Technology

OpenAI's Invisible Watermark for ChatGPT in the EU, Explained

Martin HollowayPublished 8m ago4 min readBased on 4 sources
Reading level
OpenAI's Invisible Watermark for ChatGPT in the EU, Explained
source:openai.com

OpenAI is adding an invisible, machine-readable watermark to text from ChatGPT and Codex, starting with users in the European Union.

The company announced the plan on October 5, 2026, in a post titled "Our approach to EU text provenance rules" OpenAI. The system is called textGrain. It works at sampling time — the moment the model picks the next word or word piece from several likely options — by slightly tilting those random choices, according to OpenAI's help article titled "Provenance signals in OpenAI-generated content" OpenAI. The text still reads normally. There is no visible badge or disclosure. The pattern is statistical and meant to be spotted by software, not people.

Eligible ChatGPT and Codex users on all plans in the EU will receive watermarked output over the coming weeks. That limited scope is deliberate. OpenAI is not making text watermarking a global default at launch The Verge.

API customers have a different path. Customers worldwide can choose to turn on watermarked text for select OpenAI models. That opt-in choice separates default product behavior from developer control, which matters for testing setups, existing prompts, and downstream tools that may react to even small shifts in token distribution, or the precise mix of word choices the model produces.

Detection is narrow by design. Approved researchers and expert organizations can apply for access to OpenAI's watermark detector, with early access granted case by case. The detector only says whether it finds an OpenAI watermark. It does not identify the user or reveal prompts or conversations.

OpenAI sets clear limits on what that result means. The company says textGrain does not guarantee reliable detection. It also says watermarks do not verify accuracy, determine ownership, measure human contribution, or prove human authorship. In OpenAI's reporting, watermarked and unwatermarked text scored similarly on benchmarks.

For practitioners, the key detail is where the change happens. Because textGrain biases random word selection rather than adding hidden metadata or changing formatting, it survives copy and paste but can be weakened by paraphrase, translation, heavy editing, and mixed human and machine drafting. That tradeoff is inherent to sampling-based watermarks. Signal strength depends on length, entropy — roughly, how open-ended and unpredictable the text is — and how much of the original word sequence is left intact. Short answers, highly constrained outputs such as code with fixed syntax, and text that has passed through another model will be harder to classify with confidence.

The broader context here is compliance engineering under regional rules. OpenAI presented the rollout as action under EU AI Act rules. A region-scoped default, plus a global API opt-in and a gated detector, gives regulators a machine-checkable provenance signal without committing every product surface to the same behavior on day one. It also keeps detection out of general circulation, which limits attempts to game the detector while researchers measure false positive and false negative rates.

In my view, the most useful way to read textGrain is as infrastructure, not as a truth test. A watermark that is invisible, probabilistic, and explicitly not proof of authorship will not settle disputes about who wrote what. It can help platforms, auditors, and researchers sort material at scale, link suspected AI-made datasets, and build better test sets for provenance tools. The risk is overinterpretation by employers, educators, and courts that want a yes-or-no answer the tool was not built to provide. OpenAI's cautions on reliability, accuracy, ownership, and human contribution deserve to be repeated in every policy that cites a detector result.

In practical terms, what this enables, if the rollout holds, is a cleaner experiment. EU traffic becomes the live testbed for quality impact, latency overhead, user complaints, and evasion patterns. API opt-in creates a comparison group of watermarked and unwatermarked workloads on the same model family. Gated detector access allows independent measurement before any wider release. For teams building with language models, the near-term work is practical. Log whether inputs were generated with watermarking enabled, track output variance, and treat any detector score as one weak signal among others rather than ground truth.