← News

OpenAI will secretly watermark ChatGPT text in the EU to meet the AI Act

OpenAI said Monday, Oct. 5, 2026, that it will add an invisible watermark to eligible ChatGPT and Codex text for users in the European Union over the coming weeks, because the EU AI Act requires AI-generated text to be machine-detectable. The detector that reads the watermark will go only to approved researchers at first, and OpenAI admits light editing can wipe most of the signal out.

If you use ChatGPT in Europe, your answers will soon carry a hidden fingerprint that says an OpenAI model wrote them. But OpenAI’s own numbers show how weak it is: change a quarter of the words and the detector only catches it 17% of the time, which is why OpenAI is keeping the detector away from teachers and employers for now. This is less a lie detector than a legal checkbox, and the real test is whether other labs and the EU accept it as enough.

On Monday, 5 October 2026, OpenAI published “Our approach to EU text provenance rules.” The page prints October 5, 2026. It does not print an hour. The line under the title says the post is about promoting transparency within the limits of today’s technology. OpenAI says the EU AI Act requires generative AI providers to make generated text identifiable in a machine-readable way, and that this post is its response. The EU AI Act is Europe’s law on artificial intelligence. Machine-readable means a computer can check the mark, not only a person reading the words. Generative, here, means the system writes new text. OpenAI also says text watermarking is still an early technology, with real limits, and that its rollout is phased because of those limits. Those lines are OpenAI’s.

Who gets the mark, and who does not. Over the coming weeks, OpenAI will add an invisible watermark to eligible ChatGPT and Codex text for users across all plans in the European Union only. Codex is OpenAI’s coding assistant. A watermark, here, is a hidden pattern a later check can still find. OpenAI says it is not making text watermarking a global default. Starting today, API customers anywhere in the world can opt in to watermarked text for select models. An API customer is a company that calls the model from its own product, rather than from the ChatGPT app. The watermark stays off unless that customer turns it on. OpenAI says it is also working with cloud partners so the option can cover OpenAI models reached through their services, in the coming weeks. The post does not name those partners, the select models, or a day inside those weeks.

The system is called textGrain. OpenAI says it adds an invisible statistical signal to the model’s word choices, and a detector looks for that signal to judge whether a passage carries an OpenAI watermark. A statistical signal means the pattern sits in which words were more likely, not in a label a reader can see. OpenAI published a technical report, “textGrain: Entropy-Calibrated Watermarking for Language Model Text,” written with researchers from the University of Pennsylvania and Yale. The report is dated October 5, 2026, and it says it accompanies this blog post. OpenAI says it plans to release the technology as open source, so others can build on it, and that the report will be updated with more detail in the coming weeks. Those lines are OpenAI’s.

How the report says a word gets the mark. A language model picks the next piece of a word, called a token, from a list of likely choices. textGrain uses a secret key to sort those choices into blocks, then leans toward some blocks when it picks the next word. Inside the chosen block, the words keep their usual relative chances. The detector has the same key. It reads the finished text and tests whether the words line up with that lean. The report says the detector needs the text and the key. It does not need the prompt, and it does not need to know how strong a mark the generator was aiming for. The formulas that set that strength are in the report. Those lines are the report’s account of the method. Figure 1 is the picture of those three steps.

How well OpenAI says it works, on the lab’s own tests. OpenAI says textGrain matched or beat the other approaches it tested, including Google’s SynthID for text. SynthID is Google’s watermark for AI output. OpenAI also says a strong result under ideal conditions does not guarantee reliable detection in everyday use. Those sentences are OpenAI’s. The post does not print the other methods’ scores.

What the detector misses. OpenAI says a detector can make two mistakes. It can report a watermark that is not there, which is a false positive, or it can miss a watermark that is there. At a target false-positive rate of 1 percent, the test is set so that about 1 in 100 unmarked passages would be flagged by mistake. At that setting, OpenAI says the detector caught the watermark in about 80 percent of 200-token passages and about 95 percent of 400-token passages, for content such as psychology. A token is a chunk of text, often a word or part of a word, so 200 tokens is a few paragraphs and 400 is longer. Detection was substantially lower for content such as mathematics, where the model has less freedom to choose words. Those rates are OpenAI’s, from watermarked answers to questions in a public set called ELI5. The post does not print a mathematics percentage.

Editing weakens it. In a test of 400-token passages, OpenAI says replacing 10 percent of the words with synonyms cut detection from about 92 percent to 66 percent. Replacing 25 percent cut it to 17 percent. Those passages were watermarked English answers to ELI5 questions. OpenAI says these limits are part of why the first detector is not public. The post does not say the watermark cannot be removed, and it does not give a count of users.

Whether the mark changes the answers. OpenAI says that across the benchmarks it uses for Astra, its latest frontier model, watermarking made no meaningful difference. A benchmark is a scored test of how well a model does a task. A frontier model, in that sentence, is one of the most capable models the lab is shipping. On GPQA Diamond, a hard science-question test, OpenAI’s table prints 94.44 percent without the watermark and 93.94 percent with it, both for Astra at its maximum setting. The same table prints other tests. Some are a little higher with the watermark, and some are a little lower. OpenAI’s claim is that the differences are not meaningful. Those numbers are OpenAI’s. The post does not say an outside lab repeated them.

Who can run the detector. It is not public. Approved researchers and expert organizations can apply starting today. OpenAI says access is granted case by case, under the EU Code of Practice, to support evaluation and improvement of text provenance. Provenance means where a piece of text came from. The tool reports only whether it detects an OpenAI watermark. It does not identify the user, and it does not reveal prompts or conversations. OpenAI says it is holding the detector back at launch because of missed watermarks and false positives. Those lines are OpenAI’s. The post does not name who has been approved.

What OpenAI says a watermark does not prove. It does not identify the user. It does not measure how much a human contributed: it can indicate that an OpenAI system generated or processed part of a passage, not how much human judgment, editing, or creativity went into it. It does not prove who owns the text, whether the use was lawful, or who is responsible for it. It does not prove the text is accurate, or whether it is misleading or harmful. A missing watermark does not prove a human wrote the text. OpenAI says generated text may be too short, edited, or translated for detection to work. It may also come from a model that was not covered, from before this rollout, or from another company’s tools. Those limits are OpenAI’s.

What stays public. OpenAI says this change is only about text. Its tools for checking images and audio, including the page at openai.com/verify and its Content Provenance API, stay available to organizations that want to know whether an image or an audio file came from one of its systems. Those lines are OpenAI’s.

The picture is the title and Figure 1 of the textGrain technical report. The title reads “textGrain: Entropy-Calibrated Watermarking for Language Model Text.” The line under it says the report accompanies OpenAI’s October 5th blog post. Figure 1 is a diagram in three panels. The first starts from the sentence “The morning was” and a blank, and sorts likely next words into colored blocks tied to a key. The second is a cost table: darker cells are the pairs the method prefers, and the circles show how likely each block is. The third picks one column and then a word inside that block, “cold.” A teal border frames the page. It is a figure from the paper. It is not a screenshot of ChatGPT.

In plain terms, OpenAI said on Monday that eligible ChatGPT and Codex answers for people in the European Union will carry a hidden watermark in the coming weeks, because European law says AI-written text has to be machine-detectable. The mark is called textGrain. It is not the default for the rest of the world. API customers anywhere can turn it on starting today, and it stays off unless they do. On OpenAI’s own tests, at a 1 percent false-positive target, the detector caught the mark in about 80 percent of shorter psychology-style passages and about 95 percent of longer ones, and much less often in math. Changing a quarter of the words dropped detection to 17 percent. The checker is not public. Approved researchers can apply. OpenAI says the mark does not name the user, does not measure how much a person wrote, and does not prove the text is true. A missing mark does not prove a person wrote it.

RELATED

ONLINE…

Comments

guidelines

Loading…

Loading…

Sources