Back

Apple puts a watermark on every AI image

With iOS 27 Apple adopts Google's SynthID for generated and edited images, and the iPhone 18 Pro can sign real photos at capture. Writing Tools and Siri stay unmarked. What Apple announced, with sources, and what it changes if you publish with AI.

Rephrasy Team

Rephrasy Team

Sep 10, 2026

Apple puts a watermark on every AI image  - Blog image

For two years the question "is this image AI?" had a fuzzy answer. Detectors guessed. Metadata could be stripped with a screenshot. And the companies generating the images had little incentive to make their output traceable.


That changed faster than most people noticed. In May 2026 OpenAI started embedding Google DeepMind's SynthID watermark in every image ChatGPT produces. In June, Apple said it would do the same across Apple Intelligence. And on September 9, alongside the iPhone 18 Pro, Apple went a step further with a camera sensor that signs real photographs at the moment of capture.


Three of the largest consumer AI platforms now share one invisible watermark. This post lays out exactly what Apple announced, with the primary sources, and then what it means in practice. Spoiler: images are about to become much easier to trace. Text is not, and Apple has not said a word about it.



What Apple actually announced

Two press releases matter. Everything else circulating online is derived from them.


June 8, 2026, WWDC. In the Apple Intelligence press release, Apple wrote that "generated images will automatically include a hidden SynthID watermark to identify them as AI-generated." That covers Image Playground, which was rebuilt in iOS 27 to produce photorealistic images rather than the cartoonish style of the first version.


The same release extends the watermark to edits: "Photos adjusted with Apple Intelligence will automatically include a hidden SynthID watermark to identify those that have been edited with AI." Apple names three tools: Clean Up (object removal), Extend (outpainting beyond the frame) and Spatial Reframing. The watermark ships on iOS 27, iPadOS 27, macOS 27, watchOS 27 and visionOS 27.


September 9, 2026, iPhone 18 Pro. The iPhone 18 Pro announcement narrows the timeline and the scope a little: "SynthID will be available in a software update later this year and will be included for most edited images, depending on the edits applied." So not day one of iOS 27, and not every edit. A small brightness tweak presumably does not count. Removing a person from the background does.




The bigger news in that release is Apple Reference Image. Apple describes a new main camera sensor "that can sign every pixel it sees." The signed capture is stored next to the normal photo "like a digital negative," and Apple calls it "an unalterable reference photo, visually confirming what the sensor saw at the moment of capture." MacRumors had spotted the feature in an iOS 27 beta 5 privacy disclosure in August: verification sends the raw image, sensor signatures and hardware identifiers to Private Cloud Compute, which returns an authenticated version without keeping the photo.


Put the two together and Apple is building both halves of the provenance problem. SynthID says "a machine made or changed this." Reference Image says "a real sensor saw this." That is a more complete system than anything Google or OpenAI ships today.


Why SynthID, and why it is suddenly everywhere


SynthID is Google DeepMind's watermarking family. For images it embeds a signal directly into pixel values, not into the file's metadata. That distinction is the whole point: EXIF and C2PA Content Credentials disappear the moment someone takes a screenshot or uploads to a platform that strips metadata. A pixel-level watermark survives cropping, compression and resizing, and Google's SynthID page describes it as "not noticeable to the human eye" without affecting output quality.



The adoption curve tells the story:

  • May 2025:

    Google said more than 10 billion pieces of content had been watermarked and launched a verification portal for journalists. (You will see "100 billion" quoted in trade coverage this year. We could not find a primary source for that number, so we are not repeating it.)


  • May 19, 2026:


    OpenAI joined C2PA and adopted SynthID


    for images from its own products, pairing visible Content Credentials with the invisible watermark. OpenAI's own write-up is here.


  • June 2026: Apple, as above.

Once Google, OpenAI and Apple agree on one mark, every platform that wants to label AI images has a single detector to run. Expect social networks, newsrooms and stock photo sites to do exactly that over the next year.


What Apple did not announce: text


Read both Apple press releases again and notice what is missing. Writing Tools, Siri's generated answers, Smart Reply in Mail and Messages: none of them get a watermark. Apple's SynthID plan is images only.


That is not an oversight. Text watermarking exists, and it is much weaker than image watermarking.


Google and Hugging Face open-sourced SynthID Text in October 2024. It works by nudging the model's token probabilities during generation, so the sequence of word choices carries a statistical signature that a trained classifier can pick up. It costs nothing at inference time and is invisible to readers. But the Hugging Face post is candid about the limits:


"Detector confidence scores can be greatly reduced when an AI-generated text is thoroughly rewritten, or translated to another language."


It is also "less effective on factual responses," because when there is only one correct way to phrase something, the model has no freedom to encode a signal. And the authors state it is "not built to directly stop motivated adversaries."



In other words, a text watermark survives copy-paste and light editing. It does not survive a proper rewrite. That is a fundamental property of watermarking text through word choice, not a bug someone will patch next quarter. Apple, which cares a great deal about not shipping features that half work, left text out.


What this means for you

If you publish images. Anything generated in Image Playground or edited with Clean Up, Extend or Spatial Reframing will be identifiable as AI-touched by anyone running a SynthID check, once the update lands later this year. Platforms will increasingly run that check automatically. If your workflow depends on AI-edited product photos or hero images passing as untouched, that window is closing on iPhone, on ChatGPT, and on Gemini. Our free AI image detector is a quick way to see what a downstream platform will see.


If you write with AI. Nothing changes on the watermark side today, because Apple is not watermarking text and Gemini's text watermark does not survive rewriting. What you should still care about is the same thing as before: statistical detectors like GPTZero, Turnitin and Pangram do not need a watermark. They flag prose by its rhythm and word choice. An AI Image SynthID Humanizer addresses both, since a thorough rewrite removes any token-level watermark as a side effect. We explain the mechanics on our SynthID detector page.


If you rely on proving a photo is real. Apple Reference Image is the more interesting announcement for journalists, insurers, marketplaces and anyone whose work depends on unedited photographs. It requires iPhone 18 Pro hardware, so adoption will take years, but it is the first mass-market camera that signs pixels rather than metadata.


The direction of travel


Watermarks were never going to solve AI content on their own, and the companies shipping them say so. What Apple's move does is make the image half of the problem tractable: when the three biggest generators and the biggest camera maker all mark their output the same way, "is this AI?" becomes a lookup rather than a guess.


Text remains where it was. There is no reliable watermark for it, Apple is not pretending otherwise, and detection will keep running on style rather than signatures. If you write with AI, the bar is unchanged: the text has to read like a person wrote it, because that is still the only test anyone can actually run.


Sources


Apple Newsroom, 8 Jun 2026, Apple Intelligence brings powerful AI capabilities into everyday experiences, Apple Newsroom, 9 Sep 2026, Apple debuts iPhone 18 Pro and iPhone 18 Pro Max, MacRumors, 10 Aug 2026, iOS 27 Hints at 'Apple Reference Image' Photo Authentication, The Next Web, 19 May 2026, OpenAI adopts C2PA standard and Google's SynthID, OpenAI, Advancing content provenance for a safer, more transparent AI ecosystem, Google DeepMind, SynthID, TechCrunch, 20 May 2025, Google says SynthID has been used to watermark over 10 billion pieces of content, Hugging Face, 23 Oct 2024, Introducing SynthID Text, Engadget, Jun 2026, Everything announced at Apple's WWDC 2026 keynote