Skip to main content
AI Watermark Removal

Removal query

Remove Gemini Watermark: What SynthID Text Can Survive

Removing Gemini's text watermark isn't one well-defined question, because Google's own sources disagree about whether the API applies a watermark at all. Where SynthID Text does run, Google admits thorough rewriting or translation greatly reduces detector confidence, and four independent red-teams have measured how far that goes. What none of them found is a clean, repeatable removal method an ordinary user can verify.

By Rowan ValePublished Revised Research/proposal

Key takeaways

  • SynthID Text is documented for the Gemini app and web experience. Whether the API applies it is unresolved: a Google-affiliated forum reply of August 5, 2026 said API output was not SynthID-watermarked, and the same account reversed that on August 19, calling its own answer incorrect. No Google documentation covers the API either way.
  • Google says thorough rewriting or translation can greatly reduce detector confidence, while mild paraphrasing is tolerated. That is a documented weakness, not a guaranteed removal method.
  • Independent red-teams have tried to break SynthID Text since it shipped. One 2025 paper found it no more resilient than a much older, simpler watermark; a 2026 preprint found 80 percent of genuinely watermarked text already sits inside SynthID's own uncertain zone before any attack.
  • A viral April 2026 claim that a hobbyist cracked SynthID's image watermark was corrected by its own author to a 16 percent evasion rate, not the 90 percent first reported. The real academic attack behind that story needs a roughly $10,000 GPU, not a laptop.
  • A related green-list token watermark stayed detectable after strong human paraphrasing once a detector had about 800 tokens, at a 1e-5 false-positive rate, a useful length benchmark even though it is not a SynthID-specific figure.

Removal reality check

Google: what is actually there to remove

Compare all providers

What exists to remove

  • Images, audio, video. SynthID across all three, undisputed, at reported scale of billions of assets
  • SynthID-Text, open source. Logits processor plus reference detector, runnable by anyone in Hugging Face Transformers

What can be verified

Access-gated. The SynthID Detector portal is waitlisted; the enterprise detection API is image-only and in limited preview.

For media, verification exists but you need access. For text, the open-sourced algorithm is the only end-to-end checkable path. That algorithm is not Google's production configuration.

Every state above traces to a primary source with a verification date in the status database, and the provider detail is on the full google tracker.

Is Gemini's API watermarked like the Gemini app?

Community discussion

Which Gemini wrote it? DeepMind says the app carries the watermark, a Google forum reply says API text does not, and nobody has reconciled the two.

No Google source settles it: the app is documented as watermarked, and the API has been answered both ways. Google DeepMind's own SynthID model page states that SynthID watermarks text generated by the Gemini app and web experience. That's the official line.

A Google-affiliated account on Google's AI Developer Forum wrote the opposite for developers on August 5, 2026, replying to a question about gemini-2.5-flash-lite and gemini-3.1-flash-lite under EU AI Act Article 50(2): "Generated text from the API is NOT SynthID-watermarked. There is no machine-readable providence [sic] signal... Native text watermarking is not planned at the moment." On August 19 the same account retracted that in favour of the opposite claim, without either post being edited or marked as the answer.

Nobody has reconciled the two. The likeliest explanation, that the consumer app carries a watermark while the API does not, is a plausible guess rather than a confirmed fact, since no Google source states it directly for current Gemini 3.x models.

A third Google page points the same direction. The Gemini Apps help page for verifying AI content covers only images, video, and audio, says nothing about text, and states Gemini can currently only recognize content made by Google's own AI tools.

This changes what you're even testing. Before testing anything, confirm which surface generated your text, and don't assume an answer either way.

What does SynthID Text actually mark in Gemini text?

Confirmed

Here's the mechanism, so you can tell which removal claims are even coherent.

SynthID Text is a logits processor. It runs during generation, after Top-K and Top-P sampling has already narrowed the field of candidate next tokens, and nudges the choice toward a statistical pattern tied to a watermark configuration.

A detector later checks whether a passage's token choices match that pattern more than chance would predict. There is no visible marker and no character hidden anywhere in the text.

That kills an entire category of removal advice. Stripping invisible Unicode does nothing to a SynthID Text watermark, because there's nothing sitting in the text to strip.

Google's Nature paper calls the technique tournament sampling and reports a live experiment across millions of real Gemini responses that found no detectable drop in output quality from the watermark.

Google also states plainly that detector confidence can be greatly reduced when text is thoroughly rewritten or translated, while describing the scheme as robust to mild paraphrasing. Both statements are documented specifically for the Gemini app and web experience, not the API.

What does robustness research show about SynthID Text?

Research/proposal

Four red-teams have gone at SynthID Text since it shipped, and the only quotable length benchmark, about 800 tokens, comes from a different scheme entirely.

Academic red-teams have gone after SynthID Text itself, not just a related scheme, since Google shipped it, and the findings run from no clear advantage over older schemes to outright vulnerability:

  • A 2025 paper on robustness assessment for Google's SynthID ran paraphrasing, copy-paste splicing, and back-translation attacks against the deployed scheme and found it vulnerable to all three.
  • A peer-reviewed 2025 paper found its resilience under those same attacks similar to a much older, simpler green-list watermark, with no clear advantage despite being newer.
  • A March 2026 paper proved theoretically that the default mean-scoring detector gets more vulnerable as more tournament sampling layers are used, though an alternative Bayesian scoring method built into the same system holds up better against that specific attack.
  • A 2026 preprint using an open-source reimplementation found 80 percent of genuinely watermarked text already sitting inside SynthID's own official uncertain zone before any attack, and 98 percent of detected texts losing their signal after a single paraphrasing pass.

All of this tests the open-sourced algorithm or third-party reimplementations, not Google's actual production configuration, which Google has never published. That's an asterisk worth remembering, not a reason to dismiss the findings.

A related but separate scheme adds the only useful reference point for document length. Kirchenbauer and colleagues stress-tested a green-list token watermark against human rewriting, LLM paraphrasing, and dilution in longer documents, and found it stayed detectable after strong human paraphrasing once a detector had about 800 tokens, at a 1e-5 false-positive rate.

Did a hobbyist really crack SynthID's image watermark?

Community discussion

The viral crack claimed 90 percent. Its own author later said 16. The gap comes down to which detector the thing was ever tested against.

Not at the rate the viral post claimed: its own author later put the real evasion rate at 16 percent, not 90. The April 2026 viral post claimed a hobbyist cracked Google's SynthID image watermark using 200 solid black-and-white Gemini-generated images and FFT spectral analysis, claiming 90 percent detection accuracy, released as an open-source project that reached 1.2 million views.

Three days later, a correction thread citing the researcher's own admission put the real evasion rate at 16 percent, describing the method as confusing the decoder, not deleting the watermark.

That correction pointed to a genuinely peer-reviewed attack, UnMarker, which dropped SynthID detection from 100 percent to about 21 percent without knowing the algorithm. It needs roughly a $10,000 A100 GPU.

Keep that pattern in mind before trusting any "I removed the watermark" claim about Gemini text.

Can Google's SynthID Detector check Gemini text?

Reported

Google's SynthID Detector is still waitlist-only, and the in-chat checker spent months answering about the first file of a session instead of the one you asked about.

No: Google's own SynthID Detector portal was announced for text, image, audio, and video, but only image, video and audio detection is live, and no published route accepts text, so the one modality this page is about is the one the portal cannot check. It launched at Google I/O in May 2025 gated to a waitlist of journalists and researchers, not the public.

The most recent independent check, from November 2025, found it still waitlist-only, with in-app verification for audio and video described as hit-or-miss even for people who had access.

Google's own tooling has also had a real, documented failure. Fact-checking outlet Lead Stories found Gemini's in-chat SynthID checker returning the verdict for the first image or video uploaded in a session even when asked about a later one, producing false positives and false negatives across four tested sessions, a bug Google fixed globally by mid-July 2026.

A checking tool that can be wrong on its own is one more reason to test against a specific, known detector rather than trust a single check either way.

FAQ

Does paraphrasing remove SynthID Text?

Google says mild paraphrasing may be tolerated, while thorough rewriting can greatly reduce confidence. Results depend on the text, its length, and the detector used, so verify any specific removal claim rather than take it on faith.

How much text does a watermark detector typically need to be confident?

There is no published number for SynthID Text specifically. A related green-list scheme stayed detectable after strong paraphrasing once a detector had about 800 tokens, at a 1e-5 false-positive rate, a reference point for how length affects detection, not a stated SynthID Text figure.

Is Gemini's API watermarked the same way as the Gemini app?

Nobody has confirmed that. Google DeepMind's own SynthID page says the app and web experience carry the watermark; a Google-affiliated forum reply of August 5, 2026 said API output was not SynthID-watermarked and that native text watermarking was not currently planned. The same account reversed that on August 19, calling its own answer incorrect and saying API text is SynthID-watermarked after all. No Google documentation covers the API either way, so treat the API's watermark status as open, not settled either way.

Has anyone actually broken SynthID?

Independent researchers have found real weaknesses, not a clean break: SynthID Text's confidence drops under paraphrasing and back-translation, and one theoretical attack targets its mean-scoring detector specifically. On images, a viral "cracked it" claim from April 2026 was corrected to a 16 percent evasion rate, while a separate peer-reviewed attack reached about 21 percent detection, down from 100, but needs roughly $10,000 of GPU hardware. None of this is a simple, repeatable method for an ordinary user.

Will deleting invisible characters remove a Gemini text watermark?

No. SynthID Text leaves no character in the text at all; it biases which tokens get chosen during generation, and a detector scores that pattern statistically. Invisible-character cleanup is a real fix for a different mechanism, not for this one.

Next steps

  • Confirm which surface produced your text before running any test, because the app and the API may not carry the same signal at all. Gemini watermark tracker
  • Paraphrasing is the attack every study keeps testing. What it actually does to detector confidence, across schemes, is collected on its own page. Paraphrasing AI watermarks
  • If you're chasing invisible characters rather than a statistical watermark, that's a different mechanism, and there's a free in-browser tool for it. Claude watermark checker
  • For how robustness gets measured across watermarking schemes generally, not just SynthID, start here. Text watermark robustness

Sources and citation status