Google DeepMind's SynthID Detector goes public, but it demands a Google, Apple, or ChatGPT login
- SynthID Detector at synthid.com lets anyone upload images, video, or audio to check for SynthID watermarks, but the tool requires signing in with a Google, Apple, or ChatGPT account before it will run a scan.
- It only reads media from the four companies that have adopted the watermark: Google, Nvidia, OpenAI, and Kakao. The page states plainly that it is not a general AI detector, and detection is limited to SynthID-enabled models.
- Detections are capped at roughly 10 checks per 24 hours, and there is no public API, bulk upload, or offline classification unless a customer is on an enterprise plan.
- The detector covers images, video, and audio only. SynthID watermarks text too, but the public tool has no text option, and commenters asked how text watermarking would even work.
- A false negative is expected when content came from a non-partner model, was heavily compressed or edited, or predates adoption. Google also warns that in very rare cases SynthID can falsely trigger on non-watermarked content.
Hacker News opinions
You can't use this at all without signing in with a Google, Apple, or ChatGPT account. Why does a watermark checker need auth?
OpenAI's verify tool doesn't require auth, and Google used to have a no-auth path too: upload to Image Search, open About this image, and it told you if it was Google AI-generated. That's gone now.
Any access to a watermark detector can be used to strip the watermark. They probably want to log who's doing that.
I wanted to run a ton of Wikipedia images through this to see if fakes snuck in. No bulk option, and OpenAI's tool rate limits you anyway.
The EULA you have to accept hints that they're afraid you'll set up an edit-and-check loop to remove SynthID.
These are spy marks, not watermarks. The technology can encode database identifiers and enough entropy to uniquely identify you as the author or the downloader.
OpenAI's detector is worse, honestly. It doesn't pick up SynthID from non-OpenAI models. I tried it on Imagen and Nano Banana images and got nothing.
It's deliberate. They don't want you finding a way to bypass it.
It's worth noting this is Google. It's an ad company, so they want something that connects what you're doing to the rest of their data.
I was hoping this was a vision model that identifies synthesizer models from photos of concerts and music studios.
I worry we'll have to go the other way and verify that photos came from a camera, with hardware support like Apple's Reference Image, instead of trying to detect every AI-generated one.
No option to detect generated text, even though SynthID watermarks text too. How would that even work, how is abc from an LLM different from abc?
Yes, this is Google, and OpenAI, NVIDIA, Kakao, and Apple have all said they'll implement SynthID.
Google still won't say how it actually works and gives no bulk or offline classification. The best write-up I've found is the fyx.me model extraction post, it shows how to train your own classifier with decent results.
There's a rate limit of around 10 checks in 24 hours. That makes any large-scale audit impossible.
The old implementation was so bad. Google's process was literally upload the image to Gemini and ask if it's AI generated, which made people think you could ask any chatbot that.
I tested 8 pictures, all made with OpenAI and Google. Six got caught, and the 2 with text and picture overlays passed. Interesting.
Google has no public API or open library for this unless you're an enterprise customer. Create the problem, then charge for the solution.
If you go straight to the URL it makes you agree to terms before you even know what the service is. I had to read the comments to figure it out.
The creepiest part is that even Chinese models refuse to help bypass it, they keep saying stripping SynthID is a crime.