Robustness evaluation reveals that SynthID watermarks survive consumer editing while C2PA metadata fails, highlighting fragmented cross-platform detection.
It is now hard to tell whether an image was made by artificial intelligence. To help, providers add two kinds of signals to AI images. The first is C2PA "Content Credentials," a signed piece of metadata stored in the image file. The second is SynthID, an invisible watermark placed inside the pixels. Google uses both, and OpenAI added SynthID to its images in May 2026. What is not known is whether these signals survive when an image is used in ordinary ways. This paper tests that question with a simple, repeatable method. We take ten AI images (five from ChatGPT/DALL-E and five from Google Gemini) and pass each one through four everyday actions (a Canva export, a screenshot, a WhatsApp transfer, and an Instagram post), first one at a time and then in chains of several actions. At every step, we measure the C2PA metadata and the pixel change with two small open-source Python tools, and we check the SynthID watermark with both companies' own detectors: the Gemini app and OpenAI Verify. The C2PA metadata is removed by the first action every time (survival rate 0 across fifty post-processing checks). The SynthID watermark survives every action and every chain for both companies, when read by that company's own detector. The key result concerns detection: each detector reads only its own company's watermark, so no single public tool reads both, and a "not detected" answer cannot be trusted to mean "not AI." We conclude that metadata-based provenance does not work in real use, that the pixel watermark is robust for both companies, but that provenance still fails as a usable system because detection is split across companies with no shared detector.
No takes yet. Share an insight, caveat, or question.
Anand Sundaramoorthy (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: