Two provenance layers remain after Google's Gemini change, signed metadata and an in pixel watermark, and both have known failure modes that a small evasion market is already selling around.
Google announced Friday that Gemini users will be able to toggle off the visible watermark the app applies to AI-generated images, video, and music. The change was framed in Google's own post as a top-10 user-requested feature, backed by a poll run by Gemini app VP Josh Woodward. What remains are two provenance layers most readers have never been asked to think about: C2PA content-credentials metadata, and Google's SynthID watermark embedded in the pixels themselves. Each of those layers is real, and each has known failure modes that the toggle makes easier to lean on.
The visible watermark was the easy cue. It was also the marker that mattered least, because anyone with a crop tool, a screenshot, or a free image editor could already remove it. The shift now is not that the cue is gone; it is that the default moves from on to opt-in, and unmarked AI images become the expected Gemini output.
C2PA is the metadata layer. Every AI-generated asset that supports it ships with a cryptographically signed manifest, the Content Credentials standard, that records the model, the edits, and the producing app. Most social platforms and messaging apps strip that metadata on upload, which is why the same file that verifies as "made with Gemini" in the Content Credentials Verify viewer will show no provenance on X, Instagram, WhatsApp, or iMessage. For content designed to spread, the metadata layer is often gone before the first share. Check the original export in the Content Credentials Verify viewer before trusting the metadata, because a repost has usually lost it.
SynthID is the harder layer. It embeds a pattern directly into the pixels of the image, audio, or video, so cropping and resizing do not remove it. Ars Technica's testing of the system found that detection does degrade as the image is re-encoded and re-saved, but the picture becomes uselessly blurry before the watermark fully breaks. It is the most robust layer Google points to, and it is also the one an active commercial market is already trying to defeat.
Two services, Rephrasy and SynthID Bypass, market evasion of SynthID. A Medium author who documented a multi-week adversarial effort reported a working bypass that required around 123,000 image pairs, 200 plain Gemini outputs, and enough spread-spectrum encoding expertise to fool a decoder's confidence threshold. Some of the time. The bypass is not magic, but it does not have to be: it has to be cheap enough that a determined bad actor can ship a stripped image at scale, and right now the answer is yes, for the people who care to try.
The change is sold as user choice, and it understates the second-order effect. Visible watermarks are how a casual reader notices an image is AI at all. Once the default is unmarked output, the burden of proof moves to the platform and to the reader, and the expected state of the internet shifts from "marked unless opted out" to "unmarked unless asked."
A few habits survive the change, and they are what the post-watermark internet actually runs on: opening the original Gemini export in the Content Credentials Verify viewer before trusting the metadata, since a repost has usually lost it; checking whether the platform you are reading on surfaces SynthID detection at all, since very few do; running a reverse image search to see whether the picture existed before the prompt that supposedly made it; and treating the image as unverified rather than as evidence when provenance is missing.
The Nano Banana image model is the specific toggle target, with the rollout starting on images and later extending to video and music. The three-layer provenance stack Google built has now lost its top layer to a default-off toggle, and the reader is being asked to live with what is underneath.