September 22, 2026

Spymarks: The Hidden Signals in Your Files

A new article from brand.io proposes a simple but powerful idea: stop calling hidden tracking signals "watermarks." Call them spymarks. The distinction matters because the word "watermark" obscures what is actually happening to your files[1].

What is a spymark?

A watermark is a visible mark embedded in a medium to verify authenticity or assert ownership. You can see it. You know it is there. A spymark is different. It is a hidden signal that makes your work traceable without your knowledge or consent[1].

Google's SynthID is the most prominent example. It embeds signals "imperceptible to humans" (Google's own words) into images, audio, text, and video. The SynthID-Image system can encode a 136-bit payload in a 512x512 pixel image. That is enough room for a 64-bit database identifier, with 72 bits left for error correction. That identifier can map to your user records, full name, IP addresses, date of birth, physical address, political affiliation, and more[1].

SynthID is not alone. OpenAI and many other tech companies are developing similar systems at scale. The article notes that these companies claim spymarking helps identify AI-generated content, but they have gone far beyond simple watermarking and built robust tracking mechanisms into everything you publish[1].

It is not just images

Audio spymarks operate using principles similar to image spymarks and are typically inaudible. Some methods make minute changes to the audio waveform in the time domain. Others modify features in the frequency domain. Some combine both. These schemes are engineered to be robust and can often survive compression or re-encoding[1].

Text can carry spymarks too. SynthID steers word choices to create a detectable statistical pattern that can encode a tracking payload. Eight word choices can represent eight bits. A binary value mapped to a database ID can point to a record containing an author and timestamp[1].

The open source tool audiowmark, originating in 2018, can hide 128-bit payloads in audio and protect them with a secret AES key, preventing users without the key from decoding them. This technology predates the generative AI watermarking push[1].

Why the name matters

The article's core argument is linguistic. "Watermark" has become a catchall term that covers historical marks of authenticity, banknote security features, copyright overlays, and hidden tracking signals. That last usage obscures the privacy risk[1].

By introducing the word "spymark," the privacy concern is built into the term itself. "Spy" implies clandestine surveillance and involuntary disclosure. "Mark" implies an embedded signal. The name collapses a complex technical conversation into a single word that communicates the risk[1].

The Hacker News debate

The HN discussion (428 points, 108 comments) raised several technical points. One commenter noted that spymarks are an application of steganography, not a different name for it. Steganography is the broader field of hiding information within other information. Spymarks are steganography applied to user tracking[2].

Another commenter suggested a simple defense: "I'm pretty sure that the simplest Gaussian blur will remove the spymark from any picture. Or add some noise. Just align the last bit of every pixel channel with a random bit sequence." This may work for some image-based spymarks, but the more robust systems are designed to survive exactly this kind of manipulation[2].

The discussion also touched on social media platforms. Facebook already embeds custom metadata tags so images shared outside the platform can be traced back. Social media re-compression of uploaded images and videos is a door to tracking that is far too easy for platforms to open[2].

One commenter raised a darker possibility: low-level display drivers that constantly scan for spymarks and phone home with attribution data. "First the low-end laptops and phones will incorporate some low-level driver that is constantly scanning for these and passing them to a helper app to phone home"[2].

What you can do

Standard metadata like EXIF tags in photos and ID3 tags in MP3 files can be inspected, edited, and removed. But a spymark signal embedded in pixels, audio waveforms, or word choices is invisible to you and can remain in your files even after you edit them. Metadata removal does not remove spymarks[1].

The article ends with a warning: "Spymarks are certainly not great for whistleblowers or anyone who doesn't want to be persecuted for their words or affiliations. No matter where you stand on whatever issues, spymarks can be used against you and those you care about"[1].

Sources

[1] brand.io: "Spymarks, Not Watermarks" (September 2026)

[2] Hacker News discussion: "Spymarks, Not Watermarks" (428 points, 108 comments)

← Back to all posts