2026-10-05 · ← News
OpenAI will watermark text in the EU but keep the detector private
OpenAI will add an invisible watermark to eligible ChatGPT and Codex text in the EU over the coming weeks, while API customers worldwide can enable it voluntarily. Because edits weaken detection and results can be wrong, detector access will initially be limited to approved researchers and expert organizations.
The image could not be loaded.
OpenAI is responding to the transparency obligations in Article 50 of the EU AI Act. Over the coming weeks, it will add an invisible watermark to eligible ChatGPT and Codex text outputs across all plans in the EU. This will not be a global default. API customers worldwide can enable watermarking for select models, but it remains off by default in the API.
textGrain changes word selection rather than document appearance
The technology, called textGrain, embeds a statistical signal in word choices during generation. A detector with the same secret key then checks whether a passage contains that pattern. Readers cannot see the mark, and it is not a hidden character or metadata that disappears when text is copied.
OpenAI has also opened applications for detector access. Initially, only approved researchers and expert organizations will receive access on a case by case basis. The tool reports whether it detects an OpenAI watermark. It does not identify a user or reveal prompts and conversations. The company also plans to release the technology as open source.
The European rule creates a mark without a public reader
For an EU user, text generation changes while no public verification tool is available. API developers face the reverse arrangement: they can enable the feature globally, but it does not activate by default. This distinction separates compliance inside OpenAI's own products from a tool that an API customer must configure correctly.
A watermark can indicate only that an OpenAI system generated or processed part of a passage. It does not establish authorship, the amount of human contribution, ownership or truth. A negative result does not prove that a person wrote the text either.
Editing destroys the signal faster than the meaning
In tests published by OpenAI at a target false positive rate of 1%, detection reached about 80% for 200 token passages and 95% for 400 token passages in one set of psychology answers. In an editing test on 400 token text, detection fell from about 92% to 66% after 10% of words were replaced with synonyms, and to 17% after 25% were replaced.
That is a serious constraint for schools, newsrooms and moderation systems. Translation, paraphrasing or normal editing can weaken the signal, while a false positive can harm someone who actually wrote the text. OpenAI cites the risks of missed watermarks and false positives as the reason the detector will not be public at launch.
Independent tests will decide whether the watermark can bear a dispute
Three signals matter next: how textGrain survives translation and routine editing, which organizations actually receive detector access and whether the open source release allows outsiders to reproduce the company's results. A detected mark can support provenance, but it is not sufficient as the sole evidence in a dispute involving a student, employee or author.
Regulation has made providers place a machine readable trace in generated text. Practice must now show whether that trace can be read reliably and fairly enough to become more than a checked compliance box.
Lilith's verdict
OpenAI will write on European text with invisible ink, then lend the magnifying glass only to selected labs. A mark without a reliably accessible reader protects compliance better than a person accused of cheating.
I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.
Original source ↗ ↗