AI Content Watermarking: What Can Really Be Detected - and What Can't

AI content watermarking is the topic surrounded by more empty talk in 2026 than anything else in internet marketing. Some people tell you any AI text can be exposed with one click, others that it is all impossible - while the truth is measurable and quite different from both versions. In this guide we walk through what can really be detected, who actually watermarks their content, and whether you, as a business, have any obligation at all.
Table of contents:
What a Watermark Is (and How It Differs from "AI Detectors")
This article is a natural follow-up to our practical guide to AI for small businesses - there we covered how to use AI, here we cover what traces it leaves behind. The first problem is that "watermark" actually hides three completely different techniques, which get mixed up in conversation all the time.
- A statistical watermark in text. While writing, the model chooses between equally good words following a secret pattern. Nothing is added to the text - no hidden characters - and the reader sees no difference at all. Detection is a statistical test that requires the model maker's secret key.
- An invisible watermark in images and audio (Google's SynthID). A signal embedded directly into the pixels or the audio waveform, which survives compression, cropping and filters - considerably more robust than the text version.
- C2PA "Content Credentials". Cryptographically signed metadata attached to the file, describing where the file came from. A simple screenshot or re-recording wipes them out entirely - the specification itself admits it "offers no protection against complete removal".
And there is a fourth thing most often confused with watermarking that is not a watermark at all: "AI detectors" like GPTZero. They hold no key whatsoever - they statistically guess based on writing style, which is exactly why they are unreliable. A watermark is an agreement between a model maker and a verification tool; a detector without a key is fortune-telling.

Who Actually Watermarks - and Who Just Talks
The state of play in August 2026: only two companies watermark text. Google does it in Gemini models (the SynthID-Text system, in production since 2024), and Anthropic officially announced on August 14, 2026 that "future Claude models" will carry a statistical watermark in text, plus C2PA metadata on .png, .jpg and .svg files - rollout "in the coming months", applied globally. A detection API was announced but does not yet exist, and as of this writing there is no public confirmation that any current Claude model already emits a watermark.
The biggest surprise for many: OpenAI does not watermark ChatGPT text. They built a system, then decided not to ship it. Images and audio, on the other hand, they do watermark (C2PA plus SynthID), with a public verification tool at openai.com/verify.
- Images are also watermarked by Microsoft (C2PA), Adobe Firefly (C2PA), Meta (its own system plus the IPTC standard, not C2PA) and Black Forest Labs. Midjourney has been a coalition member since 2023 - with not a single confirmed implementation.
- Audio: ElevenLabs has embedded SynthID since June 2026 and offers a public detector.
- Video: Google Veo watermarks; OpenAI shut down Sora in April 2026.
The key lesson follows from this: "C2PA coalition member" and "actually watermarks" are not the same thing. Meta sits on the coalition's board yet emits no C2PA; Anthropic is not a member yet is rolling C2PA out. Watch what companies do, not what they sign. One more detail that matters for privacy: Anthropic's watermark contains nothing about you as a user - no account, no conversation. It can only say "Claude was probably involved", and cannot distinguish whether Claude wrote the text or merely edited it.

Why Text Is Hard to Watermark and Images Easy
An image has millions of pixels, so a signal can be woven into countless places the eye cannot see. That is why SynthID is remarkably resilient on images: in measurements it maintains around 99.7% detection across 30 different types of edits - compression, cropping, filters.
Text has no such luxury. The signal can only live in word choice, so the watermark works better on longer, more "creative" text and poorly on short, factual text - where there is almost no room for variation. Its resilience is much weaker too: researchers at ETH Zürich showed that plain paraphrasing strips more than 90% of the watermark, and Google itself admits that thorough rewriting or translation "significantly reduces" detection reliability. A text watermark is a useful trace - not a permanent seal.
Why Code Is Practically Impossible to Watermark
Practically nobody watermarks program code - Anthropic itself says code carries "generally less watermarking". The reason is simple: syntax leaves no room for variation. The same logic has to be written in a very similar way, so realistically only comments could carry the signal - and formatters and linters delete or rearrange even those. On this topic there are only academic papers, not a single product.
Translated into your world: nobody can prove your website's code was written by AI. Or that it wasn't.
AI Detectors: Why Not to Trust Them
The numbers here speak for themselves. A study published in the journal Patterns in 2023 found that 61.3% of essays by non-native English speakers were wrongly flagged as AI. By 2026, Yale, NYU, Georgetown and dozens of other universities had switched off AI detection precisely because of false accusations.
For Serbian the situation is even worse: not a single public measurement of detector accuracy exists, and Turnitin does not support Serbian at all. If someone claims a detector "proved" your Serbian text was written by AI - that claim has no basis whatsoever.
The core takeaway worth remembering: a watermark is useful as a positive signal ("this did pass through AI") and worthless as negative proof - the absence of a watermark proves nothing. Nobody today can reliably prove that a specific text was written by AI, except in the case of long, unedited text from a model whose key the detector holds.
What the Law Says: EU, China, US and Serbia
European Union
Article 50 of the EU AI Act has been in force since August 2, 2026. The machine-readable labeling obligation falls on model makers - OpenAI, Google, Anthropic - not on businesses that use AI. As a user you have obligations in only two cases: deepfake content (which you must visibly disclose) and AI text published to inform the public on matters of public interest - and even there an exemption applies when there is human editorial control and editorial responsibility. The Commission's July 2026 guidelines explicitly state that ads and product descriptions are out of scope.
China and the US
China has been the strictest since September 1, 2025: even the end user who publishes must declare AI content, including text. The US has no federal law; California has applied SB 942 since August 2, 2026, covering images, video and audio - not text - and only for services with more than a million users.
Serbia
Serbia currently has no regulation in force on labeling AI content. A draft AI law, modeled on the EU's, was presented in June 2026, with adoption announced by December 2026. In practice: a Serbian business writing its blog with AI assistance has no legal obligation today to label it - and even under EU rules, a blog with human editorial oversight is exempt.
Does Google Penalize AI Content?
No. Google's official policy does not penalize AI content as such - it penalizes "scaled content abuse": mass-produced junk whose only purpose is to manipulate rankings, regardless of whether a human or a machine wrote it. Edited, useful content ranks normally.
That is exactly how we work in SEO: AI is an assistant for research and drafting, while a human is the editor who checks the facts, adds experience and gives the text a reason to exist. Text like that has nothing to hide - from Google or from readers.
What This Means for Your Business
Boiling it all down to practical conclusions:
- You do not have to label your blog. There is no legal obligation in Serbia, and even under EU rules content with human editorial control is exempt.
- Platforms already recognize AI images and video. TikTok has read C2PA since May 2024 and has labeled 1.3 billion videos that way, Meta and Instagram have added "AI info" labels since February 2024, Google has "About this image", and YouTube relies on self-declaration. Assume the label will be visible.
- If you want to verify a file, the public tools that actually work are openai.com/verify (images and audio), the ElevenLabs Audio Detector and verify.contentauthenticity.org. Google's SynthID Detector is not public - there is a waitlist for journalists.
- Do not make decisions based on AI detectors - especially not for Serbian text, for which no accuracy measurement exists.
- The fear that "Google will catch you" is empty talk. Bad content is the problem, not the tool that produced it.
Our position is simple: use AI openly and smartly, and let quality be what people remember you for. If you want content that brings visits and inquiries - drafted with AI, edited by humans - get in touch and let's build a plan for your site.

Let's talk about your project!
