we_are_coded.by CODE · The world, decoded
БГ
Concept

Watermarks (SynthID, Content Seal)

The BasicsUpdated on 7 October 2026we are coded

An invisible stamp in the photo, sound or text - proof it was made by AI. Assuming the AI-maker even bothered to sign it.

Checked on7 October 2026
In short: SynthID is an invisible watermark that Google DeepMind (Google's research unit for artificial intelligence) embeds into everything its models generate - text, photo, sound, video. Content Seal is the same idea from Meta (the company behind Facebook and Instagram), so far only for photos generated by their model, Muse Image. Both are unreadable to the eye, but a machine can read them and say "this was made by AI". The hole is simple: the mark only appears if the model's maker builds it in. Since August 2, 2026 European law requires providers to mark their output, but an open model with no built-in stamp carries nothing.

The idea is like an invisible stamp on a banknote. You look at the piece of paper and see nothing special, but under the right instrument the stamp comes out and gives away its origin. SynthID does the same at the level of a pixel, a sound wave, or even word choice - when Gemini, Google's text model, writes a sentence, it slightly tilts the odds of which words get picked, in a way invisible to the reader but recognizable to the detector. The mark survives even after compression, cropping, or being reuploaded to another platform.

Google has already put it in by default on everything it produces - the text of Gemini, the photos of Imagen, the video of Veo, the sound of Lyria. This year the mark also rolled out into Google Search and the Chrome browser, and OpenAI, the maker of ChatGPT, and ElevenLabs, an AI voice company, announced they'll use it too. Google also opened a verification portal, for now available to journalists and researchers - you drop in a file, it tells you whether it carries the mark.

Content Seal follows the same logic, but it's much younger and narrower. It only works with photos made with Muse Image, and survives even cropping, compression, resizing or a screenshot. The problem is it doesn't talk to SynthID and isn't compatible with C2PA (Content Credentials) - a separate international standard that records a file's origin in its metadata, not in the content itself. Three systems, three separate ledgers. None reads the other.

And here we get to the real weakness. A watermark isn't a law of physics. It's a decision the model maker makes voluntarily. Open up an open model with no built-in mark, generate whatever you want, and no detector finds anything - because there's nothing to find. As of August 2, 2026, the European Union makes labeling AI content mandatory by law, with fines up to 15 million euros, but the law applies to companies, not to the file. It can't make a mark appear where nobody put one.

Update, 16 August 2026: text got its stamp too. On 14 August Anthropic explained that future Claude models will carry a statistical watermark in text using DeepMind's SynthID-Text method: when the model chooses between equally suitable words, the choice is settled by a key instead of chance; whoever holds the key estimates the probability that a text came from Claude. Nothing is added to the characters, zero extra tokens, not traceable to a person or chat. The trigger is the EU AI Act - since 2 August 2026 providers in Europe must mark generated content, and the other major developers are doing the same under a common Code of Practice. The limit is the same as with images: the mark says 'probably', weakens in edited text and does not exist in an open model with no built-in stamp.

Update, 7 October 2026: OpenAI now marks text too, with its own technology called textGrain. It announced it on 5 October as its answer to Article 50 of the EU AI Act, which requires generated text to be identifiable by machine. The invisible mark is coming to ChatGPT and Codex for users in the EU "over the coming weeks", in the API it's opt-in for the customer, and the detector is for now limited to approved researchers and expert organizations. OpenAI published the honest numbers itself. At 1% false alarms, the detector finds the mark in about 80% of 200-token passages and about 95% at 400, for text with freedom in word choice; for mathematics it's substantially weaker. Swap 10% of the words for synonyms and detection drops from about 92 to 66%. At 25%, it's 17%.

The numbers say the same thing we said about Claude: the mark speaks in 'probably', and quietly. A short text, a bit of editing, and the stamp fades. That's why OpenAI isn't handing the detector to everyone either: with a signal that weakens this easily, a wrong verdict is too close.

The visual is generated code art. No third-party images.
Official primary sources
→Google DeepMind: SynthID→European AI law, labeling obligation→Anthropic - How Claude's text watermark works→OpenAI: Our approach to EU text provenance rules (Oct 5, 2026)→EUR-Lex: Regulation (EU) 2024/1689 (AI Act), Article 50