← Back to blog
NewsAbout 6 min read

Google Opened Its SynthID Detector to Everyone. Read the Fine Print.

Published Oct 7, 2026
Google Opened Its SynthID Detector to Everyone. Read the Fine Print.

Google opened its SynthID Detector to the public on October 7, letting anyone check an image, video, or audio file for a hidden AI watermark. The portal at synthid.com is live globally in English. Sign in with a Google, OpenAI, or Apple account and upload a file.

This is a genuine improvement over the previous state of affairs, when the only way to check for SynthID outside Google's trusted tester program was to ask Gemini and interpret whatever it said back. Detecting watermarks should not require a conversation with the model that applied them. Until this week, the detector sat with a test group of journalists, media professionals, and researchers who got access at Google I/O last year, and the answer often arrived as a paragraph of prose when what you wanted was a single bit.

What scaling looks like

The numbers behind SynthID are large. Since launching in 2023, Google says it has watermarked more than 180 billion images and videos, plus 240,000 years of audio content. Verification runs across Search, the Gemini app, and Chrome now handle over a million requests daily.

The mechanism is the interesting part. SynthID embeds a signal directly into the pixels of an image or video, and into the frequency components of audio, rather than in metadata that can be stripped. For images and video, the watermark is written at the moment of creation and designed to survive cropping, filters, frame-rate changes, and lossy compression. For audio, it is built to withstand added noise, MP3 compression, and playback-speed changes. Text watermarking from the Gemini app works differently, adjusting the probability scores the model assigns to candidate words so the visible output is unchanged.

That difference in where the signal lives is why SynthID survives operations that strip metadata outright. A screenshot, a re-encode, and a metadata scrub will all remove provenance tags, but they do not remove a pattern woven into the pixel values themselves. The tradeoff is that the pixel-level signal is also the one most likely to degrade under aggressive transformation, which is why the detector asks for the highest-quality file you have.

The supported formats are broad: JPG, PNG, WEBP, HEIC and several other image types; MP4, MOV, and WEBM for video; WAV, MP3, OGG, FLAC, AAC, and M4A for audio.

The partnership is the real expansion

The detector previously checked only for Google's own SynthID. ChatGPT images carried SynthID too, and Google's tool would not flag them. That limitation is gone. The detector now supports watermarks from all SynthID partners, including OpenAI, NVIDIA, and Kakao, with Apple joining soon.

The practical effect is that one upload can identify output from several major providers instead of requiring a separate check at each company's own verification page. OpenAI still maintains its own page, so a suspected ChatGPT image has two places to look.

The limits deserve equal billing

The site is explicit that it is not a general AI detector, and the disclaimer matters more than the feature. It can identify media only from companies that have adopted SynthID. Microsoft and Meta run their own watermarking and verification standards, and neither appears on the partner list. Meta's detector has already been caught missing some of its own cropped AI images.

Then there is the open-weight problem. Anyone can run an open model on their own hardware and produce output with no watermark and no metadata labeling at all. That content will never show up in the detector.

A negative result therefore means the file's origin is unknown. It does not mean the file is authentic. It may come from a model outside the partner network, or heavy modification may have degraded the signal past detection. The site's own guidance is to upload the highest-quality version available and gather multiple data points before drawing a conclusion.

The site also notes the opposite failure mode, which gets less attention. In rare cases the detector can falsely trigger on content that carries no watermark at all. A false positive is a more damaging error than a false negative, because it invites someone to accuse a real photograph of being synthetic. Both directions of error exist, and neither is a substitute for checking where a file came from.

Access is deliberately limited

The tool is free but gated. Users get a daily quota of roughly 10 image, video, and audio checks, and must be signed in. Google engineers have said the limit exists to prevent people from using the checks to develop SynthID removal tools. The quota figure is described loosely because the system may lock you out sooner if you are checking many very similar files. That pattern looks like someone tuning a bypass.

Uploaded media is processed in real time and deleted after results return, per the privacy notice, though a digital signature of the file is retained for 24 hours to enforce quotas. The terms prohibit reverse-engineering the detection logic, automating queries, and creating multiple accounts to evade limits.

Two philosophies of provenance

SynthID is proactive watermarking: label the AI content. The alternative approach is to label authentic content instead, using cryptographic standards like C2PA to sign provenance information into files at the moment of capture. Google's Pixel phones are among the few devices that do this.

The two approaches fail in different ways. Watermarking depends on the generator cooperating, which open-weight models have no incentive to do. Cryptographic signing depends on the capture device cooperating, which limits it to hardware that ships the capability. Neither covers the whole problem on its own, and the practical advice is to use both, alongside the unglamorous work of checking source, date, and context.

There is a structural reason the watermarking approach is the one that shipped first. It requires no new hardware and no change to how content is consumed. It can be retrofitted onto existing models with an update. Cryptographic provenance requires an ecosystem of capture devices, editing tools, and viewers that all agree on a standard, and that ecosystem is still mostly aspirational. The easier path got built first, and the easier path has the larger blind spot.

Then there is the adversarial question nobody has a good answer for. Watermarks are designed to be durable, which is not the same as being unremovable. Every public detection tool provides a training signal for anyone trying to defeat it, which is precisely why Google caps the quota and prohibits automated queries. The detector is useful and the detector is also a map for the people trying to erase the mark.

What to take away

The useful mental model is that SynthID gives you one strong yes and one very weak no. A positive match points toward a specific set of providers. A negative match tells you almost nothing. Anyone treating the latter as a clean bill of health is using the tool incorrectly, and Google's own documentation is unusually candid about that.

Wider access to detection is a real win for media literacy. The win is narrower than the announcement makes it sound, and the caveats are where the actual utility lives.

Related articles