Skip to main content
Back to blog

Provenance

AI watermarks are everywhere now. Here's what they actually prove

Watermarking AI generated content has gone from an experimental idea to something close to standard practice in the space of a year. Google's SynthID now sits behind more than 100 billion pieces of content across its own products, and since May 2026 it has spread beyond Google entirely, covering images from ChatGPT and the OpenAI API along with content from Nvidia, Kakao, and ElevenLabs. Anthropic started attaching signed C2PA credentials and an invisible text watermark to Claude generated content on 2 August 2026. A number of newer platforms are now pitching themselves as the layer that ties all of this together for enterprises. All of that is a genuine step forward. It also makes this a good moment to be clear about what a watermark actually tells you, because the honest answer is narrower than the marketing around it usually suggests.

What a watermark can actually tell you

When a watermark is present and it checks out, it tells you something specific and useful: this piece of content carries a signal tied to a particular generator or platform. Google's SynthID Detector, opened to early testers in May 2026, can go further and show which part of an image carries the mark, so a photo with an AI generated sky over a real foreground looks different from a fully generated frame. That is a real, checkable fact, and it is worth having. It is the same category of signal as a Content Credential or a metadata tag naming a generation tool, just harder to strip out by accident.

What it can't tell you

The gap shows up on both sides of the result. If a watermark is found, that tells you about the tool, not necessarily about intent, licensing, or context. And if no watermark is found, that is not proof the content is human made. It might mean the generator never watermarked it in the first place, that the file passed through a tool that doesn't preserve the mark, or that the mark was there and didn't survive whatever happened to the file next. Anthropic has been upfront about this limitation itself: its own documentation notes that heavy editing, paraphrasing, translation, or mixing with other writing can make its text watermark undetectable, and that file metadata can be stripped by conversion, resaving, or a simple screenshot. A watermark embedded in the pixels of an image is harder to remove than a metadata field, but harder to remove is not the same as impossible to remove, and no vendor claims otherwise in their own fine print.

This is why absence of a signal should never be read as evidence of the opposite. Not finding a watermark means exactly that: not found. It doesn't mean human made, and treating it that way is the same mistake as treating a positive result as an unqualified verdict.

Why this matters more once the law is involved

Article 50 of the EU AI Act, in force since 2 August 2026, requires providers of generative AI systems to mark their outputs in a machine readable way. That obligation sits with the company that built the generator. It doesn't automatically satisfy the separate disclosure obligation that falls on a deployer publishing or distributing that content, and it says nothing at all about content that reaches you from somewhere a watermark was never attached in the first place, or was stripped along the way. A watermark being part of the infrastructure upstream is useful context. It is not the same as confirming the file in front of you actually complies with anything.

Treat it as one piece of evidence, not the whole answer

The practical takeaway is the same one that applies to Content Credentials and embedded metadata: a watermark is one signal among several, and it is only useful once you know how certain it actually is. Was it verified against a real trust anchor, or just a claim written into the file by whatever tool touched it last? Was it detected by running an actual check, or inferred from circumstantial evidence? Those are different levels of confidence, and collapsing them into a single AI or not AI answer throws away the detail that a real decision needs. A watermark result deserves the same treatment as every other piece of evidence: shown plainly, labelled by how certain it is, and left for a person to weigh alongside everything else found on the file, rather than handed down as a verdict on its own.

This is a general summary for orientation, not legal advice. Confirm current requirements for your jurisdiction with counsel before relying on it.