Skip to content
← All news
4 min read

OpenAI will watermark ChatGPT and Codex text in the EU with textGrain

Eligible EU users on every ChatGPT and Codex plan get an invisible text watermark over the coming weeks. API customers anywhere can opt in, and only approved researchers get the detector.

Swap a quarter of the words for synonyms and OpenAI's own detector finds the mark only 17% of the time.

On October 5, 2026, OpenAI said it will add an invisible watermark to text from ChatGPT and Codex for eligible users in the European Union, on all plans, over the coming weeks. The same day, API customers anywhere got the option to switch it on for select models. The system is called textGrain, and the detector that reads it is not public.

How textGrain marks text

A language model picks each next word from a ranked list of candidates. textGrain nudges those picks. OpenAI describes it as an invisible statistical signal added to the model's word choices, and TechCrunch reports that a secret key decides how the next-word predictions get sorted. A reader sees normal text. A detector holding the key sees a pattern too consistent to be chance.

The signal sits in the word choices, not in attached metadata, so it stays with the text for as long as the words stay the same. OpenAI says it saw no meaningful performance differences on the benchmarks it uses for Astra, its latest frontier model, with and without the watermark. The method is written up in a technical report by researchers from OpenAI, the University of Pennsylvania, and Yale. It is a technical report, not a peer-reviewed paper, and OpenAI says it will add more detail in the coming weeks, and that it plans to release the technology as open source.

Who gets marked, and who chooses

The split matters more than the headline:

  • ChatGPT and Codex users in the EU: marked automatically, all plans, rolling out over the coming weeks. OpenAI says it is not making text watermarking a global default at launch.
  • API customers worldwide: opt-in for select models from October 5. OpenAI says watermarking "will remain off by default in the API." It has not named the models.
  • Cloud partners: OpenAI says it is working with them to offer the watermark on OpenAI models sold through their services.

So a product built on the OpenAI API and shown to EU users is not marked unless the team building it turns the setting on. The legal background is Article 50 of the EU AI Act, which we covered when its content-labeling rules took effect on August 2.

A private detector

At launch, only approved researchers and expert organizations can apply to use the detector, and OpenAI grants access case by case. It reports whether an OpenAI watermark is present, without identifying the user or showing prompts or conversations. OpenAI gives the reason for keeping it closed plainly: "the risk of missed watermarks and false positives."

Its published detection numbers are set at a target false positive rate of 1%. The technical report adds a caveat: that error rate comes from an idealized calculation, and a fixed deployed key needs empirical calibration checks before anyone can rely on the same rate in every application.

What editing does to the mark

OpenAI's own numbers show where the mark is weak. On psychology content, the detector found it in about 80% of 200-token passages and about 95% of 400-token passages. Mathematics did much worse, because there is less room to vary word choice. Then the editing test, run on 400-token English answers to ELI5 questions:

Words replaced with synonymsDetection rate
Noneabout 92%
10%66%
25%17%

OpenAI also warns that short, edited, or translated text may not be detected reliably, and that a missing watermark does not prove a human wrote the text. Anthropic took a different route in August, with a global text watermark and signed C2PA metadata on Claude's files.

Why a build studio cares

Our engineers build with Claude Code and Codex, and our AI Workflows service is scoped at about one week and includes eval cases built from real inputs, logs, human approval gates, and an operator runbook. For an EU-facing client workflow on an OpenAI API model, the watermark is now a setting someone either turns on or leaves off. That choice belongs in the runbook next to the model name, so the next person who touches the workflow knows whether the text it sends carries a mark. We do not use textGrain in client work today and have no detector access, so the recorded setting is the evidence we can actually check.

The audits change too. A Surface Audit tests UI claims against behavior, so a product that says its AI text is labeled or watermarked now gets asked which model wrote that text and whether the API setting is on. With the detector private, a buyer cannot test "watermarked" on their own, which makes vendor configuration evidence the thing to ask for. In a Deep Audit, the data-flow map gains one column: which generated text reaches EU users, and through which model. That column tells you whether to expect a mark from OpenAI, from Anthropic's global default, or from no one.

Next step: read OpenAI's announcement and the textGrain technical report, then list which of your features send OpenAI-generated text to EU users. If a vendor told you your product's AI text is watermarked and you want that claim checked, write to us at hello@gattyworks.com.

OpenAIAI ProvenanceEU AI ActOpenAIChatGPTtextGrainCodexAIWatermarkEUAIActOpenAIAPIContentProvenanceAITransparencyGenerativeAI

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call