Summary
- OpenAI will begin watermarking eligible ChatGPT and Codex text generated in the EU over the coming weeks.
- API customers worldwide can opt into the same textGrain watermarking system for selected models.
- Detector access will initially be limited because editing, short passages and other factors can weaken detection reliability.
Generative AI transparency is moving into the text itself as OpenAI prepares to place invisible statistical watermarks into eligible ChatGPT and Codex output for users in the European Union.
OpenAI says the system, called textGrain, alters the statistical pattern of word choices produced by supported models so that a separate detector can assess whether a passage contains the company’s watermark. The change is being introduced as the EU AI Act requires providers of generative AI systems to make machine generated content identifiable in a machine readable form.
Eligible ChatGPT and Codex text produced in the EU will begin receiving the watermark over the coming weeks, while API customers worldwide can opt into watermarked output for selected models from 5 October. The API feature remains disabled by default, so OpenAI is not making text watermarking a global standard at launch.
Regional deployment turns European AI regulation into a difference in how widely used services behave technically rather than limiting compliance to contracts, policies or documentation.
OpenAI already uses provenance mechanisms for generated images and audio, but text creates a harder engineering problem because ordinary editing can alter the sequence from which a detector attempts to recover its signal.
The watermark sits in probability
textGrain does not add hidden characters, invisible spaces or special punctuation. Instead, it changes how a model selects between possible words or word pieces during generation, creating a statistical pattern across a passage that can later be tested.
Because copying and pasting leaves the words intact, the signal is more durable than a formatting trick, although its presence proves less than a conventional signature. Detection can indicate that supported OpenAI technology generated or processed at least part of a passage, but it cannot identify the user, reveal the prompt, establish ownership or determine whether the content is accurate.
The reverse also matters because failure to detect a watermark does not establish human authorship. The material may have been generated before watermarking was enabled, produced with an unsupported model, written using another AI provider or altered sufficiently to weaken the signal.
Short and highly constrained passages are particularly difficult to classify reliably, according to OpenAI, while editing can reduce detectability. Watermarking is therefore better suited to providing provenance evidence than to making absolute decisions about authorship.
Detection creates another governance problem
OpenAI will initially restrict access to its detector to approved researchers and expert organisations rather than release it as a general public service. Applications opened on 5 October, with access granted individually while the company gathers evidence about performance in real use.
False results explain some of that caution. Incorrectly labelling human writing as AI generated could create serious problems in education, recruitment, publishing or disciplinary processes, while missed watermarks could create false confidence that a document was written without machine assistance.
Automated AI detection has already attracted scepticism because statistical classifiers can mistake writing style for provenance. Watermarking addresses a narrower problem by embedding a deliberate signal during generation rather than trying to infer origin only after the text has been written.
Even that approach remains probabilistic. OpenAI says its evaluations found that textGrain matched or exceeded other watermarking systems it tested, including Google’s SynthID for text, but controlled testing cannot guarantee the same performance after material passes through real editing and publishing workflows.
The company plans to release textGrain as open source technology, allowing researchers and other providers to inspect the approach, test attacks against it and potentially build compatible tools. Greater openness can improve scrutiny, although knowledge of a watermarking system can also encourage attempts to remove or evade its signal.
Compliance is becoming part of model behaviour
Putting the watermark inside generation moves compliance beyond the documentation surrounding a model. Earlier AI governance often concentrated on terms of use, safety evaluations, disclosures and model cards, whereas provenance rules require the system itself to produce content differently when regulatory requirements apply.
Companies using generative AI inside their own products will consequently face implementation choices of their own. An organisation calling an OpenAI model through the API may need to decide whether to enable watermarking, how users should be informed, whether generated material is subsequently altered by other software and what conclusions compliance teams should draw from detector results.
Workflows involving several models complicate the history further because text might begin in one service, be summarised by another, translated by a third and edited by a person before publication. A provenance signal may identify part of that chain without describing the complete route taken by the document.
OpenAI’s decision to keep API watermarking optional outside the EU also means multinational organisations may encounter different provenance behaviour across regions. Businesses trying to standardise governance globally will have to decide whether to follow the minimum in each jurisdiction or apply one internal policy everywhere.
The technical limits prevent watermarking from replacing clear disclosure. A durable provenance regime is more likely to combine embedded signals, metadata, platform controls and explicit statements about AI use rather than asking one detector to reconstruct the history of every passage.
European regulation is nevertheless pushing that work out of policy documents and into deployed systems. As textGrain reaches ChatGPT and Codex users in the EU, one of the AI Act’s transparency requirements becomes part of the generation process itself.












