As AI-generated media floods the internet, Google's SynthID watermarking technology has emerged as one of the most prominent tools for distinguishing authentic content from synthetic imagery. A rigorous new stress test confirms the invisible watermark is remarkably durable, surviving hundreds of rounds of compression, resizing, and even screenshots, but the results also underline a harder truth: technical labels alone are unlikely to resolve the growing crisis of AI disinformation. For ongoing reporting on the latest AI developments, the findings mark an important checkpoint in the content-provenance debate.

The scale of the problem is difficult to overstate. Starling Lab, a research collaboration between Stanford University and the University of Southern California, estimates that it took until 1975, 149 years after the invention of the camera, for humanity to produce 1.5 billion images. Generative AI matched that output in just 18 months. At its I/O conference this year, Google announced that its tools alone had been used to create more than 100 billion AI images and videos in a couple of years.

How SynthID Works

There are currently two main approaches to labeling AI-generated content: invisible watermarks like SynthID and metadata schemas such as the Coalition for Content Provenance and Authenticity (C2PA) standard. Google uses both. C2PA is cryptographically secure and cannot be faked, but it is trivially easy to strip. Simply editing and saving an image, or taking a screenshot, can remove C2PA metadata entirely.

SynthID takes a different approach. Rather than relying on metadata that sits alongside a file, the watermark is encoded directly into the pixels of an image or video, or into the waveform of an audio clip. Because the signal is woven into the content itself, Google has argued it should survive the transformations, compression, cropping, and re-encoding that happen naturally as media gets passed around the internet.

A Stress Test for the Pixel-Level Signal

Ars Technica put those claims to the test using a Python script built on the Pillow imaging library. The script simulated data loss from repeated sharing and downloading at a vastly accelerated rate, applying randomized compression and resizing values to a test image and feeding each output back in as the basis for the next iteration. Two AI-generated images from Google's Nano Banana Pro model, one created entirely from scratch and one original photo edited by AI, served as test subjects.

After 300 generations of simulated sharing, during which the crisp originals were degraded into barely recognizable blobs, the SynthID watermark still registered on both images. The watermark even survived full screenshots, because the special marker pixels transfer over to the new file. Every 50 generations the tester also produced cropped versions to weaken detection further.

Where SynthID Finally Breaks

The limits of the technology only emerged under extreme conditions. After 300 compression cycles, removing a handful of pixels from the border of the degraded test images finally broke SynthID on both the fully generated and the AI-edited images. Because the watermark signal is distributed throughout the pixels, it resists casual cropping, but once enough degradation accumulates, the detector can be defeated.

Google DeepMind scientist Pushmeet Kohli told Ars that the team designed the system expecting it would be attacked. "Through the whole development process, we sort of assumed that a technology like this will be attacked," Kohli said. "So we did a lot of research in making SynthID robust to different kinds of transformations. Whether people are adding some sort of filter or cropping the image, we used these transformations and made sure that the detector was robust against them."

Watermarks Expand Across the Industry

The test arrives as SynthID adoption is widening beyond Google's own products. The company has struck partnerships to expand use of the watermark, with OpenAI, Runway, and Nvidia among those beginning to integrate the technology into their generative tools. Google has been reluctant to release much technical detail beyond the original research paper, which is why independent testing of the kind Ars conducted matters as the watermark proliferates across the AI landscape.

Labels Alone Are Not Enough

The central tension the experiment exposes is that even a robust watermark is only as useful as the willingness of platforms and people to check for it. SynthID detection is not yet broadly built into the social networks and messaging apps where most manipulated media actually spreads. A watermark that survives 300 compression cycles offers little protection if no one on the receiving end is scanning for it.

The durability results are genuinely encouraging for the content-authenticity field. They suggest that invisible, pixel-level watermarking can serve as a reliable technical backbone for provenance. But the broader question, whether society can build the norms, infrastructure, and incentives to actually act on those signals, remains unresolved. As the volume of synthetic media continues to climb past the 100-billion-image milestone, the gap between what the technology can mark and what platforms will moderate is becoming the defining challenge.

Stay Ahead of AI

Keep up with the breaking AI news shaping policy, research, and the platforms reshaping the internet.

Read more AI news