Provider tracker
Gemini Watermark: Is Gemini Watermarked, and Where?
Google's own SynthID page says Gemini's text output is watermarked. A Google-affiliated reply on Google's own developer forum said it isn't, then two weeks later said it is. Images, audio, and video are a different story entirely: SynthID watermarking there is confirmed without dispute, at a self-reported scale of more than ten billion images and video frames. Text is the mess, and the honest answer depends entirely on which Gemini surface produced the words in front of you.
Correction,
The separate Gemini watermark tracker page was absorbed into this one, which now carries the full Google evidence file: what Google signed under the EU AI Act and what that signing left out, the SynthID Detector portal's launch scope, and the in-chat checker bug Google fixed by 2026-07-16. Two stale claims were corrected on the way in. The verdict table recorded Gemini API text as a documented "Google says no"; the same forum account withdrew that on 2026-08-19 and asserted the opposite, so the row now reads as answered both ways, matching the status database. The decision-tree figure carried the same stale reading and now names both posts.
Correction,
This page called Google's consumer verification tool the confirmed, working path for images, video and audio. An independent check in November 2025, cited on the full Gemini file, found it reliable for images but hit-or-miss for audio and video, and the page now says so. It also described the dispute over Gemini text as two Google sources contradicting each other when there are three; the third, Google's own help page for verifying AI content, covers images, video and audio and stays silent on text, and it is now named here. A robustness figure attributed the 98.3% signal loss to aggressive paraphrasing where the source says automated.
Short answer
- Gemini app and web text
- Google says yes
- Gemini API text
- Answered both ways
- Images, video, audio
- Yes, SynthID
- Public text verification
- None
- Media verification
- Access-gated portal
The first two rows are Google against Google. Three Google surfaces address text and give three different pictures: DeepMind's SynthID page, a developer forum reply that was withdrawn and replaced by its opposite, and a consumer help page that stays silent. Nothing published reconciles them.
Key takeaways
- Confirmed, no dispute: SynthID watermarks Gemini images, audio, and video; a companion DeepMind paper claims the image system alone has marked over ten billion images and video frames across Google's services, a figure Google published and no outside party has audited.
- Contested for text: DeepMind's marketing page says the Gemini app and web experience are watermarked. For the API, one Google-affiliated forum account gave opposite answers two weeks apart, denying it on August 5, 2026 and confirming it on August 19 with the words "the previous statement was incorrect." Google's documentation supports neither.
- Google offers no working way to check text, and its media tooling is imperfect where it does apply: the consumer tool covers images, video and audio only, the SynthID Detector portal that announced text support has stayed waitlist-gated since May 20, 2025, and an in-chat checker returned verdicts about the wrong upload across four tested sessions before Google fixed it globally by July 16, 2026.
- Independent, non-Google researchers have repeatedly found SynthID Text weaker under attack than Google's own presentation implies: vulnerable to paraphrasing and back-translation, and, in a 2026 theoretical analysis, its mean-score detector grows less reliable as more tournament-sampling layers are added, while its alternative Bayesian-score detector holds up better.
- Google documents the limits itself, more candidly than most marketing copy: the signal survives cropping, a few changed words and mild paraphrasing, is less effective on short factual answers where there is little room to alter token choice without hurting accuracy, and can lose most of its confidence under thorough rewriting or translation.
- Google signed the EU AI Act's transparency Code of Practice on July 24, 2026, nine days before Article 50 became applicable, but the signing announcement is modality-agnostic and commits to nothing about text or the Gemini API. No Google statement found anywhere addresses Article 50 compliance for Gemini text specifically.
Figure 1
Which Gemini surface produced it, and what that means
Gemini is not one product, and the answer flips between surfaces. Google's own pages disagree about the app versus the API, and on the API the same Google account answered twice in opposite directions, which is why the second row is a contradiction rather than a gap.
Gemini app or web
Google says yes- Evidence
- DeepMind's SynthID page states SynthID watermarks text generated by the Gemini app and web experience.
- Can you verify it?
- No. The SynthID Detector portal is access-gated, and text support is limited.
Gemini API
Answered both ways- Evidence
- A Google-affiliated reply on Google's own AI developer forum, dated 2026-08-05, stated API text is not SynthID-watermarked and that native text watermarking is not planned. The same account reversed that on 2026-08-19, saying API text "IS actually SynthID-watermarked" and that the previous statement was incorrect. Both posts are still live and no Google documentation covers the API either way.
- Can you verify it?
- No. No published route accepts text.
AI Studio
Not documented- Evidence
- Treated as a developer surface. No Google page states a text marking policy for it either way.
- Can you verify it?
- No.
Vertex AI
Not documented for text- Evidence
- Media watermarking is documented on Vertex image and video models. Text is not addressed.
- Can you verify it?
- For media, through Google's own tooling. For text, no.
Veo video
Yes- Evidence
- SynthID is documented across Google's generated video, and this is not in dispute.
- Can you verify it?
- Via the SynthID Detector portal, which is access-gated rather than open.
Imagen images
Yes- Evidence
- SynthID on images is documented by Google and is not in dispute. The Nature paper often cited alongside it is DeepMind's own and covers SynthID Text, not images.
- Can you verify it?
- Via the portal, plus C2PA metadata where it survives.
Third-party model using SynthID Text
Depends on the operator- Evidence
- Google open-sourced SynthID Text. Whether a given deployment enables it is a choice made by whoever runs the model, not by Google.
- Can you verify it?
- Only if that operator says so and publishes a way to check.
Method Compiled from DeepMind's SynthID documentation and both dated posts on the Google developer forum thread, the 2026-08-05 denial and its 2026-08-19 retraction. Where Google has said nothing, the row reads Not documented rather than No.
Checked 2026-09-04
Are Gemini images, audio, and video watermarked?
ConfirmedThe settled half: images, audio, and video are watermarked without dispute. Google's checker covers all three, about ten times a day, and never text.
Google documents SynthID watermarking for Gemini's image, audio, and video output without qualification, and without any of the hedging that surrounds the text story.
A companion DeepMind paper on the image system alone, published on arXiv in October 2025, states it "has been used to watermark over ten billion images and video frames across Google's services." That's a Google-reported figure no third party has validated, though nobody disputes that the watermarking itself happens.
Google's consumer verification tool, reachable from the Gemini app, is scoped the same way:
- Checks images, video, and audio. Explicitly not text.
- Recognizes content created by Google AI tools only, per Google's own wording.
- Caps you at roughly 10 checks per type every 24 hours.
If you're trying to verify whether a picture or a clip came from a Google AI tool, that's the documented path, though an independent check in November 2025 found it reliable for images and hit-or-miss for audio and video. If you're trying to verify text, there is no equivalent tool at all.
Why do Google's own sources disagree about Gemini text?
Community discussionOne forum account, two opposite answers fourteen days apart, and documentation that backs neither. All of it quoted in full.
Three Google surfaces address Gemini text and give three different answers. Google DeepMind's SynthID model page states it plainly: "We've expanded SynthID to watermarking and identifying text generated by the Gemini app and web experience." That's an official marketing claim, unqualified.
On August 5, 2026, a Google-affiliated account on the Google AI Developer Forum answered a narrow technical question about whether gemini-2.5-flash-lite and gemini-3.1-flash-lite output carries a machine-readable provenance signal under EU AI Act Article 50(2). The answer was a flat denial: "Generated text from the API is NOT SynthID-watermarked. There is no machine-readable providence [sic] signal... Native text watermarking is not planned at the moment."
Fourteen days later the same account withdrew it: "I need to post an important correction to my previous message: After checking further with the team, it turns out that text generated via the Gemini API IS actually SynthID-watermarked! I apologize for the confusion earlier, the previous statement was incorrect. This also applies to text generated through Google AI Studio and/or antigravity!"
Read what that does rather than what it settles. The correction is a new post, not an edit, so the denial is still live and still the first answer a reader meets. Neither post is marked as the thread's solution. The account's only visible credential is a forum user title reading Google, not a staff or moderator badge. And the correction now claims more than any Google documentation supports, where the denial claimed less: DeepMind's SynthID page still scopes text watermarking to "the Gemini app and web experience" and to consumer products, and Google's developer SynthID page, last updated in April 2025, does not mention the API at all.
A follow-up asking whether API text was always watermarked or whether it was switched on at some point has sat unanswered since August 19.
A third Google surface stays silent where it would matter. Google's own Gemini Apps help page for verifying AI content covers images, video, and audio and says nothing about text at all.
The most charitable reading is that the consumer-facing Gemini app and web chat apply SynthID Text while the developer API doesn't. That would track with how Google scoped its own verification tool, but it's an inference, and no primary source draws that line for current Gemini 3.x models.
Treat a flat "yes, Gemini text is watermarked" or "no, it isn't" as an incomplete answer until it specifies which surface generated the text.
How does SynthID Text work, and where does it apply?
ConfirmedTournament sampling, explained without the math, and the unpublished detail about which detector Google runs that keeps the check out of your hands.
Where SynthID Text does run, Google describes it as a logits processor applied during generation, after ordinary Top-K and Top-P sampling has narrowed the candidate tokens. The underlying Nature paper calls the technique tournament sampling.
That paper, authored by Google DeepMind researchers, reports a live Gemini app and web experiment across nearly 20 million responses that found no detectable drop in output quality from applying the watermark. It describes SynthID Text as productionized specifically for Gemini and Gemini Advanced.
Detection accuracy is commonly cited elsewhere as roughly 85% true positives at a 1% false-positive rate, against about 73% for prior schemes. Neither figure could be reconfirmed as a direct quote from the paper's own text, so both belong in the secondary column rather than the documented one.
The method has also been open-sourced, with a production-grade reference implementation shipping in Hugging Face Transformers since version 4.46.
Google documents the same robustness pattern independent researchers keep finding elsewhere, and it is more candid than most marketing copy. The signal survives cropping, a few changed words, and mild paraphrasing reasonably well. It is less effective on short factual answers, where there is little room to alter token choice without hurting accuracy. And confidence can be greatly reduced by thorough rewriting or translation.
What has independent research found about SynthID Text?
Research/proposalFour independent teams have attacked SynthID Text since launch. None of the results is Google's, and none of them is settled science either.
Multiple independent teams have stress-tested SynthID Text since it launched, and the results complicate Google's framing.
- "Watermark under Fire" (EMNLP 2025 Findings, peer-reviewed) found its resilience to paraphrasing and translation attacks was "similar to" a much simpler, older green/red-list watermark, meaning no clear robustness advantage despite the more sophisticated design.
- "SynGuard" (IEEE TrustCom 2025, peer-reviewed) found SynthID Text "susceptible to meaning-preserving attacks, such as paraphrasing, copy-paste modifications, and back-translation," and built a hybrid defense that improved detection accuracy by an average of 11.1% over the vanilla version.
- A 2026 theoretical analysis proved that SynthID Text's mean-score detector becomes less reliable as more tournament-sampling layers are added, while the alternative Bayesian-score detector in the same system holds up better.
A 2026 preprint went further, testing an open-source SynthID Text reimplementation and reporting four results worth holding onto:
- 80% of untouched, genuinely watermarked passages fell into SynthID's own "uncertain" confidence zone.
- 98.3% of texts that were initially detected lost their signal after a single round of automated paraphrasing.
- 5.4% of paraphrased human-written text got flagged as AI-generated.
- SynthID Text ranked lowest of the three watermarking methods the paper tested on its composite forensic-readiness measure.
None of it is first-party Google data at production scale, and the 2026 work is an unreviewed preprint testing an open-source reimplementation rather than Google's actual production keys, which Google has never published. Treat its exact numbers as early and unreplicated, not settled science.
But the pattern is consistent enough across separate independent teams, two of them peer-reviewed, that "SynthID Text is highly robust" shouldn't get repeated as an unqualified fact.
What did Google commit to under the EU AI Act?
ConfirmedGoogle signed the EU's transparency Code nine days before Article 50 applied. What it committed to there names neither text nor the API.
On July 24, 2026, Google signed the EU AI Act's Code of Practice on Transparency of AI-Generated Content. What it committed to there is worth reading closely:
- Adopt and accelerate C2PA content credentials.
- Partner with Apple, ElevenLabs, Kakao, NVIDIA, and OpenAI on interoperable SynthID adoption.
- Nothing modality-specific. The announcement makes no commitment about text or about the Gemini API.
Article 50 itself became applicable on August 2, 2026, and the European Commission concluded the Code "adequately covers" Articles 50(2), (4), and (5). No Google statement found anywhere addresses Article 50 compliance for Gemini text specifically. That gap is a finding, not a search miss.
Google also warned publicly that added regulatory complexity "could contradict Europe's goals for competitiveness." That is not the posture of a company eager to over-promise on the parts of watermarking it has not finished building.
Can you check Gemini output with Google's own tools?
ReportedA waitlist-gated portal with no API, and an in-chat checker that answered about the wrong upload until Google fixed it in July 2026.
Only for some media, and not for text: the portal is waitlist-gated, no published Google route accepts text, and the in-chat checker returned verdicts about the wrong upload until Google fixed it in July 2026. The standalone SynthID Detector portal launched at Google I/O on May 20, 2025, announced for scanning an image, audio, video or text file for a SynthID mark. Only image detection was live at launch, with video and text promised "in the coming weeks."
- Access has stayed waitlist-gated to journalists, media professionals and researchers, not the general public.
- There is still no API.
- The most recent independent check, by journalist Henk van Ess in November 2025, still found it waitlist-only.
Text is the promise that never landed. More than a year after those "coming weeks," no published Google route accepts text for a SynthID check at all: the in-app flow and the portal both take image, video and audio only. That is the gap behind the verdict table above, and it is why watermarked and verifiable are separate questions for Gemini text no matter which way the app-versus-API argument resolves.
Then there is the bug. Fact-checking outlet Lead Stories found Gemini's in-chat checker returning the verdict for the first image or video uploaded in a session even when asked about a later one, producing both false positives and false negatives across four tested sessions. Google fixed it globally by July 16, 2026.
None of that changes what Google watermarks. It changes what you can establish about a particular file, which is the question most readers actually arrive with, and it is one more reason to read a single check as evidence rather than proof.
FAQ
Does Gemini use text watermarking?
It depends which Gemini you mean. Google DeepMind's SynthID page says the Gemini app and web experience are watermarked. For the API, a Google-affiliated developer-forum reply denied it on August 5, 2026 and reversed itself on August 19, saying API text is SynthID-watermarked after all and that the earlier statement was incorrect. Google's own consumer help page for verifying AI content covers images, video, and audio, and says nothing about text. No source reconciles all three, so name the surface before you answer.
Is Gemini different from Claude and ChatGPT here?
Gemini's image, audio, and video watermarking is unambiguously confirmed. For text, Gemini is now the murkiest of the three: Claude has a clear, recent official statement covering its text watermark, while three Google surfaces address Gemini text and give three different pictures, with nothing published to resolve them.
Is the SynthID Detector portal something I can use to check my own text?
Not really, not yet. Google launched a standalone SynthID Detector portal at I/O on May 20, 2025, announced for scanning images, audio, video, and text for SynthID marks, though only image detection was live at launch. Access has stayed limited to a waitlist for journalists, media, and researchers, with no public API. The most recent independent check, from journalist Henk van Ess in November 2025, still found it waitlist-only, and nothing since confirms broader availability.
Does Google say how reliable Gemini's image watermark detection is at scale?
Only in a self-reported way. A Google DeepMind paper on the image-watermarking system, published on arXiv in October 2025, claims it has been used to mark more than ten billion images and video frames across Google's services. That's a real, dated, Google-authored figure, but it hasn't been independently validated by anyone outside Google.
Does the EU AI Act force Google to watermark Gemini text?
Article 50's transparency obligations became applicable on August 2, 2026, and Google signed the related Code of Practice on July 24, 2026. But that signing announcement is modality-agnostic and makes no commitment about text or the Gemini API, and no Google statement found anywhere addresses Article 50 compliance for Gemini text specifically. That gap is a finding, not a search miss.
Next steps
- If you want the mechanism rather than the verdict, tournament sampling and the three-state detector are covered on their own page. SynthID watermark
- If your actual question is whether a rewrite defeats it, the removal evidence is collected separately. Remove Gemini watermark
- SynthID and C2PA metadata fail in completely different ways, which matters if you're deciding which signal to trust. C2PA vs SynthID
- A watermark and an AI detector are different things that fail differently, which matters a lot if you've been accused of using AI. Watermark vs detector
- The forum thread at the center of the contradiction is short, and both posts are still on it. Google AI Developer Forum thread
Sources and citation status
- OfficialGoogle AI Developers: SynthID Text
- ResearchNature: SynthID-Text paper
- OfficialDeepMind: SynthID model page
- CommunityGoogle AI Developer Forum: Gemini API SynthID thread (denial Aug 5, 2026, retracted Aug 19, 2026)
- OfficialGoogle support: verify AI-generated content in the Gemini app
- ResearchGoogle DeepMind: SynthID-Image paper (over ten billion images/frames watermarked)
- OfficialGoogle: SynthID AI content detector portal launch
- ReportingDigital Digging: Google's SynthID, three tools, three different states of readiness
- ResearchHan, Li, Ni, Zulkernine: "SynGuard" robustness study of SynthID-Text (arXiv:2508.20228)
- ResearchOmidi, Dong, Wang: theoretical/empirical analysis of SynthID-Text (arXiv:2603.03410)
- ResearchAIES 2026 preprint: SynthID-Text forensic readiness evaluation (arXiv:2607.16010)
- Research"Watermark under Fire" (EMNLP 2025 Findings)
- OfficialGoogle: EU AI Act transparency Code of Practice signing
- RegulatoryEU AI Act: Article 50 transparency obligations
- ReportingYahoo Tech / Lead Stories: Gemini SynthID checker bug