OpenAI textGrain watermarks ChatGPT and Codex text in EU
OpenAI will start embedding an invisible watermark in text produced by ChatGPT and Codex for users in the European Union. The company says the rollout will take place over the coming weeks and will apply to "eligible" output.
The watermark cannot be seen by readers and does not survive as a visible mark when text is copied. The technology, called textGrain, works by slightly adjusting the words the model picks. Those small shifts form a statistical pattern that a detector can look for later.
"Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union," OpenAI said.
Opt-in for developers, limited access to the detector
The EU rollout does not mean watermarking is becoming a global default. Outside ChatGPT and Codex in the EU, the feature stays switched off unless someone turns it on.
API developers anywhere in the world can now opt in to watermarking for supported models. By default, it remains disabled.
OpenAI is also accepting applications for its watermark detector. At first, only approved researchers and expert organizations will get access.
Light edits weaken detection
OpenAI is open about the limits of the approach. Its own testing shows that ordinary editing can sharply cut the detector's success rate.
"In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% of words reduced it to 17%," the company noted.
Length matters too. With a 1% false-positive target, the watermark was found in about 80% of 200-token psychology answers. When the answers reached 400 tokens, that rose to roughly 95%.
Results were weaker in subjects such as mathematics. In these areas the model has less room to choose between alternative words, which leaves less space for the pattern.
"The absence of a detected watermark does not prove human authorship," OpenAI warned. "Text generated with OpenAI tools may be too short, edited, or translated for detection to work reliably."
What the watermark does not reveal
According to OpenAI, a positive detection does not identify who generated the text. It also does not expose the account, the prompt or the conversation behind it.
The detector also cannot measure how much of a finished piece was written or edited by a person. A positive result only indicates that the watermark pattern is present.
OpenAI says the watermark has no meaningful effect on the quality of GPT-6 Astra. Benchmark results stayed broadly similar with textGrain enabled.
Our Take
For security teams, the most important detail is how easily the signal breaks. OpenAI's own figures show that swapping a quarter of the words drops detection to 17%, and translation or short output can defeat it entirely. Anyone who wants to pass off AI-generated text as their own, including phishing operators or fraudsters, will likely have little trouble removing the pattern. That suggests textGrain is better suited to catching careless or unmodified output than to stopping determined abuse.
The privacy design is a positive point. The watermark does not carry account or prompt data, so it is not a tracking mechanism for individual users. Organizations should still be careful not to treat a detector result as proof of anything. OpenAI says plainly that a missing watermark does not prove human authorship.
The move comes as the industry struggles with growing volumes of machine-written content. Google recently paused an open-source bug bounty because of a flood of AI-generated reports, a case where reliable detection would be useful. It also comes shortly after OpenAI shelved its GPT-6.1 Astra launch while it works on safety cases.
It is worth watching whether OpenAI extends the default beyond the EU and how widely it opens the detector. Another open question is whether other AI vendors adopt comparable schemes, and whether independent researchers who gain access confirm OpenAI's own detection figures.
