How AI Watermarks Work and How to Check for Them
Explore how invisible and visible AI watermarks work across images, audio, video, and text from Anthropic and Google, plus detection limits.

Stock photo for illustration only, not from the actual event
- Anthropic's Claude models will soon add invisible text watermarks
- Google made visible Gemini image watermarks an optional feature
- Different media types use distinct watermarking and removal methods
As artificial intelligence-generated content continues to flood the digital space, verifying the origin of media has become increasingly complex. Recently, Anthropic announced that its Claude models will soon begin embedding invisible watermarks in text outputs. At the same time, Google revealed that the visible gray watermark on generated images from Gemini will now be optional. These contrasting updates highlight the wildly varied approaches companies take toward watermarking AI content.
Despite differences across media formats, the core principle remains consistent: embedding undetectable or subtle data into generated files so detection tools can identify AI involvement without relying on unreliable AI detectors. For images, Google's SynthID distributes an invisible signature across pixel mathematical values, meaning the watermark survives even if the image is cropped. Audio watermarking places signature frequencies outside the human hearing range, typically below 20Hz or above 20,000Hz, remaining imperceptible to ears but detectable by software.

Stock photo for illustration only, not from the actual event
Generated videos typically combine both image and audio watermarking techniques, though creators can mix AI audio with real video, leading to fragmented watermark presence. Additionally, frameworks like C2PA allow camera manufacturers to embed traceable metadata into media files, helping verify the origin of an image. However, actually detecting these watermarks or metadata remains inconsistent, as OpenAI and Google maintain separate verification tools with limited public availability.
The lack of a unified universal standard for AI watermarking creates practical hurdles for everyday users. Because different tech companies rely on proprietary detection frameworks, verifying content authenticity often requires knowing which specific tool generated the file in the first place.
Removing these identifiers varies significantly by medium. Metadata like C2PA is remarkably fragile and can be completely wiped simply by taking a screenshot of an image, which generates a fresh pixel file without the original metadata trail. Conversely, pixel-level watermarks like SynthID are far more resilient, surviving standard crops, filters, and modifications unless deliberately and heavily altered.
Text watermarks remain among the easiest to bypass since they rely on adjusting word probabilities. Running AI-generated text through another rephrasing tool or simply rewriting the sentences manually can remove the watermark entirely. Furthermore, users must remember that authentic media can accidentally acquire a watermark if an original photo is uploaded to a tool like Gemini for minor edits, triggering false positives on AI detection tools.
Source: Lifehacker
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment