Google’s new SynthID verification site means any reader, rival or regulator can now upload an image from your homepage and ask whether Google’s AI made it. That shifts disclosure from something publishers do voluntarily to something audiences can audit. The tool is narrow (it only detects Google’s own watermark), but narrow doesn’t mean harmless. For media teams using generative imagery in editorial, the real exposure isn’t getting flagged. It’s getting flagged before you said anything, and then discovering you can’t reconstruct which model made the picture, who approved it, or why. Provenance is now a newsroom operations problem, not a trust-and-safety footnote.
What Google actually shipped, and what it can’t see
According to TechCrunch, the site lets anyone check whether an image, video or audio clip was generated with AI. Under the hood it reads SynthID, the invisible watermark Google DeepMind has been embedding in output from its models since 2023, starting with Imagen and later extending to text, audio and video.
The watermark is clever. It’s baked into the pixels or the token probabilities rather than bolted on as metadata, so it survives cropping, compression and the usual screenshot-and-repost journey that strips EXIF data in seconds. The text variant was written up in Nature in 2024, and Google open-sourced it the same year, which is unusual candour for a detection scheme.
Here’s the limit that matters for editors. SynthID detects SynthID. If the image came out of Midjourney, an open-weights Flux model on someone’s GPU, or a competitor’s API that doesn’t use Google’s scheme, the checker has nothing to find. A negative result means “not marked by Google”, not “made by a human with a camera”. Expect plenty of readers to miss that distinction, and expect some of them to post screenshots about it.
Why this lands hardest on media teams
E-commerce brands can mostly shrug. Nobody expects a product hero shot on a white background to be a documentary photograph. Publishers live in a different contract with their audience, and the audience has been clear about where it draws the line. The Reuters Institute Digital News Report 2024 found people were noticeably less comfortable with AI-generated news content than with AI helping journalists behind the scenes, and that discomfort was sharpest for realistic images and video.
So picture the ordinary case. A features desk uses Nano Banana or Imagen to make an illustrative header for a piece on housing costs. It’s labelled “illustration” in the CMS, but the label gets dropped when the image is syndicated to a partner site. A reader runs it through Google’s checker, gets a positive hit, and posts it next to the headline. The publication did nothing wrong in spirit. It just can’t show its working fast enough.
The opposite case is worse. A contributor submits a photo that turns out to be generated by a model with no watermark. The checker says nothing, the desk takes that as a clean bill of health, and the picture runs as news photography. Detection tools that only see one vendor’s output make it easy to confuse absence of evidence with evidence.
Then there’s regulation. Article 50 of the EU AI Act requires providers of generative systems to mark synthetic output in a machine-readable way, and deployers to disclose deepfakes, with those transparency obligations applying from August 2026. There’s a carve-out for evidently artistic or editorial work, but “we thought it was obvious” is a weak defence when a public tool says otherwise.
Provenance has to live in the production line, not the checker
The sensible response isn’t to avoid Google’s models because they’re the ones that get caught. That’s backwards, and it rewards the vendors doing less disclosure. The response is to make your own records better than anything an outside detector can tell.
That means every generated or edited asset carries a short, boring history from the moment it’s created. Which model, which version, what prompt, what source images went in, which edits followed (background swap, inpainting, upscale), who on the desk approved it, and what caption and label were attached. If you can pull that up in thirty seconds when someone tweets a SynthID screenshot, the story becomes “publisher confirms illustration was AI-generated, as labelled” rather than “publisher caught out”.
The industry standard for carrying that history with the file is Content Credentials from the C2PA, which Google, Adobe, Microsoft and a long list of camera makers and newsrooms back. C2PA manifests are signed metadata, so they complement watermarks rather than replace them. Metadata can be stripped; watermarks survive but say little. Together they give you a durable “made by AI” signal plus a readable account of what happened.
In practice, the teams I’ve seen get this right do three things:
- Route all image generation and editing through one internal surface instead of letting each designer use whatever app they like, so every call gets logged the same way.
- Put an automated check between generation and the CMS that confirms the label, caption and credit fields exist and match the asset’s origin, and blocks publishing when they don’t.
- Run their own detection on inbound contributor and agency images, treating Google’s checker as one signal among several, never as a verdict.
None of that is exotic. It’s the same discipline wire desks already apply to photo captions and model releases, extended to a new kind of source. The friction is mostly organisational: getting the features team, the social team and the syndication partners onto the same rails. That’s also why API-first setups help. When generation, editing, moderation and approval gates are calls in one chain (the way a catalog like apiai.me bundles models from Google, ByteDance, OpenAI and others behind one interface), the audit trail falls out of the plumbing instead of depending on someone remembering to fill in a spreadsheet.
What to watch
The obvious question is whether other model makers follow. Google has pushed SynthID partnerships before, and if OpenAI, ByteDance or the big open-weights labs adopt a compatible watermark, a public checker stops being a single-vendor curiosity and starts being genuinely useful for verification desks. If they don’t, we’re heading for a world where the most transparent vendor’s images are the only ones that get flagged, which is a perverse incentive for everyone.
Watch the platforms too. If social networks and search start surfacing SynthID or C2PA results next to images automatically, the reader doesn’t even need to visit Google’s site. Your labelling choices will be judged in the feed, at a glance, without context.
And watch your own syndication contracts. Labels that live only in your CMS don’t travel. If partners strip captions, your carefully disclosed illustration becomes an undisclosed one on someone else’s page.
The practical test for this week: pick five AI-assisted images you published last month. For each one, try to answer, from records alone, which model made it and who signed it off. If that takes longer than a minute per image, that’s the gap a public checker is about to expose.