PolicyFeaturedBreakingType: news

OpenAI Will Add Invisible Text Watermarks to ChatGPT and Codex in the EU

OpenAI will add invisible textGrain watermarks to eligible ChatGPT and Codex text in the EU, while global API customers can opt in on select models.

AW
AI World Scope Editorial DeskSource-backed editorial coverage
October 6, 2026•6 min read
AI World Scope
Conceptual AI World Scope illustration of invisible OpenAI text watermarking passing through European AI-generated text and a detector.

Summary

OpenAI announced on October 5, 2026 that it will begin adding invisible text watermarks to eligible ChatGPT and Codex output in the European Union over the coming weeks, a direct response to machine-readable transparency requirements under the EU AI Act.

The system, called textGrain, embeds a statistical signal in a model's word choices. OpenAI says global API customers can opt in to watermarked output for select models starting now, while EU ChatGPT and Codex users across eligible plans will receive watermarking as the regional rollout proceeds.

OpenAI is also opening applications for its detector, but access will initially be limited to approved researchers and expert organizations because the company says detection remains imperfect and can degrade sharply after editing.

Quick Take

  • OpenAI will add invisible textGrain watermarks to eligible ChatGPT and Codex text output in the EU over the coming weeks.
  • Global API customers can opt in now for select models; watermarking remains off by default in the API.
  • OpenAI says its detector found the watermark in about 95% of 400-token passages in one tested content category at a 1% false-positive target, but performance varies by content.
  • Editing is a major weakness: replacing 25% of words with synonyms cut detection to 17% in one OpenAI evaluation.
  • The watermark does not prove authorship, ownership, accuracy, or who used the model.

What OpenAI is changing

The EU AI Act requires generative AI providers to make generated text identifiable in a machine-readable form. OpenAI's answer is a phased text-provenance system rather than a visible label attached to every response.

textGrain changes token selection in a way designed to leave a statistical pattern in generated text. A separate detector looks for that pattern and estimates whether an OpenAI watermark is present.

For users, the watermark is intended to be invisible. OpenAI says it does not associate the signal with a person's account, prompt, conversation, or identity.

The rollout has three parts: eligible EU ChatGPT and Codex text will receive watermarking over the coming weeks; global API customers can opt in for select models now; and approved researchers and expert organizations can apply for detector access.

OpenAI says it also plans to make the underlying technology available as open source.

Original-value analysis: provenance is a probability signal, not an AI lie detector

The biggest risk around watermarking may be users interpreting a detection result too strongly.

OpenAI explicitly says a watermark does not establish who wrote a document, how much a human contributed, whether use of the text was lawful, or whether the content is accurate.

QuestionCan textGrain answer it?
Does this passage contain a detectable OpenAI watermark?Sometimes
Was OpenAI involved somewhere in producing or processing it?A positive signal can support that inference
Was the whole document written by AI?No
Which user generated it?No
Is the text accurate?No
Does no watermark mean a human wrote it?No

This distinction matters for schools, employers, publishers, courts, and platforms. A watermark detector is a provenance signal with error rates, not a reliable binary test for "AI-written versus human-written."

Detection performance has a large editing problem

OpenAI published unusually concrete limitations.

At a target false-positive rate of 1%, the company says its detector identified watermarks in about 80% of 200-token passages and about 95% of 400-token passages for psychology-style content in its evaluation. Detection was substantially weaker for constrained domains such as mathematics, where models have less freedom in word choice.

Editing weakens the signal further.

In OpenAI's test of 400-token English passages, replacing 10% of words with synonyms reduced detection from roughly 92% to 66%. Replacing 25% reduced it to 17%.

Translation, rewriting, short passages, unsupported models, and content generated before the rollout can also make detection unreliable.

That is why OpenAI is not making the text detector publicly available at launch.

Original-value analysis: the EU rule creates an asymmetric provenance problem

Watermarking creates two very different evidence states.

A positive detection can be useful evidence that an OpenAI system likely participated in producing or processing a passage.

A negative detection is much weaker. It could mean the text was human-written, generated by another provider, created before watermarking, produced by an unsupported model, heavily edited, translated, too short, or simply missed by the detector.

This asymmetry has an important policy consequence: institutions should not build disciplinary or legal decisions around the assumption that "no watermark = human."

It also means watermarking works best as one layer in a broader provenance system rather than as a universal authorship test.

Does watermarking hurt model quality?

OpenAI says it does not see a meaningful performance difference between watermarked and unwatermarked output on the benchmark suite it uses to evaluate GPT-6 Astra.

The company's published table shows small movements in both directions across evaluations including AutomationBench, DeepSWE, Terminal-Bench, BrowseComp, HealthBench Professional, and GPQA Diamond.

Those are OpenAI's own measurements. Independent testing will be useful once watermarking reaches more real-world output.

How this fits with image and audio provenance

OpenAI already uses provenance mechanisms for supported image and audio output, including Content Credentials, C2PA-compatible metadata, SynthID watermarking, and verification tools.

Text is harder because ordinary editing can alter the statistical pattern without leaving obvious traces.

OpenAI therefore describes textGrain as one layer of a broader provenance strategy rather than a complete solution.

The company says its public image and audio verification tools will remain available even though initial text-detector access is restricted.

Why this matters beyond Europe

The immediate default rollout is regional, but the technical and policy effects are broader.

Global API customers can already opt in, and OpenAI says it is working with cloud partners to extend watermarking to model output delivered through their services.

If EU compliance normalizes machine-readable text provenance, other governments, enterprise procurement teams, education systems, and publishing platforms may begin asking AI providers for comparable controls even where law does not yet require them.

Anthropic has already announced text watermarking for Claude, making provenance an emerging platform feature rather than a one-company experiment.

AI World Scope take

The important development is not that AI-generated text has suddenly become reliably detectable. It has not.

The meaningful shift is that machine-readable provenance is moving from research into mainstream AI products because regulation now requires providers to operationalize it.

OpenAI's own numbers show why the distinction matters. textGrain can be strong on sufficiently long, lightly edited text and still become weak after ordinary rewriting.

The best way to understand the rollout is therefore as infrastructure for provenance, not proof of authorship.

For the EU AI ecosystem, that is still a major change: ChatGPT and Codex are about to begin carrying an invisible regulatory signal inside the text itself.

Sources & Documentation

Sources used for this article, with source type and publisher shown where available.

  • officialOur approach to EU text provenance rules
    Visit Source
  • newsOpenAI is adding text watermarking in ChatGPT and Codex
    Visit Source
AI World Scope Briefing

Stay ahead in AI

Join the list for selected AI news, model releases, comparisons and tool updates when new briefings are published.

Your email is stored for AI World Scope briefing delivery.