Remove AI Watermark: What Each Method Actually Removes

Four different things are called “the AI watermark”. A method that removes one does nothing to the others — and Google's own verification help says the embedded one usually survives exactly the edits most pages recommend.

You cannot remove all of it, and most pages on this term never say which part they mean. “The AI watermark” is four different things in four different places: a visible badge made of ordinary pixels, a metadata label attached to the file, an invisible signal embedded through the pixels themselves, and a claim about how the file was made. A method that removes one of the four does nothing to the other three — so a page can honestly advertise “removes the AI watermark” and still be describing something you do not need.

The most useful single fact on this term comes from Google's own verification help, and it points the other way from what the removal pages assume. The digital watermark, in Google's own words, “will usually still exist” even when the image, video or audio is re-scaled, re-coloured, compressed or altered in other ways.

Where this site sits, plainly: it removes one of the four, on one kind of file — the visible badge on a still image. It does not strip metadata, it does not touch the embedded signal, and it does not open video files.

“Remove” is four different jobs

The word covers four objects that live in four different places. Sorting them is most of the work, because every honest removal claim on this term is a claim about exactly one of them.

Notice the shape of that list. Three of the four live inside the file — in the pixels, in the container, in the pixels again — and the fourth lives nowhere. A tool that strips the label can advertise “removes AI metadata”. A tool that reverses the badge can advertise “removes AI watermarks”. Both statements are accurate. Neither is what a reader who wants the embedded signal gone is looking for.

The removal ladder: five actions and what each one actually destroys

Here is every action a person can actually take, ordered from least to most destructive, with the honest result for each of the four objects above. This list is the thing the results for this term never put in one place: most pages describe one rung and imply it is the ladder.

Read the list as a whole and the pattern is: each action removes exactly one object, and the object it removes is usually not the one the reader wanted gone. There is no rung on this ladder that takes out the embedded signal without also taking out the content.

Two statements on this results page, and why they look like a contradiction

Two kinds of page sit side by side on this term, and they appear to say opposite things about the embedded signal. One kind states that an invisible pixel watermark can be defeated by cropping, rotating, dithering and repeated lossy re-encoding — that these operations desynchronise the pattern a detector correlates against. The other kind is Google's own verification documentation, which states that the digital watermark “will usually still exist even if the image, video, or audio is re-scaled, re-colored, compressed or altered in other ways.”

The useful reading is not a verdict, because these are two different thresholds being described in the same words. “The mark is still in the file” and “a detector still reports the mark” are not the same claim. Google's own page leaves the door open in the same breath — “there's still a chance that after many alterations the watermark won't be detected” — so the disagreement is not about whether re-encoding does anything. It is about how many rounds of it, applied to which file, measured against which detector.

No page on this term gives you that measurement for your own file, and neither does this one. What you can do instead is run the check on the result, before you rely on it — which is the next section but one.

“Not detected” is not the same as “clean”

Google's verification help gives three outcomes, not two: detected, not detected, and unclear. It is also explicit about what the middle one means — “it means the image or video wasn't created or edited by Google AI, but it could have been created by other AI systems” — and it lists two reasons a genuinely Google-made file can come back with no detection at all: “Not enough details to watermark” (very simple or abstract content), and “Likely too small an edit” (minor alterations might not carry a detectable watermark).

So a clean result is a statement about one detector, one key and one file. It is not a statement that the file carries no mark. The same page adds that it “can currently only recognize content created by Google AI tools” — which is exactly the limit you would expect from a verification tool, and exactly the limit a removal page has no reason to mention.

How to tell which removal you actually need

Five questions, asked of your own file, in this order. Each one routes you to a different rung of the ladder.

Where this site sits, on the same list

We touch exactly one cell: the visible badge on a still image, in your browser, by reversing a known alpha blend. That is arithmetic on a known template, which is why it needs no server and can be free. It reads PNG, JPEG and WebP, one image at a time, up to 60 megapixels, and the cleaned file is written by your own browser — nothing is uploaded.

And the honest limit, kept in the same place as the promise: at the 1024×1024 output size the Nano Banana models default to, this tool did not locate the watermark correctly, and the result was worse than the original. We published the measurement instead of burying it.

If you arrived here from a different direction, the relevant page is probably one of these:

Sources