OpenAI is about to make ChatGPT’s words traceable, at least in Europe. The company announced on October 5 that it will add an invisible watermark to text generated by ChatGPT and its coding agent Codex for users in the European Union, rolling out over the coming weeks across all plans.
The move responds to the EU AI Act’s transparency rules, which require AI providers to mark content in a way machines can identify.
The technology is called textGrain. “Our text watermarking technology, textGrain, adds an invisible statistical signal to the model’s word choices,” OpenAI said. “Our detector looks for that signal to assess whether a passage contains an OpenAI watermark.” The signal lives in the words, so it survives copy and paste. OpenAI says the watermark does not identify the user and saw no meaningful change in model performance with it on.
How textGrain works
OpenAI published a technical report alongside the announcement, co-written with researchers from the University of Pennsylvania and Yale. The method uses a secret key to sort next-word predictions as each sentence is written, and hundreds of these tiny nudges form a pattern the detector can spot from the text and the key alone. The company says textGrain matched or beat the alternatives it tested, including Google DeepMind’s SynthID, and it plans to release the technology as open source.
API customers worldwide can opt in starting today for select models, though it stays off by default. OpenAI is not making watermarking a global default at launch and wants real-world feedback first.
The watermark is easy to weaken
OpenAI is unusually candid about the limits. “In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%,” the company said. “Replacing 25% of words reduced it to 17%.” Short passages, math answers, and translated text are harder to detect too.
“These limitations contribute to our decision to provide initial detector access only to approved researchers and expert organizations, who can help us evaluate reliability and responsible uses,” OpenAI said. It also cautions that a watermark “can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it.” A missing watermark, it adds, proves nothing.
OpenAI arrives late to its own technology
This is not OpenAI’s first watermark. The company built one years ago but held it back, reportedly over fears that users would switch to rivals that did not watermark. Anthropic went the other way in August, watermarking Claude’s text worldwide, a move that drew backlash from users who felt they had supplied the instructions while Claude was just the tool. Google DeepMind has been watermarking Gemini’s text with SynthID since 2024.
The difference now is the law. With the EU AI Act’s transparency obligations in force since August, watermarking has shifted from a product choice to a compliance requirement, and OpenAI is signaling that the EU rollout is only the start.


