Tuesday, 6 October 2026
Abdul Mannan Official Journalist & Media Professional
Artificial Intelligence

OpenAI Unveils Invisible Text Watermark for ChatGPT in the EU

OpenAI has announced that it will begin embedding an invisible watermark in text generated by ChatGPT and its coding agent Codex for users in the European Union, bringing the company into line with the EU AI Act’s transparency requirements.

The company said in a blog post on Monday that the watermark, which it has named textGrain, will roll out over the coming weeks to eligible ChatGPT and Codex outputs on all plans within the EU, and that there will be no opt-out for users there. Developers using OpenAI’s API anywhere in the world will be able to switch the watermark on for select models starting now, but it will be off by default, according to TechCrunch.

The watermark is not a visible mark at all. Instead, it works by subtly shaping the model’s word choices during generation, leaving a statistical pattern that readers cannot see but that a detector can identify — and because the signal lives in the words themselves, it survives copying and pasting. OpenAI published a technical report on the method alongside the announcement, co-written with researchers from the University of Pennsylvania and Yale, describing how a secret key is used to sort next-word predictions; across hundreds of such tiny nudges, a detector holding the key can determine whether a passage was likely produced by one of OpenAI’s systems.

The EU AI Act’s transparency rules, which took effect on 2 August, require providers of generative AI systems to mark AI-generated content in a machine-readable format so that other systems can identify it. OpenAI’s move follows a similar decision by Anthropic, which announced in August that it would watermark text generated by Claude — a move that drew backlash from some users who argued they had supplied “the instructions, context, decisions” while Claude was merely the tool. Google DeepMind has been watermarking its outputs for a couple of years, though Gizmodo notes the company moved in the opposite direction in August by letting users remove watermarks from images, video and music in countries where they are not required.

OpenAI itself is frank about the technology’s limits. Its tests show the watermark can be degraded by editing: replacing 10% of the words in a passage with synonyms dropped detection from around 92% to roughly 66%. Short passages, maths answers and translated text are also harder to detect. The company stresses that the watermark does not identify the user, that it saw no meaningful change in model performance with the watermark switched on, and — critically — that a missing watermark does not prove human authorship, since the text may simply be too short, too edited, or from another company’s model.

Those limitations are a key reason the detector will not be public at launch. OpenAI said initial access will be granted only to approved researchers and expert organisations “on a case-by-case basis”, to help evaluate reliability and responsible uses while guarding against false positives. The company also cautioned that the watermark can indicate an OpenAI system generated or processed part of a passage, but not how much human judgement, editing or creativity went into it.

The announcement also closes a chapter of internal hesitation. The Wall Street Journal reported in 2024 that OpenAI had already built a text watermark but held off releasing it, partly over fears that users would defect to rivals that did not watermark. Two years on, with the EU AI Act forcing its hand, the company has finally shipped one — though notably it is still stopping short of a global default, saying it wants to gather real-world usage data and feedback first.

Why It Matters

On paper, this is a compliance announcement. In practice, it is something bigger: the end of a long stand-off over one of the most debated tools in AI governance. A text watermark can help universities spot undisclosed AI-written coursework, newsrooms check whether copy came from a chatbot, and platforms trace synthetic content flooding the web. None of those problems is solved by a pattern that only a handful of approved researchers can see, but OpenAI’s move matters because it normalises the idea that provenance is the model-maker’s responsibility, not the reader’s detective work.

The technical fragility is worth keeping in perspective rather than treating as failure. OpenAI’s own figures — detection falling from roughly 92% to 66% after only one word in ten is swapped — show that a determined editor can strip the signal with a thesaurus. Watermarks are not lie detectors; they are speed bumps. They raise the cost of mass deception without stopping a dedicated deceiver, which is roughly what seatbelts did for driving. The real question is whether platforms, educators and election officials are given access to the detectors before the next wave of synthetic content arrives — and so far OpenAI has said no to public access, citing false positives.

There is also a market dynamic worth watching. Anthropic went global and mandatory with its watermark; OpenAI has gone EU-only and optional on the API. That split tells you the industry has not agreed on a standard, and the EU AI Act is the only force strong enough to make one of them move at all. Regulators elsewhere — Washington’s task forces, London’s frameworks — will be watching whether Brussels’ transparency obligations actually produce a workable layer or just a paperwork one.

For everyday users, the takeaway is narrower: ChatGPT’s words will not look or read any differently. But for the first time at this scale, a machine-readable trace of the machine’s hand will travel with the text wherever it is pasted. The ghost in the document is about to get a little less ghostly.

Sources

About the Author — Abdul Mannan

Leave a Reply

Your email address will not be published. Required fields are marked *