
Google Opened Its AI Watermark Detector to Everyone. Read the Fine Print Before You Trust It.
Mahmud Hasan
October 7, 2026
Google just gave everyone a tool to check whether an image, video, or audio clip was made with AI — and the most important sentence on its page is the disclaimer. The SynthID Detector, opened globally on October 7, is the rare detection product that's upfront about what it can't see. That honesty, and the fine print behind it, is exactly the story.
The news: one portal, every major model vendor
As of October 7, 2026, anyone can visit synthid.com, upload an image, video, or audio file, and ask Google a narrow question: does this carry a SynthID watermark? If the answer is yes, the tool highlights which parts of the file are most likely watermarked. The portal is free, global, and in English — after more than a year of being limited to a waitlist of journalists, media professionals, and researchers.
The bigger story is who's behind the watermark. The public detector now recognizes SynthID signals from Google's own models (Gemini, Imagen, Lyria, Veo, Nano Banana) and from OpenAI, NVIDIA, and Kakao, with Apple support promised soon. OpenAI's participation isn't brand-new — Google announced the partnership in May 2026 and OpenAI started watermarking supported audio with SynthID in July — but this is the first time ordinary users get one public place to check supported media across several companies at once.
The scale is worth a pause. Google says that since SynthID launched in 2023, it has applied the watermark to more than 180 billion images and videos and roughly 240,000 years of audio. Verification features already built into Search, the Gemini app, and Chrome now handle over a million requests a day, according to Google. (In May 2026, the same program was at 100 billion images and 60,000 years of audio, with the Gemini app alone recording 50 million verifications.)
The most important sentence on the page
The SynthID Detector's FAQ carries a line that no other AI-detection product has ever been brave enough to print: "This is not a general AI detector."
That matters because the last three years produced a small industry of tools that claimed to identify AI-generated content by statistical guesswork — and they failed loudly. Turnitin's AI detector misfired on real students. Freelancers lost contracts to bogus flags. Researchers showed again and again that classifiers trained to spot "AI-looking" pixels or prose were unreliable at exactly the moments that mattered.
SynthID works the other way around. It doesn't guess from the content; it looks for a machine-readable signal placed at the moment of creation by a participating model. For images and video, the watermark is a pattern embedded directly into the pixels; for audio, it rides in the waveform. Human eyes can't see it. Google's detection model can. And if the signal isn't there, the tool says so — plainly, without pretending it knows more than it does.
The fine print: 10 checks a day, sign-in required, and a missing mark proves nothing
Here's what the launch announcements don't lead with. Using the public detector requires signing in (Google, Apple, or OpenAI account), and each user is reportedly limited to roughly 10 checks per day across all supported media types. Google told Ars Technica the quota exists to make it harder for people to probe the detector repeatedly to develop watermark-removal techniques. That's an honest reason, and it quietly admits something: the watermark is only as strong as the arms race around it.
More important is the interpretation rule, which the sources state explicitly and every user should internalize:
- Watermark detected → the file carries a recognized SynthID signal from a supported AI system. That says nothing about whether the content is accurate, unedited, or being used in its original context.
- No watermark detected → the detector found no supported SynthID signal. That does not establish the file is human-made or authentic.
A clean result is not a certificate of authenticity. The detector is blind to every model that doesn't watermark with SynthID — open-weight systems, local generators, and any lab that chose a different (or no) standard. It also degrades under heavy manipulation: light cropping and lossy compression are survivable, but heavier edits can scrub the signal. A determined forger doesn't even need to remove it; the research question of stamping a fake watermark onto real content (forgery) is an active, documented problem too.
Why Google is building a provenance layer, not just a tool
Step back and the October 7 launch looks less like a product release and more like a bet on infrastructure. Google already surfaces SynthID checks inside Search, the Gemini app, and Chrome; the dedicated portal makes it a cross-company verification layer. OpenAI is playing a layered game of its own: its C2PA Content Credentials carry signed metadata about a file's origin and history, while SynthID provides an embedded mark that survives metadata stripping. NVIDIA has announced SynthID watermarking for video generated through its Cosmos platform. The industry is stacking overlapping provenance systems because nobody trusts any single one to survive contact with reality.
And reality is rough on watermarks. The counter-argument writes itself, and the research literature supplies it: text watermarking is the weak link — paraphrasing, translation, and copy-paste edits substantially degrade SynthID-Text, and the EU's own Code of Practice acknowledges lower reliability below 200 tokens. Independent work published in March 2026 claimed to identify fixed carrier frequencies in Gemini-generated images via Fourier analysis and demonstrated a spectral bypass with image-quality loss invisible to the eye (Google has not published a response, and the claims haven't been independently replicated). A 2024 result, "Watermarks in the Sand," proved the sobering theorem: no watermark survives a determined attacker. DeepMind's own paper concedes that SynthID alone will not solve misinformation, impersonation, or copyright tracking.
None of that makes the launch pointless. It makes the honest framing essential. A provenance system that admits its blind spots is more useful than a "detector" that doesn't have any. Newsrooms can check whether a viral image came from a supported generator. Advertisers can confirm provenance on creative assets. Courts can treat a positive result as one piece of evidence among several. What nobody should do is treat a negative result as proof the internet is human-made again.
What to actually do with this
If you're a developer, the practical takeaway is a small decision rule, not a tool recommendation: use the detector to confirm provenance, never to deny it. Positive result? Useful — the file was touched by a participating AI system. Negative result? Uninformative — move on to other evidence (source, context, corroboration).
And if you're building anything that consumes user-uploaded media — a newsroom CMS, a marketplace, a moderation queue — the launch is a signal about where the industry is heading: watermark verification is becoming infrastructure, like TLS certificates. The winning play isn't finding the perfect detector. It's stacking evidence: embedded watermarks, signed metadata (C2PA), and plain old source-checking, each covering the others' blind spots. Google just made its layer public. The catch is the same as it ever was: the layer only covers the companies that agreed to be covered.
References
- Google expands SynthID Detector for AI content — The Keyword (official announcement)
- Google SynthID Detector Goes Global: It Can Now Check Supported AI Media From OpenAI, NVIDIA and Kakao — Techgenyz
- Google Opens SynthID Detector Globally With Partner AI Content Checks — Unite.AI
- Google Opens SynthID Detector to the World as AI Watermarking Gains Industry Allies — WebProNews
- Google Launches New SynthID Site To Verify AI-Generated Media — NDTV Profit
- Explaining SynthID — PPC Land (limits, criticism, open disputes)
Comments
More in Artificial Intelligence

Apple's New CEO Just Made Himself Its Design Chief. He's an Engineer. That's the Point.
John Ternus visits Apple's design studio several times a week — Tim Cook came about once a month. Seven years after Jony Ive left, the CEO has made himself the company's design chief, and the bet is that one decision-maker beats a committee.
Read more
