OpenAI said on October 5, 2026 that it will add an invisible watermark to eligible ChatGPT and Codex text in the European Union over the coming weeks, and that API customers anywhere can now opt in to watermarked text for select models. The method is called textGrain. The detector stays closed to the public for now, and OpenAI’s own tests show the mark weakening fast once text is edited. This page reads OpenAI’s announcement, its technical report and the European Commission’s Article 50 FAQ as of October 5, 2026.
On this page · 9 sectionsOpen
OpenAI said on October 5, 2026 that it will add an invisible watermark to eligible ChatGPT and Codex text output in the EU over the coming weeks, on all plans.
API customers anywhere can opt in to watermarked text for select models from October 5; it stays off by default.
The method, textGrain, nudges the model’s word choices with a keyed statistical signal; OpenAI says it matched or beat the other methods it tested, including Google’s SynthID Text.
Detection is fragile: on 400-token passages, swapping 10% of words for synonyms cut detection from about 92% to 66%, and swapping 25% cut it to 17%.
The detector is not public; approved researchers and expert organizations can apply.
The trigger is the EU AI Act’s Article 50, which applies from August 2, 2026, with a December 2, 2026 deadline for systems already on the market. Anthropic chose to watermark Claude worldwide instead.
§ 01What OpenAI is changing
OpenAI’s post sets out three steps. In its words: “Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union.” For developers: “Starting today, API customers globally will be able to opt in to text watermarking for select models. Text watermarking will remain off by default in the API.” And for checking: “We’re opening applications to access our text watermark detector.”
| Surface | What changes | Where | When |
|---|---|---|---|
| ChatGPT | Invisible watermark on eligible text output, all plans | EU only | Over the coming weeks |
| Codex | Invisible watermark on eligible text output | EU only | Over the coming weeks |
| API | Opt-in watermarking for select models, off by default | Worldwide | From October 5, 2026 |
| Cloud partners | Watermarking for OpenAI models served through partners | Not stated | In the coming weeks |
| Text detector | Access for approved researchers and expert organizations | By application | Applications open October 5 |
| Image and audio checks | openai.com/verify and the Content Provenance API stay public | Worldwide | Unchanged |
OpenAI is explicit that this is regional: “We are not making text watermarking a global default at launch.” It also says it plans to release textGrain as open source.
§ 02How textGrain works
“Our text watermarking technology, textGrain, adds an invisible statistical signal to the model’s word choices.” A language model picks each next word from a range of likely options; textGrain biases those picks using a secret key, in a way a reader cannot see. The detector re-derives the key’s pattern and tests whether the text follows it. The 20-page technical report, written by OpenAI researchers with co-authors from the University of Pennsylvania and Yale, adds one practical point: “The detector requires only the generated text and the secret key and does not need to know the budget used during generation.”
That design explains the weak spots. The signal lives in word choice, so text with little freedom in wording (math, code, formulas) carries less of it, and anything that changes the words (synonyms, paraphrase, translation) erodes it.
§ 03How well it detects
OpenAI published its own numbers, at a target false positive rate of 1%: about 80% of 200-token passages detected versus about 95% at 400 tokens, for psychology-style answers, with math “substantially lower”. Editing hurts more than length helps.
| Test | Detection rate |
|---|---|
| 200-token psychology answers, unedited | About 80% |
| 400-token psychology answers, unedited | About 95% |
| 400-token passages, unedited (edit test) | About 92% |
| 400-token passages, 10% of words swapped for synonyms | About 66% |
| 400-token passages, 25% of words swapped | About 17% |
OpenAI’s own reading: “Even so, strong performance under ideal conditions does not guarantee reliable detection in everyday use.” That, plus the false-positive risk, is why the detector is not public: “Given the risk of missed watermarks and false positives, we are not making it publicly available at launch.”
§ 04Does it change the answers?
OpenAI ran GPT-6 Astra at max effort with and without the watermark on eight benchmarks and says it does not “see meaningful performance differences”.
| Benchmark | Unwatermarked | Watermarked |
|---|---|---|
| Artificial Analysis Intelligence Index | 49.57 | 49.76 |
| AutomationBench | 34.09% | 34.86% |
| DeepSWE v1.1 | 72.80% | 71.68% |
| Terminal-Bench 4.0 | 53.90% | 56.06% |
| Terminal-Bench Science 0.1 | 56.90% | 60.00% |
| BrowseComp | 87.92% | 87.35% |
| HealthBench Professional | 64.27% | 64.60% |
| GPQA Diamond | 94.44% | 93.94% |
Five of eight scores went up with the watermark on, three went down; the swings are the size of normal run-to-run noise, so the honest read is no visible cost, not that the watermark helps.
§ 05What a watermark does not tell you
OpenAI spends a full section on limits, and they matter for anyone tempted to use a detector as proof:
- “A watermark does not measure human contribution.” It can show an OpenAI model touched the text, not how much a person wrote or edited.
- “A watermark does not identify the user.” No account, prompt or conversation is attached.
- It does not establish ownership, lawfulness or accuracy.
- “The absence of a detected watermark does not prove human authorship.” Short, edited or translated text, older text, and text from other companies’ models all read as unmarked.
§ 06The EU rule behind it, and how labs differ
“Article 50 of the AI Act applies as from 2 August 2026,” per the Commission. It requires providers of generative AI to mark output, text included, in a machine-readable way. Systems already on the market before that date get a short extension for the marking duty: “Providers of such systems must comply with those obligations only as from 2 December 2026.” A voluntary Code of Practice is the Commission-endorsed way to show compliance.
The labs have answered the same law differently:
| Lab | Text watermark | Scope | Public detector |
|---|---|---|---|
| OpenAI | textGrain, own method | ChatGPT and Codex in the EU; API opt-in worldwide | No; researchers by application |
| Anthropic | Based on Google DeepMind’s SynthID-Text | All Claude output, worldwide | Private preview for eligible organizations |
| SynthID Text | Gemini app and web text (announced May 2024) | Not covered here |
Anthropic’s August 14 post explains its choice in one line: “We’re applying watermarking globally at launch because we don’t yet have a durable way to scope it by region.” OpenAI went the other way, limiting ChatGPT to the EU to “learn from real-world use and feedback” first.
§ 07What it means for you
- In the EU and using ChatGPT or Codex: within weeks, eligible text you generate carries a mark you cannot see. Nothing changes in how it reads.
- Building on the API: nothing changes unless you opt in. If you serve EU users and must meet Article 50 yourself, the opt-in is the simplest way to mark OpenAI output.
- Teachers, editors and hiring teams: do not treat any detector result as proof either way. OpenAI’s own limits section rules out “caught” and “cleared” readings.
- Businesses publishing AI-assisted writing: a watermark is a disclosure signal, not a penalty. Search engines have said they judge content on quality, not on how it was made; disclosure duties for deepfakes and certain public-interest text sit with deployers under the same Article 50.
§ 08What we are watching
- The EU rollout date. OpenAI said “the coming weeks”; we will add the date ChatGPT text starts carrying the mark.
- Open source. Whether textGrain’s code ships, and whether independent tests match OpenAI’s numbers.
- Detector access. Who gets approved, and whether a public tool follows.
§ 09Sources
- OpenAI, “Our approach to EU text provenance rules”, October 5, 2026
- OpenAI, textGrain technical report, October 5, 2026
- European Commission, Article 50 transparency obligations FAQ and Code of Practice on AI-generated content
- Anthropic, “How Claude’s text watermark works”, August 14, 2026, and Claude Help Center on marking
- Google DeepMind, SynthID
Q1Is ChatGPT text watermarked outside the EU?
Not in ChatGPT for now. OpenAI says it is not making text watermarking a global default at launch; outside the EU, only API customers who opt in get watermarked text.
Q2Can I check whether a text was written with ChatGPT?
Not with OpenAI’s text detector, which is limited to approved researchers and expert organizations at launch. OpenAI’s public verify tool covers images and audio only.
Q3Does the watermark make ChatGPT's answers worse?
OpenAI says no: on eight benchmarks for GPT-6 Astra, scores with and without the watermark were within a few points of each other, some higher and some lower.
Q4Does a watermark prove a person used AI to cheat?
No. OpenAI says a watermark does not measure human contribution, does not identify the user, and its absence does not prove a human wrote the text.
Q5Is CellCog's output watermarked?
Every CellCog tier runs on Anthropic’s Claude Opus 5.5, and Anthropic’s help center lists Opus 5.5 among the models whose text carries its watermark. CellCog adds no watermark of its own.
