OpenAI announced a text watermarking scheme called textGrain on October 5, built to meet the transparency requirements of Article 50 of the EU AI Act. Over the coming weeks, eligible ChatGPT and Codex users in the EU will have their model-written text automatically carry a statistical signal — invisible to the eye but machine-detectable.
Starting the same day, API customers worldwide can manually turn the feature on for some models; it's off by default. The announcement didn't specify which models support it.
The watermark hides in word choice
textGrain works by tweaking how the model picks words during generation. At many points in a sentence, several words fit equally well, and OpenAI uses a key to decide which one lands. A single sentence shows nothing unusual, but if the passage runs long enough, the words favored by the key accumulate into a statistically detectable pattern — and whoever holds the key can use that pattern to judge whether the text came from a watermarked model.
OpenAI's detection figures assume a 1% false-positive rate:
- For a 200-token passage, detection runs at about 80%
- For 400 tokens, about 95%
- If 10% of the words in a 400-token passage are swapped for synonyms, detection drops to 66%
- Swap 25%, and it falls to just 17%
In other words, if a reader takes a piece of ChatGPT-written text and rewrites it even slightly, the watermark essentially disappears. OpenAI doesn't dodge the point in its write-up.
On quality, the company says scores with the watermark on and off differ within noise across eight benchmarks, with one pair of scores at 49.57 versus 49.76.
The detector stays closed to the public
The most restricted part of the scheme is detection. OpenAI opened an application process the same day, but access to the detector is limited to "approved researchers and vetted institutions," reviewed case by case. Ordinary users, schools, and publishers currently have no way to check a piece of text themselves.
OpenAI drew explicit boundaries in its statement:
"A watermark does not measure human contribution, does not establish ownership or responsibility, does not identify the user, and does not verify accuracy."
The company also notes that failing to detect a watermark doesn't prove a piece of text was written by a human.
The regulatory clock
Article 50 of the EU AI Act requires providers of generative AI to make their output machine-identifiable as AI-generated. Under the published timeline, the provision has applied since August 2, with a compliance grace period until December 2 for systems already in service. OpenAI's "coming weeks" rollout in the EU lands roughly inside that window.
That also explains why the watermark defaults to on only in the EU. Elsewhere, ChatGPT and Codex output isn't watermarked for now; API users can switch it on themselves if they want.
Others on the same road
Text watermarking has gotten crowded over the past year.
Google DeepMind's SynthID was first to market with text watermarking, using the same bias-the-sampling principle, and later open-sourced its text component; in late September it extended the same idea to AI-designed protein sequences. Reports say OpenAI itself believes textGrain performs on par with or slightly better than SynthID, though that claim hasn't been independently verified yet.
Anthropic announced a watermark for Claude's text output in August, using a similar approach that runs into the same old problem — a rewrite defeats it. The inference framework vLLM turned a Gumbel-sampling-based text watermark into a built-in option in September; tests showed it catching essentially all creative-writing output at around 100 tokens, but only 43% of coding output at 400 tokens.
Lined up together, the numbers point to a clear pattern: the longer and more free-form the text, the easier the watermark is to spot; for code, formulas, and factual Q&A — content with far less room to bias word choice — the signal is inherently weaker. textGrain's published numbers are for general text; OpenAI didn't give separate figures for code.
For users in mainland China, the change has little immediate effect — the watermark defaults to on only in the EU, and ChatGPT was never directly accessible there anyway. China's own Measures for Labeling AI-Generated and Synthetic Content, in effect since last September, takes a different approach: explicit labeling combined with implicit metadata labeling.
Sources: OpenAI's EU text-provenance statement, AI Weekly, CocoLoop, CellCog technical analysis; detection rates assume a 1% false-positive rate, and the Act's effective dates follow the EU's published timeline.