OpenAI textGrain: Text Watermarks for ChatGPT in the EU
OpenAI adds invisible textGrain watermarks to ChatGPT and Codex text in the EU, with API opt-in and a detector limited to researchers.
OpenAI adds invisible textGrain watermarks to ChatGPT and Codex text in the EU, with API opt-in and a detector limited to researchers.
Introduction
On October 5, 2026, OpenAI published "Our approach to EU text provenance rules," describing how it will make ChatGPT and Codex text identifiable under the EU AI Act. The Act requires generative AI providers to make generated text identifiable in a machine-readable way, and TechCrunch notes that the transparency rules took effect on August 2. OpenAI's answer is a phased plan built on a method it calls textGrain, which adds an invisible statistical signal to the model's word choices. The post is unusually frank about limits: OpenAI says text watermarking and detection "remain early technologies with significant limitations."
What is rolling out, and where
OpenAI describes three parts, each with a different audience and timeline.
| Part | Who it covers | Timing and default |
|---|---|---|
| API watermarking | API customers worldwide, for select models | Opt-in from October 5; off by default |
| ChatGPT and Codex | Eligible text output for users in the EU, across all plans | "Over the coming weeks"; EU only |
| Detector access | Approved researchers and expert organizations | Applications open October 5; granted case by case |
OpenAI also says it is working with cloud partners to offer watermarking for OpenAI model outputs accessed through their services "in the coming weeks." It states plainly that it is "not making text watermarking a global default at launch," describing the regional approach as room to learn from real-world use.
How textGrain works
textGrain adds an invisible statistical signal to the model's word choices, and a detector looks for that signal to assess whether a passage contains an OpenAI watermark. The technical report is titled "textGrain: Entropy-Calibrated Watermarking for Language Model Text," and TechCrunch reports it was co-written with researchers at the University of Pennsylvania and Yale. OpenAI says the report will be updated with more detail in the coming weeks and that it plans to release the technology as open source so others can build on it.
OpenAI also reports that, in its own evaluations, textGrain "matched or exceeded the performance of other approaches we tested, including SynthID for text." That is a vendor evaluation, and no independent comparison accompanies it. The company adds that strong performance under ideal conditions "does not guarantee reliable detection in everyday use."
What the numbers show
OpenAI shares two evaluations to illustrate the difficulty, both at a target false positive rate of 1%.
- Length and content type: the detector identified watermarks in about 80% of 200-token passages and about 95% of 400-token passages for content such as psychology. Detection was substantially lower for content such as mathematics, where there is less flexibility in word choice.
- Editing: on 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%, and replacing 25% reduced it to 17%.
In practice this means a short answer, a math solution, or a lightly paraphrased essay is a weak candidate for detection. OpenAI cites these results as part of why detector access is limited at launch.
Does it change output quality?
OpenAI reports that across the benchmarks it uses to assess Astra, which it calls its latest frontier model, it sees no meaningful performance differences with and without watermarking. The table below reproduces OpenAI's figures for Astra at its max setting.
| Benchmark | Unwatermarked | Watermarked |
|---|---|---|
| Artificial Analysis Intelligence Index | 49.57 points | 49.76 points |
| AutomationBench | 34.09% | 34.86% |
| DeepSWE v1.1 | 72.80% | 71.68% |
| Terminal-Bench 4.0 | 53.90% | 56.06% |
| Terminal-Bench Science 0.1 | 56.90% | 60.00% |
| BrowseComp | 87.92% | 87.35% |
| HealthBench Professional | 64.27% | 64.60% |
| GPQA Diamond | 94.44% | 93.94% |
Five scores move up and three move down, with the largest gap on Terminal-Bench Science 0.1 (a 3.1-point gain). OpenAI does not publish run counts or confidence intervals in the post, so small differences should be read as noise-level until the report adds detail.
What a watermark does not tell you
OpenAI lists five limits on how a detection result should be read. A watermark does not measure human contribution, does not establish ownership or responsibility, does not identify the user, and does not verify accuracy. The absence of a detected watermark does not prove human authorship, because text may be too short, edited, or translated, may come from an unsupported model, may predate watermarking, or may come from another company's tools. For schools, publishers, and employers, this list is the most practical part of the post: a positive result is a signal about OpenAI systems, not a verdict about a person.
Images and audio are unchanged
OpenAI says its verification tools for images and audio remain publicly accessible, including openai.com/verify and the Content Provenance API. It adds Content Credentials to supported image outputs, describes itself as C2PA conformant, and embeds invisible SynthID watermarks in supported images and audio. The text detector is the exception, and OpenAI cites "the risk of missed watermarks and false positives" as the reason it is not public at launch.
Industry context
TechCrunch reports that Anthropic said in August it would watermark Claude text worldwide, which drew backlash from some Claude users. It also recalls a 2024 Wall Street Journal report that OpenAI had built a text watermark but held off, partly out of concern that users would switch to rivals. TechCrunch lists Anthropic, Google, Meta, Microsoft, and OpenAI among companies committed to the EU code of practice on AI-generated content.
Outlook and assessment
The design choices are the story. Keeping the API opt-in, limiting ChatGPT and Codex watermarking to the EU, and gating the detector all reduce exposure while the technology's error rates are studied. Open questions remain: how the report's updated analysis handles translation, how quickly the open-source release arrives, and whether researcher-only detector access produces independent evaluations. Developers who serve EU users should review the API opt-in against their own transparency obligations. Everyone else should treat the watermark as one layer, which OpenAI itself says is not enough on its own.
Editor's Verdict
OpenAI textGrain: Text Watermarks for ChatGPT in the EU earns a solid recommendation within the GPT space.
The strongest case for paying attention: the post publishes concrete detection rates and edit-robustness numbers, which lets readers judge the limits instead of relying on a general claim. That alone raises the bar for what readers should expect in this space. Reinforcing that, an opt-in, off-by-default API setting lets customers decide how watermarking fits their own transparency obligations — practical value rather than just headline appeal. The broader signal worth registering is straightforward: the regional split shows OpenAI treating watermarking as a compliance measure for the EU first, not a worldwide product default, since the post says it is not making text watermarking a global default at launch. On the other side of the ledger, one constraint is real rather than a marketing footnote: the detection rates drop steeply after light editing, so a paraphrased or translated passage may not be detected reliably. It should factor into any serious decision. Layered on top of that, a public detector is not available at launch, so most teachers, editors, and platforms cannot check a passage themselves — which narrows the set of teams for whom this is an obvious yes.
For ChatGPT power users, OpenAI API customers, and enterprise teams already running on the OpenAI stack, this is a serious evaluation candidate, not just a curiosity to bookmark. For everyone else, the safer posture is to monitor coverage and revisit once the use cases that matter to your team are demonstrated in the wild.
Pros
- The post publishes concrete detection rates and edit-robustness numbers, which lets readers judge the limits instead of relying on a general claim.
- An opt-in, off-by-default API setting lets customers decide how watermarking fits their own transparency obligations.
- OpenAI reports no meaningful benchmark change for Astra with watermarking, with five of eight scores slightly higher and three slightly lower.
- Plans to open-source the method and update the technical report give outside researchers a path to scrutinize it.
Cons
- The detection rates drop steeply after light editing, so a paraphrased or translated passage may not be detected reliably
- A public detector is not available at launch, so most teachers, editors, and platforms cannot check a passage themselves.
- The performance and SynthID comparisons are OpenAI's own evaluations, and the post does not describe independent replication.
- Watermarking in ChatGPT and Codex covers only the EU at first, so text from the same product elsewhere is not marked.
References
Comments0
Key Features
1. Method: textGrain adds an invisible statistical signal to the model's word choices; a detector checks for an OpenAI watermark. 2. Rollout: API opt-in for select models worldwide from October 5 (off by default); ChatGPT and Codex text in the EU only, across all plans, over the coming weeks. 3. Detector: applications open October 5, initially for approved researchers and expert organizations, granted case by case; not public at launch. 4. Measured limits (OpenAI): about 80% detection at 200 tokens versus about 95% at 400 tokens (1% false positive rate); 10% synonym replacement cuts detection from about 92% to 66%. 5. Quality check (OpenAI): no meaningful benchmark difference for Astra with and without watermarking.
Key Insights
- The regional split shows OpenAI treating watermarking as a compliance measure for the EU first, not a worldwide product default, since the post says it is not making text watermarking a global default at launch.
- Detection falls sharply with editing, because replacing 25% of words with synonyms cut detection on 400-token passages from about 92% to 17% in OpenAI's own test.
- Short and constrained text is the weak spot, with about 80% detection at 200 tokens against about 95% at 400 tokens, and lower still for mathematics.
- OpenAI keeps the detector away from the public because of the risk of missed watermarks and false positives, which signals that a positive result is not yet meant to settle disputes.
- The claim that textGrain matched or exceeded SynthID for text comes from OpenAI's own evaluation, so independent testing by the researchers granted detector access will matter.
- OpenAI's list of what a watermark cannot prove, including human contribution, ownership, and accuracy, is a useful guide for schools and publishers that might over-read a detection.
- Audio and image provenance stays public through openai.com/verify and the Content Provenance API, so the text detector is the one verification tool deliberately gated.
Was this review helpful?
Share
Related AI Reviews
ChatGPT Intelligent UI: Interactive Answers in GPT-6
OpenAI says ChatGPT now builds charts, maps, forms and tools inside answers, and starts replying while it thinks. Rollout began Oct 7.
OpenAI Math Repo: 722 AI-Produced Manuscripts on GitHub
OpenAI published 722 manuscripts from an internal model on GitHub, with Lean proofs for many. It says some unformalized results could have issues.
OpenAI Safety Report Lead Resigns, Citing Broken Culture
David Robinson, who oversaw safety reports on 12 frontier launches, quit OpenAI and says its culture is broken. OpenAI points to its safeguards.
ChatGPT macOS App Flaw: Patched Local Bug Exposed Chats
A patched flaw in OpenAI's ChatGPT Mac app let malware already on a machine reach chat logs and issue commands. Fixed in 26.924.20706.
