Skip to main content
Guide

Gemini watermark remover: what SynthID does to your text

Google has watermarked Gemini output for longer than anyone else, and it is the only major provider that publishes a detector. That makes Gemini the one case where a removal claim can actually be checked.

Last updated August 21, 2026 · 8 min read

0 / 300 words

A full rewrite replaces the word choices SynthID is built from. Free plan: 500 words per month, account required.

2024
SynthID text launched
Public
Google's detector status
4
Media types SynthID covers
0
Hidden characters added

Key takeaways

  • SynthID biases which token Gemini picks next, using a key plus the preceding words. Nothing is inserted into the text, so there is nothing to strip out.
  • Google publishes a SynthID Detector and open-sourced the reference implementation, including both the Weighted Mean and Bayesian detectors from the Nature paper.
  • That makes Gemini the one statistical text watermark where a removal claim is falsifiable. On Claude it currently is not, because Anthropic has not shipped its detector.
  • Detection is weak on short passages and sparser on factual writing, because constrained text offers few alternative words to bias.
  • SynthID also covers images, audio and video, where it is a different mechanism from the text watermark and needs different handling.

What Google actually watermarks

SynthID is Google DeepMind's provenance system, and it is the most widely deployed of its kind. It covers four media types — text, images, audio and video — using a different technique for each. Text is the one that matters here, and it works nothing like the image version.

Google has applied SynthID to Gemini text output since the technique was published in Nature in 2024, well before the EU AI Act transparency duties took effect. Anthropic adopted the same published approach for Claude in August 2026.

Same family, different maturity

Claude and Gemini now use the same underlying method. The practical difference is not the watermark — it is that Google publishes tooling to detect its own, and Anthropic has not yet.

How SynthID-Text works in Gemini output

A language model generates text one token at a time, choosing from a ranked list of candidates with a random element in the selection. SynthID replaces that arbitrary randomness with a value derived from a secret key and the few words immediately preceding.

No individual word choice looks unusual. Across a long passage, though, the accumulated choices lean in a direction that a detector holding the key can measure. The reader sees nothing. Google's position is that output quality is unaffected.

PropertyWhat it means
Nothing is insertedCharacter cleaners and Unicode inspectors find nothing, because there is nothing to find
Survives copy and pasteThe signal is the wording, so it travels wherever the text goes
Survives translationEvery word in the source was chosen by the model
Weak on short textToo few token choices accumulate to a confident score
Sparser on factual passagesConstrained writing offers few valid alternatives to bias
Consequences of the mechanism

Google publishes a detector — Anthropic does not

This is the single most important difference between the two, and almost nothing written about watermark removal mentions it.

Google operates a SynthID Detector portal for content it generated, and it released the SynthID-Text reference implementation as open source — including the Weighted Mean detector, which needs no training, and the Bayesian detector, which is more powerful but does.

Anthropic has said it will offer a watermark detection API and is still working out the implementation. Until that ships, no third party can check whether Claude text carries its mark, which means no removal claim about Claude can be verified by anyone.

Why this matters if you care whether a tool works

With an open detector, a claim about degrading a SynthID text watermark is testable: generate watermarked text under a key you control, rewrite it, and score both. Any vendor could run that experiment. Very few have.

We are running exactly that benchmark against the open reference implementation and will publish the distributions, including the detection rate at a stated false-positive rate. The caveat applies to us as much as anyone: measuring the open implementation under our own key is a directional proxy for Google's production configuration, not proof about it.

What does not remove a SynthID text watermark

None of these touch it:

  • Stripping zero-width or invisible characters. SynthID inserts none, so a cleaner reporting a clean result is reporting something that was already true.
  • Removing em dashes, curly quotes or stock phrases. These change a handful of tokens out of hundreds and leave the aggregate signal intact.
  • Retyping the text by hand without changing the wording. The signal is the word choices, not the keystrokes.
  • Changing file format, font or layout. The watermark is in the text, and it travels with it.
  • Running it through Google Docs, a PDF export, or a different editor.

Translation is not the escape route it looks like

Translating out and back changes the surface wording, but the translating model chose those words too — and if that model also watermarks, you may have swapped one provider's mark for another's.

What does: a full rewrite

Because the evidence is the sequence of word choices, replacing the words replaces the evidence. Anthropic, describing the same method, puts it as directly as anyone has: light editing probably will not remove the watermark completely, but a complete rewrite where every word is replaced will.

The word doing the work there is complete. Detection aggregates across a passage, so a partial rewrite yields a partial reduction. Rewriting three sentences of a 1,200-word document leaves most of the original signal exactly where it was.

In practice

  1. Rewrite the whole passage, not the obvious bits. Sentences that read as most AI-like are not the sentences carrying the most signal. The mark is distributed across the text.
  2. Restructure, do not just substitute. Splitting, merging and reordering sentences changes both the tokens and the context each later choice is keyed against.
  3. Give it enough text to work with. Short inputs produce shallow rewrites. They also carry less watermark signal to begin with, which cuts both ways.

Rewriting Gemini output with RewriteAI

RewriteAI re-expresses a passage rather than scanning it for marks. That is the mechanism that applies to a statistical watermark. It does not strip invisible characters, and it does not report a watermark score — for Gemini that is what Google's own detector is for.

0 / 300 words

Free plan: 500 words per month, 300 words per request, English only, account required.

The legal position

EU AI Act Article 50 places the machine-readable marking obligation on AI providers, not on individuals using content they generated and own. Publishing realistic synthetic media carries a separate personal disclosure duty, and institutional or contractual rules apply independently of the law.

SynthID in images, audio and video

If your question is about an image from Imagen or a clip from Veo rather than text, none of the above applies. Those use imperceptible signal-domain watermarks embedded in pixels or audio samples, which is a genuinely different technology with different failure modes.

Google also announced in August 2026 that users can remove the visible watermark from some AI generations. That is the visible corner badge, not SynthID — the imperceptible mark stays.

Sources

Frequently Asked Questions

Does Gemini watermark its text?

Yes. Google applies SynthID to Gemini text output, and has done since the technique was published in 2024 — longer than any other major provider. It is invisible to readers and detectable by Google.

What is SynthID?

Google DeepMind's provenance system, covering text, images, audio and video. For text it biases which word the model picks next using a secret key, producing a measurable pattern without inserting anything.

How do you remove a SynthID watermark from text?

By rewriting the passage so the word choices change. Nothing is inserted into the text, so there is nothing to strip. Partial edits produce partial reductions, because detection aggregates across the whole passage.

Can Google detect SynthID in text I edited?

Possibly. Light editing weakens the signal without eliminating it, and Google's detector scores the passage as a whole. The more original wording that survives, the more likely a confident detection.

Does SynthID work on short text?

Poorly. Detection needs enough token choices to accumulate a signal, so short passages produce low-confidence results. The watermark is also applied more sparsely to factual writing, which offers fewer alternative wordings.

Does copy-paste or Google Docs strip SynthID?

No. The watermark is in the words themselves rather than in formatting or metadata, so it survives copying, pasting, format conversion and export to any other application.

Is SynthID the same as an invisible character?

No, and this is the most common confusion. Invisible characters are inserted content you can delete. SynthID inserts nothing — it is a statistical pattern in word choice that only changes when the words change.

Rewrite Gemini output

A full paraphrase replaces the word choices SynthID is built from. And unlike Claude, this is the case where you can go and check the result yourself.

Try it free

Free plan: 500 words per month, 300 words per request. English only. Account required. We do not claim guaranteed watermark removal.