Tech • AI • Robotics • Game

VIDEO
ENFR

Daily Podcast full article

OpenAI adds invisible watermarks to ChatGPT and Codex in the EU

OpenAI has begun turning EU AI Act transparency rules into a product feature: an invisible text watermark for eligible ChatGPT and Codex outputs in Europe, with optional API support elsewhere and a restricted detector for researchers.

Generated October 6, 2026 at 6:11 AM1257 words
AI-generated illustration

A regulatory feature, not a cosmetic label

OpenAI’s latest compliance move is deliberately hard to see. The company says it will add an invisible watermark to eligible text generated by ChatGPT and Codex in the European Union over the coming weeks, while allowing API customers worldwide to opt in for select models rather than making the feature a global default at launch . The rollout is tied to the EU AI Act’s transparency obligations, which require providers of generative AI systems to make AI-generated content identifiable in a machine-readable way .

The key change is that OpenAI is not placing a visible badge, disclaimer or character stamp into the text. Instead, its textGrain technology changes the statistical pattern of the model’s word choices, creating a signal that can later be checked by a detector . For ordinary readers, the sentence still looks like a sentence; for a compatible verification system, the sequence of choices may carry evidence that an OpenAI system generated or processed part of the passage .

That makes this a significant product-level compliance step. The watermark is not limited to a narrow demo or media format: OpenAI says it will apply to eligible ChatGPT and Codex text output for EU users across all plans, while developers using the API can switch it on globally for supported models . BleepingComputer described the rollout as applying to text generated by ChatGPT and Codex in the EU, with the API feature available worldwide but disabled by default .

How textGrain works

At a high level, textGrain works by nudging the model’s sampling process rather than by adding visible metadata. OpenAI says the system adds an invisible statistical signal to the model’s word choices, and its detector looks for that signal to assess whether a passage contains an OpenAI watermark . The company’s technical report describes the method as a way to couple token generation to keyed randomness, so a detector can later use the text and a secret key to test for the watermark signal .

The technical report frames the problem as a trade-off between detectability and preserving normal model behavior. It says textGrain uses an entropy-calibrated approach: the watermark should introduce enough dependence on keyed randomness to be detectable, while limiting how much sampling randomness is removed from generation . In plainer terms, OpenAI is trying to leave a trail in the distribution of word choices without making the model sound obviously different.

That design choice matters because text is easier to alter than images or audio. A copied paragraph can be edited, paraphrased, translated, shortened or merged with human writing. OpenAI acknowledges that these transformations can weaken the watermark and that strong results under controlled conditions do not guarantee reliable detection in ordinary use .

Detection is useful, but fragile

OpenAI’s own numbers show why the company is being cautious. At a target false-positive rate of 1%, its detector identified watermarks in about 80% of 200-token passages in content such as psychology, compared with about 95% of 400-token passages . The company also says detection was substantially lower for material such as mathematics, where there is less flexibility in word choice .

Editing has an even clearer impact. In one evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%, while replacing 25% of words reduced it to 17% . TechCrunch highlighted the same weakness, noting that OpenAI’s tests suggest the watermark can be weakened by ordinary editing and that short passages, math answers and translated text are harder to detect .

That is why OpenAI is not opening the detector to everyone immediately. The company says it is opening applications for access, but initial use will be limited to approved researchers and expert organizations that can help evaluate and improve the technology . In practice, that means the watermark may begin appearing in EU-generated text before broad public verification is available.

This limited-access model is a compromise. Public detectors can be useful for schools, publishers, platforms and researchers, but they can also invite overconfidence, false accusations and adversarial testing. OpenAI says a watermark result does not identify a user, account, prompt or conversation, and it does not measure how much human judgment, editing or creativity went into the final text .

What the watermark can and cannot prove

The most important caveat is that a watermark is not the same thing as authorship. OpenAI says a watermark can indicate that an OpenAI system generated or processed part of a passage, but it cannot show who owns the text, whether the use was lawful, who is responsible for it, or whether the passage is accurate . The company also warns that the absence of a detected watermark does not prove human authorship, because the text may be too short, too edited, translated, produced by an unsupported model, generated before watermarking, or created with another company’s system .

That distinction will be crucial in Europe. The EU AI Act is pushing AI providers toward machine-readable provenance, but detection signals are probabilistic and context-dependent. If a school, newsroom or platform treats a missing watermark as proof that text is human, it will overread the technology. If it treats a detected watermark as proof of misconduct, it may also overread the result, because AI-assisted drafting can include meaningful human direction and editing.

For developers, the API approach is especially notable. OpenAI says API customers worldwide can opt in to text watermarking for select models starting now, while the default remains off . That gives enterprise and platform customers a compliance lever: they can decide whether their own products need watermarked outputs, depending on where they operate, what they generate and how they disclose AI use.

Why the EU rollout matters beyond Europe

The rollout is regional, but its competitive effects may not stay regional. TechCrunch reported that the EU AI Act’s transparency rules took effect on August 2 and require AI companies to mark AI-generated content in a way other systems can identify . Once one frontier AI provider implements text watermarking across consumer, coding and developer services in Europe, rivals selling generative AI into the same market face pressure to show comparable provenance controls.

OpenAI is also presenting textGrain as one layer in a broader provenance stack. The company says no single provenance technique is enough on its own, and points to a layered approach that includes open standards, durable watermarking and verification tools for other media types . For text, however, the technical limitations are sharper: a paragraph is easy to rewrite, and the watermark depends on patterns across enough tokens to be statistically meaningful.

The result is a policy milestone with practical limits. OpenAI has not solved the problem of proving where every piece of text came from. It has created a compliance mechanism that can make some AI-generated text more verifiable, especially when passages are long enough and not heavily transformed. In the EU, that may be enough to move watermarking from a research debate into a standard feature of mainstream AI products.

The watermark is invisible, but the strategic signal is not. OpenAI is treating European regulation as an architecture requirement, not just a legal notice. If the rollout works without noticeable quality loss, text provenance may become one of the next default layers in generative AI infrastructure.

Comments

Be the first to comment.

Sources from the last 72 hours

  1. [1]Our approach to EU text provenance rulesOct 5, 2026, 2:00 AM
  2. [2]OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EUOct 6, 2026, 12:46 AM
  3. [3]OpenAI will start watermarking ChatGPT’s text in the EUOct 5, 2026, 10:36 PM
  4. [4]textGrain: Entropy-Calibrated Watermarking for Language Model TextOct 5, 2026, 2:00 AM

AI-generated article based on recent web research, then preserved as a dated editorial snapshot.