Spymarks Explained: The Hidden Tracking Marks in AI Images and Text, Who Is Adding Them, and How to Check Your Own Files
What's in this guide
On September 21, a short essay called "Spymarks, not Watermarks" hit the top of Hacker News with more than 650 upvotes, and within a day a new word was bouncing around every AI privacy thread I follow. The argument is simple: the invisible signals that Google, OpenAI, Anthropic and Microsoft now bake into AI-generated pictures, audio and text are not "watermarks" in any sense you grew up with. They are hidden, they survive editing, and in at least one confirmed case they carry a unique ID that points back to the person who made the file. The author's name for that is a spymark.
Nobody has written the version a normal person needs: what is in your files, which company does what, whether it can identify you, and how to check. So I spent an evening running my own AI images through every checker I could find.
The short answer
A spymark is a hidden signal inside a file (a picture, an audio clip, a block of text) that lets someone trace where it came from, without you being able to see it or easily remove it. Brandon Thomas at Brand.io coined the word on September 21, 2026, and it stuck because it names the part "watermark" politely hides: the signal is not there for you, it is there for whoever holds the key.
Right now, an image from ChatGPT, Gemini or Microsoft Paint carries two marks: a readable metadata label (Content Credentials, also called C2PA) that you can strip, and an invisible pixel-level watermark (SynthID, or Microsoft's InvisMark) that you cannot. Text from Claude and Gemini carries a statistical pattern in word choice. Google, OpenAI and Anthropic all state that their marks identify the tool, not the user. Microsoft's, as a researcher showed in August, embeds a unique ID tied to your prompt. That is the one that earns the "spy" prefix today, and the reason the term is catching on is that the others are technically capable of the same thing.
The practical takeaway: assume anything you generate with a cloud AI tool is labelled as AI-made in a way that survives screenshots, and if that matters to you, generate locally instead.
What a spymark actually is
A watermark, in the old sense, is visible. The Getty logo across a stock photo. The faint portrait in a twenty dollar bill. You can see it, and its whole purpose is to be seen.
A spymark is the opposite. It is deliberately invisible, it is built to survive cropping, compression and screenshots, and it encodes information you cannot read. The essay's definition: "a hidden signal that makes your work traceable without your knowledge or consent."
Why does a new word matter? Because the old one was doing PR work. Call SynthID a watermark and people picture the Getty logo and move on. Call it a spymark and the first question is "what does it know about me?" That is the right question, and it is why the term spread to a dozen newsletters and two open source "spymark remover" projects in under 48 hours. The idea itself is old: colour laser printers have hidden their serial number in faint yellow dots since the 1980s.
The three layers hiding in an AI file
A picture from ChatGPT or Gemini can carry up to three separate things. The first, a visible logo, is only there if you ask for it in the prompt, so I will skip it. The other two matter.
Layer 2: Content Credentials (C2PA metadata)
A small, cryptographically signed note in the file's metadata, next to the camera EXIF data you may already know. It says which tool made the file and when. Crucially, it is only metadata. Screenshot the image, paste it into WhatsApp, or run a "strip metadata" tool and it is gone.
Layer 3: the invisible watermark (this is the spymark)
This one lives in the pixels themselves. SynthID, which Google built and OpenAI now uses for its own images and audio, subtly shifts pixel values in a pattern a detector can find but your eye cannot. Google's own paper says it has marked more than ten billion images and video frames. Microsoft's InvisMark does the same job in Paint and Photos. These survive screenshots, cropping, filters and JPEG compression. There is no toggle for it anywhere, unlike the training-data switch I covered last week.
Text works differently because there are no pixels. Claude and Gemini use a technique called SynthID-Text: whenever the model has a free choice between two equally good words ("overcast" or "grey"), a secret key decides which one it picks. Over a few hundred words that leaves a statistical fingerprint. Nothing is added, no hidden characters, and a reader cannot tell. But someone with the key can score a passage and say "Claude was probably involved."
Who is marking what right now
I checked each company's own documentation this week. Here is where things stand on September 23, 2026.
Google puts SynthID on images, video and audio from its consumer products, plus SynthID-Text on Gemini app text. Detection is built into the Gemini app: upload a file and ask "was this made by Google AI?"
OpenAI adds C2PA metadata plus a SynthID watermark to images from ChatGPT, Codex and the API, and SynthID to generated audio. No text watermark yet, though it says its goal is to cover "all modalities including text." Its checker at openai.com/verify states a result "does not identify who created the content."
Anthropic watermarks text from Claude models launched since August 2 (older ones are being added), and attaches C2PA to files. Its FAQ is the most explicit: the mark "carries no identifying information and can't be traced to a specific person, organization, or chat." The detector is a private preview for regulators, fact-checkers and enterprises, so you cannot check your own text. Claude Opus 5.5, released yesterday, ships with it.
Microsoft is the confirmed spymark. In August, developer Xusheng Li reverse-engineered Paint's AI image feature and found that every image gets a server-issued 16-byte ID encoded into the pixels with InvisMark. Your prompt goes to Microsoft for moderation, a unique ID comes back, and Paint embeds it. Microsoft's Paint documentation mentions an invisible watermark but not the ID, and Microsoft did not respond to The Register's request for comment.
Meta announced its own system, Content Seal, in August. Details are thin, so treat it as coming.
Why is this all happening at once? The EU AI Act. Since August 2, 2026, AI providers serving the EU have to mark generated content in a machine-readable way, and roughly 190 companies signed the code of practice that spells out how. Anthropic says it applies the mark worldwide because it has no reliable way to switch it off by region. Assume the others are in the same position.
Can a spymark identify you?
This is the question that matters, and the honest answer has two halves.
What the companies say is fairly reassuring. Google, OpenAI and Anthropic all state that their marks identify the tool, not the person.
What the technology can do is the other half. Google's own SynthID paper describes a payload with room for a 64-bit database ID plus error correction. That is enough to give every image ever generated a unique number. The Microsoft case proves the point: the same class of technology, the same C2PA standard, and a per-prompt ID in every file. Nothing about the pixels stopped Microsoft. Only policy stops Google and OpenAI, and policy is a setting.
A fair reading: today, an image from ChatGPT or Gemini says "an AI made this," not "you made this." An image from Paint says "this specific prompt, from this account, made this." The door between the two is a product decision, not an engineering limit.
What I found in my own files
I generated three test images: a coffee cup from ChatGPT, the same prompt in the Gemini app, and a third in Windows Paint's Image Creator. Then I ran each through the checkers and did the things a normal person does to an image before sharing it.
Straight out of the tool, all three carried Content Credentials. The Gemini app even read the ChatGPT image's manifest and reported "Info by OpenAI." OpenAI's verify page found both C2PA and SynthID on its own image in seconds.
Then I screenshotted each one, cropped about 20 percent off the edges, and saved as a JPEG at 70 percent quality. The C2PA label vanished from all three, exactly as advertised. But OpenAI's checker still found SynthID in the ChatGPT screenshot, and Gemini still found it in its own. The Paint image I could not check, because Microsoft has no public checker for InvisMark, which tells you something on its own.
A blur strong enough to kill the mark left the image visibly soft. The only clean image I made all evening came from a Stable Diffusion model on my own machine: if the computation happens in your house, nobody gets to stamp the output.
For text I had nothing to test with. Anthropic's detector is private, Google offers none, and third-party "AI detectors" use a different method entirely (spotting AI writing habits, not reading a key).
How to check your own files in two minutes
No special software needed.
A ChatGPT image or audio clip: go to openai.com/verify and drag the file in. It reports C2PA, SynthID, both, or neither.
A Gemini, Veo, Lyria or NotebookLM file: open the Gemini app, upload the file, and ask "Was this created by Google AI?" You get about ten checks a day per media type, and it also reads other companies' Content Credentials.
Any file's metadata: on a Mac, open the image in Preview and press Command-I. On Windows, right-click, Properties, Details. For the full manifest, contentcredentials.org has a free web verifier.
Text: you cannot, and anyone who says otherwise is selling something.
To drop the metadata layer only: screenshot it. That is all it takes, and it is exactly why the companies added the pixel-level mark.
Should you care? A two minute decision
For most people, most of the time, no. If you make a birthday card in ChatGPT, an invisible "made with ChatGPT" label is about as threatening as the label on a greeting card.
You should care in three situations. First, if your work needs to look human-made and you are using AI to produce it, because the mark will outlive your denial. Second, if you are a journalist, activist or whistleblower for whom "who made this file" is a safety question, because Microsoft's mark already links files to accounts and the others could. Third, if you object to being tracked on principle, which after the smart TV story and the ChatGPT cookie story is a reasonable position.
If you land in any of those, the fix is the one I keep arriving at on this blog: run the model on your own hardware. Open-weight image and text models carry no SynthID, no InvisMark and no key. My setup guide covers the hardware you need. There is a real capability gap, but it is the only complete answer.
The verdict
"Spymark" is a good word and I expect it to stick. The state of play on September 23, 2026: Google, OpenAI and Anthropic mark their output in ways that survive screenshots and say "an AI made this," while stating in writing that the marks do not identify you. Microsoft's mark in Paint and Photos carries a unique ID tied to your prompt. The gap between the two is policy, not physics.
My recommendation: know the marks are there, check one of your own files with the free tools above so you believe it, and stop worrying unless you are in one of the three situations above. If you are, generate locally. As for the companies, the fix for the "spy" half of the word is entirely in their hands: publish exactly what the payload contains, and let anyone verify it.
Comments
Post a Comment