Skip to main content
AI Watermark Removal

Tracker

AI watermark status database

Exactly one provider's own documentation currently says its text output carries a watermark: Anthropic. Every other row below is either media-only, contested, or unknown. The difference between those three is the whole point of this table.

18 product surfaces across 11 providers. Rows are split by surface rather than by company, because the same provider can watermark its consumer app and not its API. Every cell traces to a primary source with the date someone last opened it.

Download the data (JSON)How rows are verified

Status table

Showing 18 of 18 rows.

AI watermark status by provider and product surface, across text, image, audio, video and provenance metadata.
Provider and surfaceTextImageAudioVideoC2PAPublic detectorMechanism disclosedLast verified
AnthropicClaude apps, Claude Code, Claude Platform API, and Claude via AWS, Google Cloud and Microsoft FoundryModels launched on or after 2026-08-02; older models in a stated transition period
Evidence and caveats

The only provider whose own documentation states in the present tense that its text output is watermarked: a supported Claude model "weaves an imperceptible watermark directly into the text itself." Two caveats that change how to read the Yes. Anthropic's rule is that models released on or after 2026-08-02 carry the mark at launch, and its own release notes date every generally available model earlier than that (Opus 5 on 2026-07-24, Sonnet 5 on 2026-06-30, Fable 5 on 2026-06-09). It says retrofitting to earlier models is in progress but has named no model and no date. And no public detector exists, so the mark is documented rather than checkable by anyone outside Anthropic. Signed file metadata is documented as varying by platform, hence Partial. Anthropic is also not a C2PA member at any tier, unlike OpenAI, Google, Meta, Amazon and Microsoft.

Anthropic: How Claude marks AI-generated content
YesN/AN/AN/APartialNoNo2026-08-12
GoogleGemini app and web experience (consumer)Gemini consumer surfaces
Evidence and caveats

DeepMind's SynthID page states SynthID "watermarks text generated by the Gemini app and web experience." A Google-affiliated reply on Google's own AI developer forum, dated 2026-08-05, states that API text is not SynthID-watermarked and that native text watermarking is not planned. Nothing published reconciles the two, so the app/web text row stays Contested. Media watermarking is not in dispute. The SynthID Detector portal is access-gated rather than public, which is why the detector column is Partial.

Google DeepMind: SynthID
ContestedYesYesYesYesPartialYes2026-08-11
GoogleGemini API (developer)Named in the forum reply: gemini-2.5-flash-lite, gemini-3.1-flash-lite
Evidence and caveats

Split from the consumer row deliberately. The forum reply is specific, dated, names model versions, and answers an Article 50(2) question directly. But it is a forum reply, not written documentation, so it carries less weight than the DeepMind page even though it is more specific. If you are building on the API, this is the row that matters.

SynthID watermarking and Article 50(2) on the Google AI Developer Forum
NoYesYesYesYesPartialYes2026-08-11
GoogleSynthID-Text, open-sourced implementationShipped in Hugging Face Transformers 4.46.0+
Evidence and caveats

The one text watermark anyone can actually run and detect end to end: a logits processor applied after Top-K and Top-P sampling, using tournament sampling, with a reference Bayesian detector that returns watermarked / not watermarked / uncertain. Every independent robustness evaluation of "SynthID" tests this, not Google's production keys and configuration, which have never been published.

Google: SynthID safeguards documentation
YesN/AN/AN/AN/AYesYes2026-08-11
OpenAIChatGPT and API text outputAll current text models
Evidence and caveats

OpenAI describes expanding provenance signals to all modalities including text as a goal, in the future tense. Reporting from 2024 established that OpenAI built a text watermarking system internally and held it back over circumvention risk, false positives, and disproportionate impact on non-native English writers. Nothing since supersedes that.

OpenAI Help: Provenance signals in OpenAI-generated content
NoN/AN/AN/AN/AN/AN/A2026-08-11
OpenAIChatGPT, API and Codex image outputGPT-image series and DALL·E series
Evidence and caveats

Since 2026-05-19, OpenAI embeds Google DeepMind's SynthID watermark in generated images alongside C2PA Content Credentials, and is a C2PA steering committee member. OpenAI's own framing is that the two are complementary: C2PA carries context, SynthID survives when the metadata does not. A public Verify tool exists.

OpenAI: Advancing content provenance
N/AYesN/AN/AYesYesYes2026-08-11
OpenAIChatGPT Voice, GPT-Live and API audio output
Evidence and caveats

Added 2026-07-31, two days before EU AI Act Article 50 became applicable, together with a Content Provenance API for programmatic checking. Notably, OpenAI's own GPT-Live system card published three weeks earlier makes no mention of SynthID, C2PA, or watermarking.

OpenAI: Advancing content provenance (audio update)
N/AN/AYesN/AYesYesYes2026-08-11
OpenAISora video output
Evidence and caveats

OpenAI states every Sora video includes both visible and invisible provenance signals. A November 2025 investigation found the reverse in practice: videos carrying the visible watermark had no detectable C2PA metadata via OpenAI's own Verify tool or the open-source c2pa-rs CLI, while Pro-tier videos without the visible mark did. No documented OpenAI response was found.

Independent investigation: Sora watermark and C2PA inconsistency
N/AN/AN/AContestedContestedYesYes2026-08-11
MetaMeta AI app and meta.ai image outputMuse Image
Evidence and caveats

Content Seal launched 2026-07-07 for images, described as surviving cropping, compression, resizing and screenshotting. Meta says it plans to extend it to video; no video launch has been announced. Photorealistic Meta AI images separately carry visible markers plus invisible watermarks and metadata.

Meta: Introducing Muse Image and Muse Video
N/AYesN/ANoYesNoPartial2026-08-11
MetaLlama Defenders audio tooling
Evidence and caveats

Meta shipped an audio watermark detector on 2025-04-29, more than a year before Content Seal and under entirely different branding, aimed at voice fraud. Access has been through an early-adopter programme rather than a public tool.

Meta's AI Defenders Program and Llama protection tools
N/AN/AYesN/AUnknownPartialPartial2026-08-11
MetaLlama open-weight modelsLlama 3.1, Llama 4
Evidence and caveats

The Llama 3.1 and Llama 4 model cards contain zero mentions of watermarking. There is also a structural reason to expect none: once weights ship, whoever runs the model controls decoding, so a provider cannot apply a sampling-time text watermark. Meta has open-sourced a Content Seal framework whose text component, TextSeal, is a May 2026 preprint Meta never claims to have deployed. Because it is generation-time, it could not be retrofitted to text after the fact anyway. Meta signed the EU Code of Practice on Transparency of AI-Generated Content on 2026-07-28, which covers text, while its own announcement discusses only image tooling.

Meta: Stable Signature research
NoN/AN/AN/AN/AN/AN/A2026-08-11
xAIGrok output
Evidence and caveats

xAI's Acceptable Use Policy prohibits "stripping, altering or circumventing embedded provenance metadata or watermarks" in Grok output. That is the only confirmation that some embedded signal exists. The policy never says which standard, which mechanism, or which output types. xAI is not a C2PA member and did not sign the EU transparency code. Verified through an archive capture because x.ai blocks automated fetching.

xAI: Acceptable Use Policy (archived capture)
UnknownUnknownUnknownUnknownPartialNoNo2026-08-10
DeepSeekchat.deepseek.com and Open Platform
Evidence and caveats

DeepSeek's own documentation describes visible AI-content labels required by China's labeling measures, not an invisible watermark. The widely repeated claim that DeepSeek hides a digital fingerprint in its text traces to secondary press describing the national standard's "implicit labeling" requirement, and is not corroborated by DeepSeek's own pages.

DeepSeek: Model and algorithm disclosure
NoUnknownN/AN/AUnknownNoN/A2026-08-11
MicrosoftMicrosoft 365 Copilot and Designer
Evidence and caveats

Images always get C2PA Content Credentials with no opt-out; a visible watermark is user opt-in. Video and audio watermarks sit behind a tenant admin Cloud Policy that defaults to disabled, hence Partial. The full official document contains no provision for watermarking plain-text Copilot responses.

Microsoft Learn: Watermarks for AI-generated content
NoYesPartialPartialYesYesYes2026-08-11
AmazonBedrock: Titan Image, Nova Canvas, Nova Reel
Evidence and caveats

Invisible watermarks plus C2PA metadata on generated images by default, and a Bedrock Watermark Detection feature that scores whether an image carries a Titan or Nova Canvas mark. That feature is region-limited, which is why the detector is Partial. Nova Reel embeds a per-frame mark designed to survive H.264. No watermarking mechanism is documented for Amazon's text models.

AWS documentation for Amazon Titan image models
NoYesN/AYesYesPartialPartial2026-08-11
Mistral AILe Chat and La Plateforme
Evidence and caveats

Mistral's public usage policy contains no mention of watermarking, C2PA, provenance, or Article 50. Le Chat's images come from a Black Forest Labs partnership rather than a Mistral image model, and there is no confirmation Mistral enables that provider's optional invisible-watermark library. Claims elsewhere that Mistral produces unwatermarked text cite no Mistral source. This is a genuine evidence gap in both directions.

Mistral: Usage policy
UnknownUnknownN/AN/AUnknownNoUnknown2026-08-11
PerplexityAnswers and image generation
Evidence and caveats

Architecturally a router over third-party models, so any watermark present is most plausibly inherited from whichever provider served the request rather than added by Perplexity. Whether provenance metadata survives Perplexity's own pipeline is unconfirmed, and its policy pages block automated fetching.

Perplexity community: image generation models
UnknownUnknownN/AN/AUnknownN/AN/A2026-08-11
AlibabaQwen international API vs Tongyi Qianwen in China
Evidence and caveats

Alibaba Cloud co-drafted China's first national digital-watermark standard and names deployments across Amap, Xianyu, Taobao and Tmall, but not Qwen. A 2023 Chinese tech-press report describes screenshot-resistant invisible watermarks in Tongyi Qianwen, but it is three years old, tied to a draft regulation, and not locatable on an Alibaba domain. No English Qwen documentation mentions watermarking at all.

Alibaba Cloud: national digital watermark standard GB/T 45909-2025
UnknownUnknownN/AN/AUnknownNoUnknown2026-08-11

What each value means

The distinction that matters most is between No and Unknown. "No" means a provider's own documentation rules it out. "Unknown" means nobody has said either way, which is a finding about that provider's transparency, not a gap for us to fill with a guess.

Yes
The provider's own current documentation says this output is marked.
No
The provider's own documentation confirms it is not marked, or explicitly describes it as a future goal.
Partial
Marked only under conditions: a specific product surface, an admin setting, or an opt-in.
Contested
Two sources of comparable authority disagree, and nothing published reconciles them.
Unknown
No primary source says either way. Absence of a claim is not a claim of absence.
N/A
The provider does not offer this output type here.

Three things the table shows that summaries miss

Text and media are on completely different timelines

Read down the image column and it is nearly solid: invisible watermarks plus C2PA metadata are settled industry practice. Read down the text column and it is one Yes, one Contested, several explicit Nos and a row of Unknowns. Anyone who says "AI content is watermarked now" is reading the image column.

A watermark without a detector is not a check you can run

The public-detector column is where the practical answer lives. Image and audio provenance can be verified today by anyone with a browser. For text, the one confirmed production watermark has no public detector, and the one detector anyone can run belongs to an open-source implementation rather than a provider's production system.

The surface split is where the contradictions hide

Google appears three times because its consumer app, its developer API, and its open-sourced algorithm carry three different answers for text, and the sources for them disagree. Collapsing those into one "Google" row is how a real, unresolved contradiction gets flattened into a confident sentence.

Method, limits, and how to cite this

Each row starts from a primary source the provider controls: documentation, a support article, terms, a model card, or an official announcement. Secondary reporting is used to find those primaries, not to stand in for them. Where a provider blocks automated access and the claim was read through an archive capture, the row's note says so.

The honest limits: this table records what providers say, not what independent testing has confirmed. Nobody outside these companies can currently verify a text watermark's presence in a given passage, so a "Yes" in the text column means documented, not measured. Rows go stale. Check the last-verified date before relying on one.

Reuse is welcome. Cite it as: AI Watermark Status Database, www.aiwatermarkremoval.com, version 1.0.0, updated 2026-08-12. A link back to this page is the only thing asked. If you reproduce a row, please carry its last-verified date with it.

Found a row that is wrong or stale? That is a correction, and corrections get logged publicly. See the corrections policy.

Go deeper on a provider