You cannot remove all of it, and most pages on this term never say which part they mean. “The AI watermark” is four different things in four different places: a visible badge made of ordinary pixels, a metadata label attached to the file, an invisible signal embedded through the pixels themselves, and a claim about how the file was made. A method that removes one of the four does nothing to the other three — so a page can honestly advertise “removes the AI watermark” and still be describing something you do not need.
The most useful single fact on this term comes from Google's own verification help, and it points the other way from what the removal pages assume. The digital watermark, in Google's own words, “will usually still exist” even when the image, video or audio is re-scaled, re-coloured, compressed or altered in other ways.
Where this site sits, plainly: it removes one of the four, on one kind of file — the visible badge on a still image. It does not strip metadata, it does not touch the embedded signal, and it does not open video files.
“Remove” is four different jobs
The word covers four objects that live in four different places. Sorting them is most of the work, because every honest removal claim on this term is a claim about exactly one of them.
- The visible badge. Ordinary pixels composited over the picture, at a known position, through a known transparency template. Because both the position and the template are known, the original pixels underneath can be recovered by reversing the blend. This is the only one of the four that is a matter of arithmetic.
- The metadata label. A separate block in the file, not in the picture. Google describes Content Credentials as “a technology that provides media history and transparency, including whether AI was involved in the creation of the content”, built on the C2PA industry standard. It travels with the container the picture is stored in, not with the pixels. The model vendor that has just switched on text watermarking draws the line about its own equivalent: “Nothing in the file changes—it is not embedded or hidden.”
- The invisible embedded signal. Google DeepMind's own description: “SynthID embeds digital watermarks directly into AI-generated images, audio, text or video.” Directly into the content — spread through the pixels, not parked in one place that could be cut out.
- The claim. This one is not in the file at all. It is a statement about how the file came to exist. A watermark, in the words of the vendor that has just switched one on, “can only determine that [the model] was likely involved with the content at some point”. You can delete a note. You cannot delete a fact about the past.
Notice the shape of that list. Three of the four live inside the file — in the pixels, in the container, in the pixels again — and the fourth lives nowhere. A tool that strips the label can advertise “removes AI metadata”. A tool that reverses the badge can advertise “removes AI watermarks”. Both statements are accurate. Neither is what a reader who wants the embedded signal gone is looking for.
The removal ladder: five actions and what each one actually destroys
Here is every action a person can actually take, ordered from least to most destructive, with the honest result for each of the four objects above. This list is the thing the results for this term never put in one place: most pages describe one rung and imply it is the ladder.
- Crop, cover or paint over. Destroys: the visible badge, if it sits inside the crop. Leaves: the label and the embedded signal, both untouched. Google's own help notes that cropping is the step you take to make a screenshot verify better — which is a useful tell, because it means cropping is a move in the visible layer, not the hidden one.
- Re-save or re-export the file. Destroys: the metadata label — rewriting the container is enough to drop a note that was stored in the container. Leaves: the embedded signal. This is the rung people most often mistake for removal, because the visible change is real and the invisible non-change is invisible. Google: the watermark will usually still exist after compression.
- Strip the metadata with a tool. Destroys: the label, deliberately and thoroughly. Leaves: everything else. If what you wanted gone was the embedded signal, this accomplishes nothing you can see and nothing you cannot.
- Rewrite the text. For the text layer this is the real removal, and the vendor states it more plainly than any removal page: “Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will.” The catch is in its very next sentence: “In the latter case, of course, it's arguable whether the text can any longer be described as AI-generated.” The only thing that removes a text watermark is producing different text — which is not removal, it is replacement.
- Generate something new. Removes all four, including the thing you were trying to keep.
Read the list as a whole and the pattern is: each action removes exactly one object, and the object it removes is usually not the one the reader wanted gone. There is no rung on this ladder that takes out the embedded signal without also taking out the content.
Two statements on this results page, and why they look like a contradiction
Two kinds of page sit side by side on this term, and they appear to say opposite things about the embedded signal. One kind states that an invisible pixel watermark can be defeated by cropping, rotating, dithering and repeated lossy re-encoding — that these operations desynchronise the pattern a detector correlates against. The other kind is Google's own verification documentation, which states that the digital watermark “will usually still exist even if the image, video, or audio is re-scaled, re-colored, compressed or altered in other ways.”
The useful reading is not a verdict, because these are two different thresholds being described in the same words. “The mark is still in the file” and “a detector still reports the mark” are not the same claim. Google's own page leaves the door open in the same breath — “there's still a chance that after many alterations the watermark won't be detected” — so the disagreement is not about whether re-encoding does anything. It is about how many rounds of it, applied to which file, measured against which detector.
No page on this term gives you that measurement for your own file, and neither does this one. What you can do instead is run the check on the result, before you rely on it — which is the next section but one.
“Not detected” is not the same as “clean”
Google's verification help gives three outcomes, not two: detected, not detected, and unclear. It is also explicit about what the middle one means — “it means the image or video wasn't created or edited by Google AI, but it could have been created by other AI systems” — and it lists two reasons a genuinely Google-made file can come back with no detection at all: “Not enough details to watermark” (very simple or abstract content), and “Likely too small an edit” (minor alterations might not carry a detectable watermark).
So a clean result is a statement about one detector, one key and one file. It is not a statement that the file carries no mark. The same page adds that it “can currently only recognize content created by Google AI tools” — which is exactly the limit you would expect from a verification tool, and exactly the limit a removal page has no reason to mention.
How to tell which removal you actually need
Five questions, asked of your own file, in this order. Each one routes you to a different rung of the ladder.
- Can you see the mark? Then it is the visible layer, and reversing the blend is a real option.
- Is the mark only ever described in a checker's report, never visible? Then it is the embedded layer, and no action on this ladder removes it without removing the content.
- Did a tool tell you the file has “AI metadata” or Content Credentials? That is the label. Stripping it is a real and separate operation, and it changes what a viewer sees in a provenance panel — not what a detector reads out of the pixels.
- Is the mark in text? Then “removal” means rewriting, with the consequence the vendor states itself.
- Is the mark on a clip? Then none of this transfers: the embedded layer is specified to survive frame-rate changes and lossy compression, which is most of what video handling consists of.
Where this site sits, on the same list
We touch exactly one cell: the visible badge on a still image, in your browser, by reversing a known alpha blend. That is arithmetic on a known template, which is why it needs no server and can be free. It reads PNG, JPEG and WebP, one image at a time, up to 60 megapixels, and the cleaned file is written by your own browser — nothing is uploaded.
And the honest limit, kept in the same place as the promise: at the 1024×1024 output size the Nano Banana models default to, this tool did not locate the watermark correctly, and the result was worse than the original. We published the measurement instead of burying it.
If you arrived here from a different direction, the relevant page is probably one of these:
- What an “AI watermark” actually is in text, in an image and in a video — the three modalities side by side, and which of the three you can check or remove.
- Which of the two tools “AI watermark remover” means — the phrase covers both a general object-removal tool and a provenance-mark tool.
- Whether SynthID can be removed, with our own measured failure numbers rather than small print.
- What a video watermark actually is — four kinds of mark behind one phrase, and the official check you can run on a finished clip.
- What Google's own rules and forum say, with the official policy and the community answer kept apart.
- The official setting that stops the mark being added in the first place — upstream of every tool on this term, and free.
Sources
- Google, Verify AI-generated images, videos, and audio, Gemini Apps Help — support.google.com/gemini/answer/16722517. Source of the quoted answer that the digital watermark “will usually still exist” after re-scaling, re-colouring, compression or other alterations, and of the accompanying “still a chance” caveat; of the quoted distinction between watermarks (embedded directly into content) and metadata (additional context attached to the original file); of the quoted definition of Content Credentials; of the three verification outcomes and the quoted statement that a non-detection can still mean other AI systems; of the quoted “Likely too small an edit” reason; of the quoted statement that the tool can currently only recognise Google AI output; and of the screenshot cropping guidance.
- Google DeepMind, SynthID — deepmind.google/technologies/synthid/. Source of the quoted statement that SynthID embeds digital watermarks directly into AI-generated images, audio, text or video, and of the quoted statement that the mark is designed to stand up to cropping, filters, frame-rate changes and lossy compression.
- Anthropic, How Claude's text watermark works (published 14 August 2026, updated 1 September 2026) — anthropic.com/news/claude-text-watermark. Source of the quoted statements on what a watermark can and cannot determine, on light editing versus a complete rewrite, on whether rewritten text can still be described as AI-generated, on the detection API's restricted availability, and of the quoted statement that the metadata credential is “very different from a watermark”. Quoted as that company's own published account; we draw no legal conclusion of our own.
- Content Credentials / C2PA — contentcredentials.org. Source of the description of Content Credentials as a signal that content carries information about its provenance, and of the specification being hosted by the Coalition for Content Provenance and Authenticity.
- Our own observation of the results returned for this term, checked 1 October 2026. Described as a pattern only: no site is named, no ranking position is claimed, and no page's wording is reproduced.
- Our own tool's behaviour, measured on this site: only the pixels inside the watermark box are rewritten; PNG, JPEG and WebP images are accepted and video files are not; SynthID and C2PA metadata are left untouched. The 1024×1024 failure is our own measurement and is described on the Nano Banana page.