Is SynthID Reliable? What the Watermark Can and Can't Survive
By Alex | Last Updated: October 2026
Independent information site. Not affiliated with or endorsed by Google. The official detector is at synthid.com.
SynthID is reliable at one narrow job. If a supported AI tool added the mark and the file hasn't been heavily changed, the detector can usually find it. It is not a lie detector for AI content. Google says detection can fail after many alterations, very small edits may not carry a mark, the text version is weaker on factual answers, and Google's own text documentation says it isn't designed to stop determined bad actors. A clean result never proves a file is real.
Reliable for what? Four different questions
| Question | How far you can rely on it | Why |
|---|---|---|
| Did a supported tool make or edit this file, and is it mostly unaltered? | Good. A positive is strong evidence | The mark sits inside the file, not in metadata that can be stripped |
| Was this made by AI of any kind? | Not reliable | Only tools that use SynthID are covered. Others come back clean |
| Does a clean result mean a human made it? | No | The tool may not use SynthID, or the file may have been altered |
| Was this text written by AI? | Not available on the public site | The text version exists for developers and is probabilistic |
For how this compares with C2PA and AI classifiers, see our comparison guide.
What Google says the watermark survives
The clearest statement we found is on Google's help page for checking files in Gemini. It says SynthID watermarks usually survive rescaling, recoloring and compression. Google's launch announcement for the public detector, as we read it, gives no statement on limits or robustness.
| Change to the file | What the Google pages we read say |
|---|---|
| Rescaling | Usually survives |
| Recoloring | Usually survives |
| Compression | Usually survives |
| Many alterations in combination | Detection may fail |
| A very small edit | May not carry a detectable mark |
| Screenshots, collages, heavy crops | Not addressed. Test your own file rather than assume |
The word "usually" matters. Google doesn't publish a survival rate for any of these edits, so nobody outside Google can say how often a given change keeps the mark.
Where detection can fail
- Heavily or repeatedly edited files. Google says detection may fail after many alterations. Each re-save, filter and re-export is another change.
- Tiny AI edits. Google says minor edits may not carry a detectable watermark, so a small AI retouch can slip through.
- Tools outside SynthID. Gemini can currently recognize only content made with Google AI tools. The public site adds partners such as OpenAI, NVIDIA and Kakao, but a file from any other tool comes back clean.
- Simple or abstract images. Gemini can return "unclear" for very simple or abstract content, or for an edit too small to carry a mark.
- Partly AI files. A positive can mean AI made or edited only part of the file. That is a limit on what the answer means, not an error.
Text is a different story: probabilistic by design
SynthID for text works by nudging which words a model picks, so there is no pixel mark to find. Google's developer documentation says detection is probabilistic and returns one of three answers: watermarked, not watermarked or uncertain. Developers can tune two thresholds to trade false positives against false negatives.
The same documentation lists these limits:
- Watermarking is less effective on factual answers, because there is less room to vary the wording without hurting accuracy.
- Detector confidence can drop a lot if the text is thoroughly rewritten or translated into another language.
- The method is not designed to stop determined bad actors. Google says it can make misuse harder and works best alongside other safeguards.
- It survives some changes, such as cropping the text, swapping a few words or light paraphrasing.
The public SynthID Detector has no text option, so these limits matter mainly to developers and to anyone told that a text watermark "proves" something. Teachers should read our guide for teachers before using any detector on essays.
What independent research says
The most cited academic work on this question is a 2023 paper by Xuandong Zhao and colleagues, later published at NeurIPS 2024. It argues that invisible, pixel-level image watermarks can be removed using generative AI, and that the result stays close to the original picture.
Three cautions apply when reading it:
- It did not test SynthID. The authors tested four other pixel-level schemes. For one of them, RivaGAN, they report removing about 98% of watermarks while keeping image quality high. Those numbers are not SynthID numbers.
- The authors limit their claim. Their conclusion is about invisible pixel-level watermarks. They say the same weakness isn't guaranteed for watermarks that change an image's meaning, though the one they tested visibly alters the picture.
- We found no independent test of SynthID in the sources we read. We can't tell you whether the paper's conclusion carries over, and we haven't seen Google answer it directly.
Some public projects claim to defeat the SynthID detector. We haven't verified those claims, and we don't link to them or describe how they work. What we can say is that Google's own text documentation does not claim the mark withstands a determined attacker.
Error rates: what nobody has published
The Google pages we read give no false positive or false negative rates for the image, video or audio checks. Treat any site quoting a precise accuracy figure, such as "99% accurate" or "virtually zero false positives", as unsourced unless it links to a Google document that says so.
What the pages do tell us is how to read the three possible outcomes:
| Outcome | Where | How to read it |
|---|---|---|
| Detected | synthid.com, Gemini | A supported tool made or edited at least part of the file. It may have been edited since |
| Not detected | synthid.com, Gemini | No supported mark was found. This is not proof the file is real |
| Unclear | Gemini | The file may be too simple, or the edit too small, to carry a usable mark |
Why the daily cap exists
The public detector gives each user roughly 10 image, video and audio checks a day. TBreak, reporting Ars Technica's findings, says Google's engineers told Ars the cap exists to stop people from using the detector to train watermark-removal tools. TBreak also speculates that near-identical uploads may use up the allowance faster, though that is its guess, not a Google statement. See our limits and quota guide for what is and isn't known about the cap.
How to use a result responsibly
- Treat a positive as strong evidence that a supported tool touched the file, and a clean result as no evidence either way.
- Check the original file if you can. Copies, screenshots and re-exports give the detector less to work with.
- Don't test the same file repeatedly to "confirm" a clean result. The quota is limited and the answer won't change.
- Combine it with other checks: provenance data, a reverse image search and the original source. Our alternatives guide lists them.
- Never accuse anyone on the strength of a single detector result.
Questions people ask
Is SynthID reliable?
It is reliable at finding a SynthID mark in a file that hasn't been heavily altered. It can't tell you whether a file is AI-made in general, and Google says detection can fail after many alterations.
Can SynthID be removed?
Google says detection can fail after many alterations, and its text documentation says the method isn't designed to stop determined bad actors. We don't cover removal methods.
Does SynthID survive cropping, compression and filters?
Google says the watermark usually survives rescaling, recoloring and compression. It says detection may fail after many alterations, and it doesn't give a survival rate for any single edit.
Does a screenshot keep the SynthID watermark?
The Google pages we read don't say. Check the original file where you can, and treat a clean result on a screenshot as weak evidence.
Can SynthID give false positives?
Google's pages don't publish error rates for the image, video or audio checks. A positive can also mean AI edited only part of a file, so read it as made or edited, not wholly generated.
Is SynthID better than other AI detectors?
It answers a different question. It looks for a hidden mark added by supported tools instead of guessing from how a file looks, so a positive is stronger evidence than a classifier score, but it covers far fewer tools. See the comparison guide.
Why is there a daily limit on checks?
Per TBreak's report of Ars Technica's findings, Google's engineers said the cap is meant to stop people using the detector to build removal tools.
Sources
- Google: verify content with SynthID in the Gemini app
- Google AI for Developers: SynthID text watermarking and detection
- Zhao et al.: Invisible Image Watermarks Are Provably Removable Using Generative AI (arXiv)
- TBreak: Google's SynthID Detector is now open to everyone, reporting Ars Technica's findings
- Google: making it easier to identify AI-generated content globally