Key Takeaways
- Yes. Invisible watermarking is now standard across most large commercial generators, not a Google exclusive.
- OpenAI adopted Google DeepMind’s SynthID on 19 May 2026 for images produced through ChatGPT, Codex and the API, then extended it to audio on 31 July 2026.
- Google embeds SynthID across images, video, audio and text from its own models, including Gemini, Lyria and NotebookLM audio.
- Meta ships Stable Signature for images and AudioSeal for audio; Adobe Firefly, Microsoft Designer, Stability AI and Black Forest Labs also mark output.
- Midjourney remains the notable holdout, with no C2PA support and no publicly known invisible watermark. Grok carries a visible corner logo, with invisible marking unconfirmed.
- Text is the weak spot. Google’s SynthID-Text watermarks Gemini output at the token level; most other text generators embed nothing detectable.
- EU AI Act Article 50 obligations apply from 2 August 2026, requiring machine-readable marking of synthetic output, with existing systems given until 2 December 2026.

A hidden watermark in an AI-generated content, artistic impression. Image credit: Alius Noreika / AI
Google is no longer alone. As of 2026, most major commercial generative AI systems embed some form of hidden marker in what they produce — either a statistical watermark woven into the content itself, cryptographically signed provenance metadata attached to the file, or both. OpenAI, Meta, Adobe, Microsoft, Stability AI, Amazon and Black Forest Labs all mark output in some fashion.
The most consequential change came in May 2026, when OpenAI began embedding SynthID — the same DeepMind technology Google uses — into images generated through ChatGPT, Codex and the OpenAI API, and published a public tool for checking whether an image came from its systems. A rival adopting a competitor’s watermark is unusual, and it moved SynthID close to a de facto standard for image marking.
What “Hidden Watermark” Actually Means
Two different mechanisms get called watermarking, and they fail in opposite ways.
A statistical watermark lives inside the content. For images and video it means imperceptible pixel-level adjustments; for audio, inaudible signal modifications; for text, a deliberate skew in the token probability distribution during generation. These survive cropping, compression, filtering, screenshots and format conversion, because the signal is in the substance rather than the wrapper.
A provenance manifest lives beside the content. The C2PA standard — now formalised as ISO/IEC 22144 — attaches metadata and cryptographic signatures describing what created a file and how it was edited. It carries far richer information than a watermark, and it disappears the moment someone screenshots the image or a platform strips metadata on upload.
The two are complementary, which is exactly why serious implementations now use both. Anyone building detection workflows should also read our explainer on how AI detectors work, since watermark checking and statistical detection are entirely different techniques.
Which Generative AI Models Watermark Their Output
| Provider | Invisible watermark | C2PA content credentials | Visible mark |
|---|---|---|---|
| Google (Gemini, Imagen, Veo, Lyria) | SynthID on images, video, audio and text | Yes, on newer models since late 2025 | No |
| OpenAI (ChatGPT, Codex, API) | SynthID on images since May 2026, audio since July 2026 | Yes, C2PA conforming generator since February 2024 | Sora video output |
| Adobe Firefly | Durable content credentials watermark | Yes, on every generation | No |
| Meta | Stable Signature for images, AudioSeal for audio | Partial | “Imagined with AI” labelling |
| Microsoft Designer | Yes | Yes | No |
| Stability AI and Black Forest Labs FLUX | Varies, and removable on self-hosted weights | Yes on hosted APIs | No |
| xAI (Grok) | Not confirmed | Not confirmed | Corner logo, removable by cropping |
| Midjourney | None known | No | No |
Google SynthID: The Widest Coverage
SynthID is the only system currently covering all four modalities. For images and video it adds an invisible digital watermark that survives cropping, filtering and compression without visible quality loss. For audio, it marks output from the Lyria music model and NotebookLM’s podcast feature, and the mark persists through added noise, MP3 compression and speed changes.
Text is where SynthID does something structurally different. Language models pick each token according to probability scores. SynthID-Text adjusts those scores in a patterned way, so the choice of words itself carries a detectable signature while remaining fluent and unnoticeable to a reader. Google open-sourced the approach, which is why it is the reference implementation for text watermarking generally.
Verification runs two ways. Users can upload a file to Gemini and ask whether it was created or edited by Google AI, and Google operates a dedicated SynthID Detector portal for images, video and audio, currently being tested with journalists and media professionals through a waitlist.
OpenAI’s Three-Layer Approach
OpenAI now stacks three mechanisms. It became a C2PA Conforming Generator Product and joined the standard’s steering committee in 2024, so files carry signed provenance metadata. It licensed SynthID from Google DeepMind for invisible watermarking of images from 19 May 2026, extended to audio including Voice Engine output on 31 July 2026. And Sora video output carries a visible watermark on top of both.
OpenAI also published a public verification tool that accepts an uploaded image and reports whether it was generated on ChatGPT, the OpenAI API or Codex, by checking for content credentials and SynthID together. The tool is deliberately cautious — when signals are missing or stripped, it declines to draw a conclusion rather than declaring the image human-made. That is the correct behaviour, and it points at the fundamental asymmetry: a watermark proves AI origin, but its absence proves nothing.
Meta, Adobe, Microsoft and the Rest
Meta took the open-source route. Stable Signature embeds a watermark directly into the image decoder of an open generative model, so the mark is produced during generation rather than applied afterwards — harder to strip by removing a post-processing step. AudioSeal does the equivalent for speech and audio, with localised detection that can identify which segment of a longer recording was synthesised.
Adobe Firefly attaches content credentials to every generation and adds a durable watermark that mostly survives screenshots. Microsoft Designer marks output and signs it. Stability AI and Black Forest Labs sign generations made through their hosted APIs, but that guarantee evaporates for self-hosted weights, since anyone can recompile an open model without the watermarking step.
That gap is the structural weakness of the whole scheme, and it maps onto a broader trade-off examined in our comparison of open source and proprietary LLMs: openness that enables auditing also enables removal.
The Text Problem
Image watermarking works. Text watermarking barely exists outside Google. Most large language models — including the ones producing the majority of AI text on the internet — embed nothing detectable in their output. Paraphrasing, translation and light editing degrade token-level watermarks quickly, and a watermark that survives a rewrite tends to damage fluency.
This is why AI text detection still relies on statistical classifiers rather than watermark checks, with all the false-positive risk that implies. Our roundup of the best AI content detectors for text covers what those tools can and cannot establish.
One persistent myth deserves correcting: the “invisible characters” some people find in ChatGPT output are not a watermark. Zero-width spaces and unusual Unicode variants appear as artefacts of tokenisation and formatting, they are trivially removable, and OpenAI has never described them as a provenance mechanism.
Regulation Is Now Forcing the Issue
Voluntary adoption explains part of the shift. Law explains the rest. The EU AI Act’s Article 50 transparency obligations apply from 2 August 2026, requiring providers of generative AI systems to ensure output is marked in a machine-readable format and detectable as artificially generated. Systems already on the market get until 2 December 2026 to comply.
The scope is broad. Obligations bind both providers and deployers, and open-source systems are not exempt. Marking is not required where the AI performs purely assistive editing such as grammar correction, where it does not substantially alter input data, or where a system is lawfully authorised for criminal investigation. A Code of Practice, expected in mid-2026, is defining a standardised EU label — rendered as “AI”, “KI” in German and “IA” in French — along with the technical implementation detail.
Where Watermarking Still Breaks
Provenance metadata does not survive a screen capture. Photograph a screen showing a signed image and you have a clean, unsigned file. Many platforms strip metadata on upload, though TikTok, YouTube, Meta, LinkedIn and Pinterest now read content credentials at upload and surface “AI-generated” or “Captured by camera” labels when present.
Open weights can be run without watermarking. Determined removal is an active research area, and every published watermark scheme has attracted attack papers. And provenance carries its own privacy cost — a full C2PA manifest can expose photographer identity, precise GPS coordinates and device serial numbers, which C2PA 2.1 partly addresses through redactable assertions and zero-knowledge proofs.
The camera side of the chain is filling in, with C2PA-signing firmware shipping on the Leica M11-P, Sony Alpha 1 II, Nikon Z9 and Canon EOS R1, and news organisations including the BBC, AP, Reuters, AFP and the New York Times publishing with embedded credentials.
What This Means in Practice
Assume that anything generated by a major commercial image, video or audio model in 2026 carries a hidden marker. Assume that text generally does not, unless it came from Gemini. Treat a detected watermark as strong evidence of AI origin and treat its absence as no evidence at all, because stripping is easy and open models can be run unmarked.
For publishers and platforms, the useful posture is layered: check content credentials first, check for watermarks second, and fall back on statistical detection last, knowing its limits. Our list of AI detection tools covers the third layer in detail.
If you are interested in this topic, we suggest you check our articles:
- How Do AI Detectors Work?
- The 5 Best AI Content Detectors for Identifying AI-Generated Text
- Best AI Detection Tools: The Complete Year-End List
- Why Originality.AI Is the Gold-Standard AI Detector
- Open Source vs Proprietary LLMs: The Key Differences
Sources: OpenAI, Google DeepMind, Google Blog, Meta AI, EU Artificial Intelligence Act, European Commission, Lumethic
Written by Alius Noreika
