Google's SynthID watermark survived 300 rounds of simulated compression and resizing on test images without losing detectability, according to hands-on testing of the system now being adopted across the AI industry. The invisible pixel-level watermark held up on both a fully AI-generated image and a photo edited with Gemini's Nano Banana Pro, and even transferred through screenshots. It broke only after a 20 percent border crop was applied on top of the 300 compression cycles.
The scale problem SynthID is trying to solve is severe. Starling Lab, a Stanford University and University of Southern California research effort, estimates humanity took until 1975 — 149 years after the camera's invention — to produce 1.5 billion images. Generative AI produced the same volume in 18 months. Google said at I/O this spring that its own tools alone have generated more than 100 billion AI images and videos in a couple of years.
SynthID encodes an identifying signal directly into the pixels of an image or the waveform of an audio file, unlike the Coalition for Content Provenance and Authenticity (C2PA) metadata standard, which is cryptographically signed but strips out the moment someone screenshots a file. OpenAI, Runway, and Nvidia are now adopting SynthID's underlying technology, which puts Google's approach on track to become the de facto AI-labeling layer for consumer generative tools.
Key facts
- 01Google's SynthID watermark survived 300 simulated compression and resizing cycles on both fully generated and AI-edited images.
- 02A 20% border crop broke SynthID detection after 300 cycles; a 50% crop broke it at around 250 iterations.
- 03Google caps SynthID verification at roughly 10 image checks per day per user, with faster lockouts for similar images.
- 04Google's detector cannot read OpenAI's SynthID-based watermark, and vice versa, despite sharing the underlying technology.
- 05Google says its tools have generated more than 100 billion AI images and videos in a couple of years.
Google DeepMind scientist Pushmeet Kohli said the team built SynthID under the assumption it would be attacked.
The durability testing used the Python Pillow library to apply randomized compression and resizing to a fully AI-generated image and an AI-edited photo across 300 successive iterations, with a fresh crop pass every 50 generations. After 300 cycles, both images were visibly degraded into near-unrecognizable blobs — but Gemini's SynthID verifier still flagged them as AI-generated. The 20 percent crop finally defeated detection after the 300 rounds of compression; a 50 percent crop broke SynthID earlier, at around 250 iterations.
The limits become clearer when you try to use the verifier at scale. Google caps SynthID lookups at approximately 10 image checks per day and locks users out faster if they upload visually similar images in sequence — a deliberate design choice to prevent adversaries from iterating against the detector to build a bypass. There is no public API and no standalone SynthID detection webpage; verification runs through Gemini only.
Interoperability is the bigger structural problem. OpenAI, Runway, and Nvidia are using SynthID's technology but with different watermark implementations, and the detectors do not cross-read. Google's Gemini-based verifier does not recognize OpenAI's SynthID-derived watermark, and OpenAI's tools do not recognize Google's. A user trying to check whether a suspicious image is AI-generated may run it through the correct detector and still find nothing, because the image came from a different model whose watermark that detector cannot see. Meta's separate Content Seal watermark, meanwhile, has already been shown to often disappear under simple cropping.
Kohli said Google has response measures ready but will not detail them.
The company has also been explicit that SynthID is not designed to withstand adversarial attacks, only casual editing and platform re-encoding. Some researchers have claimed to have bypassed SynthID; Google says it has been unable to replicate those claims in testing. If a working bypass emerges and is published, the billions of images already carrying the watermark could be stripped of their labels in bulk, forcing Google into a rolling update cycle to keep the standard credible.
A Google spokesperson said the company is talking to industry partners about making verification less fragmented, but offered no timeline. Until those detectors interoperate — or until a single public verification endpoint exists — a watermark that survives 300 rounds of compression still fails the real-world test of a voter, journalist, or moderator trying to check one image, once, quickly.
This is coverage-of-detection déjà vu. Pangram raised $9M this month to detect AI-generated text at claimed 99% accuracy, and the pattern is the same across modalities: the labeling side is producing durable technical wins that keep losing the distribution war to fragmentation, rate limits, and the sheer volume of generated content. SynthID is a genuinely strong piece of engineering — cropping resistance through 300 compression cycles is not trivial — but strong engineering inside a walled garden solves the vendor's liability problem, not the public's information problem. Until the major labs agree on a single interoperable verifier with no cooldown, provenance for AI content will remain a per-model courtesy rather than an internet-wide guarantee, and the labeling game will keep losing ground to the generation one.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




