When people talk about "AI image labels," they're usually describing one of two fundamentally different techniques — and confusing them leads to a lot of misplaced confidence about what actually survives sharing a photo around.
This is a standardized, cryptographically-signed manifest embedded in a file's metadata, recording claims like which tool generated an image and what edits followed. It's human-inspectable — you can open a file's metadata and read it directly — and it's an open standard adopted across a growing number of generators and editing tools.
Its weakness is exactly what makes it readable: because it lives in metadata, it's removed by anything that strips or rewrites metadata — a re-save, a screenshot, many social platforms' own upload pipelines, or a one-click metadata tool.
Techniques like Google's SynthID work differently: instead of adding a metadata tag, they alter the pixel values themselves in a way that's imperceptible to the eye but detectable by a matching algorithm. Because the signal lives in the image data rather than a separate metadata block, it tends to survive things that destroy metadata outright — cropping, recompression, format conversion, screenshotting to a reasonable degree.
Its weakness is the opposite of C2PA's: it's not human-readable. You can't open a file and "see" the watermark; only the company's own detection tool can check for it, and that tool usually isn't publicly available in the same way a metadata viewer is.
Neither is complete on its own. Metadata is transparent but fragile; watermarking is durable but opaque and requires trusting a single company's detector. Using both gives a human-readable claim for images that haven't been touched, and a fallback signal for the ones that have.
You can inspect whatever metadata-based credentials a file actually carries with Nullframe's View mode — it won't detect proprietary pixel watermarks, but it will show you the full C2PA/EXIF/XMP picture.