AI Watermark: One Phrase, Three Different Technologies

An AI watermark in text, in an image and in a video are three different things — including whether you can see it, check it, or remove it. Most pages on this term answer only one of the three.

“AI watermark” is not one technology. In text it is a statistical pattern in which words a model chooses. In an image it is three separate layers in three separate places. In video it is a pattern written into the pixels, and often a visible badge as well. Whether you can see it, check it, or remove it is different in each case — and the answers do not transfer between them.

The clearest public account of the text version comes from a model vendor that has just switched it on, and its own description is unusually careful about what a watermark proves. We quote it below, because that limit applies to the other layers too, and almost nobody repeats it.

Where our own tool sits, plainly: it removes one layer of one modality — the visible badge on a still image. Nothing else. If the mark you are chasing is in text, or on a clip, this page is the end of the road, and it is better to know that now.

Text: invisible, uncheckable by you, and not removable by any tool

A language model writes by picking the next word from a set of candidates. Often several candidates are equally good — overcast or grey — and the choice is settled by a random number. Watermarking changes the source of that randomness: instead of an arbitrary random number, a key and the preceding words decide. The words are still random, but the sequence can now be checked against the key, and a probability assigned.

Two consequences follow, and both are stated by the vendor itself. Nothing is added to the text and there are no hidden characters — there is no character to delete and no invisible string to strip. And the technique is not proprietary to one company: the vendor describes its method as a version of the SynthID-Text approach published by Google DeepMind, and says the EU now requires providers serving its market to mark AI-generated content.

Here is the sentence that matters most on this whole term, from the same published description. Asked what a watermark actually proves, the answer is:

A watermark can only determine that Claude was likely involved with the content at some point. It cannot distinguish “Claude wrote this” from “Claude heavily edited this.”

And on the same page, on what a detection can and cannot establish:

Using our key, one can only answer the question “What is the likelihood this was partly written by Claude?” It doesn’t confirm whether the text was human-written.

Two things follow that almost nothing on this term says. First, a text watermark is evidence about involvement, not authorship — a document a person wrote and a model proofread can carry one, and the vendor notes that in light proofreading the mark barely lives anywhere, because only the words the model chose can carry it. Second, and less comfortable: you cannot check it. The detection tool is in private preview and limited to regulators, law enforcement, media organisations, fact-checkers, independent researchers, educational organisations and EU civil society groups. There is no public check for text, which is the exact opposite of the image case below.

Can any tool remove it? No — and the vendor says so more plainly than any removal page will. Light editing probably will not remove it; a complete rewrite will, and in that case, in its own words, it is “arguable whether the text can any longer be described as AI-generated.” That is the whole story: the only thing that removes a text watermark is producing different text. There is no reversible operation, because nothing was composited on top of anything.

Images: three layers, three different fates

An image is where the word starts doing several jobs at once. There are three separate things, in three separate places, and removing one has no effect on the others.

The distinction that decides how you should read every claim on this term is made by a vendor about its own product, which is more careful than most pages manage. The same documentation that calls the token pattern in its text a “watermark” describes the metadata credential it attaches to files like this:

This metadata label is very different from a watermark. Nothing in the file changes — it is not embedded or hidden.

So the phrase is already doing two jobs inside one company's own documentation: a signal embedded in the content itself, and a label attached to the container the content travels in. Those two have opposite properties. The embedded one survives re-encoding, cropping and re-saving, and cannot be edited out. The label is lost the moment a tool rewrites the container — which is also why stripping metadata is a different act from removing a mark, and why a page that treats them as one claim is describing two things under one word.

Can you check an image? For Google's own output, yes, publicly — that is described below. Can you remove it? The badge, yes. The embedded pattern, no. The label, technically, by any editor that rewrites the container — but that removes the label, not the mark, and they are not the same layer.

Video: the layer that is specified to survive video

Google's own developer documentation states that Videos created by Veo are watermarked using SynthID. That is the invisible layer, and DeepMind's description of what it withstands is the part worth reading slowly — the mark is:

designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression

Two of those four are not edge cases in video; they are the pipeline. Changing the frame rate is what happens when a clip is conformed to a different timeline, and lossy compression is what every delivery format does, again every time a file is uploaded to a platform and downloaded from it. So for AI-generated footage, the invisible layer is specified to come through the operations video editing consists of.

Can you check a clip? Yes, and this is the one place where the checking story is better than for text: Google's verification tool is available to signed-in users, accepts one file at a time up to 100 MB with videos under 90 seconds, and reports the result in parts — naming which portions of the video a watermark was detected in, and noting that a detection in a portion does not mean it was detected in all of that portion. A video verdict is therefore a set of partial answers, not a single fact. We went through that in full on what a video watermark actually is.

The same three questions, asked of all three

This is the comparison we would want if we were the one searching, and it is the thing the results for this term never put in one place. Three questions, three modalities:

Notice the shape of that list: the modality you can check most easily is not the one you can remove most easily, and the modality that is hardest to remove is the one nobody can check. Text is the strictest case on every axis. Images are the most tractable. Video sits in between and is measured in pieces.

What the word means, one step further back

A watermark used to be a mark of origin and quality — literally, in paper, then on stamps and currency, then in broadcast and film rights. Its function was to establish that something was genuine. As one widely-read explainer put it in August 2026, AI watermarks invert that: if physical and digital watermarks were meant to verify authenticity, AI watermarks serve more to signal inauthenticity. Rather than protecting ownership, they cast doubt on it.

The same piece quotes a Cornell researcher making the point that follows from everything above: That evidence is not a definitive binary, yes/no signal. It’s a signal that has to be interpreted. That is the honest answer to “does this have an AI watermark?” — often a probability, sometimes an “uncertain”, and in the text case something you personally cannot run at all. It is also why any page promising a guaranteed clean result is describing a measurement it cannot perform, whichever layer it is talking about.

Where this site sits, in the same three questions

We touch exactly one of the nine cells above. The tool removes the visible badge from a still image, in your browser, by reversing a known alpha blend — arithmetic on a known template, which is why it needs no server and can be free. It reads PNG, JPEG and WebP, one image at a time, up to 60 megapixels. It does not remove SynthID, it does not strip metadata, and it does not open video files.

If you have arrived at this term from a different direction, the relevant page is probably one of these:

Sources