Tracker
AI watermark status database
Exactly one provider's own documentation currently says its text output carries a watermark: Anthropic. Every other row below is either media-only, contested, or unknown. The difference between those three is the whole point of this table.
18 product surfaces across 11 providers. Rows are split by surface rather than by company, because the same provider can watermark its consumer app and not its API. Every cell traces to a primary source with the date someone last opened it.
Status table
Showing 18 of 18 rows.
| Provider and surface | Text | Image | Audio | Video | C2PA | Public detector | Mechanism disclosed | Last verified |
|---|---|---|---|---|---|---|---|---|
AnthropicClaude apps, Claude Code, Claude Platform API, and Claude via AWS, Google Cloud and Microsoft FoundryModels launched on or after 2026-08-02; older models in a stated transition periodEvidence and caveatsThe only provider whose own documentation states in the present tense that its text output is watermarked: a supported Claude model "weaves an imperceptible watermark directly into the text itself." Two caveats that change how to read the Yes. Anthropic's rule is that models released on or after 2026-08-02 carry the mark at launch, and its own release notes date every generally available model earlier than that (Opus 5 on 2026-07-24, Sonnet 5 on 2026-06-30, Fable 5 on 2026-06-09). It says retrofitting to earlier models is in progress but has named no model and no date. And no public detector exists, so the mark is documented rather than checkable by anyone outside Anthropic. Signed file metadata is documented as varying by platform, hence Partial. Anthropic is also not a C2PA member at any tier, unlike OpenAI, Google, Meta, Amazon and Microsoft. Anthropic: How Claude marks AI-generated content | Yes | N/A | N/A | N/A | Partial | No | No | 2026-08-12 |
GoogleGemini app and web experience (consumer)Gemini consumer surfacesEvidence and caveatsDeepMind's SynthID page states SynthID "watermarks text generated by the Gemini app and web experience." A Google-affiliated reply on Google's own AI developer forum, dated 2026-08-05, states that API text is not SynthID-watermarked and that native text watermarking is not planned. Nothing published reconciles the two, so the app/web text row stays Contested. Media watermarking is not in dispute. The SynthID Detector portal is access-gated rather than public, which is why the detector column is Partial. Google DeepMind: SynthID | Contested | Yes | Yes | Yes | Yes | Partial | Yes | 2026-08-11 |
GoogleGemini API (developer)Named in the forum reply: gemini-2.5-flash-lite, gemini-3.1-flash-liteEvidence and caveatsSplit from the consumer row deliberately. The forum reply is specific, dated, names model versions, and answers an Article 50(2) question directly. But it is a forum reply, not written documentation, so it carries less weight than the DeepMind page even though it is more specific. If you are building on the API, this is the row that matters. SynthID watermarking and Article 50(2) on the Google AI Developer Forum | No | Yes | Yes | Yes | Yes | Partial | Yes | 2026-08-11 |
GoogleSynthID-Text, open-sourced implementationShipped in Hugging Face Transformers 4.46.0+Evidence and caveatsThe one text watermark anyone can actually run and detect end to end: a logits processor applied after Top-K and Top-P sampling, using tournament sampling, with a reference Bayesian detector that returns watermarked / not watermarked / uncertain. Every independent robustness evaluation of "SynthID" tests this, not Google's production keys and configuration, which have never been published. Google: SynthID safeguards documentation | Yes | N/A | N/A | N/A | N/A | Yes | Yes | 2026-08-11 |
OpenAIChatGPT and API text outputAll current text modelsEvidence and caveatsOpenAI describes expanding provenance signals to all modalities including text as a goal, in the future tense. Reporting from 2024 established that OpenAI built a text watermarking system internally and held it back over circumvention risk, false positives, and disproportionate impact on non-native English writers. Nothing since supersedes that. OpenAI Help: Provenance signals in OpenAI-generated content | No | N/A | N/A | N/A | N/A | N/A | N/A | 2026-08-11 |
OpenAIChatGPT, API and Codex image outputGPT-image series and DALL·E seriesEvidence and caveatsSince 2026-05-19, OpenAI embeds Google DeepMind's SynthID watermark in generated images alongside C2PA Content Credentials, and is a C2PA steering committee member. OpenAI's own framing is that the two are complementary: C2PA carries context, SynthID survives when the metadata does not. A public Verify tool exists. OpenAI: Advancing content provenance | N/A | Yes | N/A | N/A | Yes | Yes | Yes | 2026-08-11 |
OpenAIChatGPT Voice, GPT-Live and API audio outputEvidence and caveatsAdded 2026-07-31, two days before EU AI Act Article 50 became applicable, together with a Content Provenance API for programmatic checking. Notably, OpenAI's own GPT-Live system card published three weeks earlier makes no mention of SynthID, C2PA, or watermarking. OpenAI: Advancing content provenance (audio update) | N/A | N/A | Yes | N/A | Yes | Yes | Yes | 2026-08-11 |
OpenAISora video outputEvidence and caveatsOpenAI states every Sora video includes both visible and invisible provenance signals. A November 2025 investigation found the reverse in practice: videos carrying the visible watermark had no detectable C2PA metadata via OpenAI's own Verify tool or the open-source c2pa-rs CLI, while Pro-tier videos without the visible mark did. No documented OpenAI response was found. Independent investigation: Sora watermark and C2PA inconsistency | N/A | N/A | N/A | Contested | Contested | Yes | Yes | 2026-08-11 |
MetaMeta AI app and meta.ai image outputMuse ImageEvidence and caveatsContent Seal launched 2026-07-07 for images, described as surviving cropping, compression, resizing and screenshotting. Meta says it plans to extend it to video; no video launch has been announced. Photorealistic Meta AI images separately carry visible markers plus invisible watermarks and metadata. Meta: Introducing Muse Image and Muse Video | N/A | Yes | N/A | No | Yes | No | Partial | 2026-08-11 |
MetaLlama Defenders audio toolingEvidence and caveatsMeta shipped an audio watermark detector on 2025-04-29, more than a year before Content Seal and under entirely different branding, aimed at voice fraud. Access has been through an early-adopter programme rather than a public tool. Meta's AI Defenders Program and Llama protection tools | N/A | N/A | Yes | N/A | Unknown | Partial | Partial | 2026-08-11 |
MetaLlama open-weight modelsLlama 3.1, Llama 4Evidence and caveatsThe Llama 3.1 and Llama 4 model cards contain zero mentions of watermarking. There is also a structural reason to expect none: once weights ship, whoever runs the model controls decoding, so a provider cannot apply a sampling-time text watermark. Meta has open-sourced a Content Seal framework whose text component, TextSeal, is a May 2026 preprint Meta never claims to have deployed. Because it is generation-time, it could not be retrofitted to text after the fact anyway. Meta signed the EU Code of Practice on Transparency of AI-Generated Content on 2026-07-28, which covers text, while its own announcement discusses only image tooling. Meta: Stable Signature research | No | N/A | N/A | N/A | N/A | N/A | N/A | 2026-08-11 |
xAIGrok outputEvidence and caveatsxAI's Acceptable Use Policy prohibits "stripping, altering or circumventing embedded provenance metadata or watermarks" in Grok output. That is the only confirmation that some embedded signal exists. The policy never says which standard, which mechanism, or which output types. xAI is not a C2PA member and did not sign the EU transparency code. Verified through an archive capture because x.ai blocks automated fetching. xAI: Acceptable Use Policy (archived capture) | Unknown | Unknown | Unknown | Unknown | Partial | No | No | 2026-08-10 |
DeepSeekchat.deepseek.com and Open PlatformEvidence and caveatsDeepSeek's own documentation describes visible AI-content labels required by China's labeling measures, not an invisible watermark. The widely repeated claim that DeepSeek hides a digital fingerprint in its text traces to secondary press describing the national standard's "implicit labeling" requirement, and is not corroborated by DeepSeek's own pages. DeepSeek: Model and algorithm disclosure | No | Unknown | N/A | N/A | Unknown | No | N/A | 2026-08-11 |
MicrosoftMicrosoft 365 Copilot and DesignerEvidence and caveatsImages always get C2PA Content Credentials with no opt-out; a visible watermark is user opt-in. Video and audio watermarks sit behind a tenant admin Cloud Policy that defaults to disabled, hence Partial. The full official document contains no provision for watermarking plain-text Copilot responses. Microsoft Learn: Watermarks for AI-generated content | No | Yes | Partial | Partial | Yes | Yes | Yes | 2026-08-11 |
AmazonBedrock: Titan Image, Nova Canvas, Nova ReelEvidence and caveatsInvisible watermarks plus C2PA metadata on generated images by default, and a Bedrock Watermark Detection feature that scores whether an image carries a Titan or Nova Canvas mark. That feature is region-limited, which is why the detector is Partial. Nova Reel embeds a per-frame mark designed to survive H.264. No watermarking mechanism is documented for Amazon's text models. AWS documentation for Amazon Titan image models | No | Yes | N/A | Yes | Yes | Partial | Partial | 2026-08-11 |
Mistral AILe Chat and La PlateformeEvidence and caveatsMistral's public usage policy contains no mention of watermarking, C2PA, provenance, or Article 50. Le Chat's images come from a Black Forest Labs partnership rather than a Mistral image model, and there is no confirmation Mistral enables that provider's optional invisible-watermark library. Claims elsewhere that Mistral produces unwatermarked text cite no Mistral source. This is a genuine evidence gap in both directions. Mistral: Usage policy | Unknown | Unknown | N/A | N/A | Unknown | No | Unknown | 2026-08-11 |
PerplexityAnswers and image generationEvidence and caveatsArchitecturally a router over third-party models, so any watermark present is most plausibly inherited from whichever provider served the request rather than added by Perplexity. Whether provenance metadata survives Perplexity's own pipeline is unconfirmed, and its policy pages block automated fetching. Perplexity community: image generation models | Unknown | Unknown | N/A | N/A | Unknown | N/A | N/A | 2026-08-11 |
AlibabaQwen international API vs Tongyi Qianwen in ChinaEvidence and caveatsAlibaba Cloud co-drafted China's first national digital-watermark standard and names deployments across Amap, Xianyu, Taobao and Tmall, but not Qwen. A 2023 Chinese tech-press report describes screenshot-resistant invisible watermarks in Tongyi Qianwen, but it is three years old, tied to a draft regulation, and not locatable on an Alibaba domain. No English Qwen documentation mentions watermarking at all. Alibaba Cloud: national digital watermark standard GB/T 45909-2025 | Unknown | Unknown | N/A | N/A | Unknown | No | Unknown | 2026-08-11 |
What each value means
The distinction that matters most is between No and Unknown. "No" means a provider's own documentation rules it out. "Unknown" means nobody has said either way, which is a finding about that provider's transparency, not a gap for us to fill with a guess.
- Yes
- The provider's own current documentation says this output is marked.
- No
- The provider's own documentation confirms it is not marked, or explicitly describes it as a future goal.
- Partial
- Marked only under conditions: a specific product surface, an admin setting, or an opt-in.
- Contested
- Two sources of comparable authority disagree, and nothing published reconciles them.
- Unknown
- No primary source says either way. Absence of a claim is not a claim of absence.
- N/A
- The provider does not offer this output type here.
Three things the table shows that summaries miss
Text and media are on completely different timelines
Read down the image column and it is nearly solid: invisible watermarks plus C2PA metadata are settled industry practice. Read down the text column and it is one Yes, one Contested, several explicit Nos and a row of Unknowns. Anyone who says "AI content is watermarked now" is reading the image column.
A watermark without a detector is not a check you can run
The public-detector column is where the practical answer lives. Image and audio provenance can be verified today by anyone with a browser. For text, the one confirmed production watermark has no public detector, and the one detector anyone can run belongs to an open-source implementation rather than a provider's production system.
The surface split is where the contradictions hide
Google appears three times because its consumer app, its developer API, and its open-sourced algorithm carry three different answers for text, and the sources for them disagree. Collapsing those into one "Google" row is how a real, unresolved contradiction gets flattened into a confident sentence.
Method, limits, and how to cite this
Each row starts from a primary source the provider controls: documentation, a support article, terms, a model card, or an official announcement. Secondary reporting is used to find those primaries, not to stand in for them. Where a provider blocks automated access and the claim was read through an archive capture, the row's note says so.
The honest limits: this table records what providers say, not what independent testing has confirmed. Nobody outside these companies can currently verify a text watermark's presence in a given passage, so a "Yes" in the text column means documented, not measured. Rows go stale. Check the last-verified date before relying on one.
Reuse is welcome. Cite it as: AI Watermark Status Database, www.aiwatermarkremoval.com, version 1.0.0, updated 2026-08-12. A link back to this page is the only thing asked. If you reproduce a row, please carry its last-verified date with it.
Found a row that is wrong or stale? That is a correction, and corrections get logged publicly. See the corrections policy.