← All posts

Artificial intelligence

OpenAI Has Shipped Text Watermarking. Only the EU Gets It by Default, and Nobody Outside an Approved List Gets the Detector

OpenAI's textGrain watermark became automatic for EU ChatGPT and Codex users on October 5 and stayed opt-in everywhere else. Its published detection rates show a signal that survives reading and not editing — and the detector is available by application only.

MAI
Abstract artwork in orange and pink with curved trails of light, from OpenAI's announcement page.

OpenAI started watermarking its text output on October 5, and the way it chose to ship the feature says more than the feature does. The watermark is automatic for ChatGPT and Codex users in the European Union, optional and off by default for API customers everywhere, and the detector that reads it is available to nobody outside an approved list. The technology is called textGrain, and OpenAI published its detection rates alongside it. Those rates are the most useful thing in the announcement, because they describe what the watermark actually accomplishes.

What ships, and where

textGrain embeds what OpenAI describes as "an invisible statistical signal to the model's word choices" — when several words fit a sentence equally well, the model is nudged toward one of them in a pattern a detector can later recognise. Nothing about the visible output changes, and OpenAI says its testing found no meaningful quality degradation.

SurfaceStatus as of October 5
ChatGPT and Codex, EUAutomatic, rolling out "over the coming weeks"
ChatGPT and Codex, rest of worldNot watermarked
API, select models, worldwideOpt-in, off by default
DetectorApplication only; approved researchers and expert organisations, case by case

The EU-only default is not a product decision. Article 50 of the EU AI Act requires providers of generative systems to mark synthetic output in a machine-readable form, and that obligation became binding on August 2, 2026. OpenAI is meeting a legal requirement in the jurisdiction that imposed it and leaving the rest of its user base alone.

The numbers are the story

OpenAI's own figures, measured at a 1% false-positive rate, show a watermark that survives reading and does not survive editing.

ConditionDetection rate
200-token passage, flexible prose~80%
400-token passage, flexible prose~95%
10% of words replaced with synonyms92% → 66%
25% of words replaced with synonyms→ 17%
Mathematics and other constrained domainsSubstantially lower

Code is worse still, for a reason OpenAI states plainly: there are fewer plausible choices for what comes next than in ordinary prose, so there is less room to hide a signal. A watermark that degrades to 17% under a quarter of substitutions is not a defence against anyone with a motive. Run the text through a second model, paraphrase a few sentences, change the words a human editor would change anyway, and the signal is gone.

That is not a flaw OpenAI is hiding. The company is explicit that the watermark cannot measure human contribution, establish ownership, identify a user, or verify that anything in the text is true, and that its absence does not prove a human wrote something. What it can do is tell an institution with detector access that a particular unedited passage probably came out of an OpenAI model.

The detector is the policy

Withholding the detector is the decision worth arguing about. OpenAI's stated reason is that false positives and negatives are real and a public detector would invite misuse, which is defensible — a 1% false-positive rate applied to every student essay in a university is a large number of wrongly accused students. The consequence is still that provenance becomes an institutional capability rather than a public one. A teacher, an employer, a court or a reader cannot check. A vetted research organisation can, if OpenAI grants the application.

Compare the other two implementations now in the field. Anthropic announced text watermarking in August 2026 and applied it at the model level across every Claude product and surface, with no developer opt-out. Google has shipped SynthID for text. OpenAI's version is the most conditional of the three: mandatory where the law says so, optional where it does not, and legible only through the company.

Whether that is caution or convenience depends on how you read the incentives. The generous reading is that a weak signal in public hands causes more harm than good, and OpenAI has sized the rollout to what the technology can honestly carry. The less generous reading is that an opt-in watermark with a private detector imposes no cost on OpenAI's largest customers — the ones building products on the API who would rather their output not be traceable — while satisfying Brussels. Both readings are consistent with what shipped.

The one commitment that could change the picture is open-sourcing textGrain, which OpenAI says it intends to do. If the method is public, independent detection becomes possible in principle, and the argument moves from whether we are allowed to check to whether checking works at all. On the published numbers, that second question is still the harder one.

Sources: OpenAI: Text provenance in the EU · The New Stack · Unite.AI · 9to5Mac

Keep reading