OpenAI Will Watermark ChatGPT Text in the EU. How It Works and Where It Falls Short

OpenAI said on October 5, 2026, it will add an invisible watermark to text generated by ChatGPT and Codex in the European Union to comply with the EU AI Act. OpenAI
The rollout will happen over the coming weeks to eligible ChatGPT and Codex users on all plans, but only in the EU. Developers using the API anywhere in the world can turn on text watermarking for select models starting October 5, 2026. The feature is off by default. OpenAI is not making it a global default at launch. TechCrunch
The result is two tracks. ChatGPT and Codex carry the default in one jurisdiction. API use is opt-in everywhere else.
The legal driver is Article 50 of the EU AI Act. Transparency duties requiring clear labelling in key cases apply from August 2, 2026. Providers must mark AI-generated content in a machine-identifiable way. Deployers of generative systems must clearly label AI-generated or manipulated text under Article 50(4).
Brussels has published supporting material for that duty. The Commission released a Code of Practice on Transparency of AI-generated Content, guidelines for providers and deployers of generative and interactive systems, and a set of icons for labelling AI-generated content. Anthropic, Google, Meta, Microsoft and OpenAI are among the companies that have agreed to follow the code.
The watermark is statistical, not visible. OpenAI slightly biases word choice to leave a pattern readers cannot see but a detector can find, much like a hidden weave in fabric. The pattern travels with the text when copied and pasted. OpenAI said it does not identify the user and caused no meaningful change in model performance when switched on.
OpenAI documented the method in a technical report for a system called textGrain, co-written with researchers from the University of Pennsylvania and Yale. It also published a Safety news post titled Our approach to EU text provenance rules on October 5, 2026.
Testing shows limits. In OpenAI's tests, replacing 10% of watermarked words with synonyms cut detection from about 92% to 66%. Short passages, math answers, and translated text are harder to detect. Initial detector access is restricted to approved researchers and expert organizations.
Text is only one track. Images generated with ChatGPT, Codex, and the OpenAI API include both C2PA metadata and SynthID watermarks. OpenAI describes a layered approach to content provenance that includes SynthID watermarking for images and audio.
Anthropic plans a broader rollout on text. It said it will watermark text generated by Claude worldwide. One lab is using EU defaults plus global API opt-in. The other is committing to global defaults.
The broader context here is how long provenance has been promised and how unevenly it has shipped. OpenAI, Google and other companies pledged to watermark AI-generated content in a 2023 White House process. EU lawmakers then spent three years defining what disclosure means in law, including a provisional political agreement on May 7, 2026, on revised AI rules.
In my view, practitioners should read this as compliance infrastructure, not as a solution to detection. A watermark that survives copy and paste helps downstream detectors, filters, and audit tools. It does not survive determined rewriting. It does not resolve short-form or highly constrained outputs. It does not assign attribution.
Looking at what this means for builders, three details stand out. First, off-by-default API watermarking creates fragmentation. The same model family will produce marked and unmarked text depending on settings and geography, so logging that setting becomes part of provenance. Second, closed detectors limit independent validation. Researchers can test the claims, but platform teams, educators, and newsroom technologists cannot yet run routine checks. Third, text now joins an existing stack with images and audio. C2PA and SynthID already cover pixels and waveforms in OpenAI's pipeline. TextGrain fills a gap, but orchestration across modalities is still deployer work.
Worth flagging for deployers, the law places duties on both providers and deployers. A provider-side watermark satisfies only part of the chain. Product teams still need user-facing disclosure, iconography where appropriate, and metadata handling that survives distribution. The technique has headroom in sampling, entropy calibration and detector design. If detectors become available, interoperable, and trusted enough for other systems to act on them without constant human review, these quiet marks could make AI content easier to trace and manage.


