1
0 Comments

How to Check a Nano Banana Image for Watermarks

If you're using Nano Banana to generate images, there's a simple mistake worth avoiding:

Don't assume the product name tells you what's inside the file.

The same basic checks you'd use for other Gemini-family exports apply here too. The download dialog doesn't necessarily tell you which watermark or provenance layers are present.

You have to inspect the file.

And that matters because there are three different layers to check—two of them are invisible, and one stopped being reliable as a standalone check in August 2026.

Why the product name isn't enough

Nano Banana, Gemini, and other Gemini-family surfaces can have different names and interfaces. It's natural to assume that different branding means different watermarking behaviour.

That's not a safe assumption.

Rather than maintaining a mental list of which product supposedly marks what, there's a much simpler approach:

Treat every export the same way and check the file.

It takes seconds and eliminates a whole category of guesses.

Think of the three layers as doing three different jobs:

  • Visible mark: something you can actually see in the image.

  • C2PA: provenance information stored in the file container.

  • SynthID: an invisible signal embedded in the pixels.

They're separate layers, stored differently, and they require different checks.

That's where people tend to get into trouble: they check one layer and assume they've checked the others.

You haven't.

What exactly are you checking?

1. The visible watermark

The visible mark is the easiest one to check.

Look at the image at 100% zoom, particularly around the corners. The mark is typically a four-point sparkle composited into the image.

Don't rely on a tiny thumbnail. At full size, you have a better chance of seeing the marked region clearly.

But there's an important catch: the absence of the sparkle is no longer meaningful on its own.

We'll get to that in a moment.

2. C2PA Content Credentials

C2PA lives somewhere completely different.

It's stored in the file container, typically as JUMBF boxes alongside the image data.

The manifest can contain information such as the issuer, generating model, timestamp, and a cryptographic hash of the image pixels.

You won't see any of this by opening the image and zooming in.

You need a parser.

And ideally, you want one that validates the manifest rather than simply reporting that a C2PA box exists.

There's a big difference between:

"This file contains a C2PA box."

and:

"The credential is valid, the signature checks out, and the pixel hash still matches."

The second result tells you much more.

3. SynthID

SynthID is the other invisible layer.

Unlike C2PA, it isn't sitting in the file as a metadata field. It's a statistical pattern embedded into the image's pixel information and distributed redundantly across the raster.

You can't reveal it by zooming in.

You can't find it by checking EXIF.

You need a detector.

So the basic model is simple:

Three layers. Three locations. Three checks.

If you run one check and report it as though you've run all three, you're making an assumption the file hasn't earned.

How to check a Nano Banana image

If you're doing this manually, the workflow is straightforward.

First: open the image at 100% and inspect the corners for the visible mark.

Second: run a validating parser against the file container to determine whether C2PA credentials are present and whether they validate.

Third: run a detector against the pixels for SynthID.

You can scan a Gemini image to get a read across the relevant layers rather than checking one and guessing about the others.

And one thing you should not do:

Don't check EXIF and call the job finished.

EXIF is a separate metadata system.

A file can have empty EXIF information while still carrying a complete C2PA manifest.

No EXIF does not mean no provenance.

The visible check stopped being enough

This is the part that changed in August 2026.

Google added a setting that lets users decide whether their creations carry a visible watermark.

The invisible SynthID signal and C2PA metadata remain embedded regardless of that setting.

So you can now look at a Nano Banana image, see no sparkle, and conclude that it isn't marked.

Except it may be fully marked.

If the person who generated the image turned the visible watermark off, the image can look completely ordinary while the two hidden layers remain intact.

That's why a QA process built around:

"Look at the corner. No sparkle? Approve."

is no longer reliable.

It's still worth checking the corners because older files may have been generated before the change, and some users may leave the visible watermark enabled.

Just don't treat the absence of the mark as an answer.

What your results actually mean

This is another place where it's easy to overstate what you've learned.

A positive result is strong evidence.

If a valid credential identifies a generator, that's meaningful evidence that the provenance information was attached during generation.

If a detector identifies SynthID, that's strong evidence that the signal is present.

A negative result is more complicated.

A missing C2PA credential could simply mean the file went through something that rewrote its container.

That can happen during ordinary handling.

A JPEG re-save can strip the credential. A screenshot can discard the original container. A round trip through another service can rewrite the file.

None of those outcomes necessarily tells you what happened to the original image.

SynthID results also need to be interpreted carefully.

A negative detector result can mean the signal wasn't detected at that tool's threshold. That isn't automatically proof that the signal is absent.

And different tools can have different sensitivities.

For SynthID, Google's official detector is the reference implementation. If a client, contract, or internal process specifies a particular check, run that check and report it rather than substituting whichever tool happens to be convenient.

Report what you actually checked

This sounds like a small detail, but it matters if you're building a product or reporting results to someone else.

Instead of saying:

"The file is clean."

say what you actually found.

For example:

"No SynthID detected by tool X on this date."

That's a statement about a specific test.

"The file is clean" is much broader. It implies that every relevant layer and every possible detector has been ruled out.

One negative result doesn't support that claim.

The more your workflow becomes automated, the more important this distinction becomes. Your software should tell users what it checked, not quietly turn a limited test into a universal verdict.

If you're building this into a product

If you're an indie hacker processing a lot of AI-generated images, don't make watermark checking an ad hoc manual task.

Turn it into part of your asset pipeline.

For each image, you can think in terms of three separate checks:

Visual layer: Is the visible mark present?

Container layer: Are C2PA credentials present, and do they validate?

Pixel layer: Does the detector identify SynthID?

Then record the result of each check.

That gives you something much more useful than a single green or red "clean" label.

It also makes debugging easier when a marketplace, client, or downstream platform gives you a different answer.

Instead of asking, "Why did this image fail?"

you can ask:

"Which layer did they check that we didn't?"

That's a much easier problem to solve.

The bigger lesson

Nano Banana doesn't require some special watermark-detection trick just because it has a different product name.

The safer approach is to treat it like any other Gemini-family export:

Inspect the image. Parse the container. Scan the pixels.

The visible sparkle is still useful, but it is no longer conclusive.

C2PA tells you about provenance in the file container.

SynthID tells you about the invisible signal in the pixels.

EXIF is a separate system and shouldn't be used as a substitute for either.

And perhaps most importantly, don't confuse "not detected" with "doesn't exist."

If you're building software around AI-generated images, that's the distinction worth designing your workflow around.

Because the worst QA system isn't the one that occasionally says "unknown."

It's the one that confidently says "clean" when it only checked one corner of the file.

posted toAvatar for product Gptwatermaker
Gptwatermaker