Published: October 5, 2026 · Last updated: October 5, 2026
TL;DR: OpenAI announced today it’s rolling out an invisible text watermark called textGrain to ChatGPT and Codex output in the European Union over the coming weeks, with API customers everywhere able to opt in starting now. It’s a direct response to the EU AI Act’s requirement that generative AI output be machine-identifiable. OpenAI’s own numbers show the watermark is far from bulletproof: detection drops sharply on short answers, math-heavy content, and anything a user edits afterward.

OpenAI published a post titled “Our approach to EU text provenance rules” today, laying out three moves at once. Starting immediately, API customers anywhere in the world can opt in to watermarking for select models, though it stays off by default outside Europe. Over the coming weeks, ChatGPT and Codex will start attaching an invisible watermark to eligible text output specifically for users in the EU, across every plan. And OpenAI is opening up applications for outside researchers and “expert organizations” to get access to the detector that reads the watermark back out, though that access is limited and granted case by case for now.
The technology behind it is called textGrain. OpenAI describes it as a system that nudges a model’s word choices in a way that leaves an invisible statistical fingerprint in the finished text, without changing what the text actually says. A separate detector scans a passage and reports whether that fingerprint shows up. It’s the text equivalent of SynthID, the watermarking system Google already uses for AI images and audio, and OpenAI says in its own testing textGrain matched or beat SynthID’s text watermarking on detection performance.
The push comes straight from the EU AI Act, which requires companies building generative AI systems to make their text output identifiable in a machine-readable way. OpenAI isn’t the first to move on this. Anthropic rolled out its own watermarking for Claude’s text earlier this year, and Google has had SynthID running across its own products for a while now. What’s notable here is the scope: OpenAI isn’t just checking a compliance box quietly in the background, it’s publishing its accuracy numbers, limitations, and methodology in the open, which is unusual for a company that doesn’t always volunteer the downside of its own tech.
And the downsides are real. OpenAI’s own evaluation found that at a 1% false-positive rate, the detector caught the watermark in roughly 80% of 200-token passages, rising to about 95% for 400-token passages, but only when the content was something like a psychology answer with plenty of word-choice flexibility. Math-heavy text, where there often aren’t many ways to phrase an equation or a proof step, detected at a noticeably lower rate. Editing makes it worse fast: swap out 10% of the words for synonyms in a 400-token passage and detection fell from about 92% to 66%. Swap a quarter of the words and it dropped to 17%. In plain terms, paste ChatGPT’s answer into a document, change a handful of words, and the watermark is already on its way to invisible in the statistical sense, not just the literal one.
OpenAI is upfront that the tool was never meant to solve attribution on its own. Its own list of what the watermark doesn’t tell you is longer than what it does: it doesn’t measure how much of a passage a human wrote versus the model, doesn’t establish who’s responsible for the content, doesn’t identify which user generated it, and a missing watermark doesn’t prove a human wrote something either, since the same gap shows up for short snippets, translated text, or output from an unsupported model. The company also says it plans to open source the detection method eventually, which would let outside developers inspect and improve on it rather than trusting OpenAI’s word for how well it holds up.
There’s also a business logic worth noticing. Keeping watermarking off by default in the API, and rolling it out region by region instead of globally, lets OpenAI learn from real deployments before locking in a global default it can’t easily walk back if the accuracy numbers turn out worse at scale. That’s a reasonable engineering choice. It also means the people who most need reliable detection right now, teachers checking homework, editors checking submissions, platforms checking for bulk-generated spam, are the ones who’ll be waiting the longest for a tool that actually works outside a controlled test.
Related: OpenAI’s relationship with transparency has had a rough few weeks. The company fired three safety researchers over a leak it still hasn’t explained, and it was one of four AI giants hauled in front of New York City’s full Council this week to answer questions about AI risk under oath.
Bottom Line: Publishing your own failure rates takes more nerve than most tech companies show, and OpenAI deserves some credit for that. But an 80% detection rate on short text, cut to under 20% after a light edit, isn’t a compliance solution so much as a compliance gesture that happens to come with a transparency report attached. The EU wanted AI output to be identifiable. What it’s getting, for now, is AI output that’s identifiable as long as nobody tries very hard to hide it.
Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest



