Glossary
Watermarking
Watermarking puts a mark inside generated content so it can be recognised as machine-made later, and how well it survives depends almost entirely on the format.
In plain terms
A mark left in the thing itself. Sometimes visible, like a logo across a free-tier export, and sometimes not, like a pattern in the pixels that survives cropping and resaving. The point of the invisible kind is that the content can be identified as machine-made afterwards by anybody with the right detector, without changing how it looks.
Why it matters
Because disclosure expectations are arriving faster than any obligation to label, and buyers are being asked whether their output can be identified. It also sets a reasonable expectation about what is achievable: for images there is something real to point at, and for text the honest answer is much weaker, which is worth knowing before promising anything.
How it works
Two quite different things share the name. The visible kind is a mark placed over the content, familiar from free tiers that stamp exports, and its purpose is commercial rather than disclosure. The invisible kind is a pattern embedded in the content, designed to be detectable by a matching detector and imperceptible to a viewer, and it is the one meant when the subject is synthetic media.
It works far better for images and audio than for text, and that gap is structural rather than a matter of maturity. An image has an enormous amount of room to carry a signal no viewer will notice. A paragraph has very little, and the usual approach of nudging word choice degrades under exactly the handling text receives: rewriting, translating, or asking another model to rephrase.
Detection is generally not open to everyone, which limits what it can settle in practice. The mark is designed to be found by a detector matched to the marker, so it usually answers a question for the organisation that produced the content rather than for a stranger examining it. That makes it more useful as an internal control than as a public test.
Its absence proves nothing, and this is the limit that most often gets lost. Only some generators mark, ordinary handling can weaken or remove a mark, and anything made before marking became common carries none. A detector that finds nothing has established nothing, which means it cannot be used as a test for whether something is genuine.
How well a mark survives, by format
Seen in the wild
A generator whose commercial case rests on licensed material, indemnification and provenance a legal team can trace, which is the same buyer question approached through records.
Adobe FireflyAn avatar platform governed by moderation and consent controls, where the disclosure question is settled at the point a likeness is created.
SynthesiaImage generators whose outputs carry a provenance watermark by design, which matters where disclosure norms or client expectations are already in play.
Common misconceptions
People assume
A detector finding no watermark means the content is genuine.
In fact
It means no mark was found. Only some tools mark, marks weaken under ordinary handling, and everything made before the practice existed carries none. The result is informative when something is found and close to meaningless when nothing is.
People assume
Text can be watermarked about as well as images.
In fact
It cannot, and the reason is structural. A paragraph offers very little room to hide a signal, and the ordinary handling text receives, rewriting and translating and passing it through another model, is exactly what removes one. Expectations set from image results will not be met.
Telling them apart
Watermarking vs Content provenance
Watermarking
A mark inside the content: durable, carries little, hard to strip.
A record attached to the file: detailed, informative, easily stripped.
One survives the journey and says little; the other says a lot and rarely survives. Requirements naming one usually wanted both.
Questions
- Can we tell whether an image was AI-generated?
- Sometimes, and not reliably enough to build a policy on. If it carries a mark from a generator you can detect, yes. Otherwise the honest answer is no, and a check that returns nothing has not established anything, which is the part worth saying plainly before anybody designs a process around it.
- Does it help us with disclosure expectations?
- It helps with your own material, which is where you have any control. Knowing which of your generators mark, and what survives your own pipeline, is answerable. Using detection to police material arriving from outside is where the technique underdelivers relative to how it is usually described.
- Is the visible kind the same subject?
- It shares the name and serves a different purpose. A logo across a free export exists to encourage an upgrade, not to support disclosure, and conflating the two makes conversations confusing. Where disclosure is the subject, the invisible kind is what is meant.
Key takeaways
- Two things share the name: a visible commercial mark and an invisible detectable one.
- Images and audio carry a mark well; text does not, for structural reasons.
- Detection usually needs a matching detector, so it is an internal control more than a public test.
- Finding nothing establishes nothing, which rules it out as a genuineness test.
Tools that use this
- Adobe Firefly
The same buyer question approached through records rather than marks.
- Synthesia
Moderation and consent controls settling disclosure at creation.
Last checked July 2026