Google’s SynthID watermarking technology is being rolled out across the AI landscape through partnerships with OpenAI, Runway, Nvidia, and others, and the timing could not be more urgent. The scale of AI-generated media is staggering when you stop to consider it. Stanford and USC’s Starling Lab estimates that humanity took 149 years from the invention of the camera to create 1.5 billion images, while generative AI matched that output in just 18 months. Google announced at its I/O conference this spring that its tools alone had been used to create more than 100 billion AI images and videos in a couple of years, and that is just one company among many pumping synthetic content into the online ecosystem.
To see whether SynthID can actually hold up under real-world conditions, I built a Python script to simulate the kind of degradation that happens when images get passed around the internet endlessly. The script applied random compression and resizing values repeatedly, mimicking what would happen if an image were downloaded, shared, screenshot, and reuploaded hundreds of times over months or years of circulation. Every fifty generations, I also cropped versions of the test images to further weaken detection. After three hundred rounds of this punishment, both fully AI-generated images and AI-edited photos still carried detectable SynthID watermarks. You could even take a screenshot of the battered image and Gemini would still identify it as watermarked content.
That durability has limits though. Cropping about twenty percent off the border after those three hundred compression cycles finally broke SynthID on my test images entirely. A more aggressive fifty percent crop could defeat it even earlier, around two hundred fifty iterations. So there is a breaking point where enough pixels have been removed or scrambled that the watermark simply cannot be detected anymore.
Even setting aside technical limitations, the broader problem looms large. SynthID was never designed to withstand adversarial attacks according to Google’s own research paper, meaning someone sufficiently motivated could potentially find ways to strip it intentionally. Meta released its own Content Seal watermark recently and Reuters found that simple cropping often eliminated it completely, showing how fragile these systems can be across different implementations. Some people already claim to have cracked SynthID, though neither Ars nor Google’s own team has been able to verify those claims so far.
All of which raises an uncomfortable question for anyone hoping technology will neatly solve the coming flood of synthetic media. Watermarks like SynthID are genuinely impressive engineering achievements that survive conditions no image should reasonably endure, but they are ultimately just signals embedded in files that determined actors will try to strip away. With billions upon billions of AI-generated images already circulating and production only accelerating, labeling every piece of synthetic content may be a battle that even excellent tools cannot win.

