Spymarks, Not Watermarks: SynthID Can Hide a 136-bit Tracking Payload in Images
jedisct1 · x · 2026-09-22
A brand.io essay coins spymark: unlike visible watermarks that assert ownership, spymarks are hidden signals that make your work traceable without your knowledge or consent — and they're quietly spreading across the internet.
Key points:
- Google SynthID is cited as a prime example: embedding imperceptible signals into images, audio, text, and video that can encode database identifiers mapping to user identity (full name, IP, date of birth, address, party affiliation, etc.).
- The SynthID-Image paper reports the SynthID-O variant can encode a 136-bit payload in a 512x512 image — enough for a 64-bit database ID plus 72 bits of error correction.
- SynthID wasn't the first such system; OpenAI and many other companies are developing these at scale, going beyond identifying AI content to building robust tracking mechanisms.
- A demo shows images invisibly altered in the frequency domain to carry tracking IDs that can be decoded by amplifying pixel differences.
Warning: social media, content tools, and smartphones may soon spymark everything you publish.
More from Safety
- Russia-based group used Claude Code to build autonomous FPV kamikaze drone swarm — ericelliott_ · 2026-09-23
- OpenAI Researcher Blasts 'Total Safety Transparency' Push as a Gift to AI's Enemies — trevposts · 2026-09-23
- UK AISI Partners With Evaluating Evals to Make Official AI Evaluations Reproducible — IanArawjo · 2026-09-23
- YC F26's Deepmark embeds inaudible IDs in AI agents' voices to verify callers — ycombinator · 2026-09-23
- Stanford's Anshul Kundaje Slams AI Firms for Causing Breaches Then Preaching Responsibility — anshulkundaje · 2026-09-23
- China Releases AI Safety Governance Framework 3.0 With Agentic AI Risk Annex — LuizaJarovsky · 2026-09-22