Raw data, clear context.

[
[
[

]
]
]

OpenAI plans to add an invisible watermark to eligible text generated by ChatGPT and Codex for users in the European Union over the coming weeks. API developers worldwide can opt in for supported models, but the signal will not be a global default at launch. OpenAI’s own tests show that synonym edits sharply weaken detection.[1][2]

Checked on 6 October 2026. The rollout, detector-access and European legal-guidance claims below reflect the public material available on that date and may change.

A mark hidden in the words

OpenAI’s announcement describes a watermark that readers will not see while reading or copying a passage. Instead, the system slightly changes word choices so that the resulting text carries a statistical pattern that a detector can test.[1][2]

The accompanying technical report gives the mechanism a more precise shape. textGrain uses keyed randomness and an entropy budget while generating tokens. Its detector does not need the generating model, coupling or entropy budget, but it does assume the matching tokenizer, block and column counts, context-window rule and keyed construction.[3]

That design makes the watermark portable with the text. It does not depend on a file header or a visible label that disappears when someone pastes the words into another document. It also means the signal is tied to the exact text that reaches the detector, rather than to a record of the user’s account or conversation.[1][3]

An EU rollout, not a global switch

The rollout described by OpenAI has two different scopes. Eligible ChatGPT and Codex output is due to receive the mark in the EU, while API developers elsewhere can choose to enable it for supported models. OpenAI is not making text watermarking a global default at launch.[1]

The legal text says provider marking solutions must be effective, interoperable and reliable, with resilience required only as far as technically feasible, while the separate deployer rule concerns certain public-interest text and includes a human-review or editorial-control exception.[5] The Commission says Article 50 applies from 2 August 2026, the Code of Practice is voluntary, and providers or deployers can demonstrate adequate compliance through other means.[4][6]

The rollout can therefore be described as a compliance-related product change in OpenAI’s account, not as proof that Article 50 mandates textGrain or this particular implementation. The public material does not specify the complete eligibility rules or give a timetable for every account and product surface.[1][5][6]

OpenAI textGrain infographic. The reported rollout covers eligible ChatGPT and Codex output in the European Union over the coming weeks. OpenAI API developers worldwide can opt in for supported models, off by default. In OpenAI-reported tests on 400-token passages, detection fell from about 92 percent to 66 percent after replacing 10 percent of words with synonyms, and to 17 percent after replacing 25 percent. The figures are company-reported tests, not an independent audit, and a missing watermark does not prove human authorship.
OpenAI’s proposed text watermark has two separate dimensions: where it is enabled and how well it survives editing. Rollout details come from TechCrunch’s report; detection figures are OpenAI tests reported by BleepingComputer.[1][2] The visual is an editorial synthesis, not an independent benchmark.

Editing is the weak point

OpenAI’s tests, as reported by BleepingComputer, show how quickly the signal can weaken. In 400-token passages, replacing 10 per cent of words with synonyms reduced detection from about 92 per cent to 66 per cent. Replacing 25 per cent reduced it to 17 per cent.[2]

The same report says detection in 200-token psychology responses was about 80 per cent at a one per cent false-positive target, compared with roughly 95 per cent for 400-token responses. It also says mathematics answers were harder to detect because the model has less freedom to vary its word choices.[2]

These are provider-reported results under the stated test conditions, not a universal accuracy score. They cannot be generalised to all models, languages, prompts or editing workflows. The technical report makes its own assumptions visible: its idealised false-positive calculation depends on independence conditions, while fixed keys and finite-precision arithmetic require empirical calibration. The report says the idealised calculation does not guarantee the same error rate for every key or application.[2][3]

The cited sources document editing, translation and short passages as conditions that can weaken this signal, but they do not establish rates for ordinary documents, every language or every kind of revision. A result from a clean, long passage should not be silently generalised to a short answer, a translated article or a document revised by a person.[1][2][3]

Provenance is not authorship

OpenAI says a missing watermark does not prove human authorship because the passage may be too short, heavily edited, translated or generated by another company’s system.[1][2] A detected mark has a similarly narrow meaning: it can indicate that an OpenAI system generated or processed part of a passage, but it does not identify the user, account, prompt or conversation.[1][2]

That distinction also limits what the technology can say about human contribution. A detector may provide evidence that an OpenAI system generated or processed some of the text, but it cannot determine how much judgement, editing or creativity a person supplied to the final work.[1]

For editors, teachers and employers, the sensible use is as one signal in a wider review rather than as an automatic verdict. The cited sources do not establish a threshold at which a detector result should trigger a disciplinary or publishing decision, and a negative result cannot rule out AI assistance.[1][2][5]

Other watermarking schemes are not a proxy

Independent research points in both directions, but not at textGrain. Vaporizer evaluates several other watermarking schemes against lexical changes, machine translation and neural paraphrasing, reporting that watermarks can be removed with reasonable effort while semantic content is preserved.[7] A separate study of Dual-Embedding Watermarking examines a semantic design intended to improve robustness against paraphrasing and translation.[8]

Those studies show that robustness is scheme-specific. Neither evaluates textGrain, so neither confirms nor refutes OpenAI’s reported percentages. They are useful counter-context, not a substitute for a public evaluation of OpenAI’s system.[7][8]

The next test is outside the laboratory

Several operational questions remain open. The technical report’s detector procedure assumes the matching tokenizer, block and column counts, context-window rule and keyed construction, while the public announcement limits initial access to approved researchers and expert organisations.[1][3] The cited sources do not explain how an organisation requests the required configuration, what threshold or record accompanies a result, or how a disputed result should be challenged.[1][3]

OpenAI says initial detector access will be limited to approved researchers and expert organisations while reliability and responsible uses are evaluated.[1] The restriction means the current public record does not establish general publisher access or a reader-facing service.

Until OpenAI publishes the detector’s access conditions and fuller evaluation details, a positive result can support only a bounded claim that text generated or processed by an OpenAI system may be present under the tested configuration. It cannot establish who wrote the passage, how much a person edited it or that a negative result rules out AI assistance.[1][2][3]

Sources

[1] OpenAI will start watermarking ChatGPT’s text in the EU

[2] OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

[3] textGrain: Entropy-Calibrated Watermarking for Language Model Text

[4] Guidelines on transparency obligations for providers and deployers of certain AI systems

[5] Article 50: Transparency obligations for providers and deployers of certain AI systems

[6] Code of Practice on Transparency of AI-generated Content

[7] Vaporizer: Breaking Watermarking Schemes for Large Language Model Outputs

[8] Robust Text Watermarking for Large Language Models via Dual Semantic Embeddings