Sensity AI Logo
Media Verification

Digital Watermarking and Content Provenance Need a Multi-Layer Approach for Law Enforcement

Clair Tan - Multimedia Forensic Investigator
27 May 2026

Two recent announcements on digital watermarking and content provenance demonstrate wider industry adoption of technologies intended to help creators, publishers, and consumers verify the origins and history of digital content. But neither approach is a silver bullet and only exposes the need for a multi-layered approach for law enforcement and forensic investigators when it comes to identifying and triaging suspected AI-generated content. 

OpenAI has integrated Google’s SynthID digital watermarking technology into its generative tools and launched an image verification tool that checks whether an image was created in ChatGPT, including via the API, or Codex. 

At the same time, Google has expanded SynthID detection from the Gemini app to Lens, AI Mode, Circle to Search, and Gemini in Chrome, so you can now check a file for a SynthID watermark across more applications. 

OpenAI has also added more support for Content Credentials metadata, as part of its work with the Coalition for Content Provenance and Authenticity (C2PA), the cross-industry group behind the open technical standard for content provenance.

Any approach to content provenance is ineffective on its own

Yet in the announcement, OpenAI recognizes that digital watermarking and content credentials metadata have limited effectiveness as standalone solutions, and a multi-layered approach is required. “C2PA metadata is an important foundation for provenance. It helps content carry information about where it came from, how it was created or edited, and who signed that information. But metadata is not foolproof. It can be stripped, lost through uploads and downloads, or broken by transformations like file format changes, resizing, or screenshots,” the company says. 

“To make provenance more resilient, we are taking a multi-layered approach and incorporating watermarking through Google DeepMind’s SynthID⁠… SynthID embeds an invisible watermarking layer that complements C2PA metadata-based approaches.”

But while these initiatives are useful for participating content creators and distribution platforms to help build trust, inform consumers, and potentially deter casual criminals – such as those using commercial tools to create malicious deepfakes for the purposes of fraud or harassment, they are of limited impact when it comes to more serious crime and malicious intent. 

Both digital watermarking and content credentials metadata are trivially bypassable as solutions.   

Developers note that Stable Diffusion with 10-15% denoising strength can remove the watermark, as can a ComfyUI node, and at least one GitHub repo already exists to reverse SynthID watermarking. 

With regards to content credentials metadata, this can be easily edited or stripped out. In fact, one of the biggest obstacles to this approach arises through simple distribution. When files are uploaded and distributed organically, such as via social media, the platforms typically copy the visual and audio components of the file into a new container, ignoring original metadata and degrading embedded signatures through compression.

Malicious actors deliberately obfuscate the origin of synthetic content 

For casual and serious criminals alike, the technology exists for bad actors to deliberately strip watermarks and C2PA manifests to bypass detection from large-scale industry initiatives with little effort. 

But the biggest flaw in these same initiatives, largely driven by consumer and regulatory pressure, is that they are opt-in and require voluntary involvement, which is why we will likely only see them apply to commercial and off-the-shelf tools. 

There also exists an underground market catering to Crime-as-a-Service, where non-conforming AI generators can be used to generate non-labelled deepfakes, or to bypass KYC (Know Your Customer) identity checks to help criminals rapidly scale their fraud operations. 

Furthermore, as we revealed in our recent report, The Role of Deepfakes in Cognitive Warfare, nation-states, hacktivists, and other politically-motivated actors use deepfakes for sophisticated influence campaigns, psychological operations, and cognitive warfare. These actors actively obfuscate AI content labels to ensure their deceptive content is not flagged as such.

Ultimately, the challenge for all forms of self-labelling of AI-generated content, is that it’s a voluntary approach, and there will always exist an ecosystem of malicious actors with an incentive to obfuscate the fact that their content is synthetic. 

Investigators need to deploy multiple checks at the point of evidence ingestion 

From a triage perspective, it does make sense to incorporate digital watermark and content credentials metadata checks into the investigation workflow. This approach can help identify conforming synthetic content among large volumes of evidence, and it will also catch lazy efforts to create malicious content using commercial tools. 

However, forensically speaking, authenticity and provenance checks based on these large-scale initiatives won’t stand up in court, when metadata can be easily removed and open-source denoisers can strip watermarks. No single provenance technique is enough on its own. 

To combat this, law enforcement and forensics investigators also need to incorporate complementary technologies into their workflows to ensure robust media verification and an auditable chain of custody. Specialist forensic tools can be used to provide a second opinion or expert review in circumstances that require additional technical proof and help meet the threshold for evidence authentication in court. 

We talk about all of this in our recent podcast – C2PA and similar initiatives are a genuine step forward and the idea of baking provenance directly into content at the point of creation is elegant, and for those acting in good faith, offers real value. But, fundamentally, C2PA and watermarking are systems built on trust and voluntary participation.

In a room full of unverified bottles, the label on the bottle only helps if the poisoner decided to label it. Provenance tells you where something came from, if the creator chose to tell you. Detection has to work when they didn’t.

Share the article