do more damage than any single edit, with detection in its worst combined case lower than in its worst single one.
Regeneration is the gap. The paper says SynthID was tested against “off-the-shelf weak re-generation attack models (e.g., using variational autoencoders)” and makes no claim about an image being redrawn by a full diffusion model, which is the family of attack that published removal research, and our own testing, keeps returning to. The research notes on removing SynthID go through which edits fail and which don’t.
Who puts it in their images
| Who | Since | What they say |
|---|---|---|
| Google (Gemini app, Imagen, Nano Banana models, Vertex AI) | 2023 | All media made by Google’s tools carries SynthID. Google reported over 20 billion pieces of content watermarked by November 2025. |
| OpenAI (ChatGPT, Codex and the API) | Announced 20 May 2026 | Images carry a SynthID watermark plus a C2PA manifest, checkable on OpenAI’s own verify page. |
The OpenAI row matters more than it looks. Until May 2026, “has SynthID” was close to a synonym for “made with Google AI”. Now a watermark from the same family can come from two companies, which each read it with their own tools. Gemini’s help page says it can only recognise content made by Google’s tools; we haven’t found anything from either company saying whether Gemini reads OpenAI’s mark or the reverse.
On Gemini and Nano Banana images SynthID is one of up to three marks, next to the visible sparkle and a C2PA manifest. The guide to Gemini and Nano Banana image marks sorts out which is which.
SynthID Text is a different mechanism
Text can’t hide a pixel signal, so SynthID Text works during generation instead. As the model picks each next word, a keyed scoring function tilts the choice slightly, and the finished passage ends up with a statistical bias in its word choices that a detector holding the same keys can measure. Change enough of the words, by paraphrasing or translating there and back, and the bias fades; a 2025 robustness study found exactly that for paraphrase, back-translation and copy-paste dilution.
Google published a reference implementation on GitHub, which means anyone can watermark and score text with it. We ran that round trip ourselves with the public demo configuration: clean text scored about 0.44 on average, watermarked text about 0.55, against a detection threshold of 0.5.
Neither average sat more than 0.06 from the line.
It also tells you nothing about Gemini. Production Gemini uses its own secret keys, so a score from the public code says whether text carries the demo watermark, not whether Gemini wrote it.
What a watermark only its owner can read is worth
Our view is that SynthID is strong evidence for Google and weak evidence for everyone else. Google can run the decoder and knows its error rates. A journalist, a platform or a photo contest judge gets a yes or no from a chat assistant, with no score and no stated false-positive rate. Fine for a first look. For deciding whether someone lied about a picture, we don’t think it is enough, and nobody outside Google can currently measure how often it is wrong.
Sources
- Gowal et al., SynthID-Image: Image watermarking at internet scale (arXiv 2510.09263)
- Google DeepMind: SynthID
- Google: verifying AI images in the Gemini app (20 November 2025)
- Gemini Help: check if an image was made with Google AI
- PetaPixel: OpenAI adds C2PA and SynthID to its images (20 May 2026)
- Kassis and Hengartner, UnMarker (IEEE S&P 2025)
- google-deepmind/synthid-text on GitHub
- Han et al., robustness of SynthID-Text (arXiv 2508.20228)