ISSUE 002 · Research decoded

How AI-generated content leaves a trail

What watermarks and Content Credentials can, and cannot, tell you about images, video, audio, and text.

The inference

AI watermarks are useful provenance signals, not universal AI detectors. A positive result can show that a supported lab was involved in creating or editing content. A missing result does not prove that a person made it.

The most reliable approach combines two layers: an invisible signal embedded in the content itself, and signed metadata that records where the file came from. The first can survive some transformations. The second can explain the content’s origin and edit history. Neither works perfectly alone.

Watermarking is not one technique

The word watermark covers several different methods. Some signals are embedded directly in the content. Others are attached to the file as provenance metadata.

AI content provenance stack showing embedded watermarks, signed Content Credentials, verification tools, and the limits of the conclusion

Invisible watermarks

An invisible watermark changes content just enough for a detector to recognize a pattern, while keeping the change imperceptible to people.

  • Images: The system makes tiny changes to pixel values across the image.
  • Video: The signal can be distributed across frames, so it is not dependent on a visible logo in one corner.
  • Audio: The system changes properties of the waveform or its spectrogram in a way people should not hear.
  • Text: The model adjusts token-selection probabilities while generating text. It does not add hidden characters or a visible label.

The watermark is usually tied to a model provider’s detector or cryptographic key. It does not identify the person who typed the prompt, and it does not detect every AI system.

Content Credentials

Content Credentials, based on the C2PA standard, are different. They are signed metadata attached to a file. A credential can record that an image was generated by a particular tool, when an edit happened, and which tools handled the file afterward.

C2PA is a chain-of-custody record, not an invisible watermark. It can provide more context than a watermark, but it is easier to lose. A screenshot, a format conversion, or a platform that strips metadata can remove the record without changing the visible content.

What changes by medium

Medium What can be embedded What it can survive Main limitation
Image Pixel-level watermark and signed metadata Compression, resizing, filters, and some crops Aggressive edits can weaken the signal; metadata can be stripped
Video Frame-level watermark, visible labels, and signed metadata Re-encoding and some frame changes, depending on the system Cropping, editing, or platform processing can degrade signals
Audio Waveform watermark and, in some workflows, signed metadata Noise, speed changes, and common audio compression, depending on the system Not every audio generator uses a watermark; edits can reduce confidence
Text Statistical pattern in token choices Some light edits and paraphrasing Short, factual, translated, or heavily rewritten text is difficult to identify

Text is the most misunderstood case. A text watermark is not a special font, a zero-width character, or a phrase that always sounds like a language model. It is a statistical pattern in the choices made during generation. There are fewer opportunities to insert that pattern when the answer has one correct wording, such as a short fact, a code fragment, or a formula. Longer, more varied writing gives the detector more evidence.

How the major labs approach it

The broad premise is correct, but the implementations are not interchangeable. The labs also do not support every medium in the same way.

Lab Main technique User-facing verification Important boundary
Anthropic Announced statistical text watermarking based on the SynthID-Text approach; C2PA credentials for supported files Anthropic says a text detection API and file-checking tool are forthcoming Do not assume Claude watermarks every image, video, or audio file today
OpenAI C2PA Content Credentials for supported media; SynthID for supported OpenAI images and audio; visible labels on some video products OpenAI Verify checks supported images and audio; developers can use the Content Provenance API It checks for OpenAI signals, not all AI content. “Not detected” is inconclusive
Google SynthID for images, video, audio, and Gemini-generated text; C2PA in a growing set of products Gemini can check supported image, video, and audio files. Google also provides the SynthID Detector and verification features in Search and Chrome SynthID is strongest when content remains sufficiently intact and comes from a supported generator

Anthropic

Anthropic has announced that future Claude models will watermark generated text using a method based on SynthID-Text. The method changes the source of the model’s randomness for low-stakes token choices. A detector with the right key can then estimate whether Claude was involved.

Anthropic says the signal does not add tokens, hidden characters, or identifying information. It also says the approach is weaker for short passages, factual text, proofreading, and code, where there are few acceptable choices. As of this issue, Anthropic says it is still working on a text detection API. For supported files, it plans to attach C2PA credentials and provide a file checker. That is more limited than saying Anthropic has a universal watermark for every modality.

OpenAI

OpenAI uses a layered approach. Images generated with supported ChatGPT, Codex, and API tools can carry C2PA Content Credentials and a SynthID watermark. OpenAI also says supported audio generated through its tools now carries SynthID. Sora has used visible watermarks and C2PA provenance for video assets, but OpenAI’s current public verification tool is narrower than the full set of formats its products can generate.

OpenAI Verify accepts supported image and audio files. It checks for C2PA metadata and SynthID signals associated with OpenAI tools. Its API exposes the same kind of check for developers building moderation, fact-checking, or content-review workflows.

A not_detected result means the tool found no supported OpenAI signal. It does not mean the file is human-made. Metadata may have been removed, a watermark may have degraded, or the content may have come from another provider.

Google

Google DeepMind’s public SynthID documentation covers the widest range of modalities among the three approaches described here. It embeds signals into images and video frames, audio waveforms, and the token distribution used by Gemini text generation. Google says the image, video, and audio versions are designed to remain detectable after common transformations such as compression, filters, cropping, noise, or speed changes. That means designed to survive, not guaranteed to survive every edit.

For text, SynthID changes the probabilities of plausible next tokens. It works best on longer and more varied responses. Google documents weaker detection confidence for short factual answers, exact quotations, heavy rewriting, and translation.

Users can upload supported media to Gemini and ask whether it was generated or edited with Google AI. Google also offers the SynthID Detector for watermark checks and is expanding verification through Search and Chrome. These tools are primarily provenance checks for supported signals, not a universal judgment about whether any piece of content on the internet is synthetic.

How to interpret a verification result

Result What it supports What it does not support
Watermark detected A supported generator likely created or edited the content The identity of the user, the full edit history, or that every part is synthetic
Trusted C2PA credentials A signed provenance record identifies a tool and actions That the content is true, accurate, or untouched after the signed step
Credentials invalid or missing The provenance record is unavailable or has been altered That the content is human-made or fraudulent
No supported signal detected This verifier found nothing it recognizes That no AI system was involved

Put it to work

When a suspicious image, video, audio clip, or passage matters, use this workflow:

  1. Preserve the original file. Do not start with a screenshot or a re-export.
  2. Inspect Content Credentials if the file still contains them.
  3. Use the generator’s own verifier when you have a plausible source, such as Google Gemini for SynthID or OpenAI Verify for OpenAI signals.
  4. Treat a positive result as evidence of provenance, not proof that the content is true.
  5. Treat a negative result as inconclusive. Check the source, publication history, corroborating reporting, and whether the file has passed through a platform that removes metadata.

The practical lesson is simple: provenance tools can answer “which supported system may have touched this?” more reliably than they can answer “is this real?” Watermarks and Content Credentials add useful signal to a messy information environment, but judgment still belongs in the workflow.

Sources

This week’s AI news

Cautious excitement is curdling into cost anxiety: Chinese models closing the frontier gap and agentic products going mainstream keep the upbeat beat alive, while Nvidia price hikes, debt-funded AI spending, an entry-level jobs study, and fresh surveillance backlash temper it. (Bloomberg, Reuters)

The conversation is dominated by the China price-performance gap, agents spreading beyond coding, the economics of the AI buildout, AI slop and “don’t paste the AI” developer pushback, and whether AI is closing the on-ramp to entry-level careers. (Bloomberg, TechCrunch, The Verge)

Model releases & benchmarks (the “excitement” beat)

  • Alibaba launches Wan3.0, days after a $10.2 billion AI placement: Alibaba Cloud said Wan3.0 generates up to 30-second videos from text, documents, spreadsheets, slides, and web pages. The launch followed an HK$80 billion (US$10.2 billion) share placement priced at an 8.4% discount to fund chips, AI infrastructure, and models, and Alibaba shares slid in Hong Kong. (Reuters, Reuters)
  • Chinese open-weights models are closing the gap on Anthropic and OpenAI: Bloomberg reported that Moonshot’s Kimi K3 and Zhipu’s models are close to top US performance on several agentic and coding tests at a fraction of the price, with Claude Fable 5 at about $50 per million output tokens versus $15 for Kimi K3 and roughly $4 for DeepSeek’s V4-Pro. Business Insider separately reported that Thomson Reuters built its own model on open weights, partly to rely less on costly Anthropic infrastructure. (Bloomberg, Business Insider)
  • OpenAI pushes agents past software engineers: ChatGPT Work, a Codex-derived agentic product on the $20-per-month tier, is designed to let accountants, doctors, and other non-engineers hand multistep projects to an LLM. An OpenAI-backed study cited by TechCrunch found 98% of OpenAI employees used Codex in June, versus 17% of organizational subscribers and under 1% of individual subscribers, the adoption gap the product is meant to close. (TechCrunch)

Funding, infrastructure & economics (the “boom or bubble?” beat)

  • Nvidia tells customers AI server prices are going up more than 15%: Bloomberg reported that some of Nvidia’s largest customers were notified that server prices will rise more than 15% in many cases, with increases hitting systems shipped early next year as memory chip costs soar. (CNBC, Bloomberg)
  • SoftBank plans Japan’s biggest-ever retail bond to fund AI commitments: Bloomberg reported SoftBank will sell ¥1 trillion ($6.3 billion) in yen-denominated retail bonds, a record for any Japanese issuer, to help repay a bridge loan and fund its investment commitments to OpenAI. (Bloomberg)
  • Nvidia in talks to invest in Perplexity at a $30 billion-plus valuation: Reuters reported, citing The Information, that Nvidia is discussing an investment that would value the search startup at more than $30 billion; Perplexity’s annualized revenue reportedly grew from under $250 million to over $750 million this year. Both figures remain reported, and no deal is confirmed. (Reuters)
  • OpenAI consolidates product leadership under Greg Brockman: The Verge reported that OpenAI President Greg Brockman’s role has expanded to control the company’s product and scaling teams after a wave of executive departures, with a new chief revenue officer named, as OpenAI prepares for an IPO and chases consumer revenue. (The Verge)
  • AI accounting startup Rillet hit unicorn status in 48 hours: Rillet raised $100 million as an AI-native accounting company, and its CEO argues that regulations requiring human approval of every agent transaction are being watched by top names in the industry. (TechCrunch)

Safety, security & governance (the “anxious” beat)

  • UK and Ukraine sign an AI defence partnership: Britain said it will co-develop AI tools for defence and security with Ukraine, becoming the first country granted access to Ukraine’s battlefield data platform. (Reuters)
  • Taiwan indicts nine people over alleged AI server exports to China: Prosecutors accused people of illegally exporting AI servers, and Ars Technica separately reported that a senior Nvidia manager has been linked to a Supermicro scheme smuggling AI servers to China, as export-control enforcement tightens. (Reuters, Ars Technica)
  • DOJ probes a16z over interlocking AI board seats: After Bloomberg reported a nearly year-long investigation into whether Andreessen Horowitz partners improperly serve on boards of competing AI companies (Ben Horowitz at Databricks, Martin Casado at Fivetran), VCs told TechCrunch they were baffled by the probe. (TechCrunch)
  • AI complaints are flooding UK public bodies: The BBC reported that public bodies receive a surge of mass-produced AI complaints, with grievances that once fitted on a single sheet now running to 20 pages, and AI often misquoting legislation. (BBC)

Backlash, labor & trust (the skeptical beat)

  • AI is hitting entry-level jobs hardest, Stanford study finds: Research led by Erik Brynjolfsson at Stanford’s Digital Economy Lab found employment for 22- to 25-year-olds in the most AI-exposed occupations is about 19% below peers in less exposed fields; Brynjolfsson told The Washington Post the “entry-level effects we’re measuring are real, persistent and widening.” (Ars Technica)
  • LinkedIn’s “Seems like AI slop” button has been clicked over 1 million times: Chief product officer Hari Srinivasan said more than a million people have used the feedback control since it launched at the end of July, making the flag one of the clearest user signals yet about AI slop. (The Verge)
  • Australia’s ARIA charts ban AI-generated songs: From this week, releases must be “substantially human made” to be eligible for ARIA charts, after an AI-assisted cover of Madonna’s “Like a Prayer” by DJ Josh Fawaz topped the dance chart and was streamed 48 million times on Spotify. (BBC)
  • Meta glasses are a workplace menace, The Verge reports: A The Verge investigation found public-facing workers being filmed and harassed by Ray-Ban Meta wearers, with the footage posted for views; Ars Technica reported that as demand explodes, detection apps aren’t perfect and features like facial recognition could raise the stakes. (The Verge, Ars Technica)
  • Developers push back on pasting AI output: Two Hacker News threads, “Don’t paste the AI, please” and “I’m becoming AI-blind,” argue that copy-pasting model responses into email, Slack, and code reviews shifts the burden of comprehension onto everyone else, and popularized the term “AI;DR.” (Hacker News, Hacker News)

Research & interpretability (cautious optimism)

  • A DeepMind-alumni “teammate” claims research wins: Inherent, weeks after a $50 million seed, says its Faraday agent outperformed Anthropic and OpenAI models at independently reproducing published scientific findings without being told the answer in advance. This is the company’s claim and not independently verified. (TechCrunch)
  • AI boosted homework scores, then exam scores dropped, study finds: A working paper circulated on Hacker News found students using generative AI scored higher on homework but lower on exams, and that AI crowded out the highest levels of student effort, with the negative effects largest for higher-achieving students. (Hacker News, SSRN paper)
  • Southampton AI uncovers hidden clues in breast cancer: Researchers said an AI platform called CenSeqNet examines tumour samples with “unprecedented speed and precision,” a promising but early application in medical imaging. (BBC)