ChatGPT Watermarks in the EU: What textGrain Can and Cannot Detect

Vintage typewriter on a dark wooden table
Photo by Patrick Fore on Unsplash

OpenAI will add an invisible watermark to ChatGPT text, but only in the European Union. The system is called textGrain and is set to arrive in ChatGPT and Codex over the coming weeks; outside the EU it stays off, and developers can turn it on only if they choose to. For students, employees and freelancers in Germany and across Europe, this means their ChatGPT text will soon carry a signature that no one can see and that, for now, hardly anyone can check.

Key takeaways

  • OpenAI unveiled its text watermark, textGrain, on October 5, 2026. It will roll out to EU users on all ChatGPT and Codex plans over the coming weeks, in response to the labeling requirement in the EU AI Act.
  • In the API, the watermark stays off by default. Customers worldwide have been able to opt in for select models since October 5.
  • Under ideal conditions, OpenAI’s detector identifies about 95 percent of watermarked 400-token passages. When 25 percent of the words are swapped for synonyms, the rate falls to 17 percent.
  • The detector is not publicly available for now. Only approved researchers and expert organizations can apply for access.
  • Unlike Anthropic, which has watermarked Claude text worldwide since August, OpenAI limits mandatory watermarking to the EU.

How textGrain works

A language model picks each word from several suitable candidates. Whether a sentence continues with “however” or “but” is normally decided by a random number generator. textGrain replaces that randomness with a pattern that depends on a secret key. Nothing changes for the reader, and no hidden characters are inserted. Across many words, though, a statistical signal emerges that a detector holding the same key can find again. Because the signal lives in the word choice itself, it also survives being copied and pasted into a Word document or an email.

According to OpenAI, textGrain matched or exceeded the other approaches it tested, including Google DeepMind’s SynthID for text. SynthID is also the basis for the watermark Anthropic has used on Claude text since August. OpenAI reports no meaningful loss of quality: across eight benchmarks for its current frontier model, Astra, results with and without the watermark were close, for example 49.76 versus 49.57 points on the Artificial Analysis Intelligence Index. A technical report describes the method; OpenAI plans to expand it in the coming weeks and later release the technology as open source.

What the detector can and cannot do

OpenAI is unusually candid about the weaknesses of its own system. At a target false-positive rate of one percent, the detector found the watermark in about 95 percent of 400-token passages, which is roughly 300 English words. At 200 tokens, the rate dropped to about 80 percent. These figures apply to answers to psychology questions, where wording leaves a lot of room. For math, where word choice is tightly constrained, detection at 400 tokens was only around 60 percent, according to the charts analyzed by heise and The Decoder.

The effect of editing is even starker. Replacing every tenth word in a watermarked passage with a synonym cuts detection from about 92 to 66 percent. With a quarter of the words replaced, 17 percent remain. OpenAI explicitly names translations and very short texts as cases where detection becomes unreliable.

That leads to the most important sentence in the announcement: the absence of a watermark does not prove human authorship. Conversely, by OpenAI’s own account, a detected watermark only shows that an OpenAI system was involved in the text. It does not measure how much a person wrote or revised, it does not settle ownership, and it says nothing about whether the content is accurate. Nor does it reveal the user: the signal cannot be traced to an account, a prompt or a conversation.

Why only the EU, and why the detector stays locked

The trigger is Article 50(2) of the EU AI Act. It requires providers of generative systems to mark synthetic text, images, audio and video as AI-generated in a machine-readable way. The obligation has applied since August 2, 2026. For systems that were already on the market before then, a transition period runs until December 2, 2026, as we explained in our overview of the next AI Act deadline. OpenAI is now meeting the requirement exactly where it applies and no further. The company says it wants to learn from real-world use before deciding on next steps.

OpenAI’s hesitation has a history. In August 2024, The Wall Street Journal reported that a text watermark had been ready internally for about a year but that the company was holding it back. An internal survey had found that some users would use ChatGPT less if its output were marked. OpenAI confirmed the work at the time and cited concerns that the method could be circumvented and could disadvantage people who write in a second language and use AI as a writing aid.

For now, OpenAI grants detector access only on application, to researchers and expert organizations, in line with the EU code of practice on AI transparency. That is a deliberate decision against a public checking tool. For images and audio, OpenAI takes a different approach: its verification portal at openai.com/verify is open to the public. For text, the company cites the risk of missed watermarks and false positives. It is easy to imagine where a freely available detector with these error rates would lead, for instance if teachers used it to check term papers.

What it means for users and developers

People who use ChatGPT in the EU, privately or at work, do not need to do anything. OpenAI does not mention a setting to turn the watermark off in ChatGPT. In practice, little changes for now, because no one outside a select group of researchers can run the detector. That matters for schools and universities: textGrain does not create a reliable way to prove that a paper came from ChatGPT. Anyone who revises text, puts it in their own words or translates it already weakens the signal along the way.

The situation is different for companies that build OpenAI models into their own products through the API. They decide for themselves whether to switch the watermark on. A company offering an AI service in the EU may itself be subject to the labeling requirement, though, and can use the optional watermark as one building block for compliance. OpenAI says the option will also become available through cloud partners that sell access to its models in the coming weeks. As Anthropic’s worldwide approach shows, the market will not be uniform: where people have a choice, they will use it, and tools that claim to strip watermarks have been circulating on GitHub for weeks.

Our take: an honest minimum

With textGrain, OpenAI meets an obligation and is open about how limited the result is. That is more transparency than the industry has shown on this topic for a long time. It does not, however, produce a tool against deception: anyone who wants to disguise AI text only has to rewrite it thoroughly enough. The real value lies elsewhere, with platforms and researchers examining large volumes of unedited text, such as automated disinformation campaigns. There, long and unaltered passages are the norm, and that is exactly where the method is strongest. For any single text, the watermark remains a clue, not proof, and it should be treated that way.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top