On October 5, OpenAI announced one of the most consequential changes yet to the way AI-generated writing can be identified: eligible text produced by ChatGPT and Codex in the European Union will soon carry an invisible statistical watermark.
The technology, called textGrain, does not insert a visible label, metadata tag, or obvious marker into a document. Instead, it influences the model’s word choices in ways designed to leave a statistical pattern that OpenAI’s detector can recognize later.
The rollout is a response to transparency requirements under the European Union’s AI Act. Starting October 5, API customers worldwide can opt in to watermarking for selected models, while OpenAI says eligible ChatGPT and Codex output in the EU will receive watermarking over the coming weeks. API watermarking remains off by default. OpenAI
The development could eventually affect publishers, universities, software companies, compliance teams, AI developers and anyone attempting to determine whether a document originated from a generative AI system.
But the most important part of OpenAI’s announcement may be what the company says the technology cannot do.
A detected watermark does not establish who wrote a document, how much of it was written by a human, whether its contents are accurate, or whether using AI was appropriate. And failing to detect a watermark does not establish that a human wrote the text.
Those limitations make text watermarking potentially useful infrastructure for AI provenance — but not an AI-authorship test.
What OpenAI is actually changing
OpenAI’s rollout has three distinct components.
First, API customers around the world can opt into text watermarking for supported models. The feature is not being enabled automatically for API applications.
Second, OpenAI plans to introduce watermarking for eligible ChatGPT and Codex users across all plans in the European Union. Unlike the API implementation, this is intended to become part of eligible EU output rather than a developer-selected option.
Third, OpenAI is making its watermark detector available initially only to approved researchers and expert organizations rather than releasing an unrestricted public detector. OpenAI
That last decision is significant.
The usefulness of a watermark depends not merely on inserting a signal but on how reliably that signal can later be detected. OpenAI acknowledges that false positives and false negatives remain possible, and that detection performance changes considerably depending on the length and nature of a passage.
A detector released without those caveats could easily be misused as a binary “AI or human” test.
OpenAI is explicitly warning against that interpretation.
How textGrain works
Traditional digital watermarks are easy to understand in images: information can be encoded into pixels in ways that are difficult for a viewer to notice.
Text is considerably harder.
A paragraph has no equivalent of millions of image pixels that can be subtly modified. Alter the words too aggressively and the writing itself changes.
textGrain instead creates what OpenAI describes as an invisible statistical signal in the model’s word choices. Its detector subsequently examines a passage for evidence of that pattern. OpenAI
This distinction matters because the watermark is part of the generated language rather than simply an attached file attribute.
Removing document metadata, copying text into another application or changing a file format therefore isn’t equivalent to stripping conventional metadata from an image.
However, the technique creates another vulnerability: editing the words can degrade the signal.
And OpenAI’s own results show just how quickly that can happen.
OpenAI’s tests expose the biggest limitation
In OpenAI’s evaluations, detection reliability increased substantially as passages became longer.
At a target false-positive rate of 1%, the company says its detector recognized watermarks in roughly 80% of 200-token passages and approximately 95% of 400-token passages for material such as psychology answers.
Performance was considerably weaker on material such as mathematics, where models have less freedom in choosing alternative wording. OpenAI
That already means watermark detection isn’t uniform across different types of writing.
Editing introduces a bigger problem.
In one OpenAI evaluation involving 400-token passages, replacing 10% of words with synonyms reduced detection from roughly 92% to 66%.
Replacing 25% of the words reduced detection to just 17%. OpenAI
Those figures illustrate the central technical challenge facing text watermarking.
The more freely a model can choose among plausible words, the more room there is to encode a statistical signal. But the same flexibility allows subsequent rewriting, translation or editing to disturb that pattern.
A sufficiently transformed AI-generated passage can therefore become increasingly difficult to identify.
Why this is different from an AI detector
AI-detection products have historically attempted to infer whether text looks machine-generated by examining properties of the writing.
Watermark detection is conceptually different.
Instead of guessing authorship from prose characteristics, a watermark detector searches for a signal deliberately introduced during generation.
That can provide a stronger form of provenance when the signal survives.
It still does not answer the broader question many people actually want answered: “Was this written by AI?”
Consider a writer who generates a 1,000-word draft with ChatGPT, rewrites half of it, adds original reporting and changes the structure.
A watermark detector might still find a signal.
That result would indicate involvement by a compatible OpenAI system. It would not quantify the human contribution.
Now consider the opposite case: someone generates text with AI and heavily rewrites it.
The watermark could become undetectable.
An unsuccessful detection therefore cannot establish human authorship either.
OpenAI specifically states that its watermark does not measure human contribution, establish ownership or responsibility, identify the user, or verify the accuracy of the underlying text. OpenAI
These distinctions will be crucial for schools, publishers and employers.
Treating a watermark result as proof of misconduct would go substantially beyond what the technology actually establishes.
The EU AI Act is driving the change
The immediate reason for the rollout is regulation.
Article 50 of the EU AI Act establishes transparency obligations around synthetic content. The European Commission says providers of systems generating synthetic audio, images, video or text must ensure applicable AI-generated or manipulated content is marked in a machine-readable format and detectable as artificially generated or manipulated. Estratégia Digital Europeia
The transparency rules began applying on August 2, 2026.
There is, however, an important transition provision. According to the Commission, AI systems placed on the market before August 2, 2026 have until December 2, 2026 to comply with the Article 50(2) marking and detection requirement. Content created before August 2 does not have to be labelled retroactively. Estratégia Digital Europeia
That helps explain the timing of OpenAI’s October rollout.
The Commission has also developed a voluntary Code of Practice intended to provide practical guidance for compliance. The final code was published in June 2026. Estratégia Digital Europeia
The broader regulatory objective goes beyond OpenAI. Europe is attempting to establish a technical provenance layer across generative AI systems rather than relying entirely on visible disclaimers or users voluntarily declaring that content came from AI.
Not every piece of AI-generated text is treated identically
There is another nuance frequently lost in discussions of the EU rules.
The Commission’s guidance identifies outputs that can fall outside Article 50’s marking requirements, including source code, certain short sequences of characters, machine-to-machine output and some content used solely inside closed-loop industrial or product-development environments.
The marking requirement also does not apply when an AI system merely performs an assistive function for standard editing. Estratégia Digital Europeia
There is also an important distinction between obligations imposed on AI providers and those imposed on people or organizations deploying AI-generated content.
Providers face requirements around machine-readable marking.
For deployers, the Commission says transparency requirements cover areas including deepfakes and AI-generated or manipulated text concerning matters of public interest when it is published without human review or editorial control. Estratégia Digital Europeia
In other words, “AI transparency” under the Act is not a single rule requiring every AI-assisted sentence on the internet to carry the same visible warning.
Will watermarking make ChatGPT worse?
One obvious concern is whether forcing a model to favor certain word choices for watermarking could degrade output quality.
OpenAI says its evaluations have not found a meaningful performance difference.
The company tested watermarked and non-watermarked output from its Astra model across benchmarks covering areas including software engineering, automation, science, browsing, health and general reasoning. Scores moved slightly in both directions rather than showing a consistent decline attributable to watermarking. OpenAI
Benchmark results do not prove that users will never notice differences in real-world writing.
Watermarking inherently introduces an additional constraint on generation, and stylistic effects may not be fully represented by technical benchmarks.
Still, OpenAI’s published results provide no evidence so far of a broad capability penalty.
That makes durability, rather than raw model performance, the more important unresolved issue.
Translation and rewriting remain fundamental problems
A robust provenance system needs to survive the way people actually use text.
That includes copying, editing, shortening, expanding, translating and combining passages from multiple sources.
Statistical text watermarks face difficulty precisely because these operations alter the medium carrying the signal: the words themselves.
A translated article, for example, may preserve nearly all of the original meaning while replacing virtually every original word.
A human editor can do something similar through substantial rewriting.
And future AI systems could make large-scale paraphrasing trivial.
This means watermarking is unlikely to become a universal forensic mechanism that can reliably reconstruct the origin of every piece of text.
It is better understood as one signal in a larger provenance architecture.
Why OpenAI isn’t releasing the detector to everyone
Restricting the detector may initially seem counterproductive. If transparency is the goal, why not let anyone test a document?
Reliability is one reason.
If an unrestricted detector were widely treated as an authoritative AI-authorship test, false positives could have serious consequences for students, employees, journalists and writers.
False negatives would create the opposite problem by allowing users to interpret “no watermark detected” as evidence of human authorship.
OpenAI says detector access will initially go to approved researchers and expert organizations so they can help evaluate the system and its responsible use. The detector will indicate whether an OpenAI watermark is detected but will not identify the user or expose prompts or conversations. OpenAI
There is also a security dimension to watermarking systems generally: the more attackers understand about a detector and its decision boundaries, the easier it may become to optimize text specifically to evade it.
OpenAI says it plans to make textGrain available as open source eventually, meaning that tension between transparency, research and adversarial robustness will become especially important.
What developers should pay attention to
For developers using OpenAI’s API, the immediate change is optional rather than mandatory globally.
That creates a product decision.
Applications operating in regulated environments may value machine-readable provenance enough to enable watermarking proactively. Other developers may prefer to wait until they better understand detection reliability, interoperability and the regulatory requirements affecting their particular application.
Organizations should also avoid assuming that enabling an OpenAI watermark automatically satisfies every AI Act obligation relevant to their product.
Compliance depends on the role of the organization, how the AI system is deployed, what content is produced and which transparency provisions apply.
The European Commission’s own guidance should therefore be treated as the regulatory reference point rather than a model provider’s product feature alone. Estratégia Digital Europeia
What publishers, schools and employers should take from this
The arrival of model-native text watermarking could tempt organizations to turn detection into an enforcement shortcut.
That would be a mistake.
The technically defensible interpretation is narrower:
A positive result can provide evidence that a compatible OpenAI system generated or processed text carrying the detectable signal.
It does not reveal the degree of human involvement.
And:
A negative result means the detector did not find a sufficiently strong watermark signal.
It does not prove that AI was absent.
This distinction should influence any policy built around these systems.
Universities, publishers and employers would be better served by combining provenance signals with evidence such as revision history, sourcing, citations, workflow records and human review rather than treating a single detector score as a verdict.
Text provenance is becoming infrastructure
The larger story here is not simply that ChatGPT is getting a watermark.
Generative AI is moving from an era in which provenance was largely optional to one where provenance mechanisms are increasingly becoming part of the infrastructure surrounding content creation.
Images and video have received much of the attention because manipulated media can be visually persuasive and because standards such as content credentials can travel with media files.
Text presents a more difficult problem.
It is extraordinarily portable. It can be copied into plain text, pasted into a messaging app, translated, summarized, dictated, printed and retyped while preserving its underlying meaning.
There may therefore never be a single technological solution that makes the origin of arbitrary text perfectly recoverable.
OpenAI’s own detection results reinforce that conclusion.
textGrain appears capable of producing a detectable signal under favorable conditions, particularly with longer and relatively unedited passages. But its effectiveness declines sharply when the text is transformed.
That does not make watermarking useless.
It means its value needs to be understood correctly.
The most realistic future is probably one in which watermarking operates alongside cryptographic provenance, platform metadata, disclosure requirements and human editorial processes rather than replacing them.
OpenAI’s EU rollout is an important test of whether that layered approach can work at enormous scale.
And because millions of people interact with generative AI every day, the lessons from that experiment could influence how AI-generated text is identified far beyond Europe.

Ingrid Maldine is a business writer, editor and management consultant with extensive experience writing and consulting for both start-ups and long established companies. She has ten years management and leadership experience gained at BSkyB in London and Viva Travel Guides in Quito, Ecuador, giving her a depth of insight into innovation in international business. With an MBA from the University of Hull and many years of experience running her own business consultancy, Ingrid’s background allows her to connect with a diverse range of clients, including cutting edge technology and web-based start-ups but also multinationals in need of assistance. Ingrid has played a defining role in shaping organizational strategy for a wide range of different organizations, including for-profit, NGOs and charities. Ingrid has also served on the Board of Directors for the South American Explorers Club in Quito, Ecuador.






























