Treadstone Associates
Article · 8 min read

How AI watermarking works

An AI watermark is not a visible logo stamped in the corner of an image. It is a signal embedded in the content itself at the moment it is created, engineered to survive resizing, compression and screenshots, and readable back out only by a matching detector.

Treadstone Associates · Updated 2026

Key takeaways

  • • A watermark is embedded at creation, not added afterward as a label.
  • • Google’s SynthID adjusts the probability scores a model already uses to generate content, rather than adding a separate visible marker.
  • • Watermarking only works for content generated by the specific tool that embedded it — it cannot label content from a different model.
  • • Canada has no law requiring watermarking; the closest domestic hook is a voluntary measure in a federal code that binds only its signatories, and only for systems available to the public.

What a watermark actually changes in the file

Google describes SynthID, its watermarking tool, this way: it “embeds digital watermarks directly into AI-generated images, audio, text or video,” and the watermarks are “imperceptible to humans – but can be detected by SynthID’s technology.” (deepmind.google) The mechanism differs by medium. For an image or video, the watermark is “added the moment content is created” and is “designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression.” For audio generated through Google’s music or podcast-generation tools, the watermark is “inaudible to the human ear, and can’t be altered by common modifications like adding noise, MP3 compression, or changing the speed of the track.” For text, the mechanism is different again: because a language model assigns a probability score to each candidate next word, “SynthID adjusts these probability scores to generate a watermark” rather than inserting any separate character or symbol.

How the industry’s shared standard differs

A second, unrelated mechanism comes from the Coalition for Content Provenance and Authenticity (C2PA), whose Content Credentials standard works by attaching a record rather than embedding a signal in the content itself: it “provides an open technical standard for publishers, creators and consumers to establish the origin and edits of digital content,” described on its own site as functioning “like a nutrition label for digital content, giving a peek at the content’s history available for anyone to access, at any time.” (c2pa.org) Where SynthID hides a signal inside the pixels, audio samples or token choices, a Content Credentials record travels alongside the file as attached data describing what created it and how it was edited — a different mechanism with a different failure mode, covered in the companion piece on why that record so often goes missing by the time a file is published.

Why the near-term focus is audio-visual content

Canada’s federal Voluntary Code of Conduct on advanced generative AI names watermarking as one specific, narrow obligation: signatories managing a system “available for public use” must “develop and implement a reliable and freely available method to detect content generated by the system, with a near-term focus on audio-visual content (e.g., watermarking).” (ised-isde.canada.ca) That obligation falls only on the manager of a publicly available system — not on developers generally, and not on anyone who has not signed the code — and it is framed as a near-term priority rather than a permanent, complete solution, which matches how the technology has actually developed: text watermarking of the kind SynthID performs came later than image and video watermarking.

Who actually owes this, under the code

The code’s own measures table splits every obligation two ways at once: whether it falls on the organization that develops a system or the one that manages its operations, and whether the system is generally available or restricted to internal use. Watermarking sits in the narrowest cell of that table — required only of a manager, and only where the system is “available for public use.” The same cell carries two related, easily confused obligations: publishing “a description of the types of training data used to develop the system,” and ensuring a system “that could be mistaken for humans” is “clearly and prominently identified as AI systems.” A developer building a model that is never released publicly owes none of these three under the code, however capable that model is — the obligation tracks public exposure, not raw capability.

ISED’s own list of signatories puts a number on how narrow that cell actually is: 46 organizations have signed the code, per ISED’s own list, last updated June 4, 2026. (ised-isde.canada.ca, list of signatories) Google, whose SynthID this page describes throughout, is not one of them — so SynthID is a product decision Google made on its own, not an obligation the voluntary code ever placed on it.

What watermarking cannot do

Three limits matter more than the mechanism itself. First, a watermark only ever proves a match to its own system: Google’s own description covers watermarks “embedded across Google’s generative AI consumer products” — it says nothing about, and cannot detect, output from a different company’s model. Second, Content Credentials’ own framing of the coalition’s purpose is candid about who the tools are for: “While there will continue to be bad actors who seek to label synthetic content as authentic, our goal is to provide good actors with a way to demonstrate the authenticity of their content.” (contentcredentials.org) A watermark or a credential proves what a cooperating creator did; it is not built to catch someone actively trying to defeat it. Third, even Google’s own detection tooling is young: its SynthID Detector, described as a verification portal, is currently in a testing phase with “journalists and media professionals,” not a mature, generally available product.

A worked example

A marketing team generates a product image with a tool that embeds SynthID, downloads it, resizes it for a social post, and re-uploads it a week later. On Google’s own description of the design goal, the watermark should still be detectable through Gemini after that resizing, because survival through cropping and compression is exactly what the system is engineered for. But nothing in Google’s own materials states an accuracy rate for that survival, and the image will likely pass through the social platform’s own re-encoding on top of the team’s resize — a second modification Google did not test against. The honest position for the team is that the watermark is designed to survive ordinary handling, not that it is guaranteed to.

Related: why a provenance record often does not survive to publication, putting a watermark check together with other signals, why recording origin beats guessing it afterward

Common questions

Is AI watermarking required by Canadian law?

No. It appears only as a voluntary measure in the federal Voluntary Code of Conduct, and only for the organization managing a system available to the public — it binds signatories only, and even then only as a near-term priority for audio-visual content.

Can a watermark be removed?

The vendor material reviewed here does not publish a removal-resistance rate. Content Credentials’ own framing acknowledges that bad actors will keep trying to strip or fake authenticity signals — the tools are built to help a good-faith creator demonstrate origin, not to make removal impossible.

Will a watermark tell me which AI model made an image?

Only if the checking tool matches the watermarking system. Asking Gemini about a SynthID watermark can confirm or rule out Google’s own products; it cannot identify or rule out a different company’s model, because SynthID has no visibility into another system’s output.

Watermarking and disclosure both matter once AI content reaches customers.

Labelling AI-assisted content honestly is as much a trust decision as a technical one.