Google DeepMind's SynthID works largely as advertised. The system embeds an imperceptible signal directly into AI-generated images, audio, video, and text, and the companion SynthID Detector portal can reliably identify content produced by Google's own AI tools. According to Ars Technica's testing, the technology performs well under everyday conditions. The harder question is whether that performance is enough.
A system built for scale, with real limits
By May 2026, SynthID had marked more than 10 billion pieces of content, according to Google. The SynthID Detector portal, announced at Google I/O 2025, gives journalists, researchers, and media organisations a dedicated tool to upload files and check whether a watermark is present. Google has also open-sourced the text watermarking component, and other companies including Nvidia and OpenAI have adopted parts of the SynthID specification, with partners such as Shutterstock, Snap, and Canva among those previewing a new Content Detection API on Google Cloud.
But the system carries structural limitations that Google itself acknowledges. According to Google's own documentation, detector confidence drops sharply when AI-generated text is thoroughly rewritten or translated into another language. The watermark is also less effective on short factual responses, where the model has less freedom to embed a signal without compromising accuracy. For images, the situation is compounded by a fragmented ecosystem: a Google-generated image passes clean through OpenAI's verification tool, and vice versa, because each company's verifier is keyed only to its own payload.
“"Content could also still be AI-generated by another company's model, which the tool currently does not detect." — OpenAI, on its own verification portal”
Researchers have already found a way in
The more troubling finding came from outside Google's labs. In March 2026, independent researcher Alosh Denny published a method to reverse-engineer SynthID using only a 2D Fourier transform and phase-coherence analysis applied to a large batch of Gemini-generated images. The attack removed approximately 91% of the watermark energy while leaving image quality almost entirely intact, and it required no access to Google's proprietary systems. The method was subsequently discussed widely across technical communities. A separate peer-reviewed tool, UnMarker, developed at the University of Waterloo, was reported to reduce SynthID detection from 100% to around 21% in black-box conditions, though it required high-end GPU hardware that limits its practical availability to most bad actors.
These findings do not make SynthID useless. Casual misuse is still harder with the watermark than without it, and Google has noted that its decoder can be updated to respond to known attacks. But they do illustrate the asymmetry at the heart of any watermarking strategy: the defender must protect every piece of content, while the attacker only needs one working method. The existence of publicly available removal tools, documented and distributed on GitHub within weeks of disclosure, demonstrates how quickly that asymmetry can shift.
Regulation is arriving faster than the technology is ready
The policy environment is moving regardless. The EU AI Act's transparency obligations under Article 50 take effect on 2 August 2026, requiring providers of AI systems that generate synthetic audio, images, video, or text to ensure their outputs are marked in a machine-readable format. The European Commission published a Code of Practice on 10 June 2026 as a voluntary implementation framework for marking, detection, and deepfake labelling. Separately, Google updated its advertising policies in July 2026 to allow visible AI labels on ad creatives, citing emerging requirements in the EU, India, and New York.
The consensus among compliance and security analysts is that no single technology will be sufficient on its own. Metadata standards such as C2PA (Content Provenance and Authenticity), invisible watermarking, platform-level labels, and user disclosure requirements are likely to work best in combination rather than in competition. But that layered approach also multiplies the points of failure. C2PA metadata, for example, is routinely stripped when files are screenshotted or re-uploaded through platforms that do not preserve it, meaning that real photographs can be incorrectly flagged as AI-generated while genuine AI content passes through clean.
“"The practical compliance stack is likely to combine metadata, watermarking, platform labels, and user disclosure rather than one universal technology." — eyesift.com”
The deeper difficulty is one of incentives. Platforms and regulators are building detection systems for content produced by companies that voluntarily embed watermarks. The content that poses the greatest risk to public trust, that produced by motivated actors with no interest in transparency, is precisely the content that watermarking schemes are least likely to catch. SynthID is a serious engineering effort, and its scale is genuinely impressive. Whether it is enough to anchor a regulatory regime that applies to the entire AI content ecosystem is a different question, and the honest answer remains: not yet.
This article is free to read. It always will be — no paywall, no account, no tracking.

![Rare Book Division, The New York Public Library. "Secunda pagina figurarum capitalium. [Human brain, 5 pictures]" The New York Public Library Digital Collections. 1545.](https://cdn.sanity.io/images/gt4b4gx5/production/28a5ba9b3044077d150cfaa4d5ccb7281a2fd406-1920x1280.png?rect=0,40,1920,1200&w=760&h=475&q=75&fit=crop&auto=format)


