Google DeepMind has introduced SynthID, a tool designed to help identify images made with artificial intelligence. It hides a signal in an image rather than placing a visible label on top, and a separate system can look for that signal later.
The launch offers one approach to a growing challenge: helping people distinguish AI-generated material from authentic images. But SynthID is experimental and currently tied to Google’s Imagen image generator, so its reach and reliability remain open questions.
How SynthID marks an image
At launch, SynthID is available to users of Imagen, which is hosted on Google Cloud’s machine learning platform Vertex. Users can generate an image and choose whether to apply the watermark.
The system uses two neural networks. The first makes subtle changes to some pixels in the original image, creating a pattern intended to be invisible to people while remaining detectable by the second network.
When asked to check an image, the detection network reports whether it detects a watermark, suspects one is present, or finds no watermark. That distinction matters: the tool is intended to provide a signal about an image’s origin, rather than a visible stamp that anyone can inspect.
Google DeepMind says the pattern is designed to remain detectable after changes such as screenshots, rotation, resizing, or editing. The company’s Pushmeet Kohli says it is more resistant to tampering than earlier image watermark attempts, while acknowledging that it is not perfectly immune.
Why hidden watermarks are attracting attention
Generative AI’s popularity has coincided with the spread of deepfakes, nonconsensual porn, and copyright infringements. Watermarking is one proposed way to make AI-generated material easier to identify and potentially curb some forms of misuse.
Earlier approaches often relied on a visible overlay or information stored in an image’s metadata. Those marks can be removed or lost when a file is cropped, resized, or edited, Kohli says. Embedding a subtle signal in the pixels is meant to make identification less dependent on the image remaining untouched.
The launch also follows a broader industry push. In July, the White House announced voluntary commitments from leading AI companies, including OpenAI, Google, and Meta, to develop watermarking tools. At Google’s annual conference I/O in May, CEO Sundar Pichai said the company was building watermarking and other techniques into its models from the start.
Google DeepMind is the first Big Tech company to publicly launch such a tool, but it is not alone in exploring the approach. Similar techniques exist in the open-source image generator Stable Diffusion, and Meta has conducted watermark research without launching a public tool.
Detection is not a guarantee
A watermark can help only if it survives attempts to alter or undermine it. Ben Zhao, a University of Chicago professor who has worked on systems to prevent artists’ images from being scraped by AI, is skeptical that current watermarks will remain robust over time. He points to early text watermark research that found marks could be broken, often within a few months.
Someone trying to pass off a deepfake as a real photograph, or cast doubt on a genuine image, may have a reason to go beyond simple cropping or compression. Zhao argues that such attackers could try multiple edits to disrupt a watermark. Google DeepMind’s tool may therefore help identify some images without settling the wider question of how to establish whether an image is genuine.
Claire Leibowicz, head of the AI and Media Integrity Program at the Partnership on AI, sees the launch as a useful first step. She says sharing more information about which techniques succeed or fail could help the field improve, and that the difficulty of the problem should not prevent action.
A limited launch leaves open questions
Kohli described SynthID as experimental. Google DeepMind wants to learn how people use the tool and understand its strengths and weaknesses before expanding it. He did not say whether the company would make it available for images beyond those generated by Imagen, or whether Google would add the watermark to its other AI image generation systems.
That restriction affects who can use the system. Sasha Luccioni, an AI researcher at Hugging Face, says keeping the tool proprietary means Google alone can embed and detect its watermarks. A mark that is not widely applied across image generation systems may offer less help with images made elsewhere.
Luccioni argues that applying watermarking across image generation systems could reduce risks such as deepfake pornography. SynthID’s early availability does not establish that outcome. For now, the tool is a limited experiment in identifying AI-generated images, with its usefulness depending on how well its hidden signal withstands editing and how broadly watermarking is adopted.