OpenAI Is Watermarking ChatGPT Text Only Where EU Law Forces It, and Its Own Tests Show Editing Strips It Out
OpenAI will add an invisible textGrain watermark to ChatGPT and Codex text for EU users only, as the AI Act requires, while its own tests show swapping a quarter of the words cuts detection to 17%.

OpenAI is finally watermarking the text ChatGPT writes. But only in Europe, only because the law says it has to, and with a mark that its own tests show fades fast once someone starts editing.
The company said Monday it will add an invisible, machine-readable watermark called textGrain to ChatGPT and Codex output for eligible users in the EU over the coming weeks, across all plans. Everywhere else, it stays off by default.
"We are not making text watermarking a global default at launch. This regional approach gives us room to learn from real-world use and feedback," OpenAI said. API customers anywhere can opt in for select models, though that setting is disabled by default.
The regulator made the call
The push comes from the EU AI Act, which requires AI-generated content to be marked in a way another tool can detect. Its transparency rules have been in force since 2 August, and breaching Article 50 can cost up to 15 million euros or 3% of global annual turnover.
Anthropic took the opposite route. It switched on watermarking for Claude globally in August, while OpenAI is defaulting only where regulators require it. Anthropic's rollout drew pushback from users who argued they supplied the ideas and judgment and Claude mostly helped with the writing.
There is history here too. The Wall Street Journal previously reported that OpenAI built a text watermarking system years ago and held it back over fears users would switch to rivals that do not watermark.
How textGrain works, and where it breaks
Developed with researchers from the University of Pennsylvania and Yale, textGrain uses a secret key to nudge which words the model picks, leaving a statistical pattern a detector can look for. OpenAI says it does not meaningfully affect the quality of GPT-6 Astra and that it matched or beat Google DeepMind's SynthID for text.
The company's own numbers are less flattering. In 400-token passages, replacing 10% of words with synonyms cut detection from about 92% to 66%. Replacing 25% dropped it to 17%.
Length matters too. At a 1% false-positive target, detection sat around 80% on 200-token psychology answers and roughly 95% at 400 tokens. Math fared worse. "Text generated with OpenAI tools may be too short, edited, or translated for detection to work reliably," OpenAI wrote, adding that "the absence of a detected watermark does not prove human authorship."
A positive hit says little either. The mark cannot measure how much a human contributed, establish ownership, identify the user or verify accuracy.
A detector almost nobody can use
The detector itself is locked away. Approved researchers and expert organizations can apply for access case by case, and it only reports whether an OpenAI watermark is present, without identifying the user or revealing prompts.
"Given the risk of missed watermarks and false positives, we are not making it publicly available at launch," OpenAI said. The company concedes textGrain "does not guarantee reliable detection."
That fits a wider problem. No completely reliable way to mark AI text exists, and schemes like SynthID and C2PA are relatively easy to get around with basic know-how. An open-source GitHub project called watermarks-remover already says it supports OpenAI and Gemini watermarks on top of Claude's.
So the world's biggest chatbot now tags its text in the one region where a regulator can fine it, with a mark a light rewrite can wash out and a detector the public cannot touch.
Some offers on this page may be paid placements or contain affiliate links.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free