TL;DR
The question is wrong. The field asks whether AI-labelled content gets demoted. That assumes a label is a property the document carries. It is not. A watermark is a query answered by whoever holds the key.
Earned media sits under both floors. SynthID cannot mark short, factual, low-entropy text, and the EU Code of Practice waives marking below 200 tokens. The quote, the statistic and the specification are beneath the regime by physics and by law.
Editing and evasion are the same operation. Paraphrase destroys a text watermark. Paraphrase is also what an editor does, and what the EU editorial exemption requires. A missing mark cannot tell them apart.
The mark dies as it travels; the label is born mid-journey and never dies. A platform derives a label at upload, stores it against the item and passes it to every repost. That is the exposure that actually touches your campaign assets.
Instruments: the Handling Ladder, the Detector Question and the Label Surface.
The question everybody is asking has no answer
Every conversation about synthid content labelling in 2026 converges on the same question: will content marked as AI-generated be demoted, deprioritised or refused citation? It is a reasonable question. It is also unanswerable as posed, because it smuggles in an assumption that does not survive ten minutes with the specifications.
The assumption is that being labelled is a property of a document. Something the file carries, that any observer can read, the way anyone can read a byline or a publication date. On that model the strategic question is simply which observers care, and how much.
That is not what a watermark is. A watermark is a statistical signal embedded at generation and readable only by a party holding the detection key. SynthID, Google DeepMind’s watermarking system, does not publish its watermark pattern or its detector model, and there is no public specification comparable to the C2PA provenance standard. A third-party developer cannot implement SynthID detection independently. Access to the SynthID Detector portal has been a waitlist for journalists, media professionals and researchers since it launched.
So the sentence “this content is labelled AI-generated” has no fixed truth value. It resolves differently depending on who is asking. The model provider gets a definite answer. An accredited journalist with portal access gets a probabilistic one. A platform with an integration gets a partial one. You, auditing your own agency’s output, get nothing at all.
The label is not on the document. It is inside a service. Every downstream conclusion in this article follows from that one structural fact, and almost none of the advice currently circulating in search and digital PR takes account of it.
What a watermark actually is, and who can read it
What is SynthID?
SynthID is Google DeepMind’s system for embedding imperceptible markers into content produced by its generative models. For images, audio and video it alters the signal itself in ways designed to survive cropping, compression and filtering. For text it works differently, and the difference matters more than anything else in this article.
SynthID-Text, published in Nature in October 2024, uses tournament sampling: at each token the model would ordinarily pick from a probability distribution, and the watermark nudges that choice using a pseudorandom function keyed to a secret value. Across enough tokens the bias accumulates into a statistically detectable pattern. Detection is then a hypothesis test on the whole passage, not a lookup on an embedded field.
The key is the whole story
Because detection is keyed, the ability to read the mark is a property of the reader, not the content. Google can detect Gemini output. Nobody else can, unless Google lets them. An open-source implementation of the text algorithm exists, but its detection rates and robustness are lower than the production system, and running it requires you to hold the key that was used at generation — which, for content you did not generate, you never will.
There is a sharper version of this asymmetry in the 2026 security literature. A May 2026 paper on re-watermarking as a removal strategy trained a classifier purely on visual features and found it could reliably identify which watermarking scheme had been applied to an image — with no key and no model access. The schemes leave method-specific fingerprints. Formal undetectability, the cryptographic property a watermark is supposed to have, remains an aspiration rather than a shipped feature.
Key takeaway
You can tell that an asset was marked by somebody. You cannot tell what the mark says. That combination — public class, private content — is the worst possible shape for anyone trying to build a ranking signal, and the best possible shape for anyone trying to sell a compliance dashboard.
Two different things wearing the same name
It is worth separating the two technologies people mean when they say labelling, because they fail differently. C2PA, the Coalition for Content Provenance and Authenticity standard, attaches a signed manifest — a cryptographic record of production history — to a file. Anyone can read it, because the specification is public, but a naive re-save strips it. SynthID embeds a statistical signal in the content itself, which survives handling that destroys metadata, but only the keyholder can read it.
So one is readable and fragile, the other is durable and unreadable. The Code of Practice’s answer is to require both, which is honest about the trade-off but does not escape it: you end up with a public record that can be removed and a private record that cannot be checked. Neither shape supports the thing search and digital PR teams keep hoping for, which is a durable, universally legible authenticity flag attached to a page.
Can anyone check content for a SynthID watermark?
Not independently. Verification runs through Google’s own surfaces — the Detector portal, which is waitlisted for journalists, media professionals and researchers, and consumer checks in the Gemini app, Lens and, since I/O 2026, Chrome and Search. Reported accuracy is high on unedited files and falls markedly on processed ones. There is no equivalent of a crawl or index check you can run yourself across a supplier’s output, which is why agency AI-use audits in 2026 are contractual questionnaires rather than technical tests.
Earned media sits underneath both floors
There are two independent limits on what can be marked at all. One is technical and one is legal. They land in almost exactly the same place, and that place is where earned media lives.
The entropy floor
Tournament sampling needs slack. If the model has genuine uncertainty about the next token, the watermark can bias the choice without changing the meaning. If it does not — if the sentence is a fact, a figure, a product name, a specification — there is nothing to bias. Google’s own developer documentation states plainly that watermark application is less effective on factual responses, because there is less opportunity to augment generation without reducing accuracy. Zero-entropy generations are not watermarked at all.
Length compounds it. The detection test needs enough token positions to accumulate a signal. Below roughly 200 tokens, false-positive rates rise and true-positive rates fall sharply. Short factual text is doubly unmarkable: not enough entropy per token, and not enough tokens.
The legal floor lands in the same place
Article 50 of the EU AI Act became enforceable on 2 August 2026, requiring providers of generative systems to mark outputs in a machine-readable format, with penalties reaching €15 million or 3% of worldwide turnover. Systems already on the market before that date have until 2 December 2026 to meet the marking requirement.
The Commission’s Code of Practice on AI-generated content, the document that translates the obligation into engineering, waives marking for content under 200 tokens. It permits a single watermarking layer for free-form text. It puts source code, ephemeral real-time content, machine-to-machine exchanges and closed business-to-business outputs out of scope entirely.
Now list the units of earned media. A quote given to a reporter. A statistic in a pitch. A two-line comment for a roundup. A product specification a trade title reproduces. A data point that travels from your study into somebody else’s paragraph. Every one of them is short and factual. Every one of them is below both floors.
The labelling regime is structurally blind exactly where earned media operates — and not by oversight. The Code waives the 200-token case rather than solving it because it cannot be solved: you cannot embed a statistical signal in a sentence that has no distributional slack without altering the fact the sentence carries.
The Handling Ladder
The first instrument tracks a single asset from the moment a model produces it to the moment a person decides whether to cite it. At each step, ask three separate questions: does the machine-readable mark survive, does a platform label exist, and what does a human actually see. They diverge, and the divergence is the finding.
| Handling step | Machine-readable mark | Platform label | What a person sees |
| Generation | Embedded and intact | None yet | Nothing |
| Export or re-save in a design tool | Often re-encoded; manifest may be dropped | None yet | Nothing |
| CMS derivative: resize, crop, transcode | Frequently lost; metadata stripped by naive re-saves | None yet | Nothing |
| Editorial rewrite or paraphrase (text) | Detection collapses under paraphrase and translation | None | Nothing |
| Upload to a labelling platform | Read once at ingest, then irrelevant | Applied and stored against the item | An AI-generated badge |
| Repost, share or embed | Absent | Inherited by the copy | The badge travels |
| Quotation into a journalist’s article | Absent | Not carried, but the impression is | The journalist’s own judgement |
| Paraphrase into a generated answer | Absent | Absent | Nothing at all |
Read the two middle columns against each other. The mark starts green and ends red: it degrades monotonically as the asset moves through ordinary handling. The label starts absent and ends sticky: once applied it persists and propagates. The two columns cross in the middle of the ladder, at the platform-upload step — which is precisely where most digital PR assets enter public view.
Editing and evasion are the same operation
Text watermarks degrade under exactly four transformations: paraphrasing, synonym substitution, rearrangement and back-translation. A 2025 robustness assessment of SynthID-Text found detection accuracy dropping sharply under light paraphrasing or translation. Image marks fare better against ordinary distortion but fail against generative re-synthesis: a February 2026 study of diffusion-based editing reduced decoding accuracy below 25% in every case tested, with two widely used schemes falling to roughly chance level on a 56-bit payload.
Now notice what those transformations have in common with legitimate editorial work. Rewriting a sentence. Replacing a word. Moving a paragraph. Translating for an international market. These are not attacks. They are the job.
The compliance trap this creates
The EU’s editorial exemption releases AI-assisted text from the labelling duty where it has undergone human review or editorial control and a person holds editorial responsibility for the publication. The Code’s recitals are explicit that this needs real work, not minor tweaks. Meanwhile the same Code bans humaniser tools — products designed to strip AI markings — and deliberately removing or altering a mark is prohibited for deployers.
Hold those two rules together. The route to the exemption is substantive rewriting. Substantive rewriting is also the physical process that destroys the mark. The regime distinguishes them by intent and responsibility, not by effect, because there is no effect to distinguish. An editor doing real work and an operator laundering output produce the same artefact: unmarked text that used to be marked.
Key takeaway
A missing mark measures distance travelled since generation, not human involvement. It cannot separate a careful editor from a launderer, and no improvement in watermarking will make it able to, because the two are performing the same transformation for different reasons.
Removal leaves its own trace, which helps nobody
There is a partial defence in the literature, and it is worth understanding because it is routinely overstated. Work published in 2026 on the forensic cost of watermark removal found that removal attacks perturb an image far more than the original watermarking did: editors either fail to remove the mark or introduce distortion strong enough to be detected forensically. Removal, in other words, is not free.
But notice who can act on that. Detecting removal-scale perturbation requires forensic analysis of the file, by someone who already suspects it, with tooling no publisher runs at scale. For example: a trade editor receiving forty press releases a week has no forensic pipeline, no baseline to compare against, and no incentive to build one. The finding is real and its practical audience is a handful of newsroom verification desks and platform trust teams. It does not reach the gate where a placement is won or lost.
The mirror-image error is just as common. Absence of a SynthID signal does not mean an asset is human-made. Google says so explicitly. Midjourney embeds no content credentials; the Flux family behind several popular image tools does not either; open-weight models mark nothing at all. Any internal audit built on detection is measuring a sliver of a sliver, and reporting the rest as clean.
The label outlives the mark
Two properties of platform labelling get missed because the industry keeps treating the mark and the label as the same object. They are not. The mark is cryptographic or statistical evidence embedded in a file. The label is a database row a platform writes about an item.
Scope inflation: the mark binds to a file, the label binds to a container
TikTok has auto-labelled more than 1.3 billion videos by reading Content Credentials at ingest. Meta runs comparable detection across its properties. The unit those systems label is the post, not the pixel. One generated illustration inside a nine-asset campaign package can put an AI badge on the container that a picture desk opens.
That is a scope mismatch with real consequences for digital PR work, because the decorative layer of a campaign is almost always the layer most likely to have been generated, and the load-bearing layer — the dataset, the methodology, the quote — almost never is. The label attaches to the wrong thing and is read as attaching to the whole.
Stickiness: labels do not re-derive
A platform reads credentials once, at upload, and stores the verdict against the item. Replace the underlying file with a clean one and the stored label does not recompute. Repost the item and the label is inherited. There is generally no appeal route, and none of the defensive playbook built for hostile links applies, because the label is not a claim about a file you can now produce — it is a record of a check that happened.
So the evidence is fragile and the consequence is permanent. That is the inverse of how every other compliance signal in search works, and it is why label management belongs at the point of upload rather than in the recovery workflow you would normally reach for after something goes wrong.
The Detector Question
The second instrument is a four-question test to run against any claim that a piece of content is, or is not, labelled as AI-generated. It takes about a minute and it kills most of the claims currently being made by monitoring vendors.
The Detector Question
1. Who holds the key? Provider-keyed (definite, private), platform-derived (stored, unappealable) or a statistical classifier (a guess with a false-positive rate). If you cannot name the keyholder, the claim is a guess wearing a percentage.
2. Was the file marked, or the claim? A watermark binds to bytes. A citation carries a sentence. If what travels is the sentence, no mark travels with it.
3. What has happened to it since? Walk the Handling Ladder. Count the transformations between generation and the point of decision. Two is usually enough to end the discussion.
4. Who reads the result, and what do they do next? Disclosure surface, advertising-policy enforcement, or a human being. Note what is absent from that list: no shipped ranking system consumes it.
The reading rule: if question one has no answer, stop. If question four resolves to a person, you have a persuasion problem, not a compliance problem — and those are solved with different budgets.
Where the signal is actually routed
Does an AI label hurt your search rankings?
There is no evidence that any search or answer system uses a provenance mark as a ranking or citation input, and every shipped integration points somewhere else. Google surfaces C2PA data through About this image in Search, Lens and Circle to Search — a disclosure panel a user chooses to open. Its advertising systems consume C2PA signals to inform policy enforcement. At I/O 2026 it announced SynthID and Content Credentials verification in Chrome and Search, again as a user-facing check. TikTok states that turning on its AI-content setting does not affect distribution; the penalty is for failing to label and being caught.
Why no engine will build ranking on this
There is a structural reason beyond the technical ones, and it is the part nobody says out loud. The party holding the detector is the party that generated the content. Google can detect Gemini output; it cannot detect anyone else’s. A ranking penalty built on SynthID would therefore fall hardest on the users of Google’s own models and be blind to every competitor’s, while leaving open-weight output untouched entirely.
That is not a policy a rational platform ships. It would tax its own customers, reward evasion, and produce a coverage map shaped like market share rather than like honesty. The same logic applies to every provider running its own scheme. The detector is always held by the party with the least reason to use it as a weapon, which is why marking keeps being routed to disclosure and never to selection — and why a manual action has never had a provenance analogue.
The pattern is consistent and it is not an accident. A signal that is unreadable without a key, absent from most AI content, and destroyed by ordinary editing is a terrible ranking feature and a serviceable disclosure feature. It gets routed to humans and to policy teams, never to rankers.
Which means the exposure is audience, not algorithm
The cost lands on people, and the measurements are unusually clean. Bynder’s survey of 2,000 UK and US consumers found 56% preferred AI-written copy when they did not know its source, and 52% felt less engaged once told. Same words, opposite reaction, one variable changed. A Fractl and Search Engine Land survey of 1,008 consumers in Q2 2026 found 39% said heavy AI use in a brand’s marketing would reduce their trust in it, roughly double the 20% who said so a year earlier. Parallel experiments published in Electronic Markets in early 2026, corroborated by a Copenhagen Business School study in March, found that AI-generated and AI-enhanced labels reduce engagement against identical human-labelled content.
For anyone whose job is acquiring links rather than impressions, one number matters more than all of those. In research published by PRWeek in May 2026, the large majority of UK journalists were opposed to AI-generated press releases and pitches, with almost half saying they would not consider them at all. The gate that stands between you and an earned placement is a person with a policy, and that policy is hardening.
The UK gates are declarations, not detections
The UK has no statutory marking duty, though UK firms serving EU users fall inside Article 50 anyway. What operates here is editorial. The BBC publishes a visible label — a hexagon icon and a short line explaining how AI was used — at the top of relevant content. The Guardian revised its guidance in March 2026 to permit limited generative use for tasks such as alt text, document analysis and transcription, subject to human oversight and explicit permission from a senior editor. PA Media’s position is that AI supports journalists rather than replacing them.
Every one of those is a statement by an accountable party. None of them is a detector reading. The British media’s answer to the provenance problem is a named human saying what happened, which is also the shape of the EU’s editorial exemption, and also what a regulated or gated corpus asks for before it admits a source. One artefact, three readers.
The Label Surface
The third instrument is arithmetic, and it exists to stop teams spending their governance budget in the wrong place. For any campaign, count two things.
- Labelled assets: assets that will pass through a gate that reads credentials and writes a label — in practice, anything uploaded to a major social or video platform.
- Load-bearing assets: assets that carry the campaign’s credibility — the dataset, the methodology note, the named quote, the charts a journalist will reproduce.
The Label Surface is the overlap between those two sets, divided by the load-bearing set. For most business-to-business campaigns the answer is close to zero: the dataset goes out as a file and a page, and never touches a labelling gate. For consumer campaigns built on video and social-first creative, it can approach one.
Key takeaway
A near-zero Label Surface is not good news. It means the labelled layer of your campaign is decorative, the load-bearing layer is invisible to every labelling system, and any assurance you take from a clean provenance dashboard is assurance about the wrong assets.
The operational consequence is a split you can act on immediately. Keep the load-bearing evidence off the marked layer entirely — render charts from your own data rather than generating them, use owned photography or archive imagery for anything a picture desk will handle, and publish the methodology as a page with a name on it. Then treat the decorative layer as expendable and label it honestly, because a proactive label costs little where it lands and an undisclosed one is the thing platforms actually enforce against.
This also reorders what is worth buying. If the human gate is decisive, then placements from sponsored partnerships and contributed articles or paid insertions now carry a disclosure question they did not carry two years ago, and the outlets with the strictest AI policies are the ones whose links are hardest to replace. Screen prospects for whether they publish an AI policy at all: it is a fast proxy for whether a real editor stands behind the page, which is the same property that bounded corpora and answer systems select on for entirely unrelated reasons.
The strongest case against this reading
The best counter-argument is not that the mechanics are wrong. It is that they describe a snapshot of an immature system, and every gap named here is being closed deliberately.
The EU Code requires a multilayered approach: watermark plus metadata plus logging plus fingerprinting, specifically so content can be identified even when marks are removed or degraded. It bans humaniser tools. It asks providers to ship detectors for third parties, which is a direct legislative attack on the asymmetry this article is built on. Google is putting SynthID and Content Credentials verification into Chrome and Search. Nvidia, OpenAI, Kakao and ElevenLabs have all adopted SynthID marking. On that trajectory, coverage rises by law, robustness rises by fingerprinting, detection democratises by mandate, and this entire analysis expires.
That is the right objection, and the direction of travel is real. It is bounded four ways.
One: fingerprinting relocates the keyholder rather than removing it
Fingerprinting recovers the record, not the mark. It re-identifies an asset by matching it against a database of known generations, which requires the asset to be in somebody’s corpus and requires you to have query access to that corpus. The asymmetry moves from a key to a lookup service. It does not become a public property of the file.
Two: legal coverage rises only among the compliant and in scope
Article 50 binds providers and deployers who can be reached. Open-weight systems are in scope on paper and unenforceable in practice. Midjourney and Flux carry nothing. The unmarked residue is, by definition, the material a labelling regime was built to catch, so raising compliance sharpens the selection effect rather than closing it: the mark ends up correlating with who follows rules, not with who used a machine.
Three: the floors are properties of the method, not implementation gaps
The entropy limit and the 200-token threshold are not bugs awaiting a patch. A statistical watermark needs distributional slack; a sentence stating a fact has none. That is why the Code waives short text rather than mandating it. No adoption curve reaches content that cannot carry a signal.
Four: the actions do not change
Grant the whole objection. Assume perfect coverage and perfect robustness by 2028. A mark still says a tool was used. It never says the claim is true, and nothing in any shipped system connects it to selection. Keeping load-bearing evidence off the marked layer, controlling label scope at upload, and winning the human gate remain correct under both futures — which is the test any recommendation here has to pass.
Worked example: Norhaven Outdoor, Kendal
Norhaven Outdoor is a Cumbrian outdoor-equipment brand turning over £14.2 million, with an in-house team of six running four data-led campaigns a year. Its January 2026 campaign, the Trail Pressure Index, combined freedom-of-information returns from national park authorities with a 2,400-person survey. The package contained twelve illustrated county maps produced in a generative image tool, nine charts rendered from its own data, and four photographs from its archive.
What went wrong
The maps carried marks embedded at generation. On launch day, 14 January, the LinkedIn and Instagram posts carrying them were auto-labelled at upload. Two trade titles’ picture desks declined the maps under their own AI-imagery policies. A national’s standards desk then queried the dataset because the imagery had been labelled — the label’s scope had jumped from twelve files to the whole campaign.
Against a forecast of 44 placements the campaign landed 26. Eleven of the eighteen misses cited imagery. None cited the data, which was never in question and was the only genuinely original thing in the package.
The fix, and what it cost
Between February and May the team separated the layers. The FOI dataset, the charts and a methodology note with a named author moved into a container that never passes a labelling gate: a static page and a downloadable file, pitched as documents rather than posts. Generated illustration was dropped from the pitch kit entirely and confined to owned channels. A one-page production note listed which tools were used at which step and who reviewed the output.
The July campaign landed 38 placements with zero imagery rejections, and the standards-desk query was answered in a single email.
The negatives were structural, not cosmetic. Commissioned photography and cartography added £11,400 per campaign and nine working days to production. One picture desk still declined, because its policy did not distinguish generated art from script-rendered charts and treated both as machine-made. The January posts still carry their platform labels and cannot be cleared, so the evergreen campaign page shows an AI badge on its social embeds indefinitely. And the production note became a negotiation: one retained client asked for the tool list to be removed from a co-branded asset, which the team refused and which cost them a renewal conversation.
What to do on Monday
- Run the Label Surface on your next campaign. List load-bearing assets and labelled assets separately. If the overlap is near zero, your provenance dashboard is reporting on decoration.
- Move evidence off the marked layer. Charts rendered from your own data, owned or archive photography for anything a picture desk handles, methodology as a page with a named author.
- Control label scope at upload, not after. Split packages so one generated asset cannot label a container. Labels do not re-derive and there is no appeal route you can operate.
- Write the production note before you need it. Which tools, at which step, reviewed by whom. It answers a standards desk, satisfies the editorial exemption and is what gated corpora ask for.
- Apply the Detector Question to every vendor claim. If they cannot name the keyholder, they are selling you a classifier’s guess as a fact.
- Screen prospects for a published AI policy. It is a fast proxy for a real editor standing behind the page — the property that decides both whether you earn the link and whether the page survives in a gated index.
- Stop asking whether AI content gets demoted. Ask who reads the signal and what they do next. In 2026 the answer is always a person, and people are persuaded with evidence, not certificates.
The watermark debate has been conducted as though a machine will eventually sort honest content from synthetic content on everyone’s behalf. It will not, because the mark cannot be read by the parties who would need to act on it, cannot be carried by the sentences that actually travel, and cannot survive the editing that makes content worth citing in the first place. What survives is duller and older: a named person, a dated record, and a claim somebody else is willing to repeat. That was the link building problem before any of this started, and it is the link building problem now.
