Three big labs, three different answers to the same question. As of August 2026 the picture finally has enough shape to compare properly, because Anthropic just filled the gap that made the comparison lopsided: Claude now embeds a watermark in generated text.
The short version, before the detail. Google has the broadest coverage and the only detector you can actually run yourself. Anthropic has the newest text watermark and the strongest “it applies everywhere, including the API” story. OpenAI has good file provenance and still no text watermark.
Side by side
| Anthropic Claude | OpenAI ChatGPT | Google Gemini | |
|---|---|---|---|
| Text watermark | Yes, from models launched on or after Aug 2, 2026 | Not shipped | Yes, SynthID Text |
| Applied at | Model level, no opt-out | Not applicable | Model level |
| Image provenance | Signed C2PA on .svg, .png, .jpg |
C2PA Content Credentials on generated images | C2PA plus SynthID in the pixels |
| Audio and video | Not stated | C2PA on generated video | SynthID across Imagen, Veo, Lyria |
| Public detector for text | Promised, not yet shipped | Not applicable | Open-sourced reference detector |
| Public detector for files | Standard C2PA tooling | Standard C2PA tooling | SynthID Detector portal, plus in-app verification |
| Detector availability | Documentation forthcoming | C2PA readers are open | Portal is waitlisted, text detector is open source |
| Covers the API | Yes, and Claude Code, Cowork, Tag | Images via the API | Yes |
| Geographic scope | Worldwide | Worldwide | Worldwide |
Read the “public detector” row twice. A marking scheme nobody outside the vendor can read is a compliance artefact, not a tool. Google is currently alone in shipping something a third party can run against text.
Anthropic: text-first, model-level, no opt-out
Anthropic’s approach is the most recent and the most uniformly applied. Claude models launched on or after August 2, 2026 weave an imperceptible watermark into generated text. It doesn’t change meaning, quality, or readability, and because it lives in the words it survives copy and paste into any container.
Three design choices stand out.
It’s applied at the model level. Not at the product layer. That means it’s present regardless of which Claude surface produced the text: the API, the Claude app, Claude Code, Claude Cowork, or Claude Tag. There’s no request parameter, header, or plan tier that removes it. If you resell Claude output, you resell marked text.
It’s global. The obligation driving it is European, from the Article 50(2) Code of Practice that Anthropic signed. The implementation applies wherever Claude is offered. Embedded watermarks also carry through AWS, Google Cloud, and Microsoft Foundry, though signed provenance metadata may not, depending on each platform’s file handling.
Files get C2PA. Generated .svg, .png, and .jpg files carry a signed C2PA manifest, verifiable with standard tooling.
The open gap is detection. Anthropic has committed to helping users and third parties detect its marks and says technical documentation is coming. Until it lands, nobody outside Anthropic can verify the text watermark, which is the subject of how to detect Claude’s watermark.
Full detail on the implementation is in how Claude marks AI-generated content.
Google: broadest coverage, only open detector
SynthID is the oldest and widest of the three programmes. It covers images, audio, video, and text, spanning Gemini, Imagen, Veo, and Lyria.
The design differs by modality. For images and video, SynthID embeds an imperceptible watermark into the pixels themselves, which is why it survives screenshots and compression, the two things that destroy metadata. For audio it goes into the waveform. For text it works statistically, the same general family as Anthropic’s approach.
Google also does the thing the others haven’t: it made detection available.
- SynthID Text is open source. The implementation is published on Hugging Face with a reference Bayesian detector, so a developer can run it without asking Google for access. It returns three states rather than a boolean: watermarked, not watermarked, or uncertain. That third state is honest, and every detection UI should have one.
- The SynthID Detector portal opened to early testers, including journalists and researchers, at I/O in May 2026, with a public waitlist.
- In-app verification. You can upload an image, video, or audio clip in the Gemini app and ask whether it was created or altered by Google AI, and it checks for a SynthID watermark.
Google pairs SynthID with C2PA rather than choosing between them, which is the right call: the watermark survives re-encoding, the manifest carries the detail.
OpenAI: strong on files, silent on text
OpenAI attaches C2PA Content Credentials to images generated through its models, and the same approach extends to generated video. That’s real provenance, readable with any C2PA tool, and it’s been in place longer than Anthropic’s file marking.
Two 2026 developments moved OpenAI closer to the middle of the pack. In May 2026 it joined the C2PA steering committee and committed to embedding Google DeepMind’s SynthID watermark alongside the Content Credentials it already attaches. That’s a genuine dual-layer model: metadata for detail, watermark for durability.
What’s still missing is text. OpenAI has not shipped a text watermark in ChatGPT. Given that text is by far the highest-volume output and the one that moves most freely between containers, that’s the largest single gap across the three vendors.
The practical result: if a passage came from ChatGPT, there is currently no vendor signal to find. Any tool claiming to detect ChatGPT text is a classifier making a guess, with the false positive behaviour that implies. The failure modes are the same ones described in why AI image detection fails, and they land hardest on non-native English writers.
Watermark or metadata: why nobody picked one
The two techniques fail in exactly opposite ways, which is why the industry converged on running both.
C2PA metadata is precise, rich, and tamper-evident. It names the signer, records claimed edits, and breaks visibly if bytes change without re-signing. It’s also container-bound, so a resize, a format conversion, a screenshot, or an image CDN will drop it. In practice most images lose their manifest somewhere between generation and a user’s screen, often inside the publisher’s own pipeline. Catching that is the point of your API is stripping C2PA metadata.
Watermarks are durable against exactly those transformations, because the signal is in the content. The tradeoff is that they carry almost no information, just “this was probably produced by X,” and they degrade under editing, paraphrasing, translation, and short excerpts. That erosion profile is covered in does Claude’s watermark survive copy, paste, and editing.
Neither is a proof of origin. Both are signals worth having, and they cover each other’s blind spots.
What to do if you consume more than one
Most products don’t route to a single vendor. If yours doesn’t, four things follow.
Track marking status per model ID, not per vendor. Anthropic’s fleet is split between marked and unmarked models during the transition. Google’s coverage varies by modality. OpenAI has files but not text. “We use Claude, so we’re marked” is wrong the moment a fallback fires.
Normalise provenance in your own response schema. Your callers shouldn’t have to know which upstream produced a given asset. One shape, populated from whichever check applied:
{
"provenance": {
"status": "verified",
"standard": "c2pa",
"signer": "Anthropic",
"signature_valid": true,
"checked_at": "2026-08-11T09:14:22Z"
},
"generated_by": { "vendor": "anthropic", "model": "claude-opus-5" }
}
Keep “unchecked” distinct from “unmarked.” Three states, not two, same as SynthID Text returns. A verification service being down is not the same as a clean result, and collapsing them hides outages.
Assert it in CI. Provenance handling breaks silently. A resize step added to an upload path, a model fallback, a refactor that drops a response field. All of these pass code review and none of them throw. A test scenario in Apidog that asserts the resolved model, checks the disclosure field, and round-trips a signed image fixture through your real delivery path will catch all three, and running it from apidog-cli in your pipeline turns it into a build failure. The wiring is the same as automating API tests in GitHub Actions. Download Apidog to set it up against your own endpoints.
FAQ
Which vendor has the best AI content marking in 2026? Google has the widest coverage and the only openly available text detector. Anthropic has the most uniformly applied text watermark, since it’s model-level across every surface including the API. OpenAI has solid file provenance and no text watermark.
Does ChatGPT watermark its text? No. As of August 2026 OpenAI has not shipped a text watermark. It attaches C2PA Content Credentials to generated images and committed in May 2026 to adding SynthID alongside them.
Can I detect Gemini-generated text myself? Yes. Google open-sourced SynthID Text with a reference detector on Hugging Face, and it returns watermarked, not watermarked, or uncertain.
Can I detect Claude-generated text myself? Not yet. Anthropic has committed to supporting detection and says documentation is coming.
Do these watermarks interoperate? C2PA does, since it’s an open standard any reader can parse. Watermarks do not: SynthID’s detector reads SynthID, and Anthropic’s mark will need Anthropic’s mechanism. Expect to run several checks rather than one.
Which survives a screenshot? Pixel and text watermarks survive. C2PA metadata does not, because a screenshot creates an entirely new file.
Does any of this stop AI-generated misinformation? No. Marking gives you a signal about provenance where the mark is intact. It does nothing about content from unmarked models, older models, open-weight models run locally, or anything heavily rewritten.
The takeaway
The three approaches have converged on the same architecture, dual-layer marking with a watermark for durability and C2PA for detail, and diverged on execution. Google shipped the most and made detection available. Anthropic shipped the most uniform text coverage and hasn’t opened detection yet. OpenAI covers files well and leaves text unmarked.
For anyone building on top, the useful stance is the same regardless of vendor: treat marks as signals, keep three states rather than two, and put the checks somewhere a regression fails the build.



