OpenAI Watermarks ChatGPT Text in EU: textGrain Explained

Manishraj Yadav
By -
0

OpenAI will start watermarking ChatGPT text in the EU, using a new system called textGrain that invisibly tags AI-generated words so a detector can spot them later. Announced on October 5, 2026, the move responds to the European Union's AI Act transparency rules — and OpenAI is blunt that the technology has serious limits.

ChatGPT app open on a smartphone — OpenAI is rolling out textGrain text watermarking for ChatGPT and Codex users in the EU
ChatGPT on a smartphone. OpenAI's textGrain watermarking rolls out to ChatGPT and Codex in the EU over the coming weeks. Credit: Jernej Furman (CC BY 2.0), via Wikimedia Commons.

The rollout has three parts. First, watermarking will be added automatically to text generated by ChatGPT and Codex inside the European Union, "over the coming weeks," across all plans, with no opt-out. Second, OpenAI will offer opt-in watermarking for select API models worldwide, starting October 5, 2026, off by default — including through cloud partners like Microsoft Azure. OpenAI says it is not making watermarking a global default at launch. Third, detector access is restricted: applications opened October 5, but only approved researchers and expert organizations get in, decided case by case.

How textGrain works

The watermark lives in the words themselves. Using a secret key, textGrain subtly influences which words the model picks during generation — biasing next-word predictions in a pattern only a detector holding the same secret key can spot. There are no hidden characters, Unicode tricks, or metadata stamps: the signal travels with the text even when it is copied and pasted.

OpenAI published a technical report co-written with researchers from the University of Pennsylvania and Yale, and says it plans to open-source the underlying technology. In OpenAI's tests, textGrain matched or beat alternatives — including Google DeepMind's SynthID for text — and benchmark scores showed no meaningful drop in model performance for watermarked output.

OpenAI CEO Sam Altman, whose company announced the textGrain watermarking rollout for ChatGPT in October 2026
OpenAI CEO Sam Altman. OpenAI framed the move as expanding its content-provenance approach in response to EU regulatory requirements. Credit: Office of the Prime Minister of Japan (CC BY 4.0), via Wikimedia Commons.

The catch: detectors are easy to fool

OpenAI's own numbers show the limits. Replacing just 10% of the words with synonyms dropped detection accuracy from around 92% to 66%. Detection is also length-dependent: the detector catches about 80% of watermarked text at roughly 200 tokens, and about 95% at 400 tokens. Short passages, math answers, and translated text are harder to detect — and simple editing weakens the signal.

OpenAI cautions that "strong performance under ideal conditions does not guarantee reliable detection in everyday use." A watermark can indicate that an OpenAI system generated or processed part of a passage, but it cannot identify the user, reveal prompts or conversations, or prove anything about who contributed what. A negative result does not prove a human wrote the text.

Why the EU forced the issue

The EU AI Act's transparency obligations (Article 50) took effect on August 2, 2026, requiring providers of AI systems that generate synthetic content to mark outputs in a machine-readable, detectable way. Providers of pre-existing systems have until December 2, 2026 to comply.

OpenAI is following Anthropic's lead: Anthropic released watermarking for Claude text in August 2026 — globally, mandatory, no opt-out — while OpenAI chose EU-mandatory plus global opt-in. The Code of Practice on transparency now has roughly 190 signatories, including Google, Meta, Microsoft, Anthropic, and OpenAI.

The takeaway

Watermarking is here, but it is a provenance tool, not a plagiarism detector. For EU ChatGPT users, AI text will soon carry an invisible signature — and for everyone else, the signal can be weakened by rewriting a few words. As detectors stay locked behind researcher approvals, the real question is whether marking AI text can survive contact with the open internet.

Watch: Explainer: how AI text watermarking from OpenAI, Google and Anthropic actually works under the hood — and where detection breaks down

Music in this post's reel: Kevin MacLeod - Electrodoodle (incompetech.com), licensed under CC BY 3.0

Sources

Tags:

Post a Comment

0Comments

Post a Comment (0)