OpenAI plans to introduce invisible watermarks into eligible text produced by ChatGPT and Codex across all EU plans over the coming weeks, giving generated passages a signal that its detector can recognize. API customers worldwide can opt in starting today for select models, with watermarking disabled unless they enable it. OpenAI is introducing the technology in response to the EU AI Act requirement that providers make AI-generated text identifiable by machines.
Access to the detector will initially require approval, even as watermarking becomes available to API customers globally and rolls out to eligible EU ChatGPT and Codex users. Researchers and expert organizations can apply today, with OpenAI assessing access individually to support testing and improvements. The company attributes that restriction to the risk of incorrect detection results, including both missed watermarks and signals reported in unwatermarked text.
Read more: Is OpenAI Codex down? Reports indicate trouble connecting to the servers
The technology, called textGrain, alters word selection to leave a statistical pattern that remains invisible to readers. OpenAI says it intends to release the technology as open source and is working with cloud partners to offer watermarking through their services over the coming weeks. The company says its tests found textGrain performed at least as well as the alternatives it evaluated, including SynthID for text.
Detection varied considerably with passage length: for material such as psychology, OpenAI detected roughly 80% of watermarked passages containing 200 tokens and roughly 95% containing 400 tokens, at a target false-positive rate of 1%. Mathematics produced substantially poorer results because word selection offered less flexibility. In a separate test involving passages containing 400 tokens, substituting synonyms for 10% of words lowered detection from about 92% to 66%; changing 25% pushed it down to 17%.
OpenAI says a detected watermark can signal that its systems generated or processed some text, but cannot quantify a person's contribution to the passage. The detector does not connect text to an account or expose prompts and conversations. A detection result also cannot establish accuracy, ownership, legal use or responsibility for the content.
OpenAI says failure to detect a watermark cannot establish human authorship, since editing, translation, short passages and unsupported models can prevent detection. Its evaluations of Astra found no meaningful change in benchmark performance when watermarking was enabled, according to the company. Existing image and audio verification tools will remain publicly accessible to organizations, while OpenAI says it will broaden text detector access when results can be interpreted responsibly.













