Skip to content

AI·News & analysis

OpenAI will start invisibly watermarking ChatGPT text in the EU

To meet the EU AI Act, OpenAI is adding hidden watermarks to ChatGPT and Codex text in Europe, opening opt-in watermarking to API customers worldwide, and limiting its detector to approved researchers.

By Dan Kost aka Poseidan7 min read
The curved glass facade of the Berlaymont building in Brussels, headquarters of the European Commission, with three EU flags flying in front of it
Photo: Euro Pictures / Wikimedia Commons, CC BY 2.0

Tide

Ripple

Sci-fi

3/10

Reality

Shipping

ChatGPT's words now carry a secret signature you can't see.How we rate

The Squeeze

OpenAI is starting to hide invisible watermarks in ChatGPT and Codex text for users in the EU, to comply with the EU AI Act.

Developers anywhere can switch it on through the API. Only approved researchers can use the detector for now, and OpenAI warns that edits, short text and translations can make the watermark hard to find.

What to know

  1. OpenAI will add invisible watermarks to text from eligible ChatGPT and Codex users across all plans in the EU, in the coming weeks.
  2. API customers worldwide can now opt in to text watermarking for select models. It's off by default.
  3. The detector is limited to approved researchers and expert organizations for now, because of false positives and missed watermarks.
  4. The move responds to Article 50 of the EU AI Act, which requires AI-generated text to be identifiable by machines.

Text written by ChatGPT in Europe is about to carry a hidden signature. OpenAI said on Monday it will add invisible watermarks to text from eligible ChatGPT and Codex users in the European Union, to comply with the EU AI Act.

It's a notable shift. OpenAI built a text watermarking system years ago but held off releasing it widely.

What is OpenAI rolling out?

The plan has three parts, according to Unite.AI's summary of OpenAI's announcement:

  • ChatGPT and Codex in the EU: OpenAI will introduce text watermarking for eligible users across all plans in the European Union, in the coming weeks.
  • API, worldwide: from October 5, API customers anywhere can opt in to text watermarking for select models. The setting is off by default.
  • The detector: OpenAI opened applications for access to its text watermark detector, but only for approved researchers and expert organizations, granted case by case.

OpenAI is also working with cloud partners to offer watermarking for its models accessed through their services in the coming weeks.

Not a global default: OpenAI says it isn't turning on text watermarking everywhere at launch. A regional rollout lets it learn from real-world use and feedback first.

Why is it doing this?

The EU AI Act. Its Article 50 requires providers of generative AI to make generated text identifiable in a machine-readable way.

Those transparency rules have applied since August 2, 2026, Unite.AI reports. Existing systems got a transition window until December 2, 2026, according to Crypto Briefing.

OpenAI signed the EU's Code of Practice on Transparency of AI-Generated Content in June 2026, Crypto Briefing reports. The code was drawn up by independent experts in a process run by the EU's AI Office.

OpenAI describes text watermarking and detection as early technologies with significant limitations. Its phased approach reflects both the legal requirements and those limits, the company says.

How does the watermark work?

OpenAI's technology is called textGrain. It embeds an invisible statistical signal in the words a model picks. The detector then checks a passage for that signal, Unite.AI reports.

The short version: when the model chooses between words that fit equally well, a secret key nudges which ones it picks. Over enough text, that pattern becomes detectable, but only to someone with the key.

A technical report dated October 5 lists authors from the University of Pennsylvania, Yale University and OpenAI. The detector needs only the generated text and the secret key.

OpenAI plans to release the technology as open source, and says the report will be updated with more details in the coming weeks.

How well does it work?

Under good conditions, pretty well. Under real-world conditions, less so. OpenAI itself cautions that strong lab performance doesn't guarantee reliable detection in everyday use.

Detection rates at a 1% false positive rate, for topics like psychology:

  • About 80% of 200-token passages.
  • About 95% of 400-token passages.

Rates are substantially lower for subjects like mathematics, where word choice is less flexible.

Editing hurts: in tests on 400-token passages, replacing 10% of words with synonyms cut detection from about 92% to 66%. Replacing 25% of words cut it to 17%.

Quality impact: OpenAI says it saw no meaningful difference in performance with and without watermarking on the benchmarks it uses for Astra, its latest frontier model. On GPQA Diamond, for example, Astra scored 94.44% without watermarking and 93.94% with it.

OpenAI says textGrain matched or beat other approaches it tested, including Google's SynthID for text.

What can a watermark prove?

Less than people might hope. OpenAI is unusually clear about this.

A text watermark does not:

  • Measure how much a human contributed.
  • Establish ownership or responsibility.
  • Identify the user.
  • Verify whether the text is accurate.

And no watermark doesn't mean human-written. Text might be too short, edited or translated for reliable detection, come from an unsupported model, predate watermarking, or come from another company's tools, OpenAI says.

The detector will report only whether it finds an OpenAI watermark, without identifying the user or revealing their prompts or conversations. Because of the risk of missed watermarks and false positives, OpenAI isn't making it public at launch.

What does the law actually require?

Article 50 of the AI Act covers marking and detection of AI-generated content, plus labelling of deepfakes and certain AI-generated publications, Unite.AI reports.

The code is voluntary, the law isn't: signing the Code of Practice is optional, but Article 50's transparency requirements are legal obligations. The European Commission and the AI Board have confirmed the code is an adequate voluntary tool to show compliance. About 190 companies and organizations had signed it by the end of July 2026, according to the Commission.

The final code was published on June 10, 2026, Unite.AI reports.

Editing help is treated differently: Article 50 includes an exception where AI performs an assistive editing function without substantially changing the original material or its meaning, City AM reported.

Who's responsible: a provider can supply watermarking switches, but companies deploying the models still have to decide how to use them in their own products, Crypto Briefing notes. Many details are still being clarified, including how regulators will judge opt-in tools versus default watermarks.

What's next?

OpenAI says it will keep improving detection, study how watermarks hold up through editing and translation, and explore ways to tell AI assistance apart from AI authorship. It plans to widen access to the detector once it believes results can be interpreted responsibly, according to Unite.AI.

Why did OpenAI wait so long?

OpenAI's internal prototype was reported to be about 99.9% effective back in 2024, Crypto Briefing reports. But the company held back a broad release.

Two worries, according to Crypto Briefing:

  • Robustness: text is easy to paraphrase or run through another tool, and each edit weakens the signal.
  • Fairness: non-native English speakers who use AI to polish their writing could be unfairly flagged.

What are rivals doing?

Others moved faster, Crypto Briefing notes.

  • Google has offered SynthID-Text in Gemini since 2024.
  • Anthropic introduced invisible text watermarks in new Claude models starting August 2, 2026, the day Article 50 took effect. City AM reported that Anthropic applies the marking worldwide, not just in the EU.
  • xAI was the only major model maker that didn't sign the EU code, City AM reported, though Grok still has to follow applicable AI Act rules.

Images and audio from OpenAI already carry provenance signals, including C2PA metadata and SynthID watermarks, Crypto Briefing reports. OpenAI says its verification tools for audio and images, including its openai.com/verify web tool, stay publicly available.

What it means for you

  • In the EU: your ChatGPT and Codex text will soon carry an invisible watermark. It won't change how the text looks.
  • Developers: you can switch on text watermarking in the API now, which may help with your own EU obligations before the December deadline.
  • Teachers and employers: don't expect a public AI-text checker from OpenAI yet, and treat any detector result with caution.

The bottom line

OpenAI is adding invisible textGrain watermarks to ChatGPT and Codex text in the EU and letting developers worldwide opt in. It's a direct response to the EU AI Act. But OpenAI is clear the technology is limited: edits and short text weaken it, and a watermark says nothing about who did the work.

Key facts

Technology
textGrain, an invisible statistical watermark
ChatGPT and Codex
Watermarking for eligible EU users, all plans, coming weeks
API
Opt-in for select models worldwide, off by default
Detector
Approved researchers and expert organizations only
Why now
EU AI Act Article 50, in effect since August 2, 2026

Got questions?

Quick answers, plain words

What is OpenAI changing?

It will add invisible watermarks to text from eligible ChatGPT and Codex users in the European Union in the coming weeks, and lets API customers worldwide opt in to text watermarking for select models.

Will ChatGPT text be watermarked outside the EU?

Not by default. OpenAI says it isn't making text watermarking a global default at launch, so it can learn from real-world use first.

Can I see the watermark?

No. OpenAI's textGrain technology embeds an invisible statistical signal in the words the model chooses, according to Unite.AI.

Can anyone check if text is watermarked?

Not yet. Access to OpenAI's text detector is limited to approved researchers and expert organizations, granted case by case.

How accurate is the detector?

At a 1% false positive rate, it found watermarks in about 80% of 200-token passages and about 95% of 400-token passages in some topics, OpenAI reported. Results are much weaker for math and for edited text.

Does editing remove the watermark?

It weakens it. In OpenAI's tests, replacing 10% of words with synonyms cut detection from about 92% to 66%, and replacing 25% cut it to 17%.

Does watermarking make ChatGPT's answers worse?

OpenAI says it saw no meaningful difference on benchmarks for its Astra model with and without watermarking.

Does a watermark prove someone cheated?

No. OpenAI says a watermark doesn't measure human contribution, establish ownership, identify the user or verify accuracy. And a missing watermark doesn't prove a human wrote the text.

Do other AI companies watermark text?

Yes. Google has offered SynthID-Text in Gemini since 2024, and Anthropic began watermarking text in new Claude models on August 2, 2026, Crypto Briefing reports. xAI didn't sign the EU code, City AM reported.

SourcesOpenAI
Topics and tagsOpenAI, openai, chatgpt, eu ai act

The daily newsletter

Tech news you'll actually get.

One short email a day. Five minutes. Plain words. The daily email is launching soon. Join the early list.

Free. Early list: we'll email you when the first issue goes out.

More in brief