Who watermarks what
Of the 10 provider-and-modality combinations we track, 7 are confirmed shipping some form of marking, 3 have no way for anyone outside the company to verify the mark, and 2 are reported but unconfirmed because we could not find a primary source. Anthropic and Google are the only two with primary documentation of what they actually do.
Updated 2026-09-18. Published as reusable data under CC BY 4.0. Corrections with a primary source are very welcome.
| Provider | Modality | Status | Method and scope | Can you verify it? |
|---|---|---|---|---|
| Anthropic Claude |
text | Partial | Statistical watermark in the model's word choices — a version of SynthID-Text, named by Anthropic on 14 Aug 2026[1][10][12] Models launched on or after 2 Aug 2026, worldwide. Since 16 Sep 2026 Anthropic's help centre lists which: Fable 5.1, Mythos 5.1 and Opus 5 carry the text watermark. Ten other listed models (Fable 5, Mythos 5, Opus 4.5 to 4.8, Sonnet 4.5, 4.6 and 5, Haiku 4.5) are listed for file credentials only. Earlier models in transition; Anthropic says all will be covered by 2 Dec 2026. Anthropic published a technical explainer on 14 Aug 2026 naming the scheme: a version of Google DeepMind's SynthID-Text, in the family of approaches going back to Scott Aaronson's 2022 proposal, which change only the source of the randomness used to pick among equally good next words. It also states plainly that nothing is added to the text and there are no hidden characters, and that the mark carries no information about a user, their organisation or their chats. This supersedes a note published here until 15 Aug 2026 saying Anthropic had not published the scheme's details. Marking is thinner where word choice is constrained: factual passages, proofreading, and code outside its comments. This row read 'None' in the detector column until 2 Sep 2026, which was correct until Anthropic opened the detection API to a private preview on 1 Sep 2026. |
Gated Since 1 Sep 2026 a detection API is in private preview. Anthropic offers it to organisations obliged to check under EU law — regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations and EU civil society groups — and to enterprises under the same obligation, by application through a form. It says access will widen over time. There is still nothing the public can use. |
| Anthropic Claude |
files (.svg, .png, .jpg) | Live | Signed provenance metadata, C2PA standard[1][10][11][13] Supported file types generated by Claude, worldwide. Anthropic's help centre lists 13 models for file credentials: Fable 5.1 and 5, Mythos 5.1 and 5, Opus 5, 4.8, 4.7, 4.6 and 4.5, Sonnet 5, 4.6 and 4.5, Haiku 4.5. Its developer docs name 14 signed formats, image, video and audio, and say text files, PDFs and office documents are not signed. |
Public C2PA manifests are readable by any C2PA-compatible verifier; Anthropic's developer docs name the open-source c2patool. Anthropic also runs a free one of its own, the Claude Content Checker, which reads the credential in the browser without uploading the file; the help centre began linking it in its 1 Sep 2026 edit. It checks files, not text. Metadata can be stripped by re-encoding. |
| Google Gemini |
text | Live | SynthID Text — token probability modulation[3][4] Gemini app and web experience This row said until 13 Aug 2026 that you could also upload text to Gemini and ask. DeepMind's page does not say that: both detection routes it describes take an image, video or audio file, and neither names text. Whether the Gemini route works on text is unknown to us. |
Open library The scheme is open source with a reference detector on PyPI. Google's own hosted portal is gated: DeepMind says it is working with journalists and media professionals to test it. |
| Google Imagen, Veo |
image, video | Live | SynthID — imperceptible pixel-level watermark[3] Google generative AI consumer products |
Gated SynthID Detector portal, restricted access. Gemini will also answer questions about uploaded content. |
| Google Lyria, NotebookLM |
audio | Live | SynthID audio watermark[3] Lyria music generation, NotebookLM podcast feature |
Gated Same portal restriction as image and video. |
| OpenAI ChatGPT, ImageGen, Sora, Codex |
image | Live | C2PA Content Credentials plus SynthID watermarking[9] Images generated through ChatGPT, Codex or the OpenAI API. Content Credentials since 2024; SynthID added 2026. |
Public OpenAI runs a public verification tool in preview, checking both Content Credentials and SynthID, plus verification API access since 31 July 2026. Limited to OpenAI-generated content. If nothing is detected it deliberately draws no conclusion. |
| OpenAI ChatGPT, OpenAI API |
audio | Live | SynthID watermarking[9] Supported audio generated with OpenAI tools, from 31 July 2026 |
Public Covered by the same public verification tool and verification API. |
| OpenAI ChatGPT |
text | None | No text watermarking scheme announced[9] Not covered OpenAI's provenance work covers images and, since July 2026, audio. Text is not mentioned. We read the page in full on 12 Aug 2026 to check, because reporting that lists OpenAI among companies committing to Article 50 compliance is easily misread as covering text. |
None No public detector for OpenAI text, and no scheme announced to detect. |
| Meta Meta AI, Llama |
text, image | Unverified | Unknown[5] Unknown Named in reporting as having committed to compliance. We have not located a primary source describing what Meta actually ships. This row is a known gap, not a finding. |
None Unknown. |
| Microsoft Copilot |
text, image | Unverified | Unknown[5] Unknown Named in reporting as having committed to compliance. Primary source not yet located. |
None Unknown. |
How to read this
Status is what the provider ships. Live means the provider itself confirms it. Partial means some models, surfaces or regions only. Unverified means it was reported by third parties and we have not located a primary source. Those rows are gaps in our knowledge, shown rather than hidden, and they are the rows most likely to change.
Can you verify it is the column that matters most and gets the least coverage. A mark that only its author can read gives you nothing as a reader.
The three big providers have answered that question differently, and the spread is the most useful thing on this page. OpenAI ships a public verification tool for its images and audio, and a verification API[9]. Google open-sourced its text watermarking scheme with a working detector, while keeping its own hosted portal restricted to journalists and media professionals[4][3]. Anthropic shipped the mark, and on 1 September 2026 opened a detection API in private preview to organisations that EU law obliges to check, plus enterprises under the same obligation[10][1]. Marking content and deciding who may check it are separate decisions.
Note the asymmetry by modality, too. Images and audio are comparatively well served, and Anthropic added a free file checker for C2PA credentials in September[1][11]. Text — the modality most people are actually anxious about, because it is what gets students accused — is the one where no member of the public can check anything from anyone except Google[1][9][4].
What changes this table
- Anthropic opening the watermark detection API beyond its private preview. That happened in part on 1 September 2026: the row moved from None to Gated when the API reached organisations obliged to check under EU law[10][1]. It becomes Public only if anyone can run it, and Anthropic says access will widen over time without saying how far[12].
- Primary sources appearing for Meta, Microsoft and OpenAI's text handling.
- Google opening the SynthID Detector portal beyond journalists and media professionals[3].
Sources
- How Claude marks AI-generated content primary
- SynthID primary
- google-deepmind/synthid-text primary
- Anthropic says it will watermark text generated by its AI models
- Advancing content provenance for a safer, more transparent AI ecosystem primary
- How Claude's text watermark works primary
- Check if files were made with Claude primary
- Introducing Claude Fable 5.1 and Claude Mythos 5.1 primary
- Code execution tool — Content Credentials on generated files primary
Last verified against primary sources: