Does a watermark survive re encoding?
Vendors describe robustness in prose and no published standard sets a survival threshold. Google says SynthID is designed to withstand cropping, filters, frame rate changes and lossy compression, and for audio noise, MP3 compression and speed changes. Designed to withstand is not measured to survive, and no public benchmark settles the gap.
The verdict
Open question
No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.
Key facts
What the sources say
- Record ID
- CPS-2026-0026
- Kind
- Open question
- Jurisdiction
- Global
- Last verified
- Added
- Google states that the image and video watermark is "designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression".
- For audio Google states the watermark "can't be altered by common modifications like adding noise, MP3 compression, or changing the speed of the track".
- OpenAI's framing is comparative rather than absolute: watermarking "can be more durable through transformations like screenshots", while metadata carries more information.
- The C2PA specification treats invisible watermarks as soft bindings, a separate mechanism from the hard binding hash, and maintains a referenced list of soft binding algorithms rather than a survival guarantee.
- JPEG Trust Part 3, media asset watermarking, is still at draft International Standard stage, so the standardised account of watermark behaviour does not exist yet.
What it changes
For a publisher, a platform or a newsroom
Do not build a workflow that treats a watermark check as a pass or fail gate. Robustness claims here are directional, made by the party with an interest, and untested against your specific pipeline. The defensible practice is to record which signal you found, which tool you used and when, and to keep the original file, so that a later finding about robustness does not invalidate everything you published.
Sources
What this record was verified against
- SynthID, Google DeepMindPrimary · 15 September 2026
- Advancing content provenance, OpenAIPrimary · 19 May 2026
- ISO/IEC DIS 21617-3, JPEG Trust, Part 3: Media asset watermarkingPrimary · 15 September 2026
Related
Records that sit beside this one
Google: SynthID watermarking, the SynthID Detector, and C2PA in Pixel and Photos
United States · verified 15 September 2026
Google states that "SynthID embeds digital watermarks directly into AI-generated images, audio, text or video" and that the watermarks are imperceptible to humans.
JPEG Trust, ISO/IEC 21617
Global · verified 15 September 2026
ISO/IEC 21617-1:2026, Information technology, JPEG Trust, Part 1: Core foundation, status Published, edition 2, publication date 2026-08, stage 60.60.
Is a stripped manifest evidence of tampering?
Global · verified 15 September 2026
OpenAI states that C2PA metadata "can be stripped, lost through uploads and downloads, or broken by transformations like file format changes, resizing, or screenshots".
May the absence of Content Credentials be treated as suspicion?
Global · verified 15 September 2026
OpenAI states that if no metadata or watermark is detected "the tool will not make a definitive conclusion about whether the image was generated with OpenAI tools since provenance signals can in some cases be stripped".
Who answers for a manifest that is signed and false?
Global · verified 15 September 2026
The C2PA trust model is expressed as validation states: well formed, valid and trusted, each about signatures, certificates and lists rather than about the truth of an assertion.
Cameras that sign at capture
Global · verified 15 September 2026
Leica's Content Credentials page lists the SL3-P, Q3 Monochrom, M EV1, SL3-S, M11-D and M11-P as cameras with Content Credentials.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID CPS-2026-0026 is permanent and is never reused.
- In a sentence
- According to the GAGE Content Provenance Checker (as of 15 September 2026), does a watermark survive re encoding?.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Does a watermark survive re encoding?. Content Provenance Checker. Retrieved 15 September 2026, from https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0026-does-a-watermark-survive-re-encoding
- MLA
- "Does a watermark survive re encoding?." Content Provenance Checker, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0026-does-a-watermark-survive-re-encoding.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Does a watermark survive re encoding?." Content Provenance Checker. Last modified 15 September 2026. https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0026-does-a-watermark-survive-re-encoding.
- Permalink
- https://www.gage.academy/tools/content-provenance-checker/records/CPS-2026-0026-does-a-watermark-survive-re-encoding
Last updated . Every record re verified . The ledger is checked monthly, first Monday, and the same day for any C2PA specification release.
Back to the full ledger, or every record for Global and every open question record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.