{
  "$schema_note": "Published at /data/watermarks.json under CC BY 4.0. Reuse freely with attribution to https://aiwatermarking.org",
  "updated": "2026-09-18",
  "license": "CC BY 4.0",
  "attribution": "AI Watermarks — https://aiwatermarking.org",

  "_status_values": {
    "live": "Confirmed shipping by the provider itself.",
    "partial": "Shipping for some models, surfaces or regions only.",
    "announced": "Committed to publicly, not yet confirmed shipping.",
    "none": "No marking of this modality that we can find.",
    "unverified": "Reported by third parties; we have not located a primary source. Treated as unknown, shown so the gap is visible rather than silently omitted."
  },

  "_detector_values": {
    "public": "Anyone can check content themselves.",
    "gated": "A detector exists but access is restricted.",
    "library": "An open implementation exists, but you need the model's keys or the scheme's parameters to use it in anger.",
    "none": "No way for anyone outside the provider to verify."
  },

  "rows": [
    {
      "provider": "Anthropic",
      "system": "Claude",
      "modality": "text",
      "status": "partial",
      "method": "Statistical watermark in the model's word choices — a version of SynthID-Text, named by Anthropic on 14 Aug 2026",
      "scope": "Models launched on or after 2 Aug 2026, worldwide. Since 16 Sep 2026 Anthropic's help centre lists which: Fable 5.1, Mythos 5.1 and Opus 5 carry the text watermark. Ten other listed models (Fable 5, Mythos 5, Opus 4.5 to 4.8, Sonnet 4.5, 4.6 and 5, Haiku 4.5) are listed for file credentials only. Earlier models in transition; Anthropic says all will be covered by 2 Dec 2026.",
      "surfaces": "API, Claude platform, Claude Code, Claude Cowork, Claude Tag. Also when supported models are reached through AWS, Google Cloud or Microsoft Foundry; for Opus 5 the cloud-partner rollout started 14 Sep 2026, complete within a week.",
      "detector": "gated",
      "detector_note": "Since 1 Sep 2026 a detection API is in private preview. Anthropic offers it to organisations obliged to check under EU law — regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations and EU civil society groups — and to enterprises under the same obligation, by application through a form. It says access will widen over time. There is still nothing the public can use.",
      "sources": ["anthropic-help", "anthropic-watermark-explainer", "anthropic-fable-mythos-51"],
      "reported_only": "Anthropic published a technical explainer on 14 Aug 2026 naming the scheme: a version of Google DeepMind's SynthID-Text, in the family of approaches going back to Scott Aaronson's 2022 proposal, which change only the source of the randomness used to pick among equally good next words. It also states plainly that nothing is added to the text and there are no hidden characters, and that the mark carries no information about a user, their organisation or their chats. This supersedes a note published here until 15 Aug 2026 saying Anthropic had not published the scheme's details. Marking is thinner where word choice is constrained: factual passages, proofreading, and code outside its comments. This row read 'None' in the detector column until 2 Sep 2026, which was correct until Anthropic opened the detection API to a private preview on 1 Sep 2026."
    },
    {
      "provider": "Anthropic",
      "system": "Claude",
      "modality": "files (.svg, .png, .jpg)",
      "status": "live",
      "method": "Signed provenance metadata, C2PA standard",
      "scope": "Supported file types generated by Claude, worldwide. Anthropic's help centre lists 13 models for file credentials: Fable 5.1 and 5, Mythos 5.1 and 5, Opus 5, 4.8, 4.7, 4.6 and 4.5, Sonnet 5, 4.6 and 4.5, Haiku 4.5. Its developer docs name 14 signed formats, image, video and audio, and say text files, PDFs and office documents are not signed.",
      "surfaces": "Anthropic says the credential is added when Claude creates a file, so it applies only where a platform offers Claude's file generation features: the Claude apps and the Claude Platform API, including Claude Platform on AWS and Claude in Microsoft Foundry. Google Cloud is not in that list.",
      "detector": "public",
      "detector_note": "C2PA manifests are readable by any C2PA-compatible verifier; Anthropic's developer docs name the open-source c2patool. Anthropic also runs a free one of its own, the Claude Content Checker, which reads the credential in the browser without uploading the file; the help centre began linking it in its 1 Sep 2026 edit. It checks files, not text. Metadata can be stripped by re-encoding.",
      "sources": ["anthropic-help", "anthropic-watermark-explainer", "anthropic-content-checker", "anthropic-docs-c2pa"]
    },
    {
      "provider": "Google",
      "system": "Gemini",
      "modality": "text",
      "status": "live",
      "method": "SynthID Text — token probability modulation",
      "scope": "Gemini app and web experience",
      "surfaces": "Gemini app, Gemini web",
      "detector": "library",
      "detector_note": "The scheme is open source with a reference detector on PyPI. Google's own hosted portal is gated: DeepMind says it is working with journalists and media professionals to test it.",
      "sources": ["deepmind-synthid", "synthid-text-repo"],
      "reported_only": "This row said until 13 Aug 2026 that you could also upload text to Gemini and ask. DeepMind's page does not say that: both detection routes it describes take an image, video or audio file, and neither names text. Whether the Gemini route works on text is unknown to us."
    },
    {
      "provider": "Google",
      "system": "Imagen, Veo",
      "modality": "image, video",
      "status": "live",
      "method": "SynthID — imperceptible pixel-level watermark",
      "scope": "Google generative AI consumer products",
      "surfaces": "Consumer generative products",
      "detector": "gated",
      "detector_note": "SynthID Detector portal, restricted access. Gemini will also answer questions about uploaded content.",
      "sources": ["deepmind-synthid"]
    },
    {
      "provider": "Google",
      "system": "Lyria, NotebookLM",
      "modality": "audio",
      "status": "live",
      "method": "SynthID audio watermark",
      "scope": "Lyria music generation, NotebookLM podcast feature",
      "surfaces": "Lyria, NotebookLM",
      "detector": "gated",
      "detector_note": "Same portal restriction as image and video.",
      "sources": ["deepmind-synthid"]
    },
    {
      "provider": "OpenAI",
      "system": "ChatGPT, ImageGen, Sora, Codex",
      "modality": "image",
      "status": "live",
      "method": "C2PA Content Credentials plus SynthID watermarking",
      "scope": "Images generated through ChatGPT, Codex or the OpenAI API. Content Credentials since 2024; SynthID added 2026.",
      "surfaces": "ChatGPT, Codex, OpenAI API",
      "detector": "public",
      "detector_note": "OpenAI runs a public verification tool in preview, checking both Content Credentials and SynthID, plus verification API access since 31 July 2026. Limited to OpenAI-generated content. If nothing is detected it deliberately draws no conclusion.",
      "sources": ["openai-provenance"]
    },
    {
      "provider": "OpenAI",
      "system": "ChatGPT, OpenAI API",
      "modality": "audio",
      "status": "live",
      "method": "SynthID watermarking",
      "scope": "Supported audio generated with OpenAI tools, from 31 July 2026",
      "surfaces": "ChatGPT, OpenAI API",
      "detector": "public",
      "detector_note": "Covered by the same public verification tool and verification API.",
      "sources": ["openai-provenance"]
    },
    {
      "provider": "OpenAI",
      "system": "ChatGPT",
      "modality": "text",
      "status": "none",
      "method": "No text watermarking scheme announced",
      "scope": "Not covered",
      "surfaces": "n/a",
      "detector": "none",
      "detector_note": "No public detector for OpenAI text, and no scheme announced to detect.",
      "sources": ["openai-provenance"],
      "reported_only": "OpenAI's provenance work covers images and, since July 2026, audio. Text is not mentioned. We read the page in full on 12 Aug 2026 to check, because reporting that lists OpenAI among companies committing to Article 50 compliance is easily misread as covering text."
    },
    {
      "provider": "Meta",
      "system": "Meta AI, Llama",
      "modality": "text, image",
      "status": "unverified",
      "method": "Unknown",
      "scope": "Unknown",
      "surfaces": "Unknown",
      "detector": "none",
      "detector_note": "Unknown.",
      "sources": ["techcrunch-anthropic"],
      "reported_only": "Named in reporting as having committed to compliance. We have not located a primary source describing what Meta actually ships. This row is a known gap, not a finding."
    },
    {
      "provider": "Microsoft",
      "system": "Copilot",
      "modality": "text, image",
      "status": "unverified",
      "method": "Unknown",
      "scope": "Unknown",
      "surfaces": "Unknown",
      "detector": "none",
      "detector_note": "Unknown.",
      "sources": ["techcrunch-anthropic"],
      "reported_only": "Named in reporting as having committed to compliance. Primary source not yet located."
    }
  ]
}
