Open Editor
Privacy
8 min read

SynthID and AI Watermarking in 2026: The Real Numbers, and Where Detection Actually Works

Google's invisible AI watermark has scaled by 10x since last year, and rivals are adopting it as a shared standard. An independent test of what actually survives on social media tells a more complicated story.

DateSynthID Content Watermarked
May 2025Over 10 billion pieces
November 2025Over 20 billion pieces
May 2026 (I/O)Over 100 billion images/videos, plus ~60,000 years of audio

Google DeepMind's SynthID — an invisible watermark woven into AI-generated images, audio, video, and text at the moment of creation — has become the closest thing the AI industry has to a shared technical standard for provenance. The scale is real. So is a detail that keeps getting lost: a number that was accurate eighteen months ago is still being quoted in articles published this year as if it were current.

A Number That Keeps Getting Cited Out of Date

When Google launched the public SynthID Detector in May 2025, the company said the watermark had already been applied to more than 10 billion pieces of content. That figure grew to over 20 billion by November 2025, when image verification arrived inside the Gemini app. At Google I/O in May 2026, Google announced the number had grown roughly tenfold: more than 100 billion images and videos, plus an amount of watermarked audio the company describes as roughly 60,000 years' worth. Despite that, a number of articles published well into 2026 still cite "over 10 billion" as SynthID's current scale — carrying forward a figure that was accurate at launch but is now more than a year and one full order of magnitude out of date.

What SynthID Actually Covers Now

As of the May 2026 update, SynthID watermarks four content types — images, audio, video, and text — and is embedded by default in Google's own generative tools: Gemini, Imagen, Veo, Lyria, and NotebookLM's audio output. The May 2026 announcement was as much about distribution as generation: Google added SynthID and C2PA verification directly into Search, Chrome, and Circle to Search on Android, meaning a person can check an image for AI origin without leaving the platform they found it on. Gemini's own verification feature — letting a user check whether an image, video, or audio clip carries the watermark — has been used roughly 50 million times globally since its November 2025 debut.

The bigger shift is that SynthID stopped being Google-only. OpenAI joined the C2PA steering committee and began embedding SynthID in images generated through ChatGPT, Codex, and the OpenAI API starting May 19, 2026, alongside the C2PA metadata it already attached. ElevenLabs and Kakao adopted it the same day, and NVIDIA had already integrated SynthID into its Cosmos video models back in January 2026. That's a genuinely unusual moment of cross-competitor alignment on a shared detection standard, which the earlier post on C2PA's adoption status covers from the metadata side of the same story.

What an Independent Test Found: An 18% Detection Rate on X

Scale numbers describe how much content gets marked at the moment of generation. They say much less about what survives once that content moves through the open internet — and a peer-reviewed study offers a rare, independently measured answer. Researchers collected 200 AI-generated images from GPT-Image-2 that OpenAI had disclosed as watermarked, tracked them after being shared on X, and tested whether SynthID could still be detected in them. Only 36 of the 200 — 18% — still registered a detectable SynthID watermark. In the same sample, C2PA metadata detection came back at zero, because platform uploads to X strip that metadata entirely.

A watermark surviving 18% of the trip through a single platform's upload pipeline isn't a failure of the technology so much as a demonstration of what "survives compression and re-encoding" actually means once real-world platform processing gets involved — Google's own claims about durability are about the watermark itself, not about what any given platform chooses to do with a file before displaying it.

Text Watermarking: The Field Almost Nobody Has Actually Shipped

Outside of images, audio, and video, text is the modality where the gap between "announced" and "actually available" is widest. Google's SynthID for text — a statistical pattern embedded in how the model selects among likely next words — has shipped since 2023 and is the most mature implementation of its kind. Anthropic announced text watermarking for Claude on August 11, 2026, covering all products and regions with no opt-out for new models going forward, though a public detection API was promised rather than shipped at announcement. OpenAI, by contrast, built a text watermark for ChatGPT back in 2023 and never released it, reportedly after internal testing found many users said they'd stop using the product if flagged. Microsoft has stated plainly that text Copilot writes in Word, Outlook, or Teams isn't visually watermarked. Meta, Mistral, and Cohere signed the EU's Code of Practice but haven't announced a text watermark of their own, and xAI didn't sign the Code at all.

ProviderText Watermark Status
Google (SynthID)Shipped since 2023, token-pattern based
Anthropic (Claude)Announced Aug 11, 2026; detection API not yet shipped
OpenAIBuilt in 2023, never released
Microsoft CopilotNo text watermark
Meta / Mistral / CohereSigned EU Code of Practice; no text watermark announced
xAI (Grok)Did not sign the Code of Practice

A Point of Confusion Worth Clearing Up: The Visible Toggle Isn't the Real Watermark

In August 2026, Google added a setting in Gemini that lets a person turn off the small visible watermark badge that appears on AI-generated images. Reporting on the change at the time confirmed something important: switching that setting off removes only the visible badge. The invisible SynthID signal and any C2PA metadata attached to the file stay in place either way. It's an easy detail to misread as "Google added a way to make AI images undetectable," when the actual change only affects a cosmetic marker, not the underlying provenance signal a detector actually checks for.

Why SynthID and C2PA Are Treated as Two Layers, Not Competing Standards

The two systems fail in different, complementary ways, which is why the industry has settled on using both rather than picking one. SynthID is woven into the pixels or audio itself, so it survives a screenshot, a re-compression, or a platform re-upload — but it carries no information about who made the content or what tool was used. C2PA's Content Credentials carry that context, in a cryptographically signed manifest, but the manifest is metadata sitting beside the file, and gets stripped the moment a platform strips metadata — which is exactly what the 18% detection study found happening on X. Relying on either one alone leaves a real gap; using both is the closest current approach to covering each one's blind spot with the other.

What This Means Heading Into December

None of this exists in a vacuum. The EU AI Act's Article 50(2) marking requirement, covered in more detail in the earlier post on the Act's next real deadline, requires exactly this kind of layered marking — both a signed manifest and an imperceptible watermark — for generative AI systems already on the EU market, with the grace period ending December 2, 2026. SynthID's rapid scale-up and its adoption by OpenAI, ElevenLabs, and others isn't happening in isolation from that deadline; it's a large part of how providers are positioning themselves to meet it. Whether a study like the 18% detection rate on X becomes the exception or the norm as more platforms get tested is one of the more consequential open questions heading into that date.


The honest summary: SynthID's scale is real and has grown roughly tenfold in the past year to over 100 billion images and videos, not the 10 billion figure still circulating in outdated coverage. Text watermarking remains the least mature piece of the picture, shipped meaningfully only by Google and, as of August 2026, Anthropic. And the one independent, real-world test of detection after a platform upload found a watermark surviving well under a fifth of the time — a reminder that "the technology exists" and "the technology reliably works once content leaves the platform that made it" are two different claims.

For questions or inquiries contact us at info@cleartexteditor.com