On October 7, 2026, Google opened SynthID Detector, a tool for checking watermarks in AI-generated content, to users worldwide in English. In addition to Google's own AI, SynthID as used by OpenAI, NVIDIA, and Kakao can now be checked through the same entry point. The verification portal, which began in 2025 as a limited test for journalists and researchers, is now open to the general public. It cuts the effort of investigating images of unknown origin, but a "not detected" result must not be read as a finding that the image is authentic. Comparing Google's announcement with the public portal's documentation shows that what has expanded is the range of signals, left by various companies' AI, that the tool can check.

AD

A shared entry point for checking multiple companies' watermarks

At synthid.com, you can upload image, video, and audio files and check whether SynthID is present. Google lists itself, OpenAI, NVIDIA, and Kakao as supported, and says Apple will join soon. It would be premature to assume Apple is already supported.

The earlier verification portal was offered to early testers in the May 20, 2025 announcement, and worked through a waitlist for journalists, media professionals, and researchers. That explanation centered on verifying content made with Google's AI, though other companies' adoption of the technology had already been presented, as in the NVIDIA Cosmos example. What has changed is not that other companies have started using watermarks for the first time, but that general users can now check partner companies' watermarks through a single entry point.

The technology called SynthID and the targets of this public site also need to be kept apart. SynthID has a method for text, but the current portal's FAQ lists only three types of content it checks: images, video, and audio. This is not an announcement that pasting in text will produce the same kind of determination.

According to Google, the images and videos watermarked so far total more than 180 billion, and audio amounts to 240,000 years in length. Verification features built into Search, the Gemini app, and Chrome together handle more than one million requests a day, it says. The latter figure is not usage of the new site alone, and the former does not indicate what share of all AI-generated content can be detected. The scale of watermark use and the accuracy of detection are separate measures.

Why watermarks can be found even after editing

SynthID works differently from methods that estimate how AI-like an image is from unnatural hand shapes or backgrounds. It looks for a signal deliberately embedded at the time of generation. It leaves the signal in pixels for images and video, and in frequency components for audio, so unlike a visible logo or descriptive information attached to a file, the clue to identification lives in the content itself.

In the image method Google DeepMind published in 2023, the model that embeds the watermark and the model that identifies it are trained together on a variety of images. The design aims for the watermark to be findable while remaining inconspicuous to the human eye. This describes the early image method; it cannot be said that every partner company and every medium uses the same model configuration today.

Metadata, such as the date and time a photo was taken, can be lost during editing or sharing. A watermark embedded in pixels, by contrast, can survive even after metadata disappears. The current technical explanation also says it was designed to withstand cropping, filters, compression, and similar changes to images and video. The advantage of this approach is that clues to generation and editing can still be sought after material has been reposted elsewhere.

Still, withstanding editing is not the same as being detectable after any edit. In its public FAQ, Google explains that heavy compression and editing affect detection, and recommends using files of the highest quality possible. The public release came with no announcement guaranteeing successful detection under every editing condition.

AD

The gap between "not detected" and "not AI"

When a watermark is found, the public FAQ says it indicates the content may have been generated or edited by an AI model that supports SynthID. This result alone does not settle whether an entire image was generated from scratch or only part of it was AI-edited. Nor does it determine whether the material is being used to deceive people. The SynthID Detector FAQ also acknowledges that it may occasionally respond to material with no watermark.

There is a larger caveat for non-detection. Google cites two causes: the content was made with a model that does not use SynthID, or with a model from before SynthID was adopted, and heavy processing degraded the watermark signal. AI-generated material that could not be detected and material that never involved AI can arrive at the same "not detected" result.

In other words, the information gained from a positive and a negative result is not symmetrical. A detected signal is a lead for investigating AI involvement, but the absence of a signal provides no new evidence that a human captured the image.

For example, if part of a photograph you took was edited with AI, treating even the parts that were actually photographed as fabricated would be a mistake. Conversely, if an old genuine photo is given a false date or location, the explanation can be false even without any AI watermark. In the former case you need to check the altered portion; in the latter, the time of capture and the context of publication. "Was AI involved?" and "Is the event being reported true?" are separate questions that should be answered separately.

Opening to the public and preventing misuse of the detector

The public portal's additional terms prohibit attacks that use detection results to evade or degrade watermarks, as well as automated bulk verification that bypasses the interface. They also do not allow evading usage limits through multiple accounts or similar means. Having a window anyone can use does not mean providing a service that can process material in unlimited, automated fashion. The additional terms reflect that distinction.

This restriction reflects a structural problem: the people verifying and the people trying to remove watermarks can use the same results. Google itself explains in the FAQ that trying many transformations could turn up one that is not detected. Output that gives legitimate users a lead for verification can also give those attempting evasion information for judging whether their edits succeeded. Read together with this property, the terms suggest that the more the tool's availability is widened, the more the access to the detector needs to be protected.

The privacy notice also separates the original file from information used to prevent abuse. According to Google, uploaded original files are deleted immediately after the result is returned. On the other hand, for daily usage limits and protection against automated attacks, it stores the material's "digital signature" linked to a user identifier and permanently deletes it after 24 hours. Immediate deletion of the original file cannot be extended to mean that all information associated with verification disappears immediately.

AD

What SynthID and C2PA each prove is different

Among technologies for confirming the source and editing history of material, there are Content Credentials based on C2PA. These bind information about the origin and changes of material with a digital signature, and verify the correspondence between information and material and whether it has been tampered with. The evidence it provides differs from the generation and editing signals checked with SynthID.

SynthID verifies generation and editing signals, while C2PA verifies signed provenance. Neither alone proves whether the depicted event is true.

What is checked SynthID Detector C2PA Content Credentials
What is verified Generation and editing signals embedded by adopting models Signed provenance information, its binding to the material, and whether it has been tampered with
How information is held Leaves a watermark in the pixels of images and video and in the frequency components of audio Provenance information is normally attached to the material; it can also be linked to external storage
If nothing is found Possibility remains of a non-adopting or pre-adoption model, or of signal degradation It may never have been attached or may have been removed; failing to find provenance does not settle authenticity
What it does not establish alone Whether the whole scene is fabricated, whether there is malicious intent, whether the explanation is true The integrity of the recorded provenance, or whether the depicted event is true

The comparison maps Google's FAQ and Sections 2, 6, and 7.2 of the official C2PA 2.4 explainer, both checked on October 8, 2026, onto four questions asked when verifying the same material. It is not a table comparing detection accuracy. SynthID can produce false positives and misses, and what C2PA can establish also depends on trust in the signer and the scope of the stored information.

It is also inaccurate to regard C2PA as a mechanism limited to metadata that disappears when content is shared. The official explainer includes a design that uses watermarks and fingerprint matching to rediscover, from external storage, provenance information lost from the material. This does not mean the watermarks referred to there are the same as the SynthID discussed here, but watermarks and signed provenance are technologies that can be used in combination.

In practice, for material where a watermark is detected, you would ask the provider which parts were generated or edited. Even when nothing is detected, you would keep checking the first appearance, the capture date and time, and the source. If provenance information exists, you would add that record and its signer to your evidence. The value of a shared entry point is that you can begin part of this checking without hunting for a separate entry point for each generator.

Whether Apple's support actually begins, and how large the misses and false positives are for each partner company and each editing condition, will also shape future evaluation. The public materials reviewed here give no figures broken down by those conditions. Once both the number of companies available and the conditions under which results can be trusted become clear, those receiving material will be able to use watermark detection more appropriately alongside other evidence.