0
0 Comments

Do ChatGPT Images Have Hidden Watermarks? Yes, Two

If you’re building a product that uses ChatGPT-generated images, there’s something you probably want to know before those images start going into production:

They can carry two different hidden watermarks.

As of May 2026, ChatGPT images can contain:

  • C2PA Content Credentials in the file container

  • SynthID embedded in the pixels

Neither one is visible.

You can open the image, zoom in, edit it, and stare at it at 400%. You won't see either watermark.

That sounds like a technical detail until you're running a marketplace, building an AI product, uploading assets for clients, or trying to get an automated content-review system to accept your files.

Then it becomes a very practical problem.

There are actually two different layers

The easiest mistake is thinking of "the watermark" as one thing.

It isn't.

1. C2PA Content Credentials

C2PA lives in the file container, rather than in the visible image itself.

The manifest can contain information such as the issuer, generating model, timestamp, and a cryptographic hash of the pixel data. The manifest is signed, which means a validator can check whether the credential is still valid and whether the pixels still match what was originally signed.

You won't find this by opening the image in Photoshop or your normal image viewer.

You need a parser or validator that knows how to read the C2PA manifest.

2. SynthID

SynthID is a completely different layer.

Instead of sitting alongside the image as metadata, it is a statistical pattern embedded into the image's pixel information. The pattern is distributed across the raster and designed to remain detectable through common image operations.

It's invisible to the eye.

There isn't a little SynthID icon hiding in the corner. There isn't a metadata field you can delete. Zooming in won't reveal it.

You need a detector.

And this is the part that catches a lot of teams off guard.

SynthID is Google DeepMind technology, so it's easy to assume that it only matters for Google's own image-generation systems.

That assumption is outdated.

If you're working with ChatGPT-generated images, you need to think about both the container layer and the pixel layer.

Why should an indie hacker care?

Because eventually, somebody else's system is going to inspect your file.

And it doesn't care that the image looked perfectly normal when you opened it.

Imagine you're building an AI-powered marketplace and users upload generated product images.

Everything looks fine.

Then your image gets rejected by an automated intake system.

Or you're delivering assets to a client whose procurement process requires AI-generated content to be identified.

Or your SaaS passes an image through one platform successfully, only for another platform to reject the same file.

Suddenly you're debugging a "watermark problem" without even knowing which watermark you're dealing with.

That's the frustrating part.

Different systems can inspect different layers.

One platform might care about content credentials. Another might use a pixel-level detector. Another might check both.

So a successful upload doesn't necessarily mean the file is universally "clean."

For a small team, this is exactly the kind of problem that's cheap to prevent and expensive to discover in production.

How do you actually check your images?

Don't guess.

Read the file.

For the C2PA layer, use a parser or validator that actually validates the manifest.

That's an important distinction.

Finding a C2PA box in the file tells you that credential information exists. Validation can tell you whether the signature is still valid and whether the pixel hash still corresponds to the current image.

Those are much more useful questions.

For SynthID, you need a detector because the signal isn't sitting in a metadata field.

You can scan a ChatGPT export to check across the relevant layers instead of trying to infer what's present from the file itself.

And don't make the classic mistake of checking EXIF and stopping there.

EXIF is not C2PA.

A file can have little or no EXIF information and still contain a C2PA manifest.

Likewise, removing metadata doesn't automatically remove a pixel-level signal.

Think of these as separate systems rather than one big "AI watermark."

The tricks that look like they work

This is where things get interesting.

A lot of common image-processing tricks can appear successful because they remove one layer while leaving the other completely intact.

Re-saving as JPEG

Re-saving an image as JPEG will often strip C2PA information because you're creating a new container that doesn't carry the original credential boxes across.

Great.

But that doesn't mean you've removed SynthID.

The pixel-level signal can survive JPEG re-encoding, including fairly aggressive compression.

So you can end up with a file where the C2PA credential is gone while the SynthID signal remains.

If you're testing only one layer, it can look like the problem has been solved.

It hasn't.

Screenshotting

Screenshotting is basically the same idea, but with an additional downside: you've changed the image itself.

The original container information is left behind, but the pixels are copied into the screenshot.

And if the SynthID signal is in those pixels, you may have copied the signal along with the image.

So now you've potentially lost resolution or introduced other quality changes without actually solving the pixel-level problem.

Cropping

Cropping doesn't magically reveal a corner where the watermark is hiding.

There is no corner.

The SynthID signal is distributed throughout the image.

The source material indicates that it can survive a 25% crop comfortably and only degrades sharply beyond roughly 50%—at which point you're making a very significant change to the composition anyway.

That's a terrible trade if your goal is simply to preserve the image.

The rule that's easy to miss

Here's the simplest way to think about all of this:

If an operation preserves the image's pixels well, it may also preserve the pixel-level signal well.

That's why the two watermark layers behave differently.

Re-saving a file can affect the container without necessarily affecting what's embedded in the pixels.

Cropping can affect the pixels while still leaving enough of the distributed signal for detection.

Compression can degrade the image and still leave the signal detectable.

In other words, one operation doesn't necessarily solve both problems.

And that's why repeatedly throwing an image through different export settings can become a frustrating game of whack-a-mole.

Be careful with the word "clean"

This is probably the most useful lesson if you're building something around AI-generated imagery.

Suppose you run a file through a detector and get a negative result.

It's tempting to say:

"The watermark is gone."

That's more certainty than the result gives you.

A negative detector result means that that detector didn't identify the signal at its threshold.

It doesn't necessarily prove that no signal exists.

The same applies to metadata.

If a C2PA manifest is missing, that doesn't tell you anything by itself about whether a pixel-level watermark remains.

So if you're reporting results to a client, marketplace, customer, or internal team, be precise.

Something like:

"No SynthID detected by [specific tool] on [date]"

is much more defensible than:

"This image is clean."

The first statement tells people what was actually tested.

The second implies a level of certainty you may not have.

What I'd do if I were shipping this in a product

If AI-generated images are part of your workflow, I'd treat watermark detection like any other piece of asset validation.

Before processing an image, establish a baseline.

Then check the relevant layers after processing.

At minimum, ask:

  1. Does the file contain C2PA credentials?

  2. Are those credentials valid?

  3. Does the current pixel data still match the credential's hash?

  4. Does a SynthID detector identify a signal?

  5. Does the final image still meet the quality requirements?

That last one matters.

It's easy to get so focused on making a detector return a particular result that you forget you're supposed to be shipping an image people actually want to look at.

And if a particular marketplace, client, or platform specifies the verification method, use that method.

Don't assume that passing one detector means you'll get the same result everywhere.

The bigger picture

For indie hackers, the takeaway isn't "panic about hidden watermarks."

It's much simpler:

Know what you're shipping.

ChatGPT images can carry two different hidden layers: C2PA in the file container and SynthID in the pixels.

They're invisible, but they behave differently.

C2PA can be inspected through the file's provenance information. SynthID requires pixel-level detection. EXIF is a separate system and shouldn't be treated as a substitute for checking either one.

And the common tricks don't necessarily solve both.

Re-saving may remove the container metadata while leaving the pixel signal intact.

Screenshotting can remove the original container while copying the pixels—and potentially the signal—with them.

Cropping can damage the image without reliably eliminating a distributed pixel-level watermark.

So if you're building a product that generates, transforms, stores, or distributes AI images, don't wait until an external system rejects one of your assets to start figuring this out.

Add the check to your workflow.

Ten minutes of understanding upfront is a lot cheaper than discovering your "perfectly normal" image has another layer hiding underneath it when you're already in production.

posted toAvatar for product Gptwatermaker
Gptwatermaker