Skip to main content
AI Watermark Removal

Is it watermarked?

ChatGPT Watermark: Is Anything Actually Watermarked?

Three different things get called the ChatGPT watermark, and only two of them are on your file. Since May 19, 2026, images generated by ChatGPT have carried Google DeepMind's SynthID pixel watermark stacked on top of OpenAI's own C2PA metadata, a genuine cross-company arrangement most users never notice. Audio got SynthID on July 31, 2026, though without any C2PA manifest. Ordinary chat text is a different story: OpenAI reportedly built a text watermark years ago, said plainly why it is still not shipped, and has told us more about that decision than Anthropic, Google, or Meta have told us about theirs. Which is also the honest answer to removal, because you cannot strip a mark nobody has deployed.

By Rowan ValePublished Revised Sources verified Confirmed

Correction,

This page absorbed the site's two other OpenAI pages, the head-term evidence file and the removal query, which split one subject across three URLs. Grafting their facts in surfaced three claims all three pages had wrong. All three said OpenAI marks audio the way it marks images, with C2PA metadata plus SynthID. It does not: OpenAI attaches no C2PA manifest to audio, and this site's own status database recorded that on 2026-09-03. All three also dated OpenAI's C2PA steering-committee membership to the May 2026 image rollout; OpenAI's own page places the membership in 2024 and describes only its "C2PA Conforming Generator Product" status as recent. And all three named ChatGPT Voice and GPT-Live as the watermarked audio surfaces; OpenAI's own page says "ChatGPT and the OpenAI API" and names neither product. The verdict box, the takeaways and the audio section now match the primary sources.

All corrections

Correction,

The answer box graded Sora output as confirmed for both C2PA metadata and SynthID. That contradicted this site's own evidence: the full OpenAI file records a November 2025 audit that found visibly watermarked Sora 2 videos carrying no detectable C2PA metadata, and unwatermarked Pro-tier videos that did carry it, and the provider table already marked Sora video as inconsistent. The box now separates images and supported audio, which are confirmed, from Sora video, which is contested. The same box also offered media verification as confirmed without the caveat stated further down this page, that any upload can strip the manifest and a clean result proves nothing; it now says verification holds only on an unmodified original. The shelved text watermark carried three different evidence labels on this one page and is now labelled Reported, matching the rest of the corpus.

All corrections

Short answer

ChatGPT text
No deployed public watermark
ChatGPT and API images
Yes, C2PA plus SynthID
ChatGPT and API audio
Yes, SynthID only, no C2PA
Sora video
Signals inconsistent in testing
Can you verify media?
Only on an unmodified original
Can you verify text?
No
Is there a text watermark to remove?
No, nothing is deployed
An AI detector saying 87%
Not watermark evidence

OpenAI has documented provenance on generated media for years and has repeatedly described text provenance as a goal rather than a shipped feature. That is why removing a ChatGPT text watermark is a question about a system nobody has shipped, while removing an image credential is something an ordinary upload does by accident.

Key takeaways

  • Confirmed: since May 19, 2026, images from ChatGPT, the OpenAI API, and Codex carry both C2PA Content Credentials metadata and Google DeepMind's SynthID pixel watermark, checkable through OpenAI's Verify tool, which OpenAI introduced as a preview.
  • Confirmed, with one correction: audio from ChatGPT and the OpenAI API got SynthID on July 31, 2026, two days before EU AI Act Article 50 took effect, alongside a Content Provenance API. Audio carries SynthID only. OpenAI attaches no C2PA manifest to it, so an audio file has no metadata layer to lose.
  • Reported: OpenAI built an internal ChatGPT text-watermarking method reportedly around 99.9% effective years ago and held it back, citing circumvention risk, a disproportionate false-positive impact on non-native English writers, and internal survey data suggesting roughly 30% of users would use ChatGPT less if it shipped. OpenAI's own published posts make the same arguments, so this is not only a leak.
  • Contested: OpenAI says every Sora video carries both visible and invisible provenance signals. A November 2025 independent investigation found the reverse in places, and video is the one modality OpenAI gives nobody any way to check.
  • Removal, honestly: there is no deployed ChatGPT text watermark to remove, image C2PA metadata comes off by accident on any ordinary upload, and the only reported way to defeat SynthID on an image was regenerating the whole image through a different model at a real cost to quality.
  • Community discussion, unresolved: a June 28, 2026 OpenAI Developer Community thread found that a PNG's valid C2PA metadata gets stripped down to bare file chunks the moment it is re-uploaded into a ChatGPT conversation, even though the original file still verifies fine. No OpenAI staff response was found.
  • Hidden Unicode characters, non-breaking spaces, repeated phrases, and writing-style habits get called ChatGPT watermarks constantly online. OpenAI has never named any of them as a mechanism.

Signal breakdown

OpenAI: what carries a mark, and what doesn't

Compare all providers

The clearest split between modalities of any provider: images carry two independent provenance layers, audio carries SynthID alone, ordinary text carries none.

  • Chat and API textNot marked

    Described as a future goal, in the present tense, since 2024

  • ImagesMarked

    SynthID watermark plus C2PA Content Credentials, since 2026-05-19

  • AudioMarked

    SynthID, since 2026-07-31 (two days before Article 50 applied)

  • Sora videoConditional

    Independent testing found the visible and invisible signals inconsistent

Detector: Public. The Verify tool, now at openai.com/research/verify/, checks images and audio; a Content Provenance API accepts the same two.

Every state above traces to a primary source with a verification date in the status database, and the provider detail is the rest of this page.

Removal reality check

OpenAI: what is actually there to remove

What exists to remove

  • Images. SynthID watermark plus C2PA Content Credentials, since 2026-05-19
  • Audio. SynthID, since 2026-07-31 (two days before Article 50 applied)
  • Sora video. Independent testing found the visible and invisible signals inconsistent

What can be verified

Public. The Verify tool, now at openai.com/research/verify/, checks images and audio; a Content Provenance API accepts the same two.

For an image or an audio file you can actually run the check. For text there is nothing to check, because there is nothing marked.

What are the three layers people call the ChatGPT watermark?

Confirmed

Sort out which one you are asking about first. Two of the three are on your file, they break in opposite ways, and the third was shelved before it shipped.

LayerWhat is documented
C2PA Content Credentials metadatadocumented by OpenAI, attached to generated images, and the most fragile layer by far.
SynthIDdocumented for images since May 19, 2026 and for audio since July 31, 2026. It lives in the pixels or the waveform, not in a metadata field.
An ordinary-text watermark in chat outputbuilt, reportedly, then shelved. Never confirmed by OpenAI as live.

The first two do not fail the same way. Metadata can be lost to format conversion, re-saving, screenshotting, or a plain re-upload, gone in a single step.

Losing the metadata tells you nothing about whether SynthID is still present. SynthID is embedded in the content itself and is designed to survive common transformations better than metadata does.

That difference is the whole reason a metadata-stripping tool is not a watermark remover, and the reason OpenAI keeps repeating that "no detection method is foolproof."

Are ChatGPT images watermarked?

Confirmed

Two provenance layers on every ChatGPT image, built by two rival companies, plus the one routine habit that erases your ability to check either.

OpenAI says images generated with ChatGPT, Codex, and the OpenAI API include C2PA Content Credentials metadata and a SynthID watermark, verifiable through a public tool that now sits at openai.com/research/verify/. The rollout is dated May 19, 2026, and OpenAI describes reaching "C2PA Conforming Generator Product" status as the recent part of it.

Its C2PA steering-committee seat is older than that. OpenAI's own page places the membership in 2024, alongside adding Content Credentials to DALL-E 3, so the 2026 announcement widened what gets marked rather than starting the relationship.

The detail worth pausing on is whose watermark it is. SynthID is Google DeepMind's, so two competing labs now run the same pixel-level signal on their own output.

OpenAI describes the two layers as complementary: "C2PA helps content carry detailed context, SynthID helps preserve a signal when metadata does not."

OpenAI's own caveats deserve quoting rather than glossing.

  • "No detection method is foolproof."
  • C2PA metadata "can be stripped, lost through uploads and downloads, or broken by transformations."
  • Provenance signals are "not a guarantee that content is accurate, unedited, legally owned, or presented in the correct context."

So a result of no signal detected does not mean the image was not made by ChatGPT. It can simply mean the metadata did not survive whatever happened to the file after it left OpenAI's servers.

The Verify tool, which OpenAI introduced as a preview, accepts images and audio only. It deliberately stops short of a definitive conclusion when it finds nothing, for the same reason.

Is ChatGPT audio watermarked?

Confirmed

Audio got a watermark on July 31, 2026, three weeks after a system card that never mentioned it. It did not get the metadata layer images have.

On July 31, 2026, two days before EU AI Act Article 50 transparency rules took effect, OpenAI extended SynthID watermarking to supported audio from ChatGPT and the OpenAI API. It added a Content Provenance API the same day, POST /v1/content_provenance_checks, which accepts images and audio up to 50 MiB with audio capped at 60 seconds.

Audio did not get the treatment images got, and it is worth being precise about this because the shorthand "same approach" is wrong. OpenAI marks audio with SynthID and attaches no C2PA Content Credentials to it. Two of its own surfaces agree, both listed below: the July 2026 provenance update says supported audio "now includes SynthID watermarking" and never mentions C2PA, and the help-center modality table reads "Audio | SynthID watermarks."

That has a practical upside. An audio file has no manifest to strip and no issuer to read, so the fragile-metadata caveat that dominates the image story simply does not apply to it.

GPT-Live's own system card, published three weeks earlier on July 8, 2026, makes zero mention of SynthID, C2PA, or watermarking. The audio provenance rollout was announced separately from, and after, the model's own safety documentation rather than built into it from the start.

Does every Sora video carry a watermark?

Community discussion

OpenAI says every Sora video carries visible and invisible signals. One tester found the opposite pattern, and no OpenAI tool accepts video to settle it.

A November 2025 investigation by Ethan Le Sage, published on LessWrong and cross-posted to the EA Forum, checked Sora 2 videos against both the Content Credentials Verify tool and the open-source c2pa-rs CLI. Some videos carrying the visible OpenAI watermark had no detectable C2PA metadata at all, while some Pro-tier videos without the visible watermark did carry it.

That is close to the reverse of OpenAI's public claim that every video generated with Sora includes both visible and invisible provenance signals. Rechecked on September 3, 2026, the post is unedited, carries no author correction, and its three comments are all from November 2025, none of them from OpenAI.

Two limits keep this at community discussion rather than a confirmed failure. It rests on a single independent tester using third-party tooling, and SynthID is a separate pixel-level mechanism that neither tool measures, so an absent C2PA manifest does not establish an absent watermark.

Why is ChatGPT text still not watermarked?

Reported

OpenAI shelved a reportedly 99.9%-effective text watermark and said why, in more detail than Anthropic, Google, or Meta have offered about theirs.

Leaked internal documents, reported by the Wall Street Journal and covered by Tom's Hardware on August 5, 2024, describe an internal ChatGPT text-watermarking method reportedly around 99.9% effective, built years before the 2026 provenance work. OpenAI chose not to ship it.

The reasons given, per that reporting, were specific.

  • The method could be circumvented, which invites a false sense of certainty.
  • False positives: 99.9% accurate still means a meaningful volume of wrongly flagged writing at ChatGPT's scale.
  • Those errors would land disproportionately on non-native English writers, whose phrasing patterns look more machine-like to some watermark detectors.
  • Internal survey data suggested close to 30% of users would use ChatGPT less often if the feature launched.

This is not only a leak. OpenAI has separately and publicly discussed text-watermarking research and its risks, naming false positives, circumvention, and disproportionate impact on non-native English speakers, in its own content-provenance posts. The leaked rationale and the published one make the same arguments.

That is a genuinely more detailed public rationale than Anthropic, Google, or Meta have offered about their own text-watermarking decisions. It reframes the missing ChatGPT text watermark as a considered tradeoff rather than a technical gap.

Nothing found more recently changes that. OpenAI's 2026 writing on provenance continues to describe text as a future goal, not a status change, and a corroboration pass on August 17, 2026 against OpenAI's developer content-provenance guide found it documents images and audio and does not mention text anywhere.

Secondary reporting states that OpenAI's own Responsible AI Provenance Guide says the company does not embed watermarks in text model outputs at all, relying on C2PA metadata for images instead. That specific claim could not be verified against OpenAI's own site, so it stays a secondary-source data point rather than an official confirmation, but it points the same direction as everything else here.

What can removing a ChatGPT watermark actually mean?

Community discussion

For text there is nothing deployed to remove. For an image, the metadata falls off by accident and the pixel watermark has only been beaten by regenerating the picture.

Start with the text case, because it is the query people type and the one with the cleanest answer. A tool that claims to remove ChatGPT's text watermark is making a claim about a mechanism OpenAI built and shelved. There is no known public detector to test that claim against in either direction.

Cleaning hidden Unicode characters out of copied ChatGPT text is ordinary formatting hygiene, worth doing on its own terms. It is not defeating a watermark, because OpenAI names no such mechanism for text.

For images the two layers come apart completely. The metadata is the part that breaks first, usually by accident: the June 2026 developer thread above shows an ordinary re-upload doing it, and format conversion, re-saving, or a screenshot do the same.

SynthID is the harder half, and public discussion shows a real asymmetry. The Hacker News thread about a CLI watermark-removal tool, posted May 19, 2026, pulled 387 points and 258 comments, making it the highest-engagement watermark discussion found there. It reported a hard technical limit: the tool cleanly strips the visible watermark, and defeating SynthID reportedly required regenerating the image entirely through Stable Diffusion XL, degrading quality in the process.

Commenters split on whether that is good news or bad news.

  • The privacy and resistance framing: removal tools push back on tracking built into generated media.
  • The abuse framing: the same techniques enable deepfake scams, with one commenter raising a Kentucky political deepfake ad reported to have cost $1.7 million and reached 49 million views.
  • The sidestep: newer watermark-free local models make the whole removal question moot for anyone who just does not use a watermarking provider.

A separate discussion on the same site, from the day of OpenAI's SynthID announcement, drew 332 points and 180 comments. One commenter claimed Stable Diffusion at 10 to 15 percent denoising strength was enough to defeat SynthID, saying they tested it the day Nano Banana Pro shipped. Nobody published a reproducible test alongside that claim, so it stays community discussion, not a documented result.

For text, a July 2026 thread titled "Text AI watermarks will always be trivial to remove" asked whether foundation-model labs already use watermark removal internally to keep synthetic text out of their own training data. It proposed low-denoising image-to-image regeneration as a practical bypass, which is an image technique, not a text one. Nobody in that thread demonstrated a removal method against ChatGPT text, because there is no live ChatGPT text watermark to demonstrate one against.

What gets mistaken for a ChatGPT watermark?

Rumor/speculation

Four things the internet keeps calling a ChatGPT watermark. OpenAI's documentation names none of them as a mechanism.

  • Hidden Unicode characters such as zero-width spaces.
  • Non-breaking spaces and other invisible whitespace.
  • Repeated phrases and stock openers.
  • Writing-style habits, punctuation tics, and sentence rhythm.

None of these appear in OpenAI's help-center article on images and audio, or anywhere else in its documentation, as an actual watermarking mechanism.

Given how candid OpenAI has been about why it has not shipped a text watermark, treat any claim that ordinary ChatGPT text already carries one as unconfirmed at best. Cleaning invisible characters out of pasted text is still worth doing for formatting reasons, it just is not defeating a watermark.

FAQ

Is ChatGPT output watermarked?

It depends entirely on the modality. Images from ChatGPT, the API, and Codex carry C2PA Content Credentials plus a SynthID watermark. Supported audio carries SynthID, without a C2PA manifest. Sora video is supposed to carry both visible and invisible signals, and independent testing has found that inconsistent. Ordinary chat text carries nothing OpenAI has confirmed as deployed.

Does ChatGPT's image watermarking prove ChatGPT text is watermarked too?

No. Image provenance (C2PA plus SynthID) and statistical text watermarking are entirely separate systems built for different modalities. Only the image and audio systems are confirmed deployed, and OpenAI has said its text-watermarking goal remains unmet.

Why has OpenAI not shipped a ChatGPT text watermark?

It reportedly built one, around 99.9% effective by internal measure, and held it back over circumvention risk, a disproportionate false-positive impact on non-native English writers, and survey data suggesting roughly 30% of users would use ChatGPT less if it launched. A system that is right 99.9% of the time is still wrong on a meaningful volume of text at ChatGPT's scale. That is a stated tradeoff, not a technical inability.

Can you remove a ChatGPT watermark?

There is nothing deployed in ordinary ChatGPT text to remove, so the text version of the question has no target. On an image, the C2PA metadata layer comes off through routine handling and often disappears without anyone trying. Defeating the SynthID layer is a different matter: the busiest public report of it required regenerating the whole image through a different model, at a real cost to quality.

Does cleaning hidden characters remove a ChatGPT watermark?

It removes hidden Unicode characters if they are present, which is useful formatting hygiene regardless. It does not prove those characters were ever an OpenAI watermark, since OpenAI names no such mechanism for text, and it has no bearing on image or audio SynthID and C2PA signals.

Does re-uploading an image to ChatGPT remove its watermark?

It removes part of it. A June 2026 developer forum thread found that re-uploading a PNG into a ChatGPT conversation strips its C2PA metadata down to bare file chunks, while the original file still verifies elsewhere. SynthID is a separate pixel-level signal and is not addressed by that at all.

Whose watermark is actually on a ChatGPT-generated image?

Both OpenAI's and Google's. OpenAI attaches its own C2PA Content Credentials metadata, then stacks Google DeepMind's SynthID pixel watermark on top, an arrangement OpenAI itself frames as complementary layers rather than a single proprietary system.

Can I check whether a ChatGPT image or audio clip still carries its mark?

Partly, and the two layers differ in who can check them. Any C2PA manifest viewer or the open-source c2pa-rs CLI reads the metadata layer yourself, and it often has not survived a re-upload or a re-save. The SynthID layer can only be checked by asking OpenAI's own tooling: the Verify tool and the Content Provenance API, both of which take images and audio and neither of which takes video.

Can I trust a result of no watermark detected on a ChatGPT image?

Not fully. OpenAI's own documentation says no detection method is foolproof and that metadata can be stripped by uploads, downloads, or file transformations. One observed case: re-uploading a genuinely OpenAI-generated image into a ChatGPT conversation strips its C2PA metadata down to bare file chunks, even though the original file still verifies elsewhere.

Next steps

  • See why the two layers on a ChatGPT image fail in completely different ways before you trust either one. C2PA vs SynthID
  • See the broader evidence on which watermarks have actually been broken in published research, not just in forum claims. Can AI watermarks be removed?
  • Paste text you are unsure about into the free in-browser cleaner to see whether it contains invisible Unicode characters. Hidden character cleaner
  • Understand why a watermark and an AI detector answer completely different questions before you rely on either. AI watermark vs AI detector
  • Check what the EU actually requires of providers and deployers now that the transparency rules apply. EU AI Act and AI watermarking

Sources and citation status