On October 5, 2026, OpenAI announced that it will add an invisible watermark to eligible text output from ChatGPT and Codex offered in the European Union (EU). The rollout will reach all plans, including the free tier, over the next several weeks. API users worldwide can opt in on the same day on some models. The move responds to the EU AI Act's requirement that AI-generated content be machine-identifiable.
However, the "textGrain" watermark being introduced cannot tell you how much of a text a human actually wrote. Setting the way it generates text, the detection tests, and the EU provisions side by side, what it can reveal is, at most, the possibility that AI was involved in generating the text. That is a long way from determining who wrote it, or who bears responsibility when it is published.
EU ChatGPT and Codex, and the global API, are handled differently
For eligible ChatGPT and Codex users in the EU, watermarking will be introduced for text on all plans, including the free tier. At the time of the announcement, though, the rollout had not been completed for every user; the timing is described as "over the next several weeks." OpenAI also says it is not making this a standard setting worldwide from the start. According to the official announcement, the treatment differs by delivery channel, as follows.
| Channel | Scope announced | Start and settings |
|---|---|---|
| ChatGPT / Codex | Eligible EU users, all plans | Phased rollout over the next several weeks |
| OpenAI API | Customers worldwide, some models | Optional from October 5; disabled by default |
| Via cloud partners | Output of OpenAI models offered by partners | Planned to become available over the next several weeks |
In the API, watermarking for supported models can be enabled for an entire organization or for individual projects. According to the official FAQ, a model with the setting enabled embeds the watermark automatically at generation time, so users do not need to add separate marking to each output.
Enabling the watermark, however, does not give you access to a detector. Access to the detector requires a separate application, and at first it will be limited to approved researchers and specialist organizations.
The inclusion of Codex also does not mean every piece of generated code will carry a watermark. The European Commission's FAQ says source code is outside the marking obligation. The code itself needs to be considered separately from the explanations and reports generated around it.
textGrain adds a bias to the probabilities of word choice
textGrain is not a method that embeds hidden characters or invisible whitespace in text. Instead, it slightly adjusts the probabilities with which the model selects the next word or word fragment, leaving a statistical bias across the whole text. If a string is copied without changing the wording, the signal left in how its words were chosen is, in principle, carried along with it.
Whereas general AI-text detectors estimate whether a finished text is AI-generated from features such as its style, textGrain detects a statistical signal deliberately embedded at generation time.
The technical report released the same day lists researchers from the University of Pennsylvania and Yale University alongside OpenAI. It was published not as a peer-reviewed paper but as a technical report explaining the mathematics of the method being deployed.
Language models generate text sequentially in units called "tokens." A token may correspond to a whole word or only part of one, so it does not match character counts or word counts.
In Section 3 of the report, a secret key and the preceding text are used to divide the candidate next tokens into multiple groups. After adjusting the probability of each group being chosen, a token is selected within the group according to its original relative probability.
The detector reproduces the grouping using the same secret key and settings, then checks whether the tokens actually chosen show the bias expected from a watermarked text more often than chance would allow. Detection does not require the original prompt or the model used to generate the text.
The design also includes a safeguard against giving the same answer to the same question every time. A method that always picks specific words based on a secret key can leave a strong signal, but it removes the room to generate different answers from the same input.
In the Gumbel-max-style watermark the report cites as a comparison, fixing the context and the secret key determines which token is chosen, so repeated generation under the same conditions can produce the same answer.
TextGrain therefore makes adjustable how far the watermark constrains randomness at generation time. Using a mathematical technique called "optimal transport," it aims to make the watermark easier to detect while preserving diversity in answers.
It is designed so that averaging multiple adjusted probability distributions returns the original next-token distribution. This, however, is an average property that holds under the conditions set out in the report, and it does not guarantee that quality or diversity remain unchanged for any individual text.
On quality, OpenAI says it ran Astra at the max setting, compared eight benchmarks, and found no meaningful performance differences. For example, GPQA Diamond scored 94.44% without the watermark and 93.94% with it, and DeepSWE v1.1 scored 72.80% and 71.68%, respectively.
The FAQ also says tests using past ChatGPT versions showed no change in measures such as thumbs-down rates, and that the impact on generation speed was negligible. All of these, however, are evaluations by OpenAI itself. Benchmark scores cannot be treated as equivalent to the diversity of style or of multiple answers.
What "95% detection" means
The figure of roughly 95% that OpenAI presented refers to the share of watermarked texts that the detector correctly identified. It does not mean that a text judged positive has a 95% chance of being AI-authored.
The detector, after all, does not measure how much human judgment, editing, or creative work went into a text.
In OpenAI's evaluation, with the false positive rate (wrongly flagging unwatermarked text as positive) set at 1%, detection rates on responses in fields such as psychology were about 80% at 200 tokens and about 95% at 400 tokens. The evaluation used the ELI5 dataset, which explains specialized content in plain terms.
For content with few expressive options, such as mathematics, detection rates reportedly fall sharply. When the answer or the symbolic expression is nearly fixed, there is little room to choose different wording to carry the watermark signal.
In a separate evaluation of robustness to editing, 400-token English ELI5 answers were prepared and some of their words were replaced with synonyms.
| Share of words replaced with synonyms | Watermark detection rate |
|---|---|
| No replacement | About 92% |
| 10% | 66% |
| 25% | 17% |
Even just rephrasing some words greatly weakens the statistical signal the detector relies on. In this test, the pre-editing detection rate was about 92%, which differs in conditions from the roughly 95% shown in the 400-token evaluation on psychology and similar fields, so the two need to be viewed separately.
These results also do not show that replacing the same share of words in Japanese would lower the detection rate to a similar degree.
Differences between languages are not small, either. According to the official FAQ, OpenAI created 500 synthetic English prompts, translated them into 23 other languages, and evaluated them across the EU's 24 official languages.
With the false positive rate at 1%, the detection rate was 69.0% for Spanish and 42.2% for Romanian. For languages where detection falls below 60%, improved results using a stronger watermark are also shown.
The FAQ, however, does not give detailed conditions such as text length, so it cannot be compared simply with the 400-token psychology evaluation. Japanese is not among the 24 languages evaluated.
Even for texts that go undetected, the signal may have been weakened because the text was short, edited by a person, or translated. There are also models that do not support watermarking, texts generated before the rollout, and output from other companies' models.
Therefore, whether the result is positive or negative, it cannot establish how much of a text a human wrote.
Detecting a watermark and the duty to disclose on publication are separate matters
Article 50(2) of the EU AI Act requires providers of generative AI systems to mark outputs in a machine-readable format so that they can be detected as artificially generated or manipulated.
Article 50(4), meanwhile, places a responsibility to disclose on those who publish AI-generated or manipulated text for the purpose of informing the public on matters of public interest, that is, the "deployers" who use AI systems.
The party that embeds the watermark at generation time and the party that tells readers about AI use at publication are not necessarily the same.
Article 50(4) includes an exception for cases where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. For public-interest text published after a human has substantively reviewed it and taken editorial responsibility, the disclosure obligation under Article 50(4) may not apply, even if the generation-time watermark remains.
Putting OpenAI's October 5 explanation together with the provisions and FAQ from the European Commission, the picture can be organized as follows. This is a general classification assuming AI providers covered by EU law and deployers publishing text on matters of public interest, and it does not offer a legal conclusion on any individual text.
| How the text was produced and checked | Marking at generation | Disclosure at publication |
|---|---|---|
| AI generates it; no substantive human review | Subject to the provider's obligation | Subject to the Article 50(4) disclosure obligation |
| A human substantively reviews the AI draft and also holds editorial responsibility | The generation-time watermark may remain | May fall under the Article 50(4) exception |
| AI is used only to fix typos or grammar without changing the meaning of the original draft | May fall under the exception for standard editing assistance in Article 50(2) | How the original draft was produced and the conditions of publication need to be checked separately |
The European Commission's FAQ explains that a merely formal check that corrects typos or grammar does not amount to the human review or editorial control envisioned by Article 50(4).
A person simply checking and approving an AI-generated draft is not the same as substantively verifying and editing the content using knowledge and professional judgment.
Nor can the Article 50(4) exception, which rests on review by the publishing party, be applied as is to the marking obligation under Article 50(2) that falls on providers.
The fact that watermarking is optional in the API also does not make the legal obligations that apply in the EU themselves optional. Whether to enable the watermark feature in a product is a separate question from which party is subject to which obligation under the law.
Why the detector is restricted, and what challenges remain
OpenAI has long been cautious about introducing watermarks for text. In its August 4, 2024 official update, it explained that it had already developed watermarking technology but was weighing adoption while researching alternatives.
It said the approach at that time was relatively robust against localized rewording but vulnerable to translation or heavy rewriting by another generative model. It also worried that non-native English speakers who use AI as a writing aid could be unfairly placed under suspicion.
In this announcement as well, OpenAI describes watermarking and detection for text as an early-stage technology that still has major limitations. It has not declared the earlier concerns resolved.
It can be said that, taking into account both the EU's legal requirements and current technical limits, OpenAI chose to introduce watermarking in the EU first while restricting access to the detector and verifying results in real-world use.
The EU's code of practice on transparency says that, while watermark detection for free-form text is not sufficiently reliable, access to detectors can be limited to verified experts. Section 2.1.2 of the text envisions not only researchers but also regulators and news organizations as eligible.
OpenAI's initial decision not to release the detector publicly is consistent with a framework built around these technical constraints. However, those OpenAI permits to use it in the early stage will not necessarily coincide with all the experts the code of practice envisions.
Participation in the code of practice is voluntary, but the legal obligations set out in Article 50 of the EU AI Act are not.
The code also allows an approach relying only on invisible watermarks for free-form text, which has trouble retaining metadata. It also treats texts under 200 tokens as "very short texts," for which basic reliability is hard to ensure with current technology, and exempts them.
In other words, there is also a gap between being able to deploy watermarking technology and being able to reliably detect every short text.
The transparency obligations have applied since August 2, 2026, but for existing systems placed on the market before then, a grace period until December 2 applies to the marking and detection obligation under Article 50(2).
The grace period applies to Article 50(2); it does not postpone other transparency obligations, such as disclosure at publication, across the board. Likewise, the "next several weeks" OpenAI cites for the rollout cannot be read as applying the same deadline to new and existing systems.
OpenAI has also said it plans to open-source textGrain. But publishing the method itself does not necessarily mean anyone will be able to determine whether text produced by OpenAI's production services is watermarked.
Detection requires the corresponding secret key and settings, and no timeline has been given for making a detector available to general users.
If independent verification advances on real text in each language and on drafts edited jointly by humans and AI, it will become easier to judge in which situations, and to what extent, a watermark can be used as a clue that AI was involved in generation.
