OpenAI Is Now Watermarking AI Text in the EU

On October 5, 2026, OpenAI began adding an invisible watermark to eligible ChatGPT and Codex text across the European Union. The method is called textGrain. It does not insert a marker you can see; it introduces a statistical signal into the word choices the model makes, so a detector can look for the pattern afterwards.

Here is the number we keep coming back to. In OpenAI's own published testing, the signal is remarkably fragile. Replace 10% of the words in a passage with synonyms and detection drops from about 92% to 66%. Replace 25% and it falls to about 17%.

So the most reliable way to defeat this watermark is also the most reliable way to make the writing worse. There is at least a moral dimension, which is more than most detection technology offers.

What OpenAI actually shipped

Eligible ChatGPT and Codex text in the EU is now watermarked invisibly, across all plans, over the coming weeks. API users worldwide can opt in per model, off by default. The detector is not public: at launch it is limited to approved researchers and expert organisations. The watermark is compulsory and the tool that reads it is private, which is an unusual pairing.

92% → 17% Detection after swapping a quarter of words for synonyms
1% False positive rate the published figures assume
Aug 2 When Article 50 transparency rules began applying

The rollout details are worth being precise about, because several of them are more interesting than the announcement made them sound.

Two details in that list will generate more argument than anything else. The first is that the watermark is on by default for EU users while the detector is closed to almost everyone. The second is that OpenAI has not said whether EU users can turn it off.

Why the signal is so fragile

The published testing is more interesting than the headline. OpenAI reports detection at a target false positive rate of 1%, which is the strict setting, since a detector that flags innocent text constantly is worse than no detector at all.

Reported textGrain detection rates, and what moves them
Condition Detection rate What changed
400-token passage, unmodified ~95% Baseline, psychological content
200-token passage, unmodified ~80% Shorter text, weaker signal
10% of words swapped for synonyms ~66% Down from ~92% at this test setting
25% of words swapped for synonyms ~17% Down from ~92% at this test setting
Mathematical content Much lower Word choice is constrained, so less room for signal

Figures as published by OpenAI. Synonym tests used 400-token English passages answering ELI5 questions. Assume a partial rewrite removes the signal entirely.

Detection was far weaker on mathematical text, because apparently even the watermarking cannot find the natural distribution of plus signs.

The pattern in that table is the part to take seriously. The watermark is doing its job in the one situation it was designed for: text that has been passed through untouched, by someone who had no reason to edit it. The moment a human edits the text for any reason at all, the signal degrades fast, and it degrades for ordinary reasons. Removing repetition. Tightening a sentence. Matching a house style. Doing the job.

This is not a flaw in the method. textGrain is a statistical mark on word choice, and word choice is exactly the thing an editor changes. The fragility is inherent to choosing that signal, and OpenAI published the numbers itself, which is to their credit.

How it compares to what Anthropic is doing

Anthropic is marking text too, using a version of Google DeepMind's SynthID-Text. The differences in scope and access are worth understanding if your team uses more than one model.

Text watermarking across the two major providers, as published
OpenAI Anthropic
Method textGrain, proprietary Variant of DeepMind SynthID-Text
Consumer scope EU only, eligible ChatGPT and Codex, all plans Worldwide, supported Claude models
API scope Opt-in, off by default, select models Marked on supported models
Detector access Approved researchers and expert bodies, by application Private preview for regulators, media, researchers, and enterprises
Editing results published Yes, at 10% and 25% synonym replacement No

Source: each provider's own published explainer. Anthropic has not published robustness figures, so the two cannot be compared on that axis.

One detail stands out. OpenAI says results from Anthropic's watermarked text showed minimal to no difference in their own benchmarks, whether watermarking was enabled or disabled. In other words, a detector tuned for one provider's signal does not carry over to the other. Any assumption that there is one universal AI-text detector you could simply buy is not currently supported by the evidence.

The failure that is organisational, not technical

Here is the part we think gets the least attention, and it has nothing to do with cryptography.

The watermark is applied to eligible text in the EU. It is not applied to eligible text everywhere else. Consider an agency with writers in Berlin and Toronto, both on the same company ChatGPT plan. The Berlin writer gets watermarked text. The Toronto writer does not. Both submit it to the same client project. The output is mixed, invisibly, and nobody notices until somebody runs a detector and gets a confusing result.

The only people who can run that detector, at launch, are approved researchers and expert organisations. So the practical consequence is this: the signal is not accessible to most businesses, is inconsistent across regions and plans, and degrades sharply under editing.

A detection result cannot settle a question about who wrote something. Which is unfortunate, because settling that question is the main thing people wanted the detector for.

It also does not render anywhere. There is no badge, no visible mark, and nothing a customer can see. The only people who can observe it are the people who already knew to look.

Our read is that this is a disclosure mechanism rather than a policing mechanism, and the distinction matters for how a business should use it. It says content came from a particular model. It does not say who asked the model to write it, what was in the prompt, how much a human changed afterwards, or whether the output was accurate. None of that is in the signal.

What this changes about content work

Not much, directly. Nobody's website is about to change because of a mark that renders nowhere.

The durable response is not technical, it is administrative, and it is the same regardless of whether your business operates in the EU. Keep a written record of which content was AI-assisted, what it was used for, who reviewed it, and who approved it. Keep it yourself. Do not rely on a detector, an access-controlled one held by third parties, to reconstruct that history later, because it will not do it accurately and you will not be able to run it anyway.

There is a second-order effect worth watching, and it belongs to search rather than compliance. If AI text is going to be marked at the model layer, the value of content shifts toward things a watermark cannot apply to: your own data, your own point of view, your own verification. That is the same territory our answer engine optimisation and content marketing work already operates in, and it is a reason to care about provenance that has nothing to do with regulators.

If you want to know what a content or SEO engagement looks like from your side, the cost estimator prices a scope in about a minute.

Frequently asked questions

Is ChatGPT text watermarked?

In the European Union, yes. OpenAI began adding an invisible watermark to eligible ChatGPT and Codex text across all plans over the weeks following October 5, 2026. Outside the EU it is not on by default, though API users worldwide can opt in per model. Image and audio verification has been public for longer through OpenAI's verify tool and Content Provenance API.

What is textGrain?

textGrain is OpenAI's watermarking method for text. Rather than inserting a visible marker, it introduces a statistical signal into the word choices the model makes, so a detector can look for the pattern. OpenAI reports it matched or exceeded the other methods it tested, including a variant of Google's SynthID-Text.

Can the OpenAI text watermark be removed?

Light editing substantially weakens it. In OpenAI's published testing, replacing 10 percent of words with synonyms dropped detection on 400-token English passages from roughly 92 percent to 66 percent, and replacing 25 percent dropped it to about 17 percent. A full rewrite would be expected to remove the signal entirely.

Does the EU AI Act require AI text to be watermarked?

The transparency obligations under Article 50 of the EU AI Act began applying on August 2, 2026, covering marking AI-generated content and enabling its detection. AI systems placed on the market before that date have until December 2 to meet those obligations. A voluntary Code of Practice on Transparency of AI-generated Content gives organisations an optional route to demonstrating compliance.

Will watermarking change my website content?

No. The watermark is not visible text, not a badge, and not metadata a visitor can see. Nothing renders on the page and there is no way for a customer to tell. The only people who can observe it are the parties with access to a detector, which at launch is limited to approved researchers and expert organisations.

Can I detect whether my content was written by AI?

Not reliably through OpenAI's tool, which at launch is restricted to approved researchers and expert organisations by application. Even where access exists, the published figures show detection falls sharply after light editing and is much weaker on constrained text such as mathematics. A detection result is weak evidence and should not be treated as proof of authorship.

Do other AI companies watermark text too?

Yes. Anthropic marks text on supported Claude models worldwide using a version of Google DeepMind's SynthID-Text, with detector access in private preview for regulators, media, researchers, and enterprises verifying their own compliance. The methods and access levels differ between providers.

How should businesses think about AI-written content in 2026?

The interesting constraint is provenance rather than detection. Because the signal is fragile, geography-dependent, and inconsistent across regions and plans, it cannot settle a question about who wrote something. The durable asset is a written record of which content was AI-assisted, where it was used, and who approved it, kept independently of any detector.

Related reading

← Back to Blog