In this article
OpenAI will add an invisible statistical watermark to ChatGPT and Codex output in the European Union to comply with EU AI Act transparency rules, which TechCrunch reports took effect August 2. The EU rollout will happen over the coming weeks across all plans in the EU only. From October 5, API customers globally can opt in for select models; watermarking remains off by default in the API, and OpenAI is not making it a global default at launch.
The technology, textGrain, adds an invisible statistical signal to the model's word choices rather than inserting visible symbols or appended text. OpenAI's technical report, co-written with researchers from the University of Pennsylvania and Yale, describes using a secret key to sort next-word predictions during generation. Across hundreds of inference steps, those small nudges form a statistical fingerprint that a detector holding the key can recognise. The signal lives in the token sequence rather than external metadata, so it persists when text is copied across environments. OpenAI says textGrain matched or exceeded other approaches it tested, including Google's SynthID for text. The company also notes that a positive detection does not verify accuracy, establish ownership, or identify the user.
Detection is sharply constrained by length and domain flexibility. At a target false positive rate of 1%, OpenAI's detector found watermarks in about 95% of 400-token passages and about 80% of 200-token passages for content such as psychology. Detection rates were substantially lower for low-entropy outputs such as mathematics, where there is less flexibility in word choice. Editing causes rapid decay: in 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%, and replacing 25% cut it to 17%. Those limitations are why OpenAI is opening detector applications today only to approved researchers and expert organizations rather than making the tool public.
OpenAI also cautions that a missing watermark does not prove human authorship. Text may be too short, edited, translated, produced by an unsupported model, or generated by another company's systems. The company plans to release textGrain technology in open source and is working with cloud partners to make watermarked outputs available through their services in the coming weeks. Existing image and audio verification tools, including openai.com/verify and the Content Provenance API, remain publicly available; the restricted launch applies only to text detection.
On output quality, OpenAI reports no meaningful performance differences across the benchmarks used to assess Astra, its latest frontier model.
| Benchmark | Unwatermarked text (Astra, max) | Watermarked text (Astra, max) |
|---|---|---|
| Artificial Analysis Intelligence Index | 49.57 points | 49.76 points |
| AutomationBench | 34.09% | 34.86% |
| DeepSWE v1.1 | 72.80% | 71.68% |
| Terminal-Bench 4.0 | 53.90% | 56.06% |
| Terminal-Bench Science 0.1 | 56.90% | 60.00% |
| BrowseComp | 87.92% | 87.35% |
| HealthBench Professional | 64.27% | 64.60% |
| GPQA Diamond | 94.44% | 93.94% |
AI Mastery analysis
The editing decay numbers are the real constraint for production systems. A 25% word substitution rate pushing detection from 92% to 17% means retrieval-augmented generation, iterative rewriting, and summarization steps can strip the provenance signal before a final answer reaches the user. Teams that need an auditable watermark through a multi-stage pipeline will have to treat textGrain as a fragile signal, not a durable artifact. The failure point is often pipeline architecture rather than model logic, as in production AI fails on architecture, not model intelligence.
Detector access is one-sided. TechCrunch notes that Anthropic said two months earlier it would watermark Claude globally, drawing user backlash over ownership, and a 2024 Wall Street Journal report indicated OpenAI previously held back partly over fears that users would switch to rivals. Now OpenAI API developers can opt in to token biasing, but without detector access they cannot build local automated compliance checks into their own test suites. The detector will report only whether it detects an OpenAI watermark, without revealing the user or their prompts or conversations. That leaves EU-regulated applications dependent on a verification tool they cannot call programmatically.
Text watermarking is moving from experiment to compliance requirement. The open question is not whether a statistical signal can be embedded, but whether it can survive the editing, translation, and multi-agent workflows that real AI products perform before output reaches a user.
Sources
Frequently asked questions
What is OpenAI's text watermark for EU users?
The watermark is textGrain, an invisible statistical signal embedded in ChatGPT and Codex word choices. OpenAI will roll it out to eligible EU users across all plans over the coming weeks, while API customers globally can opt in for select models from October 5.
How much does OpenAI's text watermark weaken when text is edited?
In OpenAI's 400-token passage tests, replacing 10% of words with synonyms lowered detection from about 92% to 66%. Replacing 25% of words cut successful detection to 17%.
Can developers use OpenAI's text watermark detector?
Detector access is limited at launch. OpenAI is opening applications to approved researchers and expert organizations, but is not making the tool public because of missed watermark and false positive risks.
Does text watermarking hurt OpenAI model output quality?
OpenAI reports no meaningful performance differences across benchmarks used to assess Astra, its latest frontier model. For example, GPQA Diamond was 94.44% without the watermark and 93.94% with it.
Related Reading
12 Lines of Code Could Hijack ChatGPT’s Mac App
A patched ChatGPT macOS flaw let local malicious code reach chat logs and issue trusted commands through the app, WIRED reports.

Generate and Run a Python Expression with Outlines
Use Outlines and GPT-4o mini to turn a word problem into a Python expression, execute it, and understand the risks of eval.
GPT-6.1 Sol Matches Astra on Coding at One-Fifth the Price
OpenAI's GPT-6.1 Sol hits $2/$10 per million tokens—one-fifth of Astra's rate—while matching it on DeepSWE and closing to within 2.1 points on computer use.