Google’s SynthID watermark is hard to break, but it doesn’t solve AI misinformation

← Back to the feed

Google’s SynthID watermark is hard to break, but it doesn’t solve AI misinformation

Ars Technica · 7 hours ago

Google's SynthID watermarking technology aims to label AI-generated images, video and audio in a way that survives edits, compression and resharing, and it is now being adopted beyond Google's own tools by companies including OpenAI, Runway and Nvidia. The push comes as the sheer volume of AI-generated media has exploded – Google says its tools alone have produced over 100 billion AI images and videos in the space of a few years – making reliable labelling increasingly important for helping people distinguish real content from synthetic content online.

Testing by Ars Technica examined whether SynthID's invisible watermark, which is embedded in pixel or waveform data rather than easily stripped metadata, actually holds up under real-world conditions. Using a Python script to simulate repeated compression, resizing and resharing, the outlet degraded both a fully AI-generated image and an AI-edited photograph, both produced with Google's Nano Banana Pro tool, to see whether the watermark survived. Google DeepMind scientist Pushmeet Kohli said the technology was deliberately designed and tested against such transformations, unlike the alternative C2PA metadata standard, which is cryptographically secure but trivially removed by a simple screenshot or re-save.

  • Google's SynthID watermark is designed to survive edits and resharing of AI content.
  • OpenAI, Runway and Nvidia are adopting SynthID as AI media output surges.
  • Testing shows watermarks alone may not fully solve AI misinformation concerns.

AI Technology

Read the full article at the source →