Content credentials and watermarks help show where AI content came from, but a missing label proves nothing, and the public has no way yet to check a watermark in written text.
- EU marking is now law. Article 50 requires generative AI providers to mark outputs in a machine-readable format; systems already on the market before 2 August 2026 have until 2 December 2026.
- Credentials fall off. A screenshot, re-save or re-encoding upload can strip signed metadata entirely.
- Watermarks miss most tools. They live inside the content, but most tools do not add them.
- Absence proves nothing. Treat a valid credential as useful evidence, and a missing one as no evidence at all.
- Text is the weak spot. The law covers text, and Anthropic and Google already watermark some of it, but there is no shared public standard and no public checker for written words, the highest-volume category.First-hand: until 23 Sep 2026 this summary said “Text is not covered” and that “written text has no working equivalent”. Sources in the section on where labelling does not reach yet.
Article 50 of the EU AI Act now requires providers of generative AI systems to mark their outputs in a machine-readable format, with penalties reaching €15 million or 3% of global turnover. Generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the marking duty, under Article 111.Regulation (EU) 2024/1689 as amended, Article 111, read at source 22 Sep 2026 via artificialintelligenceact.eu: “Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.” California's SB 942 was originally set for 1 January 2026 but AB 853 delayed it to 2 August 2026, aligning it with EU AI Act Article 50. An earlier version of this page gave the January date.
There is no equivalent global rule — so most content you encounter still carries nothing at all.EU AI Act Article 50, in force 2 Aug 2026 · EU transparency Code of Practice published 10 Jun 2026 · California SB 942, read at source 11 Sep 2026: it requires covered providers to embed “a latent disclosure in AI-generated image, video, audio content”, and applies to systems with “over 1,000,000 monthly visitors or users”. Its effective date moved from 1 Jan 2026 to 2 Aug 2026 under AB 853. Originally recorded 4 Aug 2026.
Two technologies, two different failures
The industry has converged on using both at once, for a reason worth understanding: each one fails in a way the other survives.
Content Credentials
An open standard. A cryptographically signed manifest travels inside the file, recording what made it and how it was edited. Because the signature is verifiable, tampering is detectable rather than silent.
Deployed by Adobe Firefly, OpenAI's image tools, Google Imagen, Microsoft's Office content, and in camera hardware from Leica, Sony and recent flagship phones.
Invisible watermarks
The mark lives in the pixels, audio or video frames rather than the metadata. Google says SynthID is “designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression.” Designed to is a goal, not a guarantee: heavy or deliberately adversarial edits can still weaken it, detection gives a likelihood rather than a certainty, and a probabilistic answer is not a basis for accusing anyone. Google reports watermarking on a scale of tens of billions of items and other providers have adopted the approach.Google DeepMind, SynthID, read at source 17 Sep 2026: “It’s added the moment content is created, and designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression.” An earlier version of this page said the mark survives screenshots and resizing, which that page does not say. Reported figures for SynthID-marked images vary by source and date between roughly 20 billion and 100 billion; treat the order of magnitude, not the number.
The European Commission's own Code of Practice endorses the layered approach explicitly, which is a quiet admission worth noticing: the regulator does not believe any single technique is sufficient.
The two are used together. Signed credentials show tampering but get stripped, while watermarks are built to survive common edits but are missing from most tools.
What this means in practice
- A credential present is meaningful. It tells you something real about origin.
- A credential absent is meaningless. It may have been stripped by any ordinary step.
- Neither is evidence of forgery. Provenance establishes what something is, not what it is not.
The practical posture is the same as for detection generally: treat a positive signal as information and a negative signal as nothing.
Present credentials mean something. A missing credential may simply have been stripped, and neither case is evidence of forgery.
The rule that matters most
A present, valid credential is useful evidence that content came from where it claims. An absent credential is evidence of nothing at all — the tool may not mark, the mark may have been stripped in transit, or the file may simply be an ordinary photograph. If labelling becomes widely expected, the dangerous failure mode is not fake labels; it is people treating "no label" as "not real", or worse, as "verified human".
Where it does not reach yet
Text can be marked, but the public cannot check it. Text watermarks exist: Anthropic adds one to text from its newest Claude models, and Google’s SynthID marks text from the Gemini app. The law covers text too.EU AI Act Article 50(2), read at source 22 Sep 2026 via artificialintelligenceact.eu: “Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs” … “are marked in a machine-readable format and detectable as artificially generated or manipulated.”Claude Help Center, How Claude marks AI-generated content, read at source 23 Sep 2026: “Generated text will carry embedded watermarks”; “Watermark detection is currently in private preview, available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups)”; “A detected mark provides a signal that content was processed by Claude, but is not fully conclusive.” Its model table, read the same day, ticks text watermarks for Fable 5.1, Mythos 5.1, Opus 5.5 and Opus 5, and says “Anthropic is adding watermarks to outputs from models released before August 2, 2026, with all covered by December 2, 2026.”Anthropic, Introducing Claude Opus 5.5, 22 Sep 2026, read at source 23 Sep 2026: “As with Fable 5.1, Opus 5.5 comes with our watermarking measures to comply with the EU AI Act”.Google DeepMind, SynthID, read at source 22 Sep 2026: “We’ve expanded SynthID to watermarking and identifying text generated by the Gemini app and web experience.” Of its SynthID Detector portal: “Just upload an image, video or audio file.” What is missing is a shared public standard and a public checker. Each company’s mark is read with its own key, Anthropic’s detector is in private preview, and Google’s SynthID Detector takes image, video or audio files.Anthropic, How Claude’s text watermark works, 14 Aug 2026, read at source 22 Sep 2026, on another company’s watermark: “it would have a different key; it might also use a different watermarking method altogether”. That gap sits in written words, precisely the category where the volume is highest — roughly half of new articles, by the figures in the quarterly record. Detection for text remains too unreliable to accuse anyone with, and provenance does not yet fill the gap. More on Claude’s text watermark.First-hand: until 23 Sep 2026 this paragraph was headed “Text has no working equivalent” and said every technique on this page “applies to images, audio and video”, with no widely implemented provenance standard for written words. Text watermarks from Anthropic and Google were already in use, and Article 50(2) names text.
Adoption is uneven. Some major generators mark by default; at least one very large image tool has been publicly noted as not implementing content credentials at all. Open-weights models running on private hardware are outside every scheme by construction — no scheme can compel a marking step in software someone downloaded.
Certificates cost money. There is no free issuing service equivalent to what exists for website encryption, which puts credential signing out of reach for many independent creators — the people whose work most needs a way to prove it is theirs.
What to actually do with this
- Check credentials when the stakes are high — a news image, a document, a claim about a person. Platforms increasingly surface a credentials indicator; the issuing provider's own verifier is usually the most reliable place to check.
- Never read absence as authenticity. This is the failure this page exists to prevent.
- Label your own work. If you publish machine-assisted material, say so — as this site does on its about page. Voluntary disclosure is worth more than compelled disclosure, because it does not depend on metadata that can be stripped.
- Keep verifying by provenance in the ordinary sense — where did this come from, does it exist elsewhere, is there a second witness. That test predates all of this technology and outlives it.
Labelling is the most encouraging development this site covers, and it is being oversold. It genuinely helps: a signed credential is stronger evidence than any detector score, and a legal requirement moves the default from "nobody marks" to "the largest providers must". But it is weakest where the volume is highest: text can now be marked, yet the public has no way to check a text mark, and a file’s credentials can be stripped by a screenshot.First-hand: until 23 Sep 2026 this box said “images and video are marked while text, the highest-volume category, is not”. Support it, use it, and do not mistake it for a solution.