Built by Pluto.Studio · find and test independent Android apps on IndieHangar
AI Watermarks

Who watermarks what

Of the 10 provider-and-modality combinations we track, 7 are confirmed shipping some form of marking, 3 have no way for anyone outside the company to verify the mark, and 2 are reported but unconfirmed because we could not find a primary source. Anthropic and Google are the only two with primary documentation of what they actually do.

Updated 2026-09-18. Published as reusable data under CC BY 4.0. Corrections with a primary source are very welcome.

ProviderModalityStatus Method and scopeCan you verify it?
Anthropic
Claude
text Partial Statistical watermark in the model's word choices — a version of SynthID-Text, named by Anthropic on 14 Aug 2026[1][10][12]
Models launched on or after 2 Aug 2026, worldwide. Since 16 Sep 2026 Anthropic's help centre lists which: Fable 5.1, Mythos 5.1 and Opus 5 carry the text watermark. Ten other listed models (Fable 5, Mythos 5, Opus 4.5 to 4.8, Sonnet 4.5, 4.6 and 5, Haiku 4.5) are listed for file credentials only. Earlier models in transition; Anthropic says all will be covered by 2 Dec 2026.
Anthropic published a technical explainer on 14 Aug 2026 naming the scheme: a version of Google DeepMind's SynthID-Text, in the family of approaches going back to Scott Aaronson's 2022 proposal, which change only the source of the randomness used to pick among equally good next words. It also states plainly that nothing is added to the text and there are no hidden characters, and that the mark carries no information about a user, their organisation or their chats. This supersedes a note published here until 15 Aug 2026 saying Anthropic had not published the scheme's details. Marking is thinner where word choice is constrained: factual passages, proofreading, and code outside its comments. This row read 'None' in the detector column until 2 Sep 2026, which was correct until Anthropic opened the detection API to a private preview on 1 Sep 2026.
Gated
Since 1 Sep 2026 a detection API is in private preview. Anthropic offers it to organisations obliged to check under EU law — regulators, law enforcement, media, fact-checkers, independent researchers, educational organisations and EU civil society groups — and to enterprises under the same obligation, by application through a form. It says access will widen over time. There is still nothing the public can use.
Anthropic
Claude
files (.svg, .png, .jpg) Live Signed provenance metadata, C2PA standard[1][10][11][13]
Supported file types generated by Claude, worldwide. Anthropic's help centre lists 13 models for file credentials: Fable 5.1 and 5, Mythos 5.1 and 5, Opus 5, 4.8, 4.7, 4.6 and 4.5, Sonnet 5, 4.6 and 4.5, Haiku 4.5. Its developer docs name 14 signed formats, image, video and audio, and say text files, PDFs and office documents are not signed.
Public
C2PA manifests are readable by any C2PA-compatible verifier; Anthropic's developer docs name the open-source c2patool. Anthropic also runs a free one of its own, the Claude Content Checker, which reads the credential in the browser without uploading the file; the help centre began linking it in its 1 Sep 2026 edit. It checks files, not text. Metadata can be stripped by re-encoding.
Google
Gemini
text Live SynthID Text — token probability modulation[3][4]
Gemini app and web experience
This row said until 13 Aug 2026 that you could also upload text to Gemini and ask. DeepMind's page does not say that: both detection routes it describes take an image, video or audio file, and neither names text. Whether the Gemini route works on text is unknown to us.
Open library
The scheme is open source with a reference detector on PyPI. Google's own hosted portal is gated: DeepMind says it is working with journalists and media professionals to test it.
Google
Imagen, Veo
image, video Live SynthID — imperceptible pixel-level watermark[3]
Google generative AI consumer products
Gated
SynthID Detector portal, restricted access. Gemini will also answer questions about uploaded content.
Google
Lyria, NotebookLM
audio Live SynthID audio watermark[3]
Lyria music generation, NotebookLM podcast feature
Gated
Same portal restriction as image and video.
OpenAI
ChatGPT, ImageGen, Sora, Codex
image Live C2PA Content Credentials plus SynthID watermarking[9]
Images generated through ChatGPT, Codex or the OpenAI API. Content Credentials since 2024; SynthID added 2026.
Public
OpenAI runs a public verification tool in preview, checking both Content Credentials and SynthID, plus verification API access since 31 July 2026. Limited to OpenAI-generated content. If nothing is detected it deliberately draws no conclusion.
OpenAI
ChatGPT, OpenAI API
audio Live SynthID watermarking[9]
Supported audio generated with OpenAI tools, from 31 July 2026
Public
Covered by the same public verification tool and verification API.
OpenAI
ChatGPT
text None No text watermarking scheme announced[9]
Not covered
OpenAI's provenance work covers images and, since July 2026, audio. Text is not mentioned. We read the page in full on 12 Aug 2026 to check, because reporting that lists OpenAI among companies committing to Article 50 compliance is easily misread as covering text.
None
No public detector for OpenAI text, and no scheme announced to detect.
Meta
Meta AI, Llama
text, image Unverified Unknown[5]
Unknown
Named in reporting as having committed to compliance. We have not located a primary source describing what Meta actually ships. This row is a known gap, not a finding.
None
Unknown.
Microsoft
Copilot
text, image Unverified Unknown[5]
Unknown
Named in reporting as having committed to compliance. Primary source not yet located.
None
Unknown.

How to read this

Status is what the provider ships. Live means the provider itself confirms it. Partial means some models, surfaces or regions only. Unverified means it was reported by third parties and we have not located a primary source. Those rows are gaps in our knowledge, shown rather than hidden, and they are the rows most likely to change.

Can you verify it is the column that matters most and gets the least coverage. A mark that only its author can read gives you nothing as a reader.

The three big providers have answered that question differently, and the spread is the most useful thing on this page. OpenAI ships a public verification tool for its images and audio, and a verification API[9]. Google open-sourced its text watermarking scheme with a working detector, while keeping its own hosted portal restricted to journalists and media professionals[4][3]. Anthropic shipped the mark, and on 1 September 2026 opened a detection API in private preview to organisations that EU law obliges to check, plus enterprises under the same obligation[10][1]. Marking content and deciding who may check it are separate decisions.

Note the asymmetry by modality, too. Images and audio are comparatively well served, and Anthropic added a free file checker for C2PA credentials in September[1][11]. Text — the modality most people are actually anxious about, because it is what gets students accused — is the one where no member of the public can check anything from anyone except Google[1][9][4].

What changes this table

Sources

  1. How Claude marks AI-generated content primaryAnthropic, 2026-08, updated 2026-09-16
  2. SynthID primaryGoogle DeepMind, 2026
  3. google-deepmind/synthid-text primaryGoogle DeepMind, 2024-10
  4. Anthropic says it will watermark text generated by its AI modelsTechCrunch, 2026-08-11
  5. Advancing content provenance for a safer, more transparent AI ecosystem primaryOpenAI, 2026-05-19, updated 2026-07-31
  6. How Claude's text watermark works primaryAnthropic, 2026-08-14, updated 2026-09-01
  7. Check if files were made with Claude primaryAnthropic, accessed 2026-09-05
  8. Introducing Claude Fable 5.1 and Claude Mythos 5.1 primaryAnthropic, 2026-09-01
  9. Code execution tool — Content Credentials on generated files primaryAnthropic, accessed 2026-09-18

Last verified against primary sources: