AI watermarks: detection, attribution, and paranoia
Sofía Pérez from Newtral asked me for my opinion on SynthID, Google DeepMind’s invisible watermark for texts, images and other content to…
AI watermarks: detection, attribution, and paranoia

Sofía Pérez from Newtral asked me for my opinion on SynthID, Google DeepMind’s invisible watermark for texts, images and other content to prevent their use by AI. After replying to her email, I started playing around with the tool, and was pleasantly surprised by its response when I asked whether my article from the previous day had been written using AI…
My first impression is that, while DeepSynth may be technically interesting, this kind of tool is creating widespread paranoia — a state of constant suspicion that’s not only extremely uncomfortable but also assumes that anything created by AI is worthless or inherently of lower value, which is, in many cases, nonsense. Obviously, AI can be misused — simply by copying and pasting the output it provides (and it’s possible that a good portion of users do just that) — but assuming that anything touched by AI is somehow tainted is conceptually incorrect, and has never been a viable trend in the history of technology.
I’ve mentioned this on numerous occasions: if I write to learn, asking AI to write for me makes no sense, because I simply wouldn’t learn anything. But asking it to help me with research and source selection, to suggest improvements and additional perspectives, or to correct potential typos or grammatical errors, on the other hand, can make a lot of sense — and it’s something I do regularly. Could there come a time when tools like SynthID would accuse me of writing my articles with AI? In fact, there are quite a few cynics in my comments section who accuse me of just that. Is the fear of such accusations lead me to include typos to make a text appear “more human”, or use other tools to remove watermarks with the same goal in mind.
Here’s Sofía’s article (in Spanish)
Below, my replies to her questions:
SynthID was developed by Google DeepMind to insert invisible watermarks into content generated by artificial intelligence. The idea is relatively simple: to embed a signal in the generated content that is imperceptible to the human eye but that can be detected using specific tools.
In the case of images, these watermarks do not consist of visible overlaid information, but rather of small modifications distributed across the image’s pixels. These alterations are designed not to noticeably affect visual quality, but to leave a mathematical pattern recognizable by detection systems.
In language models, the mechanism is different. The mark can be introduced by slightly altering the probabilities the model uses to select certain words or sequences of words during text generation. The result remains perfectly natural to a human reader but contains statistical patterns that allow one to later infer whether it was generated by a model incorporating that marking system.
Algorithms search specifically for these patterns. When an image, audio file, or text is analyzed, the system calculates the probability that it contains the signal introduced during generation. This is not an absolute identification, but rather an estimate based on the presence of certain mathematical characteristics.
The main problem is that these technologies are far from infallible. Watermarks can degrade or disappear when content is edited, cropped, compressed, translated, reformulated or processed by other systems. Furthermore, they only work reliably when the content has been generated by models that specifically incorporate that mechanism. Content generated by a model that does not implement SynthID or an equivalent technology will leave no detectable signal.
Therefore, although watermarks represent an interesting tool for improving the traceability of AI-generated content, it is an exaggeration to present them as a definitive solution to the problem of identifying synthetic content. Rather, they are an additional layer of information that can be helpful in certain contexts but comes with significant technical and practical limitations.
(En español, aquí)
메타데이터
- post_id
- 4e2517197f2f
- slug
- ai-watermarks-detection-attribution-and-paranoia-4e2517197f2f
- url
- https://medium.com/enrique-dans/ai-watermarks-detection-attribution-and-paranoia-4e2517197f2f
- canonical_url
- https://medium.com/enrique-dans/ai-watermarks-detection-attribution-and-paranoia-4e2517197f2f
- author_url
- https://medium.com/@edans
- status
- ok
- fetched_at
- 2026-07-09 13:13:48