---
title: "Spymarks, not Watermarks"
subtitle: "Watermarks that spy on users are no mere watermarks"
slug: spymarks-not-watermarks
url: https://listedarticles.com/articles/spymarks-not-watermarks
canonical_url: https://brand.io/article/spymarks/
content_type: essay
language: en
published_at: 2026-09-21T00:00:00.000Z
updated_at: 2026-09-22T03:12:17.666Z
author: "Brandon Thomas"
authored_by: human
publisher: "brand"
publisher_url: https://brand.io
topics: ["Security", "Privacy", "AI", "Opinion"]
license: all-rights-reserved
word_count: 1042
reading_minutes: 5
citation: "Brandon Thomas, brand. \"Spymarks, not Watermarks.\" 21 Sept 2026. https://brand.io/article/spymarks/ (all-rights-reserved)"
# The full text follows. The web page shows an extract and sends readers
# to the source above; quote the citation and link the canonical URL.
---

# Spymarks, not Watermarks

*Watermarks that spy on users are no mere watermarks*

> Brandon Thomas coins “spymark” for hidden tracking signals in media—like SynthID payloads that can encode user IDs—arguing privacy-hostile watermarks need a clearer name and stronger pushback.

There's a sneaky new evolution of the "watermark", let's call it — the spymark.

A watermark is a visible mark embedded in a physical or digital medium to verify authenticity or assert ownership.

A spymark is a hidden signal that makes your work traceable without your knowledge or consent.

## Spymarking is sneaking onto the internet

Google SynthID is a spymark that embeds secret hidden signals "imperceptible to humans" (Google's own words) into images, audio, text, and video. This signal can encode database identifiers that map to your identity. Your user records, full name, IP addresses, date of birth, physical addresses, political party affiliation, and more.

Google's SynthID-Image paper reports that its SynthID-O variant can encode a 136-bit payload in a 512x512-pixel image. That is enough room for a 64-bit database identifier, with 72 bits left for error correction.

SynthID was not the first spymark system designed, and it's hardly the only one under active development. OpenAI and many other tech companies are developing these systems at scale. These companies claim spymarking can help identify AI-generated content, yet they've gone beyond simple watermarking and built in robust tracking mechanisms. Social media, content production tools, and smartphones may soon find themselves filled with spymarking algorithms that sneak these signals into everything you publish.

For example, images can be invisibly altered in their frequency domain to carry tracking information such as database IDs linked to users.

## Why give it a new name?

"Watermark" has become a catchall for historical marks of authenticity, banknote security features, copyright overlays, and hidden tracking signals in our media. That last usage obscures the privacy risk that some forms of modern "watermarks" have become.

Most people tire of the discourse on privacy. It's complex, repetitive, and seems irrelevant to the typical day-to-day routine of the average citizen. We can't keep explaining the technicalities behind statistical tracking tools each and every time we need to communicate these concepts to people and expect them to pay attention.

> "To speak the name is to control the thing." — Ursula K. Le Guin, *The Rule of Names*

With a simple change of terminology we can put the privacy concern up front, cementing this issue in the conversation forever:

- **Spy-** — clandestine surveillance, involuntary disclosure
- **-mark** — embedded signal

Now we get to disambiguate friendly watermarks from concerning new technology while leveraging the familiar etymology. It collapses a technical communication salient and gains us a lot of ground with just one new word. It's clear, coherent, and straight to the point.

No more wasting energy establishing the basic facts. The privacy concern is built into the word.

"Spymark" is a privacy Rumpelstiltskin.

## More spymark examples

Here are a few more forms of spymarks so you can better familiarize yourself.

Audio spymarks operate using principles similar to image spymarks, and they are typically inaudible. Some methods make minute changes to the audio waveform in the time domain; others modify features in the frequency domain, and some combine both approaches. These methods can encode data, including identifiers linked to personal information.

These schemes are engineered to be robust. They can often survive compression or re-encoding.

These tools are already proliferating, and in fact they predated generative AI and the push to watermark generative media. The open source spymarking tool audiowmark originated in 2018 and can hide 128-bit payloads in audio and protect them with a secret AES key, preventing users without the key from decoding them.

You can even encode personal information invisibly into text! SynthID steers word choices to create a detectable statistical pattern that can encode a tracking payload.

## Watermarks are benign, spymarks are not

Watermarks remain easy for the user to spot and are typically not nefarious. Sometimes watermarks deter counterfeiting; sometimes they claim ownership; and sometimes they're just annoying. But these watermarks don't track you.

Printer tracking dots, on the other hand, are an early example of spymarks, dating back to the 1980s.

## Standardized, user-editable tags are not spymarks

We need to be clear that spymarks are a form of metadata you have limited knowledge of and control over, and that their purpose is entirely antagonistic to you.

Metadata such as the EXIF tags in photos and the ID3 tags in MP3 files are standardized, well-documented fields. While EXIF can expose sensitive data such as GPS coordinates, these standardized fields can be inspected, edited, and removed from files you control.

You can strip standard metadata tags out of your files. Unfortunately, a spymark signal embedded in pixels, audio, or word choices is invisible to you and can remain in your files even after you edit them.

Furthermore, whereas tags are helpful for maintaining information such as song titles or a photo's exposure settings, spymarks encode user-tracking identifiers that are entirely opaque and useless to you. These signals can survive metadata removal and some edits, allowing marked copies to remain traceable as they circulate.

## Keeping our files free of spying

It's hard to imagine the future where we can't even trust our own files. And the sad thing is that this has already started.

Spymarks are certainly not great for whistleblowers or anyone who doesn't want to be persecuted for their words or affiliations. No matter where you stand on whatever issues, spymarks can be used against you and those you care about.

Imagine a future where every device is attested and every social media post carries an account-linked spymark. Where every file or post served to you for sharing has spymarks embedded within. Combined with account records and observations of where copies appear, these identifiers can help reconstruct how content spreads. In this world, it would be dangerously easy to hunt down anyone from a JPEG or a tweet. Or track the web of humans through which "dangerous ideas" flow.

That future lies halfway between now and 1984. So let's stay off that timeline, shall we?

Call a spymark what it is. A spy tool used to spy on you and everyone you interact with.

— Brandon Thomas

## Usage

**spy·mark** /ˈspaɪmɑːrk/ *noun* — A hidden signal embedded in media to trace its origin, tools, or distribution history without the user's meaningful control.

**spymark** *verb, transitive* — To embed a spymark in a file or piece of media.

**spymarking** *noun* — The practice of embedding spymarks.

**spymarked** *adjective* — Containing a spymark.
