OpenAI's EU text watermark tests what AI labels can prove
OpenAI plans to watermark eligible ChatGPT and Codex text in the EU. Its tests show why detecting a machine-readable signal still leaves authorship unanswered.
Written by AI. Yuki Okonkwo

OpenAI plans to add an invisible watermark to eligible ChatGPT and Codex text in the European Union over the coming weeks. The mark is meant to help machines identify text from its models under the EU AI Act. For anyone hoping to settle an argument over who wrote a paragraph, though, the interesting question comes one step later: what can a machine actually conclude when it finds the mark?
The rollout covers eligible users across ChatGPT and Codex plans in the EU. API customers worldwide can opt in for select models, but watermarking remains off by default for them. OpenAI is also working with cloud partners to offer watermarking through their services. That creates several routes by which a piece of OpenAI-generated text could enter the world, with different marking defaults. A detector result will make more sense if the person reading it knows which route was used.
OpenAI calls its method textGrain. It adds a statistical signal to the words a model chooses while generating text; a detector then looks for that pattern. Picture a cook choosing between equally workable ingredients according to a private recipe. The dish still looks like dinner, but someone who knows the recipe can check for the pattern. Large language models choose tokens, small units of text, from a range of possibilities as they write. The Register explains the word-choice mechanism: changing some choices can leave a detectable statistical trace. The analogy has a limit. Rewriting the dish afterward changes the thing being checked.
The Signal Gets Harder to Find
OpenAI's tests put numbers on that problem. At a target 1% false-positive rate, its detector found the watermark in about 80% of 200-token passages and 95% of 400-token passages on subjects such as psychology. A false positive means the detector flags text that lacks the mark. These are company-reported test results, not a promised success rate for every document someone might paste into a checker. OpenAI reported lower detection on subjects such as math, where the model has less freedom to vary its wording.
Editing changed the result sharply in a separate test using 400-token English responses to questions from the ELI5 dataset. Replacing 10% of words with synonyms lowered detection from about 92% to 66%; replacing 25% lowered it to 17%. Those figures describe that synonym-swap test, rather than every form of ordinary editing. They show why a finished paragraph can retain substantial model-written language while its detectable signal fades. A short answer and a longer essay also give the detector different amounts of pattern to work with.
There is a strong case for adding the mark anyway. Machine-readable provenance gives organizations a way to ask a narrower question than “Does this sound AI-written?” OpenAI says textGrain matched or exceeded other approaches it tested, including SynthID for text, and its benchmarks found minimal to no difference with watermarking enabled. If a signal can travel with output without disrupting its use, even imperfect detection could help people study where marked text appears. OpenAI plans to release the technology as open source, according to The Next Web's account of its announcement. That plan is separate from giving everyone access to a detector today.
At launch, approved researchers and expert organizations can request access to OpenAI's detector on a case-by-case basis. The public cannot use it yet. OpenAI cites missed watermarks and possible false positives as reasons for restricting access; the detector also does not reveal a user's identity, prompts or conversations. That combination has a practical consequence. The person who receives a piece of text may be unable to check it with OpenAI's tool, while someone granted access still receives a result about a signal, not an account of the writing process.
A detected mark could support the inference that a passage contains an OpenAI watermark. It cannot tell a school, newsroom or client how much a person rewrote that passage, who approved it, or whether its claims are accurate. A missing mark is ambiguous too: the passage might be short or edited, or the text might come from an unmarked route or a different company's model. My read is that watermark detection belongs alongside context about how a document was produced, rather than serving as a verdict on its author.
Why the Rollout Has a Border
The EU's transparency rules under Article 50 began applying on August 2, 2026. The European Commission says systems placed on the market before then have until December 2 to meet the relevant marking and detection obligation. OpenAI's move therefore arrives against a regulatory timetable, while its regional rollout also lets it learn from use and feedback, the company says. The EU focus explains why two people using ChatGPT for comparable writing tasks in different places may encounter different watermark defaults. It does not, by itself, say anything about the quality of their writing.
The product history makes the change more revealing. In 2024, OpenAI decided against text watermarking for ChatGPT after a company survey found almost 30% of users said they would use the service less if watermarking were introduced, Search Engine Journal reported. That survey describes stated intentions among respondents, not a measured loss of users. Now OpenAI is preparing EU defaults for eligible ChatGPT and Codex output while keeping the API opt-in. The shift shows a different regulatory and product decision; it offers no reason to assume the editing and detection problems have vanished.
Anthropic offers a useful comparison because it is tackling the same broad provenance problem with a different geographic choice. It began watermarking text from supported Claude models worldwide in August, with exemptions. Anthropic says it does not yet have a durable way to confine that watermarking by region. OpenAI is choosing an EU default for eligible ChatGPT and Codex text and an optional route for select API models elsewhere. Both companies restrict detector access: Anthropic offers a private preview to eligible organizations, while OpenAI initially accepts applications from approved researchers and expert organizations. Anthropic uses a version of Google's SynthID-Text; OpenAI uses textGrain.
OpenAI has reported synonym-editing results for textGrain, but Anthropic's explainer gives no equivalent figures for the same test. Calling either company's watermark tougher on the strength of those disclosures would be comparing different scoreboards. Geography, meanwhile, changes what an absence can suggest: an unmarked passage might reflect a product's rollout rules before editing even enters the picture.
OpenAI is trying to make text identifiable by machines. Its own tests show that the identification depends on the passage and what happens to it afterward, and its access rules determine who can ask the machine. The next time a watermark result turns up in a dispute over a document, the useful follow-up question is wonderfully unglamorous: which output was marked, what happened to the text, and what did the detector actually test?
More Like This
How Claude's AI Text Watermark Actually Works
Anthropic's Claude hides a statistical watermark in word choices, not characters. Here's how tournament sampling works—and why forging beats removing it.
Newsom’s AI Kill Switch Order Is Mostly a Blueprint
California's AI order revives a vetoed shutdown idea, speeds oversight work, and leaves questions of authority, testing, and cost unresolved in practice.
Claude's AI Watermark and What It Means for SEO
Claude's new text watermark is triggering SEO panic. Here's what Anthropic's documentation actually says—and why the fear may be worse than the feature.
EU AI Act Enforcement Begins with RFIs to AI Firms
The EU has issued its first AI Act RFIs to model providers including OpenAI and Anthropic. Here is what the enforcement powers actually mean and why it matters.
Claude's Invisible Watermark and What It Actually Does
Anthropic's invisible text watermark covers every Claude output globally, raising questions about EU AI Act scope, developer code, and who controls the detector.
When No One Reads the Code: AI, Trust, and Accountability
Brian Casel argues developers should stop reading AI-generated code. The workflow is compelling—but what happens when it runs into regulated industries and liability?
GPT 5.6 Sol vs Fable 5: Early Numbers, Real Tradeoffs
GPT 5.6 Sol is half the price of Fable 5 — but is it half as good? Early benchmark comparisons, alignment regressions, and the politics reshaping who gets access.
Claude Fable 5 Prompting Habits That Actually Matter
Nate Herk distilled Anthropic engineer insights into six Claude Fable 5 prompting habits. Here's what holds up, what's wild, and what it means for how you work.