What it takes to remove SynthID from image files
Creators who want to remove SynthID from image files face an invisible watermark embedded directly into pixel values. Google DeepMind introduced the SynthID watermark on 29 August 2023 for Imagen on Vertex AI. While metadata scrubbers delete EXIF tags, SynthID embeds an imperceptible pattern across pixel values. In a blog post on 7 October 2026, Google reported that over 180 billion images and videos have already been watermarked.
When you download a generated image from Gemini, the file can carry two separate signals: provenance metadata in the file container, and the SynthID pattern in the pixels. Cleaning the metadata leaves the pixel pattern where it was. To see how the two differ, read our SynthID vs C2PA guide or the SynthID remover overview.
Which image generators embed SynthID into pixel values?
Google’s image models embed SynthID into image pixels at generation time. The SynthID overview describes the watermark as added “the moment content is created” for AI-generated images and video.
OpenAI announced in May 2026 that images generated through ChatGPT, Codex and the OpenAI API carry a SynthID watermark alongside C2PA Content Credentials. NVIDIA and Kakao are the other partners Google names. Google’s 7 October 2026 post adds Apple as “soon”, without a date.
Image formats and limits accepted by Google’s detector
The public verification portal at synthid.com provides an official decoder interface launched globally on 2026-10-07. Inspection of the client web application on 2026-10-08 shows that incoming raster files must satisfy strict file constraints:
| Image format | File extension | MIME type accepted | File size ceiling |
|---|---|---|---|
| JPEG / JPG | .jpg, .jpeg |
image/jpeg |
100 MiB (104,857,600 bytes) |
| PNG | .png |
image/png |
100 MiB (104,857,600 bytes) |
| WebP | .webp |
image/webp |
100 MiB (104,857,600 bytes) |
| AVIF | .avif |
image/avif |
100 MiB (104,857,600 bytes) |
| HEIC / HEIF | .heic, .heif |
image/heic, image/heif |
100 MiB (104,857,600 bytes) |
| TIFF / BMP / GIF | .tiff, .bmp, .gif |
image/tiff, image/bmp, image/gif |
100 MiB (104,857,600 bytes) |
Every image file uploaded to the portal must not exceed the 100 MiB client limit. Files that exceed this size return an immediate client rejection before network transit. The portal processes single image files one at a time and requires account authentication through Google, Apple, or OpenAI credentials before scanning. Detailed interface limits and operational quotas are documented in our synthid detector analysis.
What image edits does Google state the watermark survives?
In a blog post published on 29 August 2023, Google DeepMind explained that SynthID uses two deep learning models, one to add the watermark and one to identify it, trained together so the mark stays invisible and detectable.
According to that post and the SynthID overview, Google says the image watermark is designed to remain detectable after:
- Lossy compression, including JPEG.
- Changes to colors and brightness.
- Adding filters.
- Cropping (named in the SynthID overview).
However, Google explicitly states that the watermark is not infallible. Google notes in the synthid.com FAQ that if an image undergoes many transformations, detection may fail. As documented by Google DeepMind, extreme manipulations can degrade the signal. Creators working specifically with Google-generated files can consult our gemini synthid remover and chatgpt synthid remover pages for model-specific details.
Why does the detector return an unsure verdict for images?
The public detector returns an unsure verdict when image quality or resolution prevents confident classification. When analyzing an uploaded image, client-side strings observed on 2026-10-08 show three core result states: Made with Google AI, Not made with Google AI, and Unsure if made with Google AI.
Inspection of the client bundle on 2026-10-08 identified specific diagnostic strings for unsure image results:
The image resolution is too low.The image is too low quality.We suspect the image has been tampered with or Google AI was only used for a very small part.Not enough details to watermark.
In the detector client, unsure is its own state, separate from “Not made with Google AI”. It means the detector could not reach a confident answer for that file, not that the watermark is gone.
How SynthID Pass fits into image workflows and verification
SynthID Pass is an independent tool in development to remove SynthID from image pixels. While metadata scrubbers delete EXIF tags, SynthID Pass targets imperceptible pixel-level signatures. The tool is currently in development and is not open for public processing yet.
Early access opens on synthidpass.com first, with image processing as the primary launch focus. Nothing is uploaded from our website today; the drop zone above serves as a demand-measuring access portal. SynthID Pass is completely independent and is not affiliated with Google or DeepMind.
When checking assets, remember that the official portal on synthid.com applies daily usage quotas per account. Its Terms of Service explicitly forbid using the detector to conduct black-box attacks or tune transformations.
Removing watermarks from synthetic media carries ethical responsibilities. SynthID Pass must never be used to disguise synthetic media as authentic photojournalism or to dodge disclosure rules. Article 50 of the EU AI Act sets transparency duties for AI-generated content, and platforms set their own labeling rules. Our website does not provide legal advice.