10 October 2026 · By Hadi Ataei
OpenAI Is Watermarking ChatGPT Text in the EU: How It Works

OpenAI has announced that text produced by ChatGPT and Codex in the European Union will carry an invisible watermark, rolling out over the coming weeks. It is one of the first large-scale attempts to mark AI-written text (not just images) so that it can be identified later, and it arrives as the EU's AI Act pushes providers to make AI-generated content detectable. Here is what was announced, how text watermarking works in general, and why its limits matter.
What was announced
- The system: OpenAI calls it textGrain. It slightly adjusts the model's word choices so that the text carries a statistical pattern that a detector can find later. Readers cannot see it, and the text quality is described as preserved.
- Where: eligible ChatGPT and Codex output in the EU, over the coming weeks, on all plans. Developers anywhere can opt in through the API for supported models, but it is off by default.
- Detection: OpenAI is taking applications for its detector, but access starts limited to approved researchers and expert organizations rather than the general public.
- Privacy: according to press reports of the announcement, the watermark does not reveal who wrote the text, which account or prompt produced it, or how much of it was written by a person versus the AI.
How text watermarking works (the general idea)
The press coverage does not include a full technical description of textGrain, so here is the general idea from the published research on the topic; textGrain may differ in detail.
A language model picks each next token from a probability distribution (see What Is a Transformer?). Often several words would be equally good, "big" or "large", "begin" or "start". A watermarking scheme uses that freedom. Using a secret key, it quietly favours a pseudo-random subset of the acceptable choices at every step. No single word looks odd, but over a few hundred tokens the text contains more favoured words than chance would produce. A detector that knows the key counts them and measures how unlikely that excess is by chance. A strong excess means "watermarked".
That is why the watermark is in the wording itself. Copying and pasting the text into another document does not remove it, unlike an invisible character or file metadata.
The limits OpenAI reported
- Editing breaks it. Replacing 10% of the words with synonyms cut detection from about 92% to 66%, and replacing 25% cut it to 17%.
- Short text is harder. At a 1% false-positive target, about 80% of 200-token responses were detected, against about 95% at 400 tokens.
- Absence proves nothing. OpenAI itself warns that not finding a watermark does not show that a person wrote the text. Heavily edited, translated or very short text may escape detection.
The false-positive target matters too. A detector that wrongly flags human writing causes real harm to students and employees, which is why the numbers are quoted at a fixed false-positive rate, and why a detection should be treated as evidence, not proof.
Why the EU
The EU AI Act includes transparency rules for generative AI, including that providers should mark AI-generated content in a machine-readable way so it can be recognised. Press coverage links OpenAI's rollout to those requirements. Making it default only in the EU, and opt-in elsewhere, suggests the move is driven by regulation rather than by a global policy change. (For the wider US picture, see our piece on the White House Super Intelligence Force.)
What it means if you are learning AI
- Provenance is becoming an engineering requirement. Building tools that generate text now raises the question of whether, and how, to mark it. See also our article on why AI models are hard to interpret.
- Detection is statistics. The whole scheme is hypothesis testing: how unlikely is this count of favoured words under the "no watermark" assumption? Understanding false positives and thresholds is core data science.
- Watermarks are fragile. They are one tool among several, not a way to prove authorship.
Questions like these are covered in our AI Ethics and Bias course.
What to watch next
- Whether other providers (Google, Anthropic, Meta, Mistral) ship comparable watermarks, and whether detectors become interoperable.
- Independent tests of how easily textGrain can be removed by paraphrasing or translation, including Arabic.
- Who gets detector access, and how false positives are handled in schools and workplaces.
Sources: press reports of OpenAI's announcement, including BleepingComputer and TechRepublic, October 2026. OpenAI's own page could not be opened when this was written, so figures are as reported by the press; details may change as OpenAI publishes more. The general explanation of watermarking is background, not a description of OpenAI's exact method.



