The Intricacies of AI Watermarking: How It Works and How to Spot It
By Editor • September 2, 2026 • 3 min read
The landscape of AI watermarking is rapidly evolving, highlighted by recent announcements from tech giants Anthropic and Google. Anthropic's Claude models are set to incorporate invisible watermarks in their text outputs, while Google has made its visible watermark for generated images optional. These contrasting approaches underscore the variety of methods employed in watermarking AI-generated content.
Understanding AI watermarking requires a look at the techniques used across different media types. At its core, watermarking embeds data within the generated content—often imperceptibly—to identify it as AI-produced. This data can be detected using specialized tools that confirm the AI origin without relying on unreliable detection methods.
For images, watermarking modifies pixel values to create a digital signature that remains unnoticed by the human eye. Google's SynthID exemplifies this, embedding an invisible watermark across generated images, ensuring even cropped versions retain detectable elements. This is separate from the visible watermark that may be displayed in the corner of Gemini images, which can be turned off but does not eliminate the invisible signature.
Audio files present another layer of complexity. Watermarks can be placed in frequencies beyond human hearing, utilizing ranges below 20Hz or above 20,000Hz. SynthID also has an audio component that is silent to our ears but identifiable by watermark detection tools. In video, a combination of image and audio watermarking is typically used, which can complicate the detection of AI-generated content.
Text-based watermarks function differently. Large language models (LLMs) like Claude generate text by predicting the likelihood of word sequences. By inflating the probability of certain uncommon words, these models can embed a watermark that helps identify AI-generated text without altering its meaning. However, this method is more effective with longer texts, where the presence of these less-likely words can be more easily detected.
Another aspect to consider is metadata. The C2PA framework allows for the addition of metadata that verifies the origin of media, including indications of AI generation. While this isn’t a watermark per se, it plays a crucial role in authenticating content. Various companies, including camera manufacturers, have started to implement C2PA to provide traceability for digital images.
Despite advances with SynthID and C2PA, detecting AI watermarks remains a challenge. OpenAI offers a tool for checking SynthID or C2PA in files, while Google provides verification options through Gemini, often requiring specific prompts to access detection features. However, limitations exist; for instance, OpenAI's tool primarily detects content generated by its own models, which can lead to inconsistencies when testing images from other sources.
Given the plethora of watermarking methods, it’s possible for a piece of media to possess various types of watermarks, each requiring different detection tools. For text watermarks, current options for public detection are limited, leaving many users uncertain about the authenticity of AI-generated content.
While the removal of watermarks is technically feasible, methods vary in difficulty. For instance, SynthID watermarks are resilient against common modifications, whereas removing C2PA metadata can be as simple as taking a screenshot, which generates a new image file devoid of the original metadata. This underscores the importance of preserving original files to maintain a clear authenticity record.
As watermarking technology continues to evolve, the implications for authenticity in digital media grow increasingly complex. A watermark does not automatically indicate that a piece of media is entirely AI-generated; authentic images can also carry watermarks if processed through AI tools. Conversely, the absence of a watermark does not guarantee authenticity, as it could simply mean a different technique was employed.
Source: lifehacker.com