OpenAI to watermark ChatGPT text in EU, limits detector access
Invisible watermarks will be embedded in eligible ChatGPT and Codex text output inside the European Union over the coming weeks, OpenAI said, in a phased response to the EU AI Act’s requirement that generated text be identifiable by machine.
· Originally published by ontime+ · Last verified: 6 Oct 2026 (Nicole Jeffrey)

Key Points
- OpenAI will add invisible watermarks to ChatGPT and Codex text output in the EU within weeks.
- The move answers the EU AI Act requirement that generated text be machine-readable.
- Detection weakens sharply on short or edited passages, so the detector stays restricted to vetted researchers.
The latest:
Invisible watermarks will be embedded in eligible ChatGPT and Codex text output inside the European Union over the coming weeks, OpenAI said, in a phased response to the EU AI Act’s requirement that generated text be identifiable by machine. The company said text watermarking and detection remain early technologies with significant limitations, and it is not switching the feature on globally by default.
Details:
- The API step: Starting Monday, API customers worldwide can opt in to text watermarking for select models, OpenAI said. The feature remains off by default, meaning developers must actively enable it. The company did not name which models qualify.
- The EU scope: The ChatGPT and Codex watermark applies to the European Union only, not as a global default, according to OpenAI, which framed the geographic limit as a reflection of the EU AI Act’s obligations on generative AI providers rather than a worldwide product change.
- The technology: OpenAI said its system, called textGrain, adds an invisible statistical signal to the model’s word choices, which a detector then searches for to assess whether a passage carries an OpenAI watermark. The company said textGrain matched or exceeded other approaches it tested, including Google’s SynthID for text.
- Detection rates: At a 1% target false positive rate, the detector identified watermarks in roughly 80% of 200-token passages and about 95% of 400-token passages for content such as psychology, OpenAI said. Performance was substantially lower for material like mathematics, where word choice is more constrained.
- Editing breaks it: In a test on 400-token passages, replacing 10% of words with synonyms cut detection from about 92% to 66%, OpenAI said. Replacing 25% of words dropped it to 17%. The company also noted detectors can return both false positives and false negatives.
- Who gets the detector: OpenAI is opening applications for access to the text watermark detector, but said access will initially go only to approved researchers and expert organizations able to help evaluate and improve the technology. It tied that restriction directly to the accuracy limitations it disclosed.
- Quality claim: Across benchmarks for its latest frontier model, Astra, OpenAI reported no meaningful performance gap between watermarked and unwatermarked text, citing an Artificial Analysis Intelligence Index score of 49.57 versus 49.76 and GPQA Diamond results of 94.44% against 93.94%.
- The caveats: A watermark does not measure human contribution, establish ownership or legal responsibility, identify the user, account or prompt, or verify accuracy, OpenAI said. It added that the absence of a detected watermark does not prove human authorship, since text may be edited, translated, too short, or produced by another company’s tools.
- Images and audio: The announcement covers text provenance only. OpenAI said its verification tools for images and audio remain publicly accessible through openai.com/verify and its Content Provenance API, and that it already embeds Content Credentials in supported image outputs and is C2PA conformant.
Background:
The EU AI Act obliges generative AI providers to make machine-readable any text their systems produce. OpenAI had previously released public tools for identifying images and audio generated by its models, but text had remained outside that provenance stack until this announcement.
Between the lines:
The gap between the regulatory requirement and the published detection numbers explains the design. A system that misses a fifth of short passages and collapses to 17% after a quarter of the words are swapped would be unreliable in the hands of employers, schools or publishers. Limiting the detector to vetted researchers lets OpenAI satisfy the EU’s machine-readability obligation without producing a tool the public could read as proof of authorship.
What’s next
Watch for the EU rollout to ChatGPT and Codex in the coming weeks, which models OpenAI enables in the API, and whether detector access widens beyond approved researchers once results are judged interpretable.