Skip to content
AI EmployeeSuper-AgentsAgent-to-AgentTutorialsPricingBlogContact

OpenAI Text Watermark: ChatGPT EU Rollout and textGrain

At a glanceQuick answers
What changes?
ChatGPT and Codex text in the EU gets an invisible watermark; API users worldwide can opt in.
Can anyone check for it?
Not yet. Only approved researchers and expert organizations can apply for the detector.
Does it survive editing?
Partly. Replacing a quarter of the words dropped detection to 17% in OpenAI’s own test.
Data illustration on off-white paper: a sheet of text under a magnifying glass revealing hidden teal dots between the words, beside three numbers: 92% detected unedited, 66% with 10% of words swapped, 17% in amber with 25% of words swapped
Fig 0Swap a quarter of the words and detection falls to 17%. Made by CellCog's image agent, running GPT Image 2.5.

OpenAI said on October 5, 2026 that it will add an invisible watermark to eligible ChatGPT and Codex text in the European Union over the coming weeks, and that API customers anywhere can now opt in to watermarked text for select models. The method is called textGrain. The detector stays closed to the public for now, and OpenAI’s own tests show the mark weakening fast once text is edited. This page reads OpenAI’s announcement, its technical report and the European Commission’s Article 50 FAQ as of October 5, 2026.

On this page · 9 sectionsOpen
  1. What OpenAI is changing
  2. How textGrain works
  3. How well it detects
  4. Does it change the answers?
  5. What a watermark does not tell you
  6. The EU rule behind it, and how labs differ
  7. What it means for you
  8. What we are watching
  9. Sources
Key points6 · 7 min full read
  1. A text page with faint dots between the lines, ringed by stars: ChatGPT text in the EU gets an invisible watermark.
    OpenAI said on October 5, 2026 that it will add an invisible watermark to eligible ChatGPT and Codex text output in the EU over the coming weeks, on all plans.
  2. A toggle switch set to off beside a globe: API watermarking is opt-in worldwide and off by default.
    API customers anywhere can opt in to watermarked text for select models from October 5; it stays off by default.
  3. A key above a row of word blocks, some marked with dots: textGrain nudges word choices with a keyed signal.
    The method, textGrain, nudges the model’s word choices with a keyed statistical signal; OpenAI says it matched or beat the other methods it tested, including Google’s SynthID Text.
  4. An eraser rubbing out a trail of dots along a line of text: edits weaken detection.
    Detection is fragile: on 400-token passages, swapping 10% of words for synonyms cut detection from about 92% to 66%, and swapping 25% cut it to 17%.
  5. A magnifying glass with a padlock on its handle: the detector is closed to the public.
    The detector is not public; approved researchers and expert organizations can apply.
  6. A calendar page beside a gavel: the EU AI Act deadlines behind the change.
    The trigger is the EU AI Act’s Article 50, which applies from August 2, 2026, with a December 2, 2026 deadline for systems already on the market. Anthropic chose to watermark Claude worldwide instead.

§ 01What OpenAI is changing

OpenAI’s post sets out three steps. In its words: “Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union.” For developers: “Starting today, API customers globally will be able to opt in to text watermarking for select models. Text watermarking will remain off by default in the API.” And for checking: “We’re opening applications to access our text watermark detector.”

Surface What changes Where When
ChatGPT Invisible watermark on eligible text output, all plans EU only Over the coming weeks
Codex Invisible watermark on eligible text output EU only Over the coming weeks
API Opt-in watermarking for select models, off by default Worldwide From October 5, 2026
Cloud partners Watermarking for OpenAI models served through partners Not stated In the coming weeks
Text detector Access for approved researchers and expert organizations By application Applications open October 5
Image and audio checks openai.com/verify and the Content Provenance API stay public Worldwide Unchanged
Table 1OpenAI’s text watermarking, surface by surface (OpenAI announcement, read October 5, 2026)

OpenAI is explicit that this is regional: “We are not making text watermarking a global default at launch.” It also says it plans to release textGrain as open source.

§ 02How textGrain works

“Our text watermarking technology, textGrain, adds an invisible statistical signal to the model’s word choices.” A language model picks each next word from a range of likely options; textGrain biases those picks using a secret key, in a way a reader cannot see. The detector re-derives the key’s pattern and tests whether the text follows it. The 20-page technical report, written by OpenAI researchers with co-authors from the University of Pennsylvania and Yale, adds one practical point: “The detector requires only the generated text and the secret key and does not need to know the budget used during generation.”

That design explains the weak spots. The signal lives in word choice, so text with little freedom in wording (math, code, formulas) carries less of it, and anything that changes the words (synonyms, paraphrase, translation) erodes it.

§ 03How well it detects

OpenAI published its own numbers, at a target false positive rate of 1%: about 80% of 200-token passages detected versus about 95% at 400 tokens, for psychology-style answers, with math “substantially lower”. Editing hurts more than length helps.

Test Detection rate
200-token psychology answers, unedited About 80%
400-token psychology answers, unedited About 95%
400-token passages, unedited (edit test) About 92%
400-token passages, 10% of words swapped for synonyms About 66%
400-token passages, 25% of words swapped About 17%
Table 2textGrain detection rates in OpenAI’s tests (OpenAI announcement, October 5, 2026; 1% target false positive rate)
Watermark detection on 400-token passages falls as words are swappedBar chart of detection rate: unedited 92%, 10% of words swapped 66%, 25% swapped 17% highlightedUnedited9210% swapped6625% swapped17Watermark detection on 400-token passages falls as words are swappedBar chart of detection rate: unedited 92%, 10% of words swapped 66%, 25% swapped 17% highlightedUnedited9210% swapped6625% swapped17
Fig 1Watermark detection on 400-token passages falls as words are swapped

OpenAI’s own reading: “Even so, strong performance under ideal conditions does not guarantee reliable detection in everyday use.” That, plus the false-positive risk, is why the detector is not public: “Given the risk of missed watermarks and false positives, we are not making it publicly available at launch.”

§ 04Does it change the answers?

OpenAI ran GPT-6 Astra at max effort with and without the watermark on eight benchmarks and says it does not “see meaningful performance differences”.

Benchmark Unwatermarked Watermarked
Artificial Analysis Intelligence Index 49.57 49.76
AutomationBench 34.09% 34.86%
DeepSWE v1.1 72.80% 71.68%
Terminal-Bench 4.0 53.90% 56.06%
Terminal-Bench Science 0.1 56.90% 60.00%
BrowseComp 87.92% 87.35%
HealthBench Professional 64.27% 64.60%
GPQA Diamond 94.44% 93.94%
Table 3GPT-6 Astra (max) with and without textGrain (OpenAI announcement, October 5, 2026)

Five of eight scores went up with the watermark on, three went down; the swings are the size of normal run-to-run noise, so the honest read is no visible cost, not that the watermark helps.

§ 05What a watermark does not tell you

OpenAI spends a full section on limits, and they matter for anyone tempted to use a detector as proof:

  • “A watermark does not measure human contribution.” It can show an OpenAI model touched the text, not how much a person wrote or edited.
  • “A watermark does not identify the user.” No account, prompt or conversation is attached.
  • It does not establish ownership, lawfulness or accuracy.
  • “The absence of a detected watermark does not prove human authorship.” Short, edited or translated text, older text, and text from other companies’ models all read as unmarked.

§ 06The EU rule behind it, and how labs differ

“Article 50 of the AI Act applies as from 2 August 2026,” per the Commission. It requires providers of generative AI to mark output, text included, in a machine-readable way. Systems already on the market before that date get a short extension for the marking duty: “Providers of such systems must comply with those obligations only as from 2 December 2026.” A voluntary Code of Practice is the Commission-endorsed way to show compliance.

The labs have answered the same law differently:

Lab Text watermark Scope Public detector
OpenAI textGrain, own method ChatGPT and Codex in the EU; API opt-in worldwide No; researchers by application
Anthropic Based on Google DeepMind’s SynthID-Text All Claude output, worldwide Private preview for eligible organizations
Google SynthID Text Gemini app and web text (announced May 2024) Not covered here
Table 4How the big labs are marking AI text (vendor pages, read October 5, 2026)

Anthropic’s August 14 post explains its choice in one line: “We’re applying watermarking globally at launch because we don’t yet have a durable way to scope it by region.” OpenAI went the other way, limiting ChatGPT to the EU to “learn from real-world use and feedback” first.

§ 07What it means for you

  • In the EU and using ChatGPT or Codex: within weeks, eligible text you generate carries a mark you cannot see. Nothing changes in how it reads.
  • Building on the API: nothing changes unless you opt in. If you serve EU users and must meet Article 50 yourself, the opt-in is the simplest way to mark OpenAI output.
  • Teachers, editors and hiring teams: do not treat any detector result as proof either way. OpenAI’s own limits section rules out “caught” and “cleared” readings.
  • Businesses publishing AI-assisted writing: a watermark is a disclosure signal, not a penalty. Search engines have said they judge content on quality, not on how it was made; disclosure duties for deepfakes and certain public-interest text sit with deployers under the same Article 50.

§ 08What we are watching

  • The EU rollout date. OpenAI said “the coming weeks”; we will add the date ChatGPT text starts carrying the mark.
  • Open source. Whether textGrain’s code ships, and whether independent tests match OpenAI’s numbers.
  • Detector access. Who gets approved, and whether a public tool follows.

§ 09Sources

Frequently asked5 questions

Q1Is ChatGPT text watermarked outside the EU?

Not in ChatGPT for now. OpenAI says it is not making text watermarking a global default at launch; outside the EU, only API customers who opt in get watermarked text.

Q2Can I check whether a text was written with ChatGPT?

Not with OpenAI’s text detector, which is limited to approved researchers and expert organizations at launch. OpenAI’s public verify tool covers images and audio only.

Q3Does the watermark make ChatGPT's answers worse?

OpenAI says no: on eight benchmarks for GPT-6 Astra, scores with and without the watermark were within a few points of each other, some higher and some lower.

Q4Does a watermark prove a person used AI to cheat?

No. OpenAI says a watermark does not measure human contribution, does not identify the user, and its absence does not prove a human wrote the text.

Q5Is CellCog's output watermarked?

Every CellCog tier runs on Anthropic’s Claude Opus 5.5, and Anthropic’s help center lists Opus 5.5 among the models whose text carries its watermark. CellCog adds no watermark of its own.

Published 05 October 2026 All Choosing a platform →