Google Announces 'SynthID Detector' Tool to the Public So Anyone Can Verify Watermarked AI Media Across Partners

For years, people who wanted to know whether a photo, clip, or recording had come from a generative model had to rely on visual clues, source claims, or tools that only covered a narrow set of systems. 

Those signals were uneven. Some models left traces, others did not, and public checkers often failed once a file had been cropped, filtered, or re-encoded.

The good thing is that, pretty much all files carry metadata, or an invisible badge that says how, or when, or where they were made. 

However, since those labels sit beside the content, a save a copy, a screenshot, or running the file through a compressor, will make this metadata disappear. 

The remaining solution is to go back to square one, and analyze anything inside the pixels, the frames, or the sound itself still records where the file came from.

Google DeepMind started writing one such signal, called SynthID, into generated media in 2023. 

On October 7, 2026, the company opened a public checker at synthid.com, in English and without a geographic restriction. 

With it, anyone who signs in with a Google, OpenAI, or Apple account, can upload an image, a video, or an audio file, and have the site report whether it finds a SynthID watermark. 

In the announcement, Google said that the checker now looks for marks from Google and from partners that have adopted the scheme, currently OpenAI, Nvidia, and Kakao, with Apple listed as forthcoming. 

Some accounts of the partner set also include ElevenLabs. 

Coverage is not automatic for every product or every older file from those companies. It applies where each provider has turned watermarking on.

Until this release, people outside a tester program mostly had to ask Gemini, and that check only recognized Google's own mark. An image produced by ChatGPT could carry SynthID and still come back unmarked. 

An earlier portal, introduced in 2025, was limited to journalists and other media professionals. 

The public site is narrower than some internal tools: it returns a finding on whether a supported watermark is present, rather than highlighting the regions of an image that carry the signal. Use is capped at roughly ten image, video, and audio checks a day. 

Google engineers have told reporters the limit is meant to make it harder to probe the detector while building a removal method. The site itself states that it is not a general detector of AI-generated media.

Google says more than 180 billion images and videos, and audio equivalent to 240,000 years, have already been marked. The portal sits alongside checks in Search, the Gemini app, and Chrome, which Google says now handle more than one million verification requests a day.

The mark is not a scan for general signs of synthesis. 

It is a signal inserted by participating systems and later read back. 

For images, DeepMind uses two neural networks trained together. An encoder adds a low-amplitude pattern across the pixel values of a finished image. A decoder searches for that pattern and returns a detection score, and in the partner version a short payload that can distinguish one deployment from another. 

A technical account of the image system, SynthID-Image, describes the process as post-hoc and model-independent: the mark is applied after generation, so one encoder can cover output from different models. 

The change is lossy in principle. 

Training is set so the alteration stays below what viewers notice, while remaining readable after common operations such as cropping, color shifts, filters, resizing, and lossy compression. DeepMind has said the mark is not reliable against extreme manipulation.

Video uses the same pixel approach on each frame, so trimming or a change in frame rate does not automatically erase every copy of the signal. Where a clip also has a generated soundtrack, the audio track can be checked on its own.

Audio follows a different path. 

The waveform is converted into a spectrogram, a time-frequency picture of the sound. The watermark is written into that representation, then the spectrogram is turned back into a waveform. The insertion is tuned to properties of human hearing so the added pattern stays inaudible. Google says the audio mark is built to survive added noise, MP3 compression, and moderate changes in playback speed, and that a scan can indicate which stretches of a file carry the signal.

Text uses a separate technique and is not something the public upload portal checks. 

In the version described in a 2024 Nature paper and later open-sourced, the model still samples tokens from its usual distribution, but a keyed function slightly shifts which tokens are preferred. 

The watermark is that statistical bias, not hidden characters. Detection grows more reliable as the passage gets longer and weakens under heavy rewriting.

Other provenance systems work differently. 

C2PA content credentials attach signed metadata that records a claimed history of creation and editing. That record can be rich, and it can also be stripped when a file is re-saved. 

SynthID does the opposite: it hides a signal in the content and says nothing about cameras, edits, or publishers beyond the presence of the mark. Meta and some other providers use their own watermarking or labeling schemes. Many open-weight models add none.

A positive result on synthid.com is evidence that the file passed through a participating pipeline. 

A negative result does not establish that the file is photographic, recorded, or otherwise free of generative tools.

Image
SynthID

In an age where accessible AI tools produce photorealistic media in seconds, human perception is no longer a reliable line of defense. 

The subtle visual glitches and audio artifacts that once exposed synthetic media are rapidly disappearing, leaving even trained eyes and ears unable to reliably distinguish real from fake.

Google's public SynthID detector provides a critical safeguard by shifting verification from subjective human judgment to objective mathematical signals. By reading imperceptible patterns embedded directly inside pixels and sound waves, the tool can verify origin even when media looks entirely convincing.

While watermarking is not a complete fix for every unflagged or open-source generator, putting cross-industry verification directly into the public's hands is a major step forward. 

When seeing is no longer believing, algorithmic proof offers a dependable way to trace where synthetic media came from.

Further reading: SynthID Watermark Google Gemini Uses Allegedly Extracted: Consequences Will Follow

Published