Google SynthID устойчив к взлому, но не решает проблему AI-дезинформации
Google SynthID — система водяных знаков для AI-контента от Google DeepMind — успешно прошла технические тесты: метки устойчивы к сжатию, кадрированию и цветокоррекции. Однако дезинформаторы просто не будут маркировать свой контент. Пока большинство AI-инструментов не поддерживают единый стандарт, отсутствие метки ничего не гарантирует — и борьба с AI-фейками остаётся проигрышной игрой.
AI-processed from Ars Technica; edited by Hamidun News
Google's SynthID watermarking system works reliably from a technical standpoint: the embedded marks are difficult to remove or bypass. But marking AI-generated content is unlikely to become an effective weapon against disinformation — this is the conclusion reached by Ars Technica journalists following tests published in July 2026.
What SynthID Testing Showed
SynthID from Google DeepMind embeds invisible watermarks in AI-generated content — images, text, audio, and video. During testing, the marks withstood typical attacks: JPEG compression, cropping, resizing, and minor changes to brightness and saturation. Google's detector correctly identified marked content even after aggressive post-processing.
Key system characteristics based on testing data:
- Supports four formats: images, text, audio, video
- The watermark is invisible to humans but readable by Google's detector
- Resistant to compression, cropping, color correction, and format conversion
- Open to third-party developers via Google Cloud and Hugging Face
From a technical standpoint, SynthID is one of the most mature implementations of AI content marking on the market.
Why Doesn't Marking Solve the Problem?
SynthID's technical reliability does not address a systemic flaw. The system only marks content created by Google's tools; OpenAI, Midjourney, Stability AI, and hundreds of other AI services use their own standards or do not mark anything at all.
The key flaw is voluntariness. A bad actor creating deepfakes or fake news will simply choose a tool without marking. The absence of a SynthID mark does not mean the content is real: it may simply mean it was created by another system.
"Solving the content authentication problem requires participation from the entire ecosystem, not just one player," — follows from the
Ars Technica analysis.
According to the publication, this coverage gap is precisely what makes AI content marking a "losing game" in its current form: without a mandatory unified standard, the system creates a false sense of security.
What Is Needed for a Real Solution
Experts cite three conditions under which AI content marking could actually work. First — a unified technical standard: initiatives like the Coalition for Content Provenance and Authenticity (C2PA) are working on a common metadata format, but support remains fragmented. Second — legislative requirements: a number of jurisdictions are already discussing mandatory AI content marking, but there is no global consensus. Third — consumer tools: the average user needs a browser plugin or built-in social media verification; otherwise, even reliable marks remain invisible.
Without these conditions, SynthID remains a useful corporate tool for tracking one's own content, but not a system for protecting against disinformation.
What This Means
SynthID proves that technically marking AI content is possible and reliable. But the technology is ahead of the ecosystem. As long as most AI tools have not joined a unified standard and regulators have not made marking mandatory, distinguishing real content from generated content remains impossible for the majority of users.
Frequently Asked Questions
What is SynthID and who developed it?
SynthID is a system of invisible watermarks for AI-generated content from Google DeepMind. It embeds marks in images, text, audio, and video created by Google's tools, and allows them to be detected using the company's detector. The system is open to third-party developers via Google Cloud and Hugging Face.
Can the SynthID watermark be removed?
According to Ars Technica's test results, standard manipulations — JPEG compression, cropping, changes to brightness and color — do not destroy the mark. Complete removal without visible degradation of image quality is extremely difficult.
Want to stop reading about AI and start using it?
AI News is a curated feed of AI/tech news. Hamidun Academy teaches you to use AI systematically in your work.
The AI world, distilled — once a week
Seven stories that actually mattered, hand-picked. No noise, no reposts, no press releases.
Done! Check your inbox for a confirmation.