AI Watermark Detector · hidden characters

About this tool

A free checker for hidden characters in text and provenance metadata in images. It runs in your browser, and it tells you what it cannot see.

Last updated

Why this exists

Search for “AI watermark detector” and you will find tools that list a byte-order mark or a bidirectional control character as an “AI watermark”. That is not accurate, and it makes the whole category hard to trust.

“AI watermark” is used for at least three different things:

  • Hidden characters inserted into text — zero-width code points, Unicode tag characters, variation selectors. A per-copy fingerprint, and exactly readable.
  • Metadata and manifests attached to a file — C2PA Content Credentials, EXIF, XMP, the IPTC trainedAlgorithmicMedia declaration. A signed or unsigned statement, and trivially removable.
  • Statistical watermarks biased into a model’s sampling — Google SynthID and similar. Readable only with the provider’s key, which is why only the provider can build the detector.

This tool handles the first two completely. It states plainly that the third is out of reach. For images, video and audio there is now an official answer, and it is Google’s, not ours — see what the SynthID Detector does and does not cover.

How it works

No model runs here. There is nothing to download and nothing to wait for.

For text, the page walks the string one code point at a time and classifies each one against the Unicode ranges that are invisible, reserved, or able to reorder what you see. Payloads carried in tag characters or variation selectors are decoded and shown as plain text.

For images, the page reads the file’s own structure: the APP11 segment that carries a C2PA manifest, the caBX chunk in a PNG, and the EXIF, XMP and IPTC blocks. Nothing is inferred from pixels.

How to check the “nothing is uploaded” claim

Do not take it on trust. Three ways to verify it yourself:

  • Open your browser’s developer tools, switch to the Network tab, and run a check. You will see a page-view request to Google Analytics. You will see no request that carries your input.
  • Look at the response headers. This site sends Content-Security-Policy: connect-src 'self' https://www.googletagmanager.com https://*.google-analytics.com. That short list is every host the page may talk to. The browser refuses everything else.
  • Read /analytics.js. It counts page views, and does nothing else.

There is no account, no upload endpoint and no queue. That last part matters: a tool that queues your file on someone else’s machine is not running locally, whatever the landing page says.

What it does not do

  • It cannot read a statistical watermark such as SynthID. That needs the provider’s key. Google now publishes its own detector for images, video and audio at synthid.com; use that for the question it answers, and use this page for the two it does not.
  • It cannot tell you whether a picture was made by a model. There is no pixel property that separates a generated image from a photograph.
  • It cannot recover a manifest that was stripped. If the C2PA data is gone from the file, it is gone.

Corrections

If this tool reports something wrong — a false positive, a missed character range, a claim on this page that is not accurate — please send it. Reports that reproduce are added to the test suite as regression cases, so the same mistake cannot come back.

Send a correction →