OpenAI Is Now Watermarking AI Text in the EU
On October 5, 2026, OpenAI began adding an invisible watermark to eligible ChatGPT and Codex text across the European Union. The method is called textGrain. It does not insert a marker you can see; it introduces a statistical signal into the word choices the model makes, so a detector can look for the pattern afterwards.
Here is the number we keep coming back to. In OpenAI's own published testing, the signal is remarkably fragile. Replace 10% of the words in a passage with synonyms and detection drops from about 92% to 66%. Replace 25% and it falls to about 17%.
So the most reliable way to defeat this watermark is also the most reliable way to make the writing worse. There is at least a moral dimension, which is more than most detection technology offers.
What OpenAI actually shipped
Eligible ChatGPT and Codex text in the EU is now watermarked invisibly, across all plans, over the coming weeks. API users worldwide can opt in per model, off by default. The detector is not public: at launch it is limited to approved researchers and expert organisations. The watermark is compulsory and the tool that reads it is private, which is an unusual pairing.
The rollout details are worth being precise about, because several of them are more interesting than the announcement made them sound.
- Consumer scope. Eligible ChatGPT and Codex text inside the EU, across all plans, arriving over the coming weeks rather than instantly
- API scope. Available worldwide from the same day, but opt-in only, off by default, and limited to select models
- Detector access. Approved researchers and expert organisations, granted case by case. Not open to the public at launch
- What the detector shows. Whether it detects an OpenAI watermark. It does not disclose user identities, and it does not expose prompts or chats
- What stays public. Image and audio verification through OpenAI's verify tool and the Content Provenance API remain open to everyone
- Cloud partners. OpenAI says it is working with cloud providers to add watermarking to model outputs delivered through their services
Two details in that list will generate more argument than anything else. The first is that the watermark is on by default for EU users while the detector is closed to almost everyone. The second is that OpenAI has not said whether EU users can turn it off.
Why the signal is so fragile
The published testing is more interesting than the headline. OpenAI reports detection at a target false positive rate of 1%, which is the strict setting, since a detector that flags innocent text constantly is worse than no detector at all.
| Condition | Detection rate | What changed |
|---|---|---|
| 400-token passage, unmodified | ~95% | Baseline, psychological content |
| 200-token passage, unmodified | ~80% | Shorter text, weaker signal |
| 10% of words swapped for synonyms | ~66% | Down from ~92% at this test setting |
| 25% of words swapped for synonyms | ~17% | Down from ~92% at this test setting |
| Mathematical content | Much lower | Word choice is constrained, so less room for signal |
Figures as published by OpenAI. Synonym tests used 400-token English passages answering ELI5 questions. Assume a partial rewrite removes the signal entirely.
Detection was far weaker on mathematical text, because apparently even the watermarking cannot find the natural distribution of plus signs.
The pattern in that table is the part to take seriously. The watermark is doing its job in the one situation it was designed for: text that has been passed through untouched, by someone who had no reason to edit it. The moment a human edits the text for any reason at all, the signal degrades fast, and it degrades for ordinary reasons. Removing repetition. Tightening a sentence. Matching a house style. Doing the job.
This is not a flaw in the method. textGrain is a statistical mark on word choice, and word choice is exactly the thing an editor changes. The fragility is inherent to choosing that signal, and OpenAI published the numbers itself, which is to their credit.
How it compares to what Anthropic is doing
Anthropic is marking text too, using a version of Google DeepMind's SynthID-Text. The differences in scope and access are worth understanding if your team uses more than one model.
| OpenAI | Anthropic | |
|---|---|---|
| Method | textGrain, proprietary | Variant of DeepMind SynthID-Text |
| Consumer scope | EU only, eligible ChatGPT and Codex, all plans | Worldwide, supported Claude models |
| API scope | Opt-in, off by default, select models | Marked on supported models |
| Detector access | Approved researchers and expert bodies, by application | Private preview for regulators, media, researchers, and enterprises |
| Editing results published | Yes, at 10% and 25% synonym replacement | No |
Source: each provider's own published explainer. Anthropic has not published robustness figures, so the two cannot be compared on that axis.
One detail stands out. OpenAI says results from Anthropic's watermarked text showed minimal to no difference in their own benchmarks, whether watermarking was enabled or disabled. In other words, a detector tuned for one provider's signal does not carry over to the other. Any assumption that there is one universal AI-text detector you could simply buy is not currently supported by the evidence.
The failure that is organisational, not technical
Here is the part we think gets the least attention, and it has nothing to do with cryptography.
The watermark is applied to eligible text in the EU. It is not applied to eligible text everywhere else. Consider an agency with writers in Berlin and Toronto, both on the same company ChatGPT plan. The Berlin writer gets watermarked text. The Toronto writer does not. Both submit it to the same client project. The output is mixed, invisibly, and nobody notices until somebody runs a detector and gets a confusing result.
The only people who can run that detector, at launch, are approved researchers and expert organisations. So the practical consequence is this: the signal is not accessible to most businesses, is inconsistent across regions and plans, and degrades sharply under editing.
A detection result cannot settle a question about who wrote something. Which is unfortunate, because settling that question is the main thing people wanted the detector for.
It also does not render anywhere. There is no badge, no visible mark, and nothing a customer can see. The only people who can observe it are the people who already knew to look.
Our read is that this is a disclosure mechanism rather than a policing mechanism, and the distinction matters for how a business should use it. It says content came from a particular model. It does not say who asked the model to write it, what was in the prompt, how much a human changed afterwards, or whether the output was accurate. None of that is in the signal.
What this changes about content work
Not much, directly. Nobody's website is about to change because of a mark that renders nowhere.
The durable response is not technical, it is administrative, and it is the same regardless of whether your business operates in the EU. Keep a written record of which content was AI-assisted, what it was used for, who reviewed it, and who approved it. Keep it yourself. Do not rely on a detector, an access-controlled one held by third parties, to reconstruct that history later, because it will not do it accurately and you will not be able to run it anyway.
There is a second-order effect worth watching, and it belongs to search rather than compliance. If AI text is going to be marked at the model layer, the value of content shifts toward things a watermark cannot apply to: your own data, your own point of view, your own verification. That is the same territory our answer engine optimisation and content marketing work already operates in, and it is a reason to care about provenance that has nothing to do with regulators.
If you want to know what a content or SEO engagement looks like from your side, the cost estimator prices a scope in about a minute.
Frequently asked questions
Is ChatGPT text watermarked?
In the European Union, yes. OpenAI began adding an invisible watermark to eligible ChatGPT and Codex text across all plans over the weeks following October 5, 2026. Outside the EU it is not on by default, though API users worldwide can opt in per model. Image and audio verification has been public for longer through OpenAI's verify tool and Content Provenance API.
What is textGrain?
textGrain is OpenAI's watermarking method for text. Rather than inserting a visible marker, it introduces a statistical signal into the word choices the model makes, so a detector can look for the pattern. OpenAI reports it matched or exceeded the other methods it tested, including a variant of Google's SynthID-Text.
Can the OpenAI text watermark be removed?
Light editing substantially weakens it. In OpenAI's published testing, replacing 10 percent of words with synonyms dropped detection on 400-token English passages from roughly 92 percent to 66 percent, and replacing 25 percent dropped it to about 17 percent. A full rewrite would be expected to remove the signal entirely.
Does the EU AI Act require AI text to be watermarked?
The transparency obligations under Article 50 of the EU AI Act began applying on August 2, 2026, covering marking AI-generated content and enabling its detection. AI systems placed on the market before that date have until December 2 to meet those obligations. A voluntary Code of Practice on Transparency of AI-generated Content gives organisations an optional route to demonstrating compliance.
Will watermarking change my website content?
No. The watermark is not visible text, not a badge, and not metadata a visitor can see. Nothing renders on the page and there is no way for a customer to tell. The only people who can observe it are the parties with access to a detector, which at launch is limited to approved researchers and expert organisations.
Can I detect whether my content was written by AI?
Not reliably through OpenAI's tool, which at launch is restricted to approved researchers and expert organisations by application. Even where access exists, the published figures show detection falls sharply after light editing and is much weaker on constrained text such as mathematics. A detection result is weak evidence and should not be treated as proof of authorship.
Do other AI companies watermark text too?
Yes. Anthropic marks text on supported Claude models worldwide using a version of Google DeepMind's SynthID-Text, with detector access in private preview for regulators, media, researchers, and enterprises verifying their own compliance. The methods and access levels differ between providers.
How should businesses think about AI-written content in 2026?
The interesting constraint is provenance rather than detection. Because the signal is fragile, geography-dependent, and inconsistent across regions and plans, it cannot settle a question about who wrote something. The durable asset is a written record of which content was AI-assisted, where it was used, and who approved it, kept independently of any detector.
Related reading
- AI Broke the Bug Bounty — the same trust problem, in software security.
- Google's DESIGN.md: What the Design System Spec Means — how structured intent beats guesswork.
- Answer Engine Optimization — structured information for AI search.
- Content Marketing — what happens after the model writes the first draft.
- Website Cost Estimator — price your own scope in about a minute.