OpenAI is rolling out invisible watermarks for ChatGPT and Codex text in the EU and opening a detector to vetted researchers. The company is candid that the tech catches long, lightly edited writing far better than short answers.
Why OpenAI Is Watermarking Text Now
The EU AI Act requires providers of generative AI to make generated text identifiable in a machine-readable way. OpenAI published its approach on October 5 to meet that rule, and the timing is tied to Article 50, the transparency provision that applies from August 2, 2026, with a December 2, 2026 deadline for systems already on the market.
The plan has three parts. API customers worldwide can opt in to text watermarking for select models starting now, and it stays off by default. Over the coming weeks, OpenAI will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union. And the company is opening applications for its watermark detector, limited at first to approved researchers and expert organizations that can help evaluate reliability.
That last detail shapes how useful the system is in practice. Regular users and most platforms won't be able to check a passage themselves, at least not yet. Watermarking shows up on the output side. Verification stays behind a gate while OpenAI evaluates reliability.
How textGrain Embeds a Watermark in ChatGPT Text
OpenAI calls its method textGrain. It adds an invisible statistical signal to the words the model picks. Nothing about the sentence looks different to a reader. The detector, however, knows the pattern and checks whether a passage carries it.
Audio and image verification already work through public tools like the openai.com/verify page and the Content Provenance API, and those stay open to anyone. Text is the harder problem. There's no file to attach a signature to.
Where the Watermark Breaks Down
OpenAI is unusually direct about the limits. In its own evaluations, at a target false positive rate of 1%, the detector caught watermarks in about 80% of 200-token passages and about 95% of 400-token passages for content like psychology. Detection dropped sharply for math, where there's less freedom to choose words.
Editing weakens the signal fast. Across 400-token passages, replacing 10% of words with synonyms cut detection from roughly 92% to 66%. Swap a quarter and it falls to 17%.
Scenario | Detection rate |
|---|---|
200-token passage | about 80% |
400-token passage | about 95% |
400 tokens, 10% words swapped | about 66% |
400 tokens, 25% words swapped | about 17% |
The takeaway for anyone hoping to spot AI text: short answers, formula-heavy writing, and lightly paraphrased passages are exactly the cases where a watermark gives the least signal. OpenAI says it tested textGrain against other methods, including Google's SynthID for text, and that it matched or exceeded them under ideal conditions, while warning that strong lab performance doesn't guarantee reliable detection day to day.
What the Detector Means for Researchers and Readers
The detector matters because a watermark only helps if someone can read the signal. OpenAI is limiting early access to vetted researchers and expert organizations who can help test reliability and work out responsible uses.
There's a privacy angle worth naming. Provenance can confirm that someone leaned on an AI assistant, even in situations where that use is lawful, private, or commercially sensitive. A watermark can't tell whether writing is true, either. A human can write falsehoods. A model can produce accurate lines. All the signal does is hint at where text came from.
Is Text Watermarking Reliable Enough for the EU AI Act?
OpenAI frames text watermarking as an early technology with real limits, and its phased rollout reflects that. The opt-in default for API customers and the restricted detector access are both hedges, not oversights.
If you build on the API, watermarking is a switch you can flip, and it stays off unless you turn it on. If you're a ChatGPT user in the EU, expect the invisible mark to arrive in the coming weeks whether or not you notice it. For everyone else, the practical question is whether a signal that fades under light editing can carry the weight the law asks of it. OpenAI says it plans to open-source the technology so that others can build on it, test it independently, and help answer that question over time.






