OpenAI Text Watermarks in the EU: How textGrain Works

Illustration of a flowing ribbon of text blocks with a few glowing gold blocks carrying a hidden dot pattern, revealed by a magnifying glass, beneath a ring of EU stars over a map of Europe, representing OpenAI's textGrain watermark

OpenAI will hide a statistical watermark in the words ChatGPT and Codex write for users in the European Union, starting over the coming weeks. The mark, called textGrain, comes from the AI Act's labelling rule. It survives copy and paste but weakens under editing, and only approved researchers can run the detector for now.

What Happened

On Monday, 5 October 2026, OpenAI said in a blog post that it would add an invisible watermark to "eligible ChatGPT and Codex text output in the European Union." The rollout covers users on every plan, but only inside the EU. OpenAI said it is not making text watermarking a global default at launch, and described the regional approach as a way to learn from real-world use before going further.

Three changes arrived at once. First, the EU-only watermark in ChatGPT and Codex, phased in over the next few weeks. Second, developers anywhere in the world can opt in to watermarked output for select models in the API from the same day. It stays off unless a developer turns it on, and OpenAI said it is working with cloud partners to offer the same option for its models served through their platforms. The Decoder named Microsoft Azure as one of them. Third, OpenAI opened applications for its detector, limited at first to approved researchers and expert organisations.

Alongside the post, OpenAI published a 20-page technical report on textGrain, dated 5 October 2026 and co-written by researchers at the University of Pennsylvania, Yale University and OpenAI. The company says it will update the report in the coming weeks and plans to release the technology as open source.

The figures OpenAI published are unusually candid. TechCrunch, 9to5Mac and The Decoder all reported the same numbers from the post. With the detector tuned to a 1% target false-positive rate, it found the watermark in about 95% of 400-token passages on psychology, falling to about 80% at 200 tokens. Swapping 10% of the words in a 400-token passage for synonyms cut detection from about 92% to 66%, and swapping 25% cut it to 17%. Maths answers scored "substantially lower" because there are fewer ways to word them.

On quality, OpenAI reported no meaningful difference across eight benchmarks, including GPQA Diamond, BrowseComp and DeepSWE, when it ran its frontier model with the watermark on and off. 9to5Mac noted that the watermarked runs actually scored slightly higher on several of them.

Why It Matters

The trigger is Article 50 of the EU AI Act, which applies from 2 August 2026. It requires providers of generative AI systems to mark their output, including text, in a machine-readable way so that it can be detected as AI-generated. The European Commission's questions and answers on Article 50 add one important detail: systems already on the market before 2 August get a grace period for the marking and detection duty, and must comply from 2 December 2026. That is the deadline OpenAI, Anthropic, Google, Microsoft and Meta are working toward.

Images and audio were the easy part, because a file can carry signed metadata such as C2PA Content Credentials, or a pixel-level watermark. Plain text has neither. Once you copy a paragraph out of ChatGPT, nothing is attached to it. The only place left to hide a signal is the choice of words itself, which is why every big provider has landed on the same family of technique.

It also ends a long holdout. The Wall Street Journal reported in 2024 that OpenAI had built a working text watermark and shelved it, partly because users might move to rivals that did not watermark. The law has now removed that competitive worry inside the EU. Anthropic went further in August and watermarked Claude's text worldwide, using an approach based on Google DeepMind's SynthID. Some Claude users objected, arguing that they supplied the ideas and decisions while the model was only a tool. OpenAI's EU-only, opt-in-elsewhere approach looks designed to avoid that fight for now.

For ordinary users the change should be invisible. Your replies will read the same, nothing in the text will look different, and OpenAI says the mark does not identify you. What changes is that text you paste into an essay, report or website carries a hidden fingerprint that a licensed detector could pick up later.

How It Works

A language model writes one token at a time, where a token is a word or a piece of a word. At each step it has a probability for every possible next token. Normally it rolls the dice against those probabilities. A text watermark replaces part of that dice roll with pseudo-random numbers generated from a secret key and the last few tokens of context.

Take the technical report's own example. After "The morning was", the model might give "warm" a 30% chance, "cold" 25%, "mild" 15%, and "calm", "sunny" and "bright" 10% each. Any of those is a fine continuation. textGrain uses the key to split the vocabulary into blocks, then nudges the model toward whichever block the key favours at that position. Inside the chosen block, tokens keep their original relative odds, so the model still picks a sensible word.

The clever part is how hard it nudges. The report frames the choice as an optimal transport problem, a way of pairing the model's probabilities with the keyed random values at the lowest "cost", with a penalty for straying from ordinary sampling. That penalty is exactly the amount of randomness the watermark removes. OpenAI exposes it as an entropy budget: a cap on what fraction of the model's natural variety may be traded for watermark signal. A small budget keeps answers varied. A large one makes the signal stronger.

That matters for a known weakness of older schemes. Some earlier watermarks always picked the same token for the same context and key, so asking the same question twice could produce identical answers. Spending only part of the randomness keeps repeat answers different. The method is also "unbiased": averaged over all possible keys, the model's word choices are unchanged, which is why benchmark scores barely move.

Detection runs in reverse. The detector needs only the text and the secret key. It rebuilds the keyed blocks for every position and checks whether the words fall into the favoured blocks more often than chance would allow. One nudge proves nothing, but hundreds of them add up to strong statistical evidence. The detector does not need to know which entropy budget was used.

The same design explains the limits. Short passages have too few nudges to add up. Maths and code often have one correct way to write them, so there is little room to nudge. Every synonym swap or rewrite breaks some of the pattern, and translation breaks almost all of it, because the words are no longer the model's words.

What's Still Unknown

OpenAI has not said which models or regions count as "eligible", which API models support the opt-in, or exactly when the EU rollout will finish before the 2 December deadline. It has not said whether the watermark will follow EU users who travel, or how it decides who counts as being in the EU.

Detector access is the biggest open question. OpenAI's content provenance documentation says text checks are available only to approved organisations, including AI research and academic institutions, reviewed case by case. Public access will come "when we believe results can be interpreted responsibly", with no date. Teachers, publishers and employers who want to check text themselves cannot do so yet.

It is also unclear how detectors from different companies will work together. Each provider uses its own secret key, so OpenAI's detector cannot spot a Claude watermark, and Anthropic's cannot spot OpenAI's. The EU's Code of Practice asks for marking that is effective, interoperable and robust "as far as technically feasible", but no shared checker exists yet. Finally, the open-source release has no date, and outside researchers have not yet tested textGrain's robustness claims independently.

Frequently Asked Questions

Will I notice the watermark in ChatGPT's answers?

No. textGrain leaves no visible symbol, hidden character or label. It only shifts which of several equally good words the model picks, according to a secret key. OpenAI reports no meaningful quality change across eight benchmarks with the watermark switched on. Answers to the same question still vary from one try to the next, because the method spends only part of the model's natural randomness on the signal.

Does the watermark identify who wrote the prompt?

OpenAI says it does not. The detector reports only whether it found an OpenAI watermark in a passage. It does not identify the user, reveal prompts or show conversations. The signal comes from a company-wide secret key and the surrounding words, not from your account. A positive result can suggest that an OpenAI system produced part of the text, but it cannot say who used it.

Does the watermark apply outside the European Union?

Not by default for ChatGPT and Codex. OpenAI is rolling the watermark out to eligible users on all plans in the EU only, and says it is not a global default at launch. Developers anywhere can switch it on for select API models, but it stays off unless they choose it. Anthropic, by contrast, applies its Claude text watermark worldwide whichever way people reach the model.

Can editing remove the textGrain watermark?

Editing weakens it a lot. In OpenAI's own tests on 400-token passages, replacing 10% of words with synonyms dropped detection from about 92% to 66%, and replacing 25% dropped it to 17%. Translation and paraphrasing break the pattern further. Short passages and maths answers are hard to detect even without edits, because they contain too few flexible word choices to carry a reliable signal.

Can teachers or employers check text for the watermark now?

Not yet. OpenAI's text detector is open only to approved researchers and expert organisations, which apply through a form and are reviewed case by case under the EU Code of Practice. OpenAI says it is holding back public access because of the risk of missed watermarks and false positives. Its public tools at openai.com/verify and the Content Provenance API currently check images and audio, not text.

Does a missing watermark prove a human wrote the text?

No, and OpenAI says so directly. A passage may show no watermark because it is too short, has been edited or translated, was written before watermarking began, or came from a model the detector does not cover, such as a rival's or an open-weight model. A detected watermark also does not show how much human thought, editing or creativity went into the final text, or whether it is accurate.

Why is the EU requiring AI text watermarks?

Article 50 of the AI Act, which applies from 2 August 2026, requires generative AI providers to mark output in a machine-readable, detectable way to curb deception, fraud and impersonation. Systems on the market before that date have until 2 December 2026 for the marking duty. Separately, organisations that publish AI-generated text on matters of public interest without human editorial review must label it for readers.

Related Reading

Watermarks are a very different tool from the guess-based detectors schools already use. Our look at how accurate ZeroGPT and other AI detectors really are explains why style-based checkers produce so many false positives. Google's own watermark came to voice output earlier this year, covered in Gemini 3.1 Flash Live and SynthID watermarking. For the politics behind the law's timetable, see how the EU Parliament reshaped AI Act deadlines.

If you are weighing which assistant to use now that Claude marks text everywhere and ChatGPT marks it only in the EU, our ChatGPT vs Claude vs Gemini comparison covers the wider differences. Educators deciding how to handle AI writing will find practical ground rules in our guide to bringing ChatGPT into classroom learning.