Google opened its SynthID detector to the public this week. The pitch is clean: paste in an image, a clip, or an audio file, and the site will tell you whether it carries a Google-family AI watermark. The problem is that this is a lock on one door of a house with no walls.
SynthID is good work. It's also, by design, a partial answer to a problem that is no longer partial. By one estimate cited by EDMO, AI now generates at least 57% of online content. The World Economic Forum's Global Risks Report 2026 ranked misinformation and disinformation, driven by synthetic media, as the second most severe short-term risk globally. Against that backdrop, a watermark that only reads its own ink is a useful tool and a limited one. Both things are true.
What SynthID actually does
The tool embeds imperceptible signals directly into the pixels of AI-generated images, audio, text, or video — invisible to humans, legible to Google's detector. The public site at synthid.com supports JPG, MP4, and WAV, identifies content from Google, OpenAI, NVIDIA, and Kakao models, and is already fielding around 1 million requests a day, according to Ars Technica. Apple support is coming. The watermarks are engineered to survive resizing, cropping, compression, color shifts, filtering, and overlay noise, per technical documentation summarized by Medium.
That last point matters. Most prior watermarking schemes dissolved the moment someone screenshotted a thing or ran it through a basic filter. SynthID doesn't. It's a real step up.
Google has also been widening the surface. In September 2026, DeepMind introduced SynthID Bio, which embeds watermarks into AI-designed protein sequences while preserving biological function — published in Nature. The ambition is obvious. Watermark everything that gets generated, everywhere it gets generated, before the generation outruns the auditing.
The structural problem no engineer can fix alone
Here's where the whole thing gets uncomfortable. SynthID only detects what SynthID marked. Run an image through Midjourney, OpenAI's DALL-E, or a Stable Diffusion model on a laptop in a bedroom, and the detector returns nothing — because there is nothing to detect. The absence of a watermark is not evidence of authenticity. It is evidence of absence.
That is the first ceiling. The second is adversarial. Researchers have already demonstrated bypass techniques — most notably "re-nosing," which regenerates an image in a way that scrambles the embedded signal, creating what one write-up called a technological cat-and-mouse game. Text watermarks degrade under thorough paraphrasing. None of this is Google's fault. It's physics plus incentives.
Which is why the OpenAI, NVIDIA, and Kakao partnerships are the actual news, not the public URL. A watermark standard that one company owns is a product. A watermark standard that a coalition owns is infrastructure. SynthID is trying, in slow motion, to become the latter.
It's not there yet. Not close.
A tool for the careful, not the careless
Who benefits from SynthID in its current form? Journalists verifying a specific image before publication. Platform trust-and-safety teams triaging high-stakes uploads. Researchers studying how synthetic media moves. These are important users. They are not the users driving the misinformation crisis.
The crisis lives downstream of Facebook aunts, group chats, and TikTok reposts, where no one is pasting a suspect JPG into a detector site before forwarding it. For that audience, the only interventions that scale are platform-level: automatic checks at upload, labels at display, friction at share. Google can't impose that on Meta or ByteDance. Nobody can, yet.
So the honest read on this week is that Google shipped a careful, legitimately useful piece of safety infrastructure and simultaneously demonstrated how small any single company's piece of this is going to be. SynthID is the right shape of answer. It's just one answer among the dozens that would need to exist, agree on a standard, and get adopted by platforms that currently have no commercial reason to add friction.
The watermark is clever. The flood is cleverer. Build the levees anyway — just don't tell people they're safe.




