DeepMind Provenance Architecture

How Google SynthID Works: Inside the AI Watermarking System

Google DeepMind built SynthID to embed imperceptible provenance marks directly into AI media without hurting quality. Discover how the technology works across pixels, audio spectrograms, and language model tokens.

Updated 8 October 2026 · Sources linked in the text

How Does SynthID Work Across Different Media?

How does SynthID work? It embeds an imperceptible signal into the content itself rather than into file headers that are easy to strip. Google DeepMind designed SynthID so that the signal stays readable after ordinary handling without lowering quality for people. Instead of applying a visible icon or saving EXIF metadata, SynthID adds a pattern at generation time:

  • Images: Tiny shifts applied directly to pixel values across coordinate arrays.
  • Video: The image watermark applied to each generated video segment.
  • Audio: Inaudible signatures woven across acoustic frequency components.
  • Text: Controlled token selections shaped during autoregressive language model generation.

Google DeepMind first introduced SynthID on August 29, 2023, for Imagen on Vertex AI. In an update published on October 7, 2026, Google reported that over 180 billion images and videos and 240,000 years of audio have been watermarked across global services. Google also noted that partners including OpenAI, NVIDIA, and Kakao have adopted the technology, while built-in verification checks in Google Search, Chrome, and Gemini process over 1 million queries daily.

Because each medium uses different underlying representations, Google DeepMind developed dedicated approaches for pixels, waveforms, and text tokens. The table below compares them. For the practical side, see how to read a SynthID Detector result, the SynthID vs C2PA comparison, the SynthID watermark remover guide, or the SynthID remover home page.

Modality Embedding Approach Primary Source Reference Key Claimed Behavior
Image Neural encoder in pixel space arXiv 2510.09263 (2025) Designed to survive filters, color changes and lossy compression
Video Image watermark per video segment DeepMind overview Designed to survive cropping, filters, frame-rate changes, lossy compression
Audio Inaudible watermark in the audio signal DeepMind overview Designed to survive added noise, MP3 compression and speed changes
Text Tournament sampling with g-values Nature s41586-024-08025-4 (2024) Preserves generation quality and factual accuracy
[Generative AI Output] ---> [SynthID Encoder Network] ---> [Watermarked Output File]
                                                                   |
                                                                   v
                                                       [SynthID Detector Network]
                                                                   |
                                                                   v
                                                       [Three-State Verdict Score]

How SynthID Watermarks Images and Video

SynthID marks images by running a trained neural network over pixel data right after image creation. In the research paper published on arXiv 2510.09263 (2025), Sven Gowal, Pushmeet Kohli, and colleagues describe SynthID-Image as a post-hoc, model-independent watermarking system.

The framework pairs two neural models trained jointly to balance imperceptibility with detection accuracy:

  • The Encoder Network: Takes an already generated image and introduces a subtle perturbation to pixel values. Perceptual loss constraints ensure the added pattern remains invisible to human observers.
  • The Detector Network: Analyzes an image and predicts whether the specific watermark pattern is present, outputting a statistical confidence score.

Because the encoder operates post-hoc, Google can update base diffusion architectures without needing to retrain the watermarking pipeline. DeepMind evaluated an external variant named SynthID-O, confirming that the model provides strong detection while maintaining high image fidelity.

Video generation models such as Veo carry the watermark in each generated video segment, according to the DeepMind overview. Verification tools examine video and audio tracks separately. As observed in the client code of the official SynthID Detector on October 8, 2026, positive verdicts specify the affected track as (Video), (Audio), or (Audio & Video), and a video under 10 frames per second gets an unsure verdict. For image-specific detail, read our guide to removing SynthID from an image.

How SynthID Watermarks Audio in Lyria and NotebookLM

SynthID for audio embeds provenance signatures into sound files so that human listeners hear no difference. Google DeepMind deployed this system in music generation models such as Lyria and synthetic speech tools within NotebookLM.

Google has not published the audio method in the same detail as the image and text methods. What its SynthID overview does state:

  • Where it is used: audio generated or published through Lyria and the podcast feature of NotebookLM.
  • Perception: the watermark is inaudible to the human ear.
  • Robustness claim: Google says it withstands common modifications such as added noise, MP3 compression and changes to playback speed.
  • Detection length: the SynthID Detector client has a “too short to be processed” reason, so very short clips can come back unsure. Gemini accepts audio files under one hour.

How SynthID Watermarks Text with Tournament Sampling

SynthID Text operates on a completely different mathematical foundation because text lacks pixel grids or continuous sound waves. Instead of modifying words after generation, it guides token selection while the model generates text. Google DeepMind published the underlying mathematics in Nature s41586-024-08025-4 (2024) by Sumanth Dathathri et al.

Preceding Context Tokens (ngram_len - 1)
                   |
                   v
[Pseudorandom g-Function] ---> [Keyed g-Values for Candidate Tokens]
                                                |
                                                v
                                [Pairwise Tournament Matchups]
                                                |
                                                v
                                [Winning Next Token Emitted]

Standard large language models sample next tokens from probability distributions filtered by Top-K or Top-P criteria. SynthID Text introduces tournament sampling as an integrated logits processor:

  • Context Window: The system evaluates preceding tokens defined by ngram_len. According to DeepMind documentation on ai.google.dev, the standard setting is ngram_len = 5.
  • Keyed Pseudorandom Scoring: A cryptographic pseudorandom function $g(\cdot)$ parameterized by private secret keys computes a numerical value ($g$-value) for candidate tokens based on preceding context.
  • Tournament Matchups: Several candidate tokens are first sampled from the model’s own probability distribution, then compared in knockout rounds by their keyed $g$-values; the higher $g$-value advances.
  • Winning Token Emission: The winning candidate from the tournament bracket is emitted as the generated word.

Verifying text does not require running the full generative model again. An independent Bayesian detector reconstructs context $n$-grams, computes observed $g$-values with the shared private key, and evaluates whether the distribution matches watermarked text. While tournament sampling preserves natural phrasing in open-ended text, Google notes that factual answers offer low entropy and fewer candidate tokens, which naturally reduces watermark strength.

How Detection Works and What the Three Verdicts Mean

SynthID detection provides an empirical statistical measurement rather than a binary guarantee. On the public SynthID Detector portal launched globally on October 7, 2026, the client bundle examined in October 2026 displays three primary verdict states:

  • Made with Google AI (detected): SynthID detected in all or part of the uploaded content.
  • Not made with Google AI (not_detected): SynthID is not detected anywhere in the uploaded content.
  • Uncertain State (uncertain): Labeled in client strings as Unsure, indicating that degraded media prevents a confident decision.

A negative detection verdict does not prove that a file was created by a human. In its official FAQ, Google identifies two primary reasons why an AI-generated file receives a not detected verdict:

  1. The media was created by an AI model that does not incorporate SynthID, or was generated before a partner integrated the technology.
  2. Subsequent heavy edits or extreme transformations weakened the signal below the detection threshold.

The client bundle records nine diagnostic reasons when returning an unsure verdict:

  • 0: “Not enough information to detect SynthID.”
  • 1: “The uploaded media was empty.”
  • 2: “The __ resolution is too low.”
  • 3: “Not enough details to watermark.”
  • 4: “The __ has less than 10 frames per second.”
  • 5: “The __ is too low quality.”
  • 6: “We suspect the image has been tampered with or Google AI was only used for a very small part.”
  • 7: “The __ is too long to be processed.”
  • 8: “The __ is too short to be processed.”

Robustness Claims and Does SynthID Work on Screenshots?

Google designed SynthID to survive everyday media handling, but official documentation emphasizes that the system has defined limits. In the portal FAQ, Google explicitly states: “the watermark is not infallible and if someone tries many transformations, they may be able to find one that doesn’t get detected.”

Google’s published materials say where the watermark is meant to hold. The 2023 DeepMind announcement says the image watermark remains detectable after filters, changes to colors and brightness, and lossy compression such as JPEG, and the SynthID overview adds cropping for images and video.

The same 2023 post says SynthID “isn’t foolproof against extreme image manipulations”. For SynthID Text, documentation on ai.google.dev says the signal survives cropping pieces of text, changing a few words and mild paraphrasing, but confidence drops after thorough rewriting or translation into another language.

Regarding screen captures, users frequently ask: does SynthID work on screenshots? Google has not published a screenshot robustness result. What it has published is guidance for people who verify screenshots in Gemini Apps Help:

“If you’re taking a screenshot of an image to verify, make sure to crop tight around the image to get maximum accuracy, and don’t upload a collage of multiple distinct images.”

That guidance implies two things: a screenshot can be submitted for verification, and what surrounds the image in the capture affects accuracy. It does not say how often the watermark is still found.

What SynthID Means for Digital Content Provenance

SynthID represents a meaningful evolution from metadata-only tracking toward content-level provenance. While standards like C2PA provide transparent manifest chains, metadata is routinely stripped when files are uploaded to social platforms or captured via screenshots. By embedding provenance signals directly into pixel values, audio frequencies, and token distributions, SynthID maintains an underlying verification trail.

For creators and organizations examining digital provenance, the answer to how SynthID works also explains its limits: it only exists where a SynthID-enabled model put it, and only Google’s detector can read it. SynthID Pass, an independent tool in development for SynthID-marked images, is built around that layer. Early access opens on synthidpass.com first.

Frequently asked questions

How does SynthID work for images?

SynthID-Image uses two neural networks trained together: an encoder that embeds an imperceptible pattern directly into pixel values, and a detector that spots it.

How does SynthID work for text?

SynthID Text uses tournament sampling during generation. Candidate tokens compete based on keyed pseudorandom g-values, leaving a statistical pattern across token choices.

Does SynthID work on screenshots?

Google does not publish a screenshot test result. Its Gemini help page tells users who verify a screenshot to crop tightly around the image and not to upload a collage, which shows screenshots can be checked but that framing affects accuracy.

How accurate is SynthID?

SynthID provides statistical confidence rather than binary proof. Official checks return three states: detected, not detected, or unsure if made with Google AI.

How reliable is synth id?

Google states the watermark withstands routine edits like cropping, filters, and lossy compression, but explicitly notes that the watermark is not infallible.

What does SynthID look like?

SynthID is invisible to the human eye and inaudible to human ears. It exists only as subtle mathematical shifts in pixels, sound frequencies, or word choices.

How does SynthID work, in one line? It hides a keyed pattern inside the content itself, pixels, sound or word choices, and only Google's detector with the matching keys can read it back. Early access to SynthID Pass opens on synthidpass.com first.

SynthID Pass is not open yet

We are building the SynthID Pass tool now. Early access opens on this site first.

Until then you can check any file yourself on Google's official SynthID Detector.

How to read a SynthID result