Skip to content
Skip to content

Independent e-magazine

the OUTSPOKEN digest

How AI Watermarking Actually Works, and Why It Is Two Different Things

There is no watermark on your AI image in the sense of a visible logo. There are two invisible systems doing different jobs: a statistical signal inside the pixels, and a signed record attached to the file.

Outspoken Digest Technology Desk

Thursday, August 13, 2026/4 min read

An abstract visualisation of a pattern embedded across a digital image grid
Editorial illustration generated for Outspoken Digest

Since 2 August 2026, providers of generative AI in the European Union have had a legal duty to make their outputs detectable as artificially generated, in a machine-readable format. Most coverage has described this as watermarking, which is accurate and hides an important distinction.

There is no single technology called AI watermarking. There are two, they work in completely different ways, and neither is sufficient alone. Understanding the difference explains both why the industry is deploying both and why neither is a solution to the problem people think it solves.

Layer one: the statistical watermark

A watermark of this kind lives inside the content itself. Google DeepMind's SynthID is the best known implementation.

For images, the model adjusts pixel values across the image in a pattern that is imperceptible to a human eye but detectable by a matching detector. It is not a mark in one corner. It is a distributed statistical signature spread through the whole thing.

For text, the approach is different and cleverer. A language model choosing the next word has many acceptable options. A watermarking scheme nudges those choices towards a particular subset according to a secret key, in a way that does not change meaning or fluency but leaves a statistical fingerprint across a long enough passage.

For audio, the watermark is embedded in the spectrogram, surviving conversion to a waveform.

The strength

It survives handling. Compression, cropping, screenshotting, re-encoding and moderate editing generally leave the signal intact, which is the crucial property, because content in the wild is screenshotted constantly.

The limits

  • It needs a detector. The signal is meaningless without the matching system, and if that is proprietary, only the issuing company can confirm it.
  • Text is the weak case. Short passages carry too little signal, and paraphrasing degrades it substantially.
  • Determined removal works. Heavy transformation, regeneration through another model, or purpose-built adversarial tools can strip or scramble it.
  • It only covers participating models. An open-weight model run locally with the watermarking removed produces content with no signal at all, and nothing prevents this.

Layer two: cryptographic provenance

The second approach does the opposite. Rather than hiding a signal in the content, it attaches a signed record to the file describing where the content came from.

This is the C2PA standard, developed by a coalition including Adobe, Microsoft, the BBC and others, and surfaced to users as Content Credentials.

The manifest records what created the asset, when, and what has been done to it since. Each step is cryptographically signed, so tampering is detectable, and edits append to the history rather than replacing it. A press photograph can in principle carry a chain from the camera through each edit to publication.

The strength

It is verifiable by anyone, it is an open standard rather than one company's system, and it is far richer than a binary AI or not AI answer. It can say this was photographed on this camera, cropped, colour corrected, and had a generative fill applied to one region.

The limits

The manifest is metadata, and metadata is fragile. Screenshot the image and it is gone. Upload it to a platform that strips metadata, which many still do, and it is gone. Nothing about the pixels changes, so the absence of credentials tells you nothing at all.

Why both, together

The failure modes are complementary, which is why the emerging industry approach is a two-layer strategy: an invisible watermark inside the content plus cryptographic credentials attached to it.

The watermark survives a screenshot but tells you little. The credentials are rich but do not survive a screenshot. Together they degrade more gracefully than either alone.

The EU AI Act does not name either technology. The regulation is written to be technology-neutral, and Article 50 requires that outputs be marked in a machine-readable format and detectable as artificially generated. The Commission's draft Code of Practice on transparency does cite C2PA as an example of a solution meeting its criteria, alongside complementary signals such as SynthID, which is how a neutral law ends up with a de facto answer.

The regulatory picture, including who has to disclose what, is covered in our piece on the transparency rules.

The thing to understand before you rely on any of it

Watermarking answers one question well and another not at all.

It can often tell you that a piece of content was made by a participating AI system. It cannot tell you that a piece of content was not, because absence of a watermark is not evidence of human authorship. It might mean the content is real. It might mean it was made with a model that does not watermark, or that the mark was stripped, or that it was screenshotted.

This asymmetry is the single most misunderstood point in the entire subject, and it matters enormously in practice. A verification system that produces false confidence in the negative case is worse than no system, because people will treat unmarked content as authenticated.

The realistic goal is not a detector that catches all fakes. It is a world in which trustworthy sources carry verifiable provenance, so the question shifts from can you prove this is fake to can you prove this is real. That is a lower bar and a much more achievable one.

Why regulators pushed for it at all, and what it means for everyone downstream, is in our companion piece on why watermarking was introduced.

Published in The Outspoken Digest

Editorial desk

Outspoken Digest Technology Desk

Software, hardware, artificial intelligence and what they change for everyone else.

Newsletter

The Digest, in your inbox

One edition, sent when it is ready. No noise, and your address is never passed on.

We send a confirmation first. One click to leave, always.

Share this story

the OUTSPOKEN digest

Beyond boundaries. Independent stories on technology, culture, and the trends shaping how we live.