Short answer: yes — videos downloaded from Sora carry a visible moving watermark and C2PA Content Credentials metadata identifying them as AI-generated. But the more useful question is what those marks actually survive once a video leaves OpenAI's app — and the honest answer is: not much. Here's how the major AI generators mark their output, how those marks hold up in the wild, and what that means whether you're trying to spot AI content or protect your own.
How Sora marks its videos
- Visible watermark — downloads from the Sora app carry a moving Sora logo overlaid on the frame.
- C2PA metadata — a signed Content Credentials manifest identifying the video as AI-generated by OpenAI.
Both are stripped in practice. Within days of every Sora release, "Sora watermark remover" tools appear — visible overlays are a solved inpainting problem. And C2PA metadata is deleted by most social platforms on upload, or by a simple screen recording (why metadata dies on the social web). A Sora video that's been re-uploaded twice is usually indistinguishable, mark-wise, from any other video.
How Google does it: SynthID
Google's approach is closer to the robust end: SynthID, from DeepMind, embeds an invisible watermark into the pixels of generated images and video. There's nothing visible to crop out, and it survives compression and modest edits far better than an overlay. As of May 2026 it is no longer Google-only: OpenAI joined the C2PA steering committee and now embeds SynthID alongside Content Credentials in images from ChatGPT, Codex, and its API, which makes SynthID something close to a cross-vendor default. Limitations remain: it marks generated output only, and heavy re-editing or re-generation still degrades it. SynthID answers "did an AI make this?" — nothing else. We looked at how well it actually holds up, and where it misreads in a separate piece.
Why the marks keep getting stripped anyway
Regulation is pushing every major generator toward marking output — the EU AI Act's Article 50 requires machine-readable marking from August 2026 (our breakdown here). But enforcement targets providers, not the people stripping marks. So the practical reality stands: the presence of a mark proves AI origin, but the absence of a mark proves nothing. Anyone treating "no watermark" as "authentic" is reading the signal backwards.
The flip side: marking what's real
That asymmetry is the real lesson. You can't rely on AI companies marking their output to protect you — but you can mark your own originals. An invisible watermark in your published photos and video means that when a copy — cropped, re-encoded, or AI-modified — shows up somewhere, you can prove it started as yours. Same technology family as SynthID, opposite direction: instead of labeling the synthetic, you authenticate the real. And as producer-side marking becomes standard across Google and OpenAI, the gap only gets starker — generated content is increasingly labeled at birth, while the authentic photo you shot yourself carries no mark at all unless you add one. That's exactly what HALLMARK.AI does, free, for your own content — and our public benchmarks show precisely which transformations it survives.