Three Distinct Watermark Layers Found on AI Images
AI images carry three different watermark types: invisible pixel marks, container metadata, and visible app badges. People searching for a SynthID watermark remover often mix these three layers up, so the first job is to find out which ones a file carries. SynthID Pass is in development, and this page explains how each layer works.
Google DeepMind introduced SynthID technology to protect AI-generated content. In an announcement on August 29, 2023, Google launched SynthID for Imagen on Vertex AI. On October 7, 2026, Google announced that over 180 billion images and videos carried SynthID marks.
SynthID embeds an imperceptible pattern directly into raw pixel values during generation. Google uses two models trained together: one model adds the watermark, and another model detects it. Because the mark alters pixel values, it does not live in file headers.
The second tracking system relies on cryptographic metadata. The Coalition for Content Provenance and Authenticity maintains the C2PA specification for signed provenance manifests stored in the file container. A manifest can record which tool made the image, when, and which edits followed.
C2PA data sits entirely outside the image pixels. If you strip file headers, you delete the C2PA record completely. Yet the visual picture remains totally unchanged. A basic metadata tool cleans these tags in seconds.
The third layer consists of visible badges added by consumer apps. Gemini, for example, can add a visible watermark to generated images, and Google’s help page lets users turn it on or off in settings (in India, South Korea and Vietnam only with an AI Ultra subscription). The same page says that setting does not affect SynthID or Content Credentials.
Knowing the difference between these three systems saves time. A visible badge is a design element anyone can see. Container metadata is a record that a metadata tool can read and delete. SynthID is neither: it sits in the pixel values, and only Google’s detector can read it.
How SynthID adds an invisible watermark to images
According to the SynthID-Image paper published by Google DeepMind in October 2025, SynthID-Image is a deep-learning watermark applied to AI-generated images, and the paper reports that it had been used on over ten billion images and video frames across Google’s services.
Google’s 2023 announcement describes two models trained together, one to add the watermark and one to identify it, optimized both to detect the mark and to keep it visually aligned with the original content. Google does not publish where in the image the signal sits beyond “the pixels”, and this page does not guess.
Comparing AI Watermark Layers: Where Signals Live and What Survives
Different watermark systems react differently to edits because they live in separate parts of an image file. An edit that destroys one watermark may leave another completely intact. The table below outlines how these three markers function based on official documentation and technical specifications.
| Watermark System | Where It Lives | How to inspect it | What the owner says about durability |
|---|---|---|---|
| Google DeepMind SynthID | Pixel values | SynthID Detector at synthid.com | Designed to stay detectable after filters, color changes, lossy compression and cropping; “not infallible” (synthid.com FAQ) |
| C2PA Content Credentials | File container (for JPEG, APP11 segments) | A Content Credentials verifier such as verify.contentauthenticity.org | Signed, so tampering is evident while the manifest is present; lost when a file is re-saved without it |
| Visible app overlays | Visible pixels on the canvas | Looking at the image | Not a hidden signal; Gemini users can switch its visible watermark off in settings |
Screenshots show the difference between a container record and a pixel mark. A screenshot is a new file, so it carries none of the original container metadata, including any C2PA manifest. Whether the SynthID pattern is still found in a screenshot is a different question, and Google has not published a result for it. What Google does publish is guidance in Gemini help article 16722517: crop a screenshot tightly around the image and do not upload a collage, “to get maximum accuracy”.
Metadata strippers work only on the container. When you run an AI image through one, you remove C2PA manifests and EXIF tags, and the pixels stay as they were. To see how these two systems interact, read our comparison of SynthID vs C2PA.
Google is clear about the boundaries of its technology. The synthid.com FAQ says the watermark stays detectable after modifications like adding filters, changing colors and saving with lossy compression, and also that “the watermark is not infallible and if someone tries many transformations, they may be able to find one that doesn’t get detected.”
What Google says about compression and edits
Google’s 2023 post names lossy compression, “most commonly used for JPEGs”, among the edits SynthID was designed to survive, together with filters and color and brightness changes. The SynthID overview adds cropping, frame-rate changes for video, and for audio, added noise, MP3 compression and speed changes. Google does not list a size, quality level or number of edits at which detection stops, and the detector’s FAQ asks users to upload the highest quality file they have.
Understanding these boundaries helps set realistic expectations. SynthID is a durable provenance signal by design, and Google itself calls it one layer of provenance, not a guarantee.
How to Verify Which Marks an AI Image Contains
You can verify the marks on an image by checking both the container headers and the raw pixels. Checking only one area leaves blind spots. An image might lack C2PA metadata but still carry SynthID in its pixels. A clear two-step workflow reveals the full provenance status of any file.
Step 1: Scan for Pixel Watermarks Using the SynthID Detector
The primary tool for finding SynthID marks is Google’s public portal at synthid.com. Google opened global access to this web application on October 7, 2026. The portal checks image, audio, and video files. It accepts image uploads up to 100 MiB (104,857,600 bytes) in standard formats. Supported formats include JPEG, PNG, WebP, AVIF, HEIC, TIFF, BMP, and GIF.
To run a scan, you must sign in with a Google, Apple, or OpenAI account. Once you upload an image, the portal evaluates the pixel patterns. The client code observed on October 8, 2026, displays three main outcome states:
- Made with Google AI. The detector found a SynthID pattern across all or part of the content. This result indicates that the image was generated or edited with a model that uses SynthID, such as Google Imagen or Gemini.
- Not made with Google AI. The detector found no SynthID pattern anywhere in the file. This result means the image was created without SynthID, was made before a partner joined the program, or was modified enough to weaken the signal. It does not prove the image was made by a human.
- Unsure status. The portal could not make a clear determination. The client code lists specific reasons for this state:
Not enough information to detect SynthID.The uploaded media was empty.The image resolution is too low.Not enough details to watermark.The video has less than 10 frames per second.The image is too low quality.We suspect the image has been tampered with or Google AI was only used for a very small part.The media is too long to be processed.The media is too short to be processed.
If you need help interpreting portal limits and verdicts, review our guide on the SynthID detector.
Step 2: Inspect Container Headers with C2PA Validators
To check whether an image carries C2PA Content Credentials, use a Content Credentials verifier such as the Content Authenticity Initiative’s Verify tool.
When an image contains valid credentials, a verifier typically shows:
- The organization that signed the credentials.
- The software or AI tool that produced the file.
- The recorded creation date.
- Edit actions recorded in the manifest.
If the credentials were dropped along the way, for example by re-saving the file, taking a screenshot or uploading it to a service that strips metadata, the verifier reports that none were found. That says nothing about the pixels: a file without credentials can still carry SynthID.
When you work with Google models, files often carry both markers. You can read our guide on Gemini SynthID watermarks to see how Google pairs C2PA headers with pixel marks. If you want practical steps for evaluating image formats, see our article on how to remove SynthID from image files.
Why a SynthID Watermark Remover Focuses on Pixel Structures
A SynthID watermark remover has to work on pixel values rather than container metadata, because that is where SynthID is. Standard file utilities only clean header tags and leave the pixel pattern untouched.
The hard requirement for any such tool is image quality: a result that visibly damages the picture is not useful. SynthID Pass is being developed for that pixel layer. We are working on image support first, with video and audio planned for later milestones.
Here are the verified facts about our current product status:
- SynthID Pass is an independent project. It is not affiliated with Google or Google DeepMind.
- Our software is currently in active development. It is not open for public processing yet.
- Early access opens on synthidpass.com first.
- No files are uploaded or stored on our servers today.
Which Watermark Type Does SynthID Pass Target?
SynthID Pass focuses on the invisible SynthID watermark. It does not create or edit C2PA manifests, and it does not deal with visible logos or badges.
If you want to study the science behind pixel watermarks, read our guide on how SynthID works. It covers the image watermark, audio, and the tournament sampling method for text described in Nature (2024).
Ethical Provenance and Responsible Handling of Synthetic Media
Responsible use of watermark modification tools requires transparency about whether media was generated by AI. Removing provenance signals brings ethical and legal responsibilities that users must respect. The notes below offer general context and do not constitute legal advice.
Transparency helps maintain trust between content creators and their audiences. You should never remove a watermark to pass off synthetic imagery as authentic news photography. Misrepresenting AI media as real footage deceives viewers and violates major platform rules. Social networks and search engines have policies that require creators to label synthetic media clearly. Bypassing these rules can result in content removal or account suspensions.
Legal requirements around AI provenance continue to grow around the world:
- The European Union AI Act (Article 50) requires providers of generative AI systems to mark their outputs in a machine-readable way, and requires deployers who publish deepfakes to disclose that the content is artificial, with lighter rules for evidently artistic, satirical or fictional work.
- United States Copyright Law (17 U.S.C. § 1202) prohibits removing or altering copyright management information with intent to conceal copyright infringement. While courts are still examining how this applies to AI tags, altering provenance on copyrighted works creates legal exposure.
Legitimate reasons to study watermarks include testing model robustness, evaluating privacy protections, and researching image processing limits. Creators should always evaluate their technical workflows against local laws:
- Confirm whether your project requires disclosure under Article 50 of the EU AI Act.
- Ensure that synthetic media is never used to impersonate individuals or falsify historical evidence.
- Check which marks your file carries, pixel or metadata, before choosing a tool.
Choosing a SynthID watermark remover starts with knowing whether the mark is in the pixels or in the metadata. Early access to SynthID Pass opens on synthidpass.com first.