What OpenAI is turning on

OpenAI said on Monday that it will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union over the coming weeks, across all plans. From the same day, API customers anywhere in the world can opt in to watermarked text for selected models. In the API it stays off by default, and the company said it is “not making text watermarking a global default at launch”.

The trigger is the EU AI Act, which requires providers of generative AI to make machine-generated text identifiable in a machine-readable way. OpenAI is also opening applications for access to its detector, granted case by case to approved researchers and expert organisations in line with the EU Code of Practice. It is not publicly available.

textGrain, and what it does to the model

The technology is called textGrain, and it works by adding an invisible statistical signal to the model’s word choices. OpenAI said textGrain matched or exceeded the other approaches it tested, including Google’s SynthID for text, and that it plans to release the technology in open source.

A laptop keyboard photographed close up on a desk
The watermark adds a statistical signal to the model's word choices. Illustrative photograph. Christian Naccarato · pexels · Pexels License

The company published benchmark results for Astra with and without the watermark and reported no meaningful difference: 49.57 against 49.76 points on the Artificial Analysis Intelligence Index, 94.44% against 93.94% on GPQA Diamond, and 53.90% against 56.06% on Terminal-Bench 4.0. These are OpenAI’s own figures for its own model.

The numbers that undercut the idea

The more interesting part of the post is how candidly it reports the limits. At a target false positive rate of 1%, OpenAI said its detector found the watermark in about 80% of 200-token passages and about 95% of 400-token passages for content such as psychology. For mathematics, where word choice is more constrained, detection was substantially lower.

Editing degrades it faster. In an evaluation of 400-token passages, replacing 10% of the words with synonyms cut detection from about 92% to 66%. Replacing 25% took it to 17%. That is the number to hold on to: a light rewrite defeats the mark.

European Union flags flying outside a building
The requirement comes from the EU AI Act. Illustrative photograph. Christian Wasserfallen · pexels · Pexels License

OpenAI is explicit that a detection does not measure human contribution, does not establish ownership or responsibility, does not identify the user and does not verify accuracy — and that the absence of a watermark does not prove a human wrote the text, since it may be too short, edited, translated, from an unsupported model, or from another company’s tools.

What to watch

The company already applies Content Credentials to supported images, is C2PA conformant, and embeds SynthID watermarks in supported images and audio, with public verification tools for both. Text is the part that resists the approach, because text is the part people rewrite. The things to watch next are the updated technical report, the open-source release, and whether detector access widens beyond the approved list.