Lilith.
⌕
Editorial illustration: OpenAI will watermark EU text while rationing access to the detector
Lilith illustration · editorial remix

OpenAI will begin adding an invisible watermark to eligible ChatGPT and Codex text output in the European Union over the coming weeks. API customers worldwide can already opt in for selected models, while the feature remains off by default in the API.

EU users get the mark automatically while API developers choose it

The company is creating different regimes for consumer products and the API. Selected ChatGPT and Codex output in the EU will carry the mark across all plans. In the API, watermarking is a global opt-in for selected models.

The watermark changes the statistical pattern of word selection rather than the appearance of a document. OpenAI calls it textGrain. Its detector can indicate that an OpenAI system generated or processed part of a text, but it cannot identify the user, measure the human contribution, establish ownership or determine whether the content is true.

A mandatory trace with a restricted reader shifts who holds power

Organizations can apply for detector access, but the initial group will be limited to approved researchers and expert organizations. Control over reading the mark therefore sits with a narrower group than the people whose output receives it. A school, newsroom or employer may want to assess provenance, while an ordinary user cannot independently check the result.

That governance question matters more than the watermark mechanism alone. A provenance tool can shape disputes about authorship, so it needs clear rules for access, appeals and uncertain results. Article 50 of the AI Act creates pressure for machine-readable marking, but it does not automatically create a fair process around the signal.

Editing weakens the signal and a negative result proves little

OpenAI's technical report shows that reliability depends on text length and editing. In one test, at a target false-positive rate of 1%, detection reached about 80% for 200 tokens and 95% for 400 tokens. For a 400-token text, replacing 25% of words with synonyms reduced detection to roughly 17%.

The watermark therefore cannot safely decide a disciplinary or employment dispute by itself. Translation, paraphrasing and routine editing can weaken the trace. A negative result also does not prove that a human wrote the text.

Independent tests and appeal rules will determine whether it is usable

The useful signals will be who actually receives detector access, whether outside researchers can reproduce the company's results and how institutions handle disputed findings. Performance across languages, after translation and after ordinary editorial work will matter as well.

The European requirement will put a trace into text. The system will earn trust only when people can see not merely a detector verdict, but its uncertainty and a route to challenge it.

Lilith's verdict

The watermark may appear in every European student's essay while the key to read it stays behind OpenAI's counter. Anyone handing out stamps also owes people a way to challenge a bad impression.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗ ↗