TLDR
- OpenAI is rolling out textGrain, an invisible watermark, for ChatGPT and Codex outputs in European Union territories.
- The watermark fulfills transparency obligations mandated by the EU AI Act.
- Internal testing reveals that replacing 25% of words with synonyms reduces detection accuracy to merely 17%.
- Detection access is currently limited to vetted researchers and specialized institutions.
- While mandatory only in the EU, API users globally can enable the watermark through their settings.
On October 5, OpenAI revealed plans to embed an invisible watermark into all ChatGPT and Codex-generated text throughout the European Union. The initiative addresses transparency mandates outlined in the EU AI Act.
The watermarking technology, dubbed textGrain, operates by subtly steering the language model’s word selection to create a concealed statistical signature.
A companion detection application then analyzes text for this distinctive pattern. According to OpenAI, the technique does not insert hidden characters, invisible whitespace, or unusual punctuation marks.
This design prevents users from simply stripping hidden formatting to eliminate the watermark. The signal is woven directly into the linguistic structure and word choices.
How Effective Is the Watermark Against Modifications?
The system’s effectiveness varies significantly based on passage length. OpenAI quantifies text using tokens—word fragments that AI systems process. Approximately four tokens equal three English words.
During internal evaluation, the detector successfully identified roughly 66% of unmodified responses containing approximately 150 words. When passages extended to around 300 words, detection rates improved to approximately 92%.
However, even minor edits severely degrade watermark reliability. For 300-word segments, substituting just 10% of words with synonyms reduced detection accuracy from 92% to 66%.
When users replaced 25% of words, detection plummeted to a mere 17%. OpenAI’s own research demonstrates the system becomes unreliable once content undergoes editing, condensing, or rephrasing.
The organization also noted that watermarking produced minimal impact on performance benchmarks for its newest model, GPT-6 Astra.
Why Isn’t the Detector Available to Everyone?
OpenAI has chosen not to make the detection tool publicly accessible immediately. Access will instead be granted exclusively to verified researchers and specialized institutions.
The company emphasizes that a positive detection does not disclose user identity, prompt content, or conversation details.
Conversely, a negative result carries limited meaning. Brief, modified, or translated passages can evade detection without raising flags.
Content generated by competing AI platforms will not activate the system, since it exclusively identifies OpenAI’s proprietary pattern. OpenAI explicitly clarified that the lack of a detected watermark cannot confirm human authorship.
Media files such as images and audio operate under different protocols. These files can already be uploaded to OpenAI’s publicly available verification platform to check for its SynthID watermark.
Beyond European borders, the ChatGPT watermark remains disabled by default for standard users. However, API clients worldwide can activate it for supported models through their project or organizational configuration panels.
This deployment follows the EU’s implementation of AI Act transparency provisions that took effect in August. OpenAI characterized the watermark as a component of its continued compliance efforts.
The company also referenced broader security trends in its statement. According to research conducted by TRM Labs, criminal exploitation of AI technologies increased 40% compared to the previous year.
OpenAI has not disclosed a timeline for potentially expanding public access to the detection tool. Currently, the EU implementation and restricted researcher availability represent the program’s operational scope.


