OpenAI Will Start Watermarking ChatGPT Text in the EU
OpenAI said Oct. 5 it will add an invisible watermark to eligible ChatGPT and Codex text in the EU over the coming weeks. API customers anywhere can opt in now. The detector is limited to approved researchers.
So basically: OpenAI said on Monday, Oct. 5, that it will start hiding an invisible watermark in ChatGPT and Codex text for users in the European Union over the next few weeks, because EU law now says AI text has to be marked in a way machines can read.
What is changing
API customers anywhere in the world can now opt in to text watermarking for select models. It stays off by default.
Over the coming weeks, eligible ChatGPT and Codex text in the EU gets an invisible watermark. OpenAI says that covers all plans. Outside the EU, ChatGPT is not changing for now.
OpenAI opened applications for its watermark detector. At first, only approved researchers and expert groups get in, case by case.
Image and audio checks are not part of this. OpenAI’s openai.com/verify tool and its Content Provenance API stay public.
How it works
The system is called textGrain. It nudges which words the model picks in a way you can’t see, and that leaves a statistical pattern. The detector looks for that pattern.
The detector only needs the text and a secret key. OpenAI says it reports whether its watermark is there, and it does not identify the user or reveal prompts or chats.
The technical report is dated Oct. 5 and lists authors from the University of Pennsylvania, Yale, and OpenAI. OpenAI says it plans to release the tech as open source.
The numbers
OpenAI was upfront that this is far from perfect. At a 1% false positive target, the detector caught about 80% of 200-token passages and about 95% of 400-token passages on topics like psychology. It did a lot worse on math, where there are fewer ways to word things.
Editing hurts it fast. In 400-token tests, swapping 10% of the words for synonyms dropped detection from about 92% to 66%. Swapping 25% dropped it to 17%.
OpenAI says the watermark did not hurt quality. On Astra, which it calls its latest frontier model, GPQA Diamond went from 94.44% without the watermark to 93.94% with it. The Artificial Analysis Intelligence Index score went from 49.57 to 49.76.
OpenAI also says textGrain matched or beat the other methods it tested, including Google’s SynthID for text.
Why the EU
Article 50 of the EU AI Act covers marking AI-generated content and labeling deepfakes. Those rules apply from Aug. 2, 2026.
The European Commission published a final Code of Practice on transparency of AI-generated content on June 10. Signing the code is voluntary. The Article 50 duties are not. The Commission and the AI Board say the code is an adequate way to show you comply.
What a watermark can’t tell you
OpenAI lists the limits itself.
A hit does not show how much a person edited or added. It does not say who owns the text or who is responsible for it. It does not say whether the text is accurate.
A miss does not prove a human wrote it. The text could be too short, edited, translated, made by an older or unsupported model, or made by another company’s tool.
That’s a big reason the detector isn’t public yet. OpenAI says it will widen access once results can be read responsibly.
My take
This is a careful rollout. OpenAI put the watermark where the law requires it, kept it off by default everywhere else, and published numbers that show how easy it is to break. Swap a quarter of the words and it mostly disappears. So it will catch straight copy and paste, and not much more. Keeping the detector away from schools and bosses for now is smart, because a 1% false positive rate is a lot of wrongly accused people at scale. One company’s watermark only covers one company’s text, so this only really matters once the other big model makers do the same.
So basically — pass it on.