Short answer: yes — videos downloaded from Sora carry a visible moving watermark and C2PA Content Credentials metadata identifying them as AI-generated. But the more useful question is what those marks actually survive once a video leaves OpenAI's app — and the honest answer is: not much. Here's how the major AI generators mark their output, how those marks hold up in the wild, and what that means whether you're trying to spot AI content or protect your own.
How Sora marks its videos
- Visible watermark — downloads from the Sora app carry a moving Sora logo overlaid on the frame.
- C2PA metadata — a signed Content Credentials manifest identifying the video as AI-generated by OpenAI.
Both are stripped in practice. Within days of every Sora release, "Sora watermark remover" tools appear — visible overlays are a solved inpainting problem. And C2PA metadata is deleted by most social platforms on upload, or by a simple screen recording (why metadata dies on the social web). A Sora video that's been re-uploaded twice is usually indistinguishable, mark-wise, from any other video.
How Google does it: SynthID
Google's approach is closer to the robust end: SynthID, from DeepMind, embeds an invisible watermark into the pixels of images and video generated by its models. There's nothing visible to crop out, and it survives compression and modest edits far better than an overlay. Limitations: it only marks Google's own AI output, detection is largely restricted to Google's tools, and heavy re-editing or re-generation still degrades it. SynthID answers "did Google's AI make this?" — nothing else.
Why the marks keep getting stripped anyway
Regulation is pushing every major generator toward marking output — the EU AI Act's Article 50 requires machine-readable marking from August 2026 (our breakdown here). But enforcement targets providers, not the people stripping marks. So the practical reality stands: the presence of a mark proves AI origin, but the absence of a mark proves nothing. Anyone treating "no watermark" as "authentic" is reading the signal backwards.
The flip side: marking what's real
That asymmetry is the real lesson. You can't rely on AI companies marking their output to protect you — but you can mark your own originals. An invisible watermark in your published photos and video means that when a copy — cropped, re-encoded, or AI-modified — shows up somewhere, you can prove it started as yours. Same technology family as SynthID, opposite direction: instead of labeling the synthetic, you authenticate the real. That's exactly what HALLMARK.AI does, free, for your own content — and our public benchmarks show precisely which transformations it survives.