
OpenAI says it will begin watermarking eligible ChatGPT and Codex text for users in the European Union over the coming weeks. The statistical marker is a provenance signal, not a definitive test of authorship, and editing can weaken it.
OpenAI plans to roll out textGrain, an invisible statistical marker, to eligible text generated by ChatGPT and Codex for users in the European Union. The rollout is expected over the coming weeks and will cover eligible users across all plans. The company is not making text watermarking a global default at launch. Separately, from October 5, API customers worldwide can opt in to watermarking for select models.
The move comes as Article 50(2) of the EU AI Act requires providers of generative AI systems to mark generated or manipulated content, including text, in a machine-readable format so it can be detected as AI-generated or altered. The provision does not prescribe watermarks specifically. The European Commission says technical measures should be effective, interoperable, robust and reliable as far as technically feasible. The transparency obligations have applied since August 2, 2026.
OpenAI says textGrain does not insert hidden characters or watermark-specific tokens. Instead, generation subtly influences the model’s word choices, creating a statistical pattern that a detector can later analyse. A technical paper released with the announcement says the method uses a secret key and preceding context to influence token selection.
In OpenAI’s tests on psychology-related material, the detector found watermarks in about 80% of 200-token passages and 95% of 400-token passages, at a target false-positive rate of 1%. Performance was substantially lower for mathematics, where word choice is less flexible. Editing also weakened the signal: in 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%; replacing 25% cut it to about 17%.
OpenAI plans to restrict access to its detector initially to approved researchers and expert organisations. The tool will indicate whether an OpenAI watermark was detected, but will not identify a user or reveal prompts or conversations.
The company cautions that the watermark is a provenance signal, not a conclusive AI-authorship test. It cannot measure how much human judgement, editing or creativity went into a passage, establish ownership or responsibility, identify who generated it, or determine whether it is accurate. Nor does a missing watermark prove that a person wrote the text: detection can fail when content is short, edited or translated, comes from an unsupported model, predates watermarking, or was generated by another AI system.
EU rules separately require deployers to clearly label certain AI-generated or manipulated text published to inform the public about matters of public interest. OpenAI says it plans to release textGrain as open-source technology and sees text watermarking as one part of a broader provenance system. For images and audio, it uses technologies including C2PA-based Content Credentials and invisible SynthID watermarks, alongside verification tools. The company says no single provenance technique is sufficient on its own.
