SenseDefend

Synthetic-media instruments, by article and effective date

What an upload leaves of each kind of mark

Every marking mechanism in this record meets the same test on the way to a viewer: a platform that transcodes. One mechanism usually survives it, one usually does not, and one survives whatever the frame survives. As of 2026-09-12.

One ordinary upload, three different outcomesA platform that transcodes keeps the content and rewrites the file around it. An embedded signal usually survives that, a manifest usually does not, and a rendered notice survives whatever the frame survives.ExportWhatever thetool applied ispresent:manifest,signal, notice,or nothingA fileUploadThe platformrebuilds thecontainer andre-encodes thecontentA new fileDeriveThumbnails,previews andalternaterenditions aregenerated fromitMore filesWatchThe manifest isusually gone,the signalusually thinner,the notice stillvisible
Fig. 1 Assuming a file still carries what it carried at export is the most reliable way to be wrong about this.
What one ordinary upload does to each of the three mechanisms. Recorded 2026-09-12.
PointWhere it sitsWhat the record holds
An embedded signalThree entriesSurvives a rebuild; degrades under heavy compression and cropping
An attached manifestFour entriesDropped by any rebuild that does not copy it across
A visible noticeTen entriesSurvives whatever the frame survives; removed by a crop

Inclusion rule. Mechanisms described by at least one entry in this record. Counts are of entries describing that mechanism, not of products in the market. Order. Grouped by mechanism, most durable against a rebuild first.

1A rebuild is not an attack, it is the normal case

Uploading through a platform that transcodes touches all three mechanisms at once, and it happens to nearly every published asset. Assuming a file still carries what it carried at export is the most reliable way to be wrong about this.

Which is why the useful robustness claim names ordinary operations rather than adversarial ones. One entry in this record does exactly that, listing four steps that happen to every video on its way to a viewer.

2The most informative mark is the easiest to lose

A manifest can carry a chain of signed claims. Anything that rebuilds the container without copying it drops the whole record in silence, and platforms rebuild containers by default.

So the four entries that reach the provider duty most convincingly are also the four whose marks are most likely to be missing from the copy an audience sees. That is not a criticism of them; it is the mechanism.

3Checking the route beats checking the file

What a delivered file carries is decided by the route it took, and a route changes rarely once it is in place. Establishing it once per delivery path is usually enough, and far cheaper than establishing it per file.

None of that is recorded here for any vendor, because no vendor page can speak for somebody else's pipeline. It is the gap between every statement in this record and the question an audience's copy actually raises.

  • SynthID
    Designed to stand up to cropping, filters, frame-rate changes and lossy compressionstated robustnessGoogle DeepMind, SynthID / recorded 2026-09-12
  • Adobe Firefly (adobe.com)
    Outputs include Content Credentials that indicate AI was used in the creation processa generative image and video toolAdobe, Firefly product page / recorded 2026-09-22
  • ElevenLabs (elevenlabs.io)
    Watermarking embeds imperceptible patterns into audio at frequencies masked by existing sounda speech and audio generatorElevenLabs, documentation / recorded 2026-09-22
  • Meta AudioSeal
    A perceptual loss inspired by auditory masking, presented as achieving better imperceptibilitythe stated quality trade-offMeta AI, research publication / recorded 2026-09-22

4Sources

Article wording from AI Act Explorer, Article 50; vendor statements from the pages listed on each generator entry. Both read 2026-09-12. Related: Naming a standard, What buying changes, Two kinds of mark.