OpenAI Starts Watermarking ChatGPT Text in the EU

iEXExchanger
OpenAI Starts Watermarking ChatGPT Text in the EU

OpenAI is rolling out invisible textGrain watermarks in ChatGPT and Codex output for EU users to meet AI Act transparency rules. The mark barely survives editing, and the detector isn't public yet.

Swap one word in ten for a synonym, and the odds of catching AI-generated text drop from 92% to 66%. That's the number OpenAI itself published while rolling out textGrain, a new invisible watermarking system for ChatGPT and Codex in the European Union.

There's no visible marker to strip out. A secret key nudges the model's word choices just slightly, hundreds of times over a passage, leaving a statistical fingerprint invisible to readers but detectable by an algorithm. OpenAI built textGrain with researchers from the University of Pennsylvania and Yale.

The timing isn't a coincidence. The EU's AI Act transparency rules, in force since August 2, require companies to label AI-generated content in a verifiable way. Over the coming weeks, ChatGPT and Codex users in the EU — on every plan, free through enterprise — will start getting watermarked output. Developers using the API can already switch it on worldwide for select models, though it stays off by default and isn't becoming a global standard yet.

The detector itself stays locked down for now: only vetted researchers and organizations get access, not any employer or teacher who wants to run a check. And the method has real limits. On 400-token passages, accuracy hits 95% at a 1% false-positive rate — but swap a quarter of the words for synonyms and that falls to 17%. Short replies, math answers and translated text are harder to flag, and a missing watermark proves nothing about human authorship.

Anthropic rolled out something similar for Claude two months earlier, and promptly got pushback from users worried about being outed at work. OpenAI seems to have seen that coming: it's going out of its way to stress the watermark reveals nothing about the account, the prompt, or the conversation behind it — just that a model wrote the words.

Questions and answers

Frequently asked questions about this article

What is textGrain and how does it work?

It's OpenAI's invisible watermarking system: a secret key slightly nudges the model's word choices, leaving a statistical pattern that's invisible to readers but detectable by a dedicated tool.

Why is OpenAI rolling this out only in the EU?

It's required by the EU AI Act, which has obliged companies since August 2 to label AI-generated content in a verifiable way. API developers can enable it worldwide, but it's off by default.

Can the watermark be removed or bypassed?

Partly. Swapping 10% of words for synonyms drops detection accuracy from 92% to 66%, and swapping a quarter of the words drops it to 17%. Short texts, math and translations are even harder to flag.

Who can currently check text for the watermark?

For now, only researchers and organizations vetted by OpenAI — there's no public detector yet.