Menu

AI

OpenAI to watermark ChatGPT and Codex text in the EU: a regional rollout and its limits

To comply with the EU AI Act, OpenAI will embed an invisible watermark (textGrain) in EU ChatGPT and Codex text. How it works, where detection falls short, and uses for companies.

Published
Boil time
6 min
Language
English · 日本語

TL;DR

  • To comply with the EU AI Act, OpenAI will roll out an invisible watermark called "textGrain" in ChatGPT and Codex text in the EU over several weeks. Outside the EU it will not be on by default
  • For the API, users worldwide can opt in on supported models. It is off by default
  • The detector will not be public. It goes only to approved researchers and specialist organizations. For a 400-token text, replacing 10% of words with synonyms drops detection from about 92% to about 66%
  • No watermark does not prove a human wrote it. Anyone using this in internal document review or AI-use policies should start from that limit
Contents
  1. Where and when it applies
  2. How the watermark works
  3. How it differs from Anthropic’s
  4. For images and audio, detection tools are already public
  5. The limits of detection
  6. What companies should consider

On October 5, 2026, OpenAI announced that it will embed an invisible watermark in ChatGPT and Codex text in the EU. The EU AI Act requires providers of generative AI to make the text they generate machine-identifiable. The question is what a watermark can and can’t tell you. OpenAI itself has published detection rates and a list of “what the watermark does not show”, so I read from those.

Where and when it applies

In OpenAI’s announcement, scope and timing split three ways.

  • ChatGPT and Codex: EU users only, rolling out over several weeks on all plans. OpenAI says it is “not a global default”
  • API: users worldwide can opt in on supported models from the day of the announcement. It stays off by default
  • Detector: applications are open to approved researchers and specialist organizations. It is not public. According to The Verge, watermarking will also become available within weeks for OpenAI model output delivered through cloud partners

For now, text from people using ChatGPT outside the EU won’t carry a watermark. Companies building business systems on the API, on the other hand, can turn it on themselves, even outside the EU.

How the watermark works

OpenAI’s “textGrain” puts an invisible statistical signal into the bias with which the model chooses its next word. The detector looks for that signal to decide whether a text contains OpenAI’s watermark. It doesn’t add symbols or special characters, so the signal survives copy and paste. The watermark doesn’t identify the user and doesn’t include the prompt.

OpenAI set out the mathematical details in a report, “textGrain: Entropy-Calibrated Watermarking for Language Model Text”, published as a PDF the same day as the announcement. It is co-authored by five people at OpenAI and four researchers from the University of Pennsylvania and Yale University, and OpenAI says it will add content in the coming weeks.

In the report’s method, when the model chooses the next token (a word or part of one), the choice is tied to a pseudorandom number determined by a secret key and the preceding context. The tie is solved as an optimal transport problem. The stronger the tie, the more of the model’s range of choices (its entropy) is lost, so a cap (a budget) on how much may be lost sets the strength of the watermark. Splitting the vocabulary into blocks to cut computation is another feature. The detector needs only the text and the key, and doesn’t need to know the generation-time cap. The bias is small for each token, and the longer the text, the more it adds up and the easier it is to detect. OpenAI also plans to release the technique as open source.

How it differs from Anthropic’s

OpenAI calls its method “on par or better” compared with Google DeepMind’s SynthID for text. The Claude watermark Anthropic announced in August also uses the SynthID text method. The source of randomness for choosing the next word is derived from a key and the previous few words, and no characters or extra tokens are added. The two companies differ in their approach.

  • Where it applies: Anthropic applied it to Claude worldwide from the start, saying it has no way yet to split by region. OpenAI limits it to ChatGPT and Codex in the EU
  • Detector: Anthropic plans a detection API. OpenAI offers its detector only to approved researchers and specialist organizations
  • What is hard to watermark: Anthropic says watermarks are hard to embed in facts with a single answer and in code that needs to be exact. In OpenAI’s detection figures too, content with little freedom of phrasing, such as math, has lower detection rates

Both share the trait that detection becomes less reliable as the text gets shorter and as editing or translation is applied.

On quality impact, OpenAI compared benchmark results for its latest model, Astra, and says there was no big difference with or without a watermark. For example, the Artificial Analysis Intelligence Index is 49.57 without a watermark and 49.76 with.

For images and audio, detection tools are already public

OpenAI started on provenance for images and audio before text. Supported images carry Content Credentials (C2PA), images and audio get a SynthID watermark, and anyone can check at openai.com/verify and through the Content Provenance API. Metadata can be stripped, so the explanation is that it is combined with a watermark. Anthropic’s approach of attaching signed C2PA metadata to PNG, JPG and SVG follows the same idea. Text can’t carry metadata and is easy to rewrite or translate, so a detector hasn’t been made public the way it has for images and audio.

The limits of detection

OpenAI gives the limits of detection in numbers. These are with the false positive rate set to 1%.

ConditionDetection rate
200-token text (psychology topic)about 80%
400-token text (same)about 95%
400 tokens, 10% replaced with synonymsabout 92% to about 66%
400 tokens, 25% replaced with synonyms17%

For content with little freedom of phrasing, such as math, detection rates are lower still. OpenAI also writes that translated text is hard to detect.

The announcement also includes a list of what a watermark “does not show”.

  • It doesn’t show how much a human was involved
  • It doesn’t show who owns the text, whether its use is lawful, or who is responsible
  • It isn’t linked to the user or the prompt
  • It doesn’t show whether the content is accurate
  • Not finding a watermark does not prove a human wrote it. Output that is short, edited, translated, from an unsupported model, or from another company’s AI may go undetected

What companies should consider

On the EU regulatory side, obligations such as watermarking began to apply on August 2, 2026. The final Code of Practice consists of marking and detection rules for providers and disclosure rules for users (deployers). Signing the Code of Practice is voluntary, but the watermarking obligation in Article 50 of the AI Act is itself legally binding. According to an explainer on the draft, the draft held that no single technique is enough and took a multi-layer approach to marking. In addition to watermarks and metadata, it listed logging output and fingerprint matching where needed. It also asked those who publish AI-written text of public interest to disclose that fact.

Here is what this announcement lets those on the using side review.

  • If you build your own product on the API: decide how you will meet your transparency obligations toward your own users, and whether to use the opt-in. OpenAI says customers can decide how to build it into their transparency obligations
  • If you want to tell internally whether text was written by AI: the detector isn’t public, and editing or translation sharply lowers detection. A process that decides on the presence of a watermark alone doesn’t hold up
  • In settings that evaluate people, such as reviewing students’ or applicants’ writing: whether or not a watermark is detected, that alone doesn’t show cheating. OpenAI itself says a watermark shows neither how much a human was involved nor whose text it is

A watermark is only one clue to where a text came from. The first things to check are whether the API models you use are in scope, and whether the opt-in setting has been left at its default of off.

udon
Microsoft 365, ServiceNow, Copilot and more, tested first-hand and written up as practical notes with real bite.