AI Provenance Standards

SynthID and C2PA: DeepMind Watermarks vs Content Credentials

Evaluating SynthID vs C2PA reveals two complementary approaches to AI provenance: imperceptible watermarks embedded in pixels versus cryptographically signed metadata manifests attached to file headers.

Updated 8 October 2026 · Sources linked in the text

SynthID vs C2PA: Core architectural differences

When comparing SynthID vs C2PA, analysts examine two distinct layers of digital provenance engineered to verify artificial intelligence media. The core technical difference lies in where provenance information is stored. SynthID embeds statistical patterns directly into raw pixel values, video frames, or audio waveforms. C2PA appends cryptographically signed metadata records to file container headers.

Both approaches address the challenge of tracking synthetic media across the web. Yet their architectural assumptions diverge significantly. Google DeepMind created SynthID as an embedded signal check that remains detectable after format re-encoding and platform metadata stripping. The Coalition for Content Provenance and Authenticity established C2PA as an open industry specification that records detailed editorial lineage and cryptographic authenticity.

The comparison table below details how these two provenance technologies compare across governance, storage, verification mechanisms, and persistence:

Technical Criterion SynthID (Google DeepMind) C2PA Content Credentials
Fundamental Type Imperceptible statistical watermark embedded in media signals Cryptographically signed metadata container manifest
Storage Location Raw image pixels, video frames, and audio frequencies Container headers (JUMBF boxes, EXIF, XMP) or remote URIs
Governing Body Google DeepMind (Google technology, offered to partners) C2PA (open standard; founding members include Adobe, Arm, BBC, Intel, Microsoft and Truepic)
Information Recorded Binary statistical presence of partner AI generation or editing Detailed assertions: model name, timestamp, creator, edit history, asset hashes
Verification Mechanism Trained detector models hosted on official verification portals Public key infrastructure (PKI) validating signatures against trust lists
Common Verification Tools synthid.com, Google Gemini, Google Search, Chrome contentcredentials.org/verify, Adobe Verify, open-source C2PA tools
Stripping Susceptibility Not affected by metadata strippers; Google calls it “not infallible” Erased by metadata cleaners, screenshots and services that drop metadata
Post-Processing Survival Google states it is designed to remain detectable after cropping, filters, color changes and lossy compression Preserved only when the manifest is kept in the container
Supported Modalities Images, video, audio, and text Images, video, audio and documents
Primary Implementers Google (Gemini, Imagen, Veo, Lyria), OpenAI, NVIDIA, Kakao Camera makers, editing apps and AI generators that adopt the standard, including Adobe, OpenAI and Google

Understanding these structural differences explains why organizations increasingly treat the technologies as complementary rather than competing standards. One protects raw media content against metadata loss. The other provides an auditable paper trail of modifications.

How each provenance technology works under the hood

SynthID embeds mathematical patterns directly into synthetic media representations, whereas C2PA binds cryptographic assertions to file headers. The underlying engineering principles reflect this fundamental distinction between signal processing and cryptographic signing.

Google DeepMind introduced SynthID on August 29, 2023 for Imagen on Vertex AI. The system relies on two neural models trained together: one adds the watermark and one detects it, optimized so the mark stays invisible to people and readable by the detector. Google describes the image watermark as living in the pixels and does not publish more detail about where.

For video, the SynthID overview says the watermark is added to each generated video segment. For audio from Lyria and NotebookLM, it describes an inaudible watermark. Text uses a separate technique called tournament sampling, published by DeepMind researchers in Nature (2024), which shapes which tokens the model picks during generation.

In contrast, the C2PA technical specification operates entirely at the file format layer. When an authorized application exports media, it packages provenance data into standard JUMBF (JPEG Universal Metadata Box Format) structures. This manifest contains several core components:

  • Asset Hash: A cryptographic digest (such as SHA-256) calculated over the media data, binding the manifest to exact pixel values.
  • Assertions: Structured statements about the asset, such as the generating tool, actions taken and ingredients it was made from.
  • Claim Signature: A digital signature generated using the signing organization’s private key, authenticated by an X.509 certificate.
  • Certificate Chain: Public certificates tracing back to an accredited certificate authority recognized on approved trust lists.

When an end user inspects an asset through Content Credentials, the verification engine recalculates the asset hash and compares it against the signed manifest. If a single pixel changes without an accompanying signed edit assertion, the hash check fails. The validator then warns users that the content has been altered.

How Google and OpenAI deploy both standards together

Leading generative artificial intelligence developers combine SynthID and C2PA into a defense-in-depth architecture to prevent provenance loss during distribution. Rather than choosing between pixel watermarking and metadata signing, major platforms deploy both layers simultaneously.

Google joined the C2PA steering committee in February 2024. In the Gemini app, both layers are applied: Google’s Gemini help says all AI-generated media created or edited with Gemini Apps includes an invisible SynthID watermark, and that Gemini Apps include Content Credentials (C2PA) metadata. That covers images from Google’s Nano Banana image models in the app. According to Google DeepMind’s October 7, 2026 announcement, more than 180 billion images and videos and 240,000 years of audio carry SynthID.

OpenAI followed a parallel path. It says it began adding C2PA Content Credentials to DALL·E 3 images in 2024, and in May 2026 it added SynthID to images generated through ChatGPT, Codex and the OpenAI API, then to supported audio in July 2026. OpenAI’s verification tool checks both signals.

Google’s October 2026 post lists OpenAI, NVIDIA and Kakao as partners whose media the SynthID Detector can check. For both companies the logic is the same: if one layer is lost, the other may still be there.

Creators researching pipeline verifications can explore our ChatGPT SynthID detection analysis and our Gemini watermark detection guide for model-specific deployment details.

What a metadata cleaner removes compared to SynthID

Standard metadata cleaners strip external header tags and C2PA manifests from files, leaving embedded SynthID pixel watermarks completely intact. Many users mistakenly believe that running an image through an EXIF stripper or re-saving it in photo software removes all artificial intelligence markers.

Metadata cleaning utilities process file headers. They locate and delete EXIF blocks, IPTC captions, XMP sidecars, and C2PA JUMBF metadata boxes. For example, dedicated utilities such as AI Label Cleaner remove C2PA provenance manifests by stripping the signed metadata wrapper from image files. Once processed, the image file contains no external C2PA assertions. Standard validators report that no Content Credentials exist.

However, stripping file headers does not change pixel values, and that is where SynthID lives. A stripped JPEG or PNG keeps whatever SynthID pattern it had, so Google’s detector at synthid.com or Gemini’s verification can still find it.

The list below outlines how different provenance layers respond to standard file cleaning:

  • EXIF and IPTC camera data: Erased completely by standard image editors and web optimizers.
  • C2PA Content Credentials manifests: Stripped by metadata cleaners, social media uploads, or container conversions.
  • Visible watermarks and badges: Not metadata at all; they are part of the picture and are a separate question.
  • SynthID imperceptible watermarks: Not touched by metadata stripping. Google says they are designed to stay detectable after cropping, color adjustments and lossy compression.

Understanding this separation clarifies the role of specialized tooling. Our independent tool, SynthID Pass, is currently in development to address pixel-level watermark processing rather than simple metadata removal. While metadata cleaning utilities handle file headers, managing embedded pixel patterns requires distinct processing techniques. Early access opens on synthidpass.com first, and nothing is uploaded from our website today.

How to verify SynthID watermarks and C2PA Content Credentials

Verifying C2PA requires checking public digital certificates against trust lists, while verifying SynthID requires submitting media to specialized detector models. Because the verification pipelines rely on entirely different technologies, users must use distinct verification tools for each standard.

To verify C2PA Content Credentials, users submit files to public verification portals such as contentcredentials.org/verify or inspect them using compliant software like Adobe Photoshop. The verification workflow follows four automated steps:

  1. The verifier scans file headers for standardized JUMBF metadata boxes.
  2. The engine computes a cryptographic hash of the image pixel data and compares it against the manifest claim.
  3. The tool validates the digital signature against public keys published by accredited certificate authorities.
  4. The user interface displays verified attributes, including the signing organization, creation timestamp, and ingredient lineage.

If an asset passes verification, the verifier confirms that the metadata matches the exact pixels without unauthorized tampering.

Verifying SynthID involves a neural evaluation rather than cryptographic validation. On October 7, 2026, Google DeepMind launched its public portal at synthid.com. Creators and journalists can upload images, video clips, and audio files to receive official detection verdicts. The public portal enforces clear operational limits:

  • File Size Cap: Accepts individual files up to 104,857,600 bytes (100 MiB) across supported modalities.
  • Accepted Formats: Supports common image types (jpg, jpeg, png, bmp, webp, avif, heic, heif, tiff, tif, gif), video containers (mp4, mov, webm), and audio formats (wav, mp3, ogg, flac, aac, m4a).
  • Video Frame Rates: Video clips must maintain at least 10 frames per second to avoid uncertain evaluation verdicts.
  • Official FAQ Verdicts: The public portal reports two official verdicts: Watermark detected and Watermark not detected.
  • Client UI Labels: Observed strings in the client bundle on October 8, 2026 show three main states: Made with Google AI, Not made with Google AI, and an uncertain classification category.
  • Client Unsure Explanations: The client bundle includes exact phrases for uncertain verdicts. These include Not enough information to detect SynthID, The uploaded media was empty, and The resolution is too low. Other observed strings include Not enough details to watermark and The media has less than 10 frames per second. The client also lists The media is too low quality and We suspect the image has been tampered with or Google AI was only used for a very small part.

In parallel, Google integrates SynthID detection into consumer services. As documented in the Google Gemini verification guide, users can ask Gemini to verify uploaded images. Gemini inspects both SynthID watermarks and C2PA Content Credentials within a single check. Gemini enforces separate operational boundaries: single files up to 100 MB, video under 90 seconds, audio under 1 hour, and rolling 24-hour limits of roughly 10 images, 10 videos, and 10 audio clips. For a complete walkthrough of public detection verdicts, consult our guide to the official SynthID Detector portal.

Which provenance signal to trust when detectors disagree

When provenance signals conflict, analysts must evaluate whether metadata was stripped during transmission or whether an embedded pixel pattern decayed under editing. Disagreements between C2PA validators and SynthID detectors occur frequently in real-world workflows.

Consider the primary conflict scenarios encountered when evaluating synthetic media:

  • Scenario A: C2PA is present, but SynthID is not detected. This can mean the media came from a system that signs C2PA but does not use SynthID, such as Adobe Firefly. It can also mean the SynthID signal was weakened. If the C2PA signature validates against a trusted list, the signed origin data is authentic, whatever the detector said.
  • Scenario B: SynthID is detected, but C2PA is missing. This is what metadata loss looks like: the file was re-saved, screenshotted or passed through a service that dropped its metadata, and the pixel watermark was still read. The synthid.com FAQ notes that false positives are very rare but possible, so treat it as strong evidence, not proof.
  • Scenario C: Neither signal is detected. A negative result across both checks does not prove human authorship. Many generators apply neither standard, and heavily transformed files can lose both.

Can C2PA be faked?

An attacker cannot forge a valid C2PA signature without the signer’s private key. C2PA uses ordinary public key infrastructure: manifests are signed with X.509 certificates, and verifiers decide which certificate issuers to trust.

What that does and does not protect, under the C2PA specification:

  • Trust lists: Verification tools keep lists of recognized certificate issuers. A manifest signed with a self-made certificate shows up as untrusted.
  • Stripping: Anyone can remove credentials from a file. The result simply has no credentials, which is not proof of anything.
  • False claims: A holder of a valid certificate can still sign a misleading assertion. C2PA proves who signed a claim, not that the claim is true.
  • Layers: This is why Google and OpenAI pair C2PA with a watermark, so that losing the metadata does not lose every signal.

Analyzing SynthID vs C2PA shows that provenance holds up best with both a signed manifest in the container and a watermark in the content. To learn more about the watermark side, read how SynthID works or our guide to the SynthID watermark remover.

Frequently asked questions

What does C2PA stand for and what is its purpose?

C2PA stands for the Coalition for Content Provenance and Authenticity. Its purpose is to define an open technical specification for attaching tamper-evident cryptographic metadata manifests to digital media, documenting asset origins, editing history, and creator assertions.

Can C2PA be faked?

A valid signature cannot be forged without the signer's private key, and verifiers check the signing certificate against trust lists. What an attacker can do is strip the manifest, or sign with a certificate the verifier does not trust. And a holder of a valid certificate can still sign a false claim: C2PA proves who signed, not that the claim is true.

Does ChatGPT have C2PA?

Yes. OpenAI says it began adding C2PA Content Credentials to DALL·E 3 images in 2024 and is now a C2PA Conforming Generator Product. In May 2026 it also started adding Google DeepMind's SynthID watermark to images from ChatGPT, Codex and the OpenAI API.

What is the difference between SynthID and C2PA?

SynthID is a watermark inside the content itself, in the pixels of images and video, the audio signal, or the word choices of text, read by Google's detector. C2PA is a signed metadata record stored in the file container, read by any Content Credentials verifier. SynthID is harder to lose; C2PA says much more.

Does removing C2PA metadata remove SynthID?

No. Standard metadata strippers remove EXIF data, XMP blocks, and C2PA JUMBF containers from file headers. Because SynthID modifies the raw pixel values rather than file headers, stripping metadata leaves the SynthID watermark completely intact.

Why do Google and OpenAI use both SynthID and C2PA?

Because they fail in different ways. OpenAI's 2026 provenance post puts it plainly: metadata can be stripped or lost in uploads, format changes, resizing or screenshots, while a watermark can be more durable through transformations like screenshots, and metadata carries far more detail than a watermark can.

Evaluating SynthID vs C2PA highlights how multi-layered verification protects synthetic media provenance. To explore deeper architectural details, review our technical guide on how SynthID works, inspect verdicts on the official SynthID Detector portal, or track our independent SynthID watermark remover development on our website.

SynthID Pass is not open yet

We are building the SynthID Pass tool now. Early access opens on this site first.

Until then you can check any file yourself on Google's official SynthID Detector.

How to read a SynthID result