/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers demo “washing out” watermarks on AI images and adding watermarks to human-generated images, meaning online services can't reliably flag AI content

Wired Kate Knibbs

Context & Ripple Effects

Google had just introduced SynthID’s invisible image watermark for Imagen-made images, making provenance labels a practical product feature rather than a purely theoretical safeguard.

This demonstration identifies the weak point in that approach: a label is useful only if services can trust both its presence and absence. Later coverage reinforced that constraint when OpenAI acknowledged C2PA metadata can be removed, even as providers continued adding watermark support.

First-order effects

  • Online services cannot treat a watermark check as a reliable standalone decision rule: removed marks can produce false negatives, while marks applied to human-made images can produce false positives.
  • Image generators and platforms using watermarking lose the ability to present the marker alone as conclusive proof of an image’s origin.

Second-order effects

  • Watermark providers face pressure to pair embedded labels with provenance records, verification tools, or other signals rather than relying on detection alone; OpenAI’s later SynthID support and planned verification portal illustrate that broader verification direction.
  • Moderation, disclosure, and trust workflows must account for ambiguous results, raising the operational value of contextual review over a simple AI-versus-human flag.

Third-order effects

  • If evasion and spoofing remain accessible, image provenance is likely to become a layered trust problem—combining technical signals with platform policy and source context—rather than a universal classifier.
  • The durable divide may be between content produced inside ecosystems that preserve provenance and content arriving without a trustworthy chain of custody; watermark robustness alone cannot close that gap.

The trend: AI-content labeling is shifting from a single watermarking feature toward layered provenance and verification systems that manage, rather than eliminate, uncertainty.

Discussion

  • @jonasgeiping Jonas Geiping on x
    There's a neat article on adversarial attacks on image watermarks that came out today https://www.wired.com/.... The attacks are cool, but I don't really agree with the framing in the first half, arguing that “breakable watermarks -> watermarking is useless” 🧵...
  • @katiedrumm Katie Drummond on x
    Watermarking has been held up as one of the most promising ways to identify AI-generated images and text. A new study tested different AI watermarks and broke every single one of them: https://www.wired.com/...