You can reveal it later when you come up with a new mechanism and out all the fake images. Basically the first layer is first defence, second layer is cleanup when releasing a new mechanism. That way your generated images will always be identifiable eventually.
Of course if you need to regenerate the image with an unwatermarked image-generation model to remove it, it more or less still serves its purpose.