SynthID-Text · Gemini · DeepMind

Markdown

SynthID-Text is a keyed trail in word choice. It is not a hidden character.

SynthID-Text is Google DeepMind’s statistical text watermark. At each step the model already has several good next words. A secret key tilts the choice. The sentence looks like ordinary English because it is. Nothing is inserted. Gemini uses this in production. A rewrite chooses different words. We cannot see Google’s key, so we cannot certify their detector. SynthID in pixels, audio or video is a different mark and is out of scope.

Reviewed by · Published

Process

How to verify the job

  1. 01

    Name the surface

    If the file is an image, audio or video, SynthID-Text is the wrong page. Those marks sit in the media. Gifi does not remove them.

  2. 02

    Inspect the string

    Paste the text. Hidden Unicode is a different, deletable payload. A statistical trail will not appear in that list.

  3. 03

    Rewrite only the words

    A credit buys new wording. That breaks the keyed sequence. It does not come with a certificate from Google’s detector.

Scope

Supported and unsupported surfaces

SurfaceGifi actionVerification limit
Named metadata or invisible UnicodeInspect, remove, and report named actionsReinspect the returned bytes independently
Statistical patterns in ordinary wordsRewrite the proseNo certificate against a private detector
Visible logos, pixels, audio, or videoUnsupportedNo removal claim

The dice, not the ink

A language model writes one token at a time. When two words would do, SynthID-Text uses a key and the words so far to lean toward some candidates and away from others. Do that across a passage and a later reader who holds the key can ask whether the text was likely generated with that configuration.

The Nature paper is the public method. The production key is not in the paper. An open reference detector can score text against a known research configuration. It cannot read Gemini’s private key.

Who actually ships it on text

Gemini applies SynthID across text and media. That is the production text watermark people mean when they say “Google’s mark.” Claude’s published text mark is the same family of idea — keyed word choice — under Anthropic’s key, not Google’s.

ChatGPT uses SynthID on supported images and audio, not on text. Saying “SynthID” without naming the surface is how this category gets confused.

What a rewrite can honestly say

Light edits usually keep a statistical trail. Synonym swaps and shuffled sentences are light edits. A rewrite that chooses different words is the lever. The prose will change. Tone will move toward the rewriting model.

Gifi cannot certify that Google’s detector will fail. Anyone who says otherwise is guessing at a key they cannot see.

Questions this usually raises

Is SynthID-Text the same as a Gemini logo on an image?
No. A visible logo is appearance. Pixel SynthID is a mark in the picture. SynthID-Text is a pattern in ordinary words.
Can I delete SynthID-Text like EXIF?
No. There is nothing to delete. The mark is the path through the vocabulary.
Does an open-source detector prove Gemini wrote this?
Only against the key it was given. Google’s production key is private. A research detector is not Gifi, and it is not a Gemini certificate.