Google Wants SynthID to Become the Web’s AI Watermark Checker

Google’s SynthID Detector can now check AI watermarks from OpenAI, NVIDIA, Kakao, and Google itself. The expansion could make AI content verification easier, but an undetected watermark does not prove authenticity. As regulators push for machine-readable AI labels, questions about reliability, independent auditing, and Google's role in verification are becoming harder to ignore.

Oct 8, 2026
10 minute read

Imagine a video starts spreading online. It looks real enough: a politician speaking, a CEO admitting something explosive, maybe just a suspiciously perfect clip of an animal doing something the laws of physics strongly discourage.

You upload it to Google's new SynthID Detector.

The answer comes back: Not detected.

So... real?

Not necessarily. And that small gap between "we didn't find an AI watermark" and "this is authentic" may be the most important thing to understand about Google's newest attempt to make sense of the AI-generated internet.

On October 7, Google opened its SynthID Detector to the public, making the service available worldwide in English. The tool examines images, videos, and audio files for invisible watermarks embedded by participating AI systems. It supports content from Google, OpenAI, NVIDIA, and Kakao, with Apple expected to join later.

Previously tested with journalists and media professionals, SynthID Detector is now available to ordinary users who want another way to investigate suspicious media.

But Google's expansion introduces a bigger question. As more AI companies adopt a common watermarking system, the company operating its verification portal gains influence over how people identify AI-generated content.

That influence has limits, and Google has not announced plans to become the internet's universal verification authority. Still, its growing network of participating providers offers an early glimpse of how a shared verification service could develop.

The real question is whether a privately operated tool can become widely trusted verification infrastructure without independent accountability.

SynthID works more like a barcode scanner than a lie detector

Advertisement

The name "AI detector" invites the wrong mental model.

Most people imagine software examining a suspicious image for signs of artificial generation: strange fingers, inconsistent shadows, unusual pixels, or other clues suggesting a computer made it.

SynthID takes a different approach.

When a participating AI system generates media, it embeds an invisible digital watermark into the resulting file. Google's detector subsequently looks for that watermark.

Think of it like a supermarket barcode scanner. The scanner recognizes the code because somebody intentionally put it there. It doesn't examine the ingredients to decide which company probably manufactured the product.

Similarly, SynthID searches for a known signal rather than trying to identify every possible sign of AI generation.

According to Google, SynthID watermarks have been embedded in more than 180 billion images and videos, along with an amount of audio equivalent to 240,000 years. The company also reports that verification features integrated into Search, Gemini, and Chrome collectively handle more than one million requests daily.

Those are substantial deployment figures, although Google has not published an independently audited breakdown establishing exactly how the totals were calculated.

More importantly, those numbers do not tell us what proportion of AI-generated media circulating online actually contains SynthID watermarks.

That distinction becomes increasingly relevant as Google expands beyond its own products.

OpenAI, NVIDIA, and Kakao are participating in the SynthID ecosystem. OpenAI's provenance documentation also describes how the company incorporates watermarking and other provenance signals into supported generated content.

For someone checking a suspicious file, compatibility across different companies is a meaningful improvement. Instead of visiting separate verification services for every participating provider, users can check multiple sources through one portal.

Of course, the convenience only extends to the systems and content types the detector actually supports.

Advertisement

The most important result is also the easiest to misunderstand

Imagine a journalist receives a suspicious video claiming to show a public official making an inflammatory statement.

They upload it to SynthID Detector.

There are two broad outcomes, and they carry very different meanings.

If SynthID detects a watermark, the result provides evidence that a participating AI system generated or edited the media. That is useful information, but it does not establish whether the depicted statement is true, whether the clip is misleading, or how extensively AI was involved.

If SynthID does not detect a watermark, the journalist has learned considerably less.

The video might have originated from an unsupported AI system. It might have been created before a provider introduced watermarking. The watermark could have been degraded by subsequent processing, or the video might genuinely be camera-recorded footage.

The detector cannot reliably distinguish between those explanations based on a negative result alone.

Google's SynthID documentation acknowledges the limitations of watermark verification and recommends using multiple forms of evidence when assessing media.

That creates a practical rule for anyone using the service:

Treat a detected watermark as evidence of supported AI involvement. Treat an undetected watermark as an unanswered question.

For journalists, the next steps remain familiar: establish where the file originated, identify the earliest available version, examine its surrounding context, and corroborate the events it supposedly depicts.

For ordinary users, that might mean checking the original source, comparing the material against reliable reporting, and resisting the temptation to share something simply because a detector returned no match.

There is another wrinkle here. Even completely authentic footage can be misleading when paired with a false caption or presented without context.

A genuine recording from three years ago might circulate as evidence of something happening today. No amount of watermark checking will resolve that discrepancy.

Advertisement

Provenance helps explain a file's origins. Truthfulness still depends on evidence about what the file actually shows.

Google is entering a market where verification is becoming a regulatory requirement

The timing of Google's expansion matters.

On August 2, 2026, transparency requirements under Article 50 of the European Union's AI Act began applying to covered AI systems.

Among those requirements, providers of AI systems generating synthetic audio, images, video, or text must ensure that applicable outputs carry machine-readable indications identifying them as artificially generated or manipulated.

There is an important qualification: providers of qualifying AI systems placed on the market before August 2, 2026, have until December 2, 2026, to comply with the marking and detection requirements under Article 50(2).

The European Commission also clarifies that content generated before August 2 does not generally need to be labeled retroactively.

These obligations help explain why AI companies have growing incentives to develop reliable watermarking, detection, and provenance technologies.

The EU has also been developing a Code of Practice on Transparency of AI-Generated Content to help companies implement the relevant requirements.

SynthID fits naturally into that environment. A provider that embeds recognizable watermarks into generated media gains a technical mechanism for demonstrating how its systems support content identification.

But adopting SynthID does not automatically establish compliance with every applicable legal requirement. Regulators must still assess matters such as technical effectiveness, reliability, scope, and interoperability.

Google is also operating within a broader ecosystem rather than creating the only available verification approach.

The Coalition for Content Provenance and Authenticity has developed Content Credentials, a standard for attaching cryptographically verifiable information about digital media's origin and editing history.

The distinction is useful. SynthID embeds a signal within media, while Content Credentials use signed provenance information that can document aspects of a file's creation and modification history.

Advertisement

Other tools attempt to identify synthetic content by analyzing the media itself. In The Neuron's coverage of UCLA's optical deepfake detection research, researchers explored another route to distinguishing artificial imagery from camera-captured material.

Each approach answers a different verification question. Combining them provides more context than relying on any single technique.

Which raises another problem: How dependable is an invisible watermark once someone deliberately tries to remove it?

Watermarks have a security problem that cannot be solved with marketing claims

Google says SynthID is designed to withstand common modifications, including cropping, filtering, compression, and changes to video frame rates.

That resilience matters because online media rarely stays untouched. Images get screenshotted, videos get recompressed, and files move through platforms that modify them automatically.

A watermark that disappears after ordinary processing would have limited value as a verification mechanism.

But deliberate manipulation presents a more difficult challenge.

At the 2026 USENIX Security Symposium, researchers presented MarkNull, a watermark-removal technique designed to interfere with several watermarking systems while preserving the appearance of generated images.

The researchers reported successful attacks against the SynthID-Image implementation they tested.

That finding is significant, but its scope matters. The experiments do not establish that every current SynthID deployment is vulnerable, nor do they provide a comprehensive assessment of Google's newly expanded public detector across every participating provider.

They demonstrate something more specific: under certain conditions, attackers can interfere with watermark detection without making an image obviously damaged.

And that introduces a difficult tradeoff for Google.

Publishing extensive technical details about detection thresholds and failure conditions would help researchers independently evaluate the technology.

However, unrestricted access to those details could also help attackers repeatedly test modifications until they find a way around the detector.

Both concerns are legitimate.

Security systems frequently restrict sensitive operational details. The challenge is establishing mechanisms that allow meaningful independent scrutiny without making evasion easier.

Advertisement

For SynthID, those mechanisms could include controlled research access, independent testing laboratories, and published performance results that do not disclose exploitable detection thresholds.

Google's public documentation explains how the technology works and describes its intended resilience. What remains difficult for outside observers to assess is a comprehensive, independently audited performance breakdown covering every participating provider, supported modality, and common real-world transformation.

That missing information matters because users need to know how much confidence to place in the results.

The bigger question is who sets the rules for verification

Google's most consequential move may be convincing other major AI companies to participate in the same verification ecosystem.

OpenAI, NVIDIA, and Kakao are already included. Apple is expected to follow.

Those partnerships could reduce fragmentation and make AI provenance easier for ordinary people to understand. Instead of learning several different detection systems, users gain a common place to look for compatible watermark signals.

There's a reasonable argument that this is exactly what the industry needs.

Building and maintaining a publicly accessible detector requires infrastructure, ongoing security work, technical coordination, and a willingness to collaborate with competitors. Google is investing in a service that could make verification more convenient.

And the company's existing scale gives it a practical advantage in making the tool accessible.

The concern emerges when convenience begins to create dependence.

Consider four decisions involved in operating a verification portal:

  • Coverage: Which providers, products, models, and media formats can the detector recognize?
  • Access: How many checks can users perform, and do professional verification teams receive additional access?
  • Interpretation: How does the interface describe positive, negative, or inconclusive results?
  • Accountability: Who independently evaluates error rates, investigates failures, and challenges misleading results?

Google makes important operational decisions about its own detector, including its interface, access conditions, and supported integrations.

That does not mean Google controls every watermarking system, the underlying standards adopted by other providers, or the broader market for digital provenance.

However, increasing adoption could make decisions about Google's particular service more consequential for the people and organizations relying on it.

A casual user checking a suspicious meme might tolerate limited daily access. A newsroom investigating dozens of videos during a breaking event has different requirements.

A platform considering automated provenance checks also needs repeatable performance, clear technical specifications, and reliable access at scale.

And companies using watermarking to support their transparency obligations need evidence that the technology performs as intended.

As those uses expand, questions about independent audits, higher-volume access, interoperability, and oversight become increasingly important.

Google does not necessarily need to surrender control of its technology to answer those questions.

But a verification service that aspires to widespread trust needs ways for people outside its operator to evaluate its performance.

Otherwise, users are being asked to trust the technology largely on the strength of assurances from the company providing it.

What would make SynthID genuinely trustworthy?

The most useful next step would be greater transparency about what the detector can reliably identify.

That begins with a detailed explanation of coverage. Naming participating companies is helpful, but users also need to understand which products, media types, and versions are supported.

A video generated by an unsupported system should never be implicitly treated as equivalent to one examined against a known compatible watermark.

Independent performance evaluations would provide another important layer.

Researchers could test representative files across supported systems, measure false-positive and false-negative rates, and examine how results change after common transformations such as cropping, compression, or re-recording.

The findings would not need to reveal sensitive detection thresholds to provide useful information about reliability.

Professional access is another consideration. Google previously tested SynthID with journalists and media professionals, making those users a natural group for evaluating whether the public service meets demanding verification workflows.

Their needs go beyond individual uploads. Newsrooms may require higher-volume checking, consistent result documentation, and clear explanations of technical limitations.

Finally, the interface itself matters.

The language presented alongside a negative result should make clear that the absence of a detected SynthID watermark does not establish authenticity.

That is a small design decision with significant consequences for how people interpret the technology.

Google has made AI content easier to check. Trust is the harder problem.

Google's SynthID expansion represents a meaningful step toward more accessible AI provenance.

A single portal that recognizes compatible watermarks from multiple major AI companies offers something genuinely useful, especially as synthetic images, videos, and audio become increasingly common.

Its value could grow as additional providers participate.

But wider adoption will also increase the importance of understanding the system's limitations, measuring its reliability, and ensuring that verification does not depend entirely on one company's assurances.

The broader goal should be a verification ecosystem where multiple signals complement one another, where independent researchers can assess technical claims, and where users understand what the results actually establish.

Google has demonstrated that competing AI companies can participate in a common watermark-checking service.

The next challenge is showing how well that service performs outside controlled conditions, including when files have been modified, copied, or deliberately manipulated.

Because the internet's trust problem has never been limited to identifying which software produced an image.

It's deciding what evidence deserves belief.

And even the best watermark detector can only answer part of that question.

Eric Gerard Ruiz, CPA

Eric Gerard Ruiz, CPA

Accounting and Bookkeeping Expert at Fit Small Business

Eric Gerard Ruiz, a licensed CPA in the Philippines, specializes in financial accounting and reporting (IFRS), managerial accounting, and cost accounting. He has tested and review accounting software like QuickBooks and Xero, along with other small business tools. Eric also creates free accounting resources, including manuals, spreadsheet trackers, and templates, to support small business owners.

The Neuron Logo

Don't fall behind on AI. Get the AI trends & tools you need to know. Join 700,000+ professionals from top companies like Microsoft, Apple, Salesforce and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

Stay in the loop

Get notified when we publish new articles.