OpenAI Will Watermark ChatGPT Text in the EU With textGrain
OpenAI will add an invisible textGrain watermark to ChatGPT and Codex text in the EU over the coming weeks to meet the AI Act, while API customers worldwide can opt in from 5 October 2026.
PromptCrates Editorial
Staff Writer

OpenAI said on Monday, 5 October 2026, that it will add an invisible watermark to text generated by ChatGPT and Codex for users in the European Union, its answer to the EU AI Act’s requirement that AI-generated text be identifiable by machines. The change reaches eligible users on all plans over the coming weeks, while API customers anywhere can switch watermarking on for select models from the same day. In OpenAI’s own tests, swapping just 10% of a passage’s words for synonyms cut detection from about 92% to 66%.
The announcement, published as Our approach to EU text provenance rules, is deliberately cautious. OpenAI calls text watermarking an early technology with significant limits and says a regional rollout gives it room to learn from real-world use before making any broader decision.
What OpenAI is rolling out under the EU AI Act
The plan has three parts. First, API customers around the world can opt in to watermarked text output for selected models, with the feature off by default. Second, over the coming weeks OpenAI will add the invisible signal to eligible ChatGPT and Codex output in the EU only, and the company says text watermarking will not become a global default at launch. Third, OpenAI is taking applications for its text watermark detector, but access will at first be limited to approved researchers and expert organizations, granted case by case in line with the EU Code of Practice.
OpenAI also says it is working with cloud partners so that watermarking reaches OpenAI model outputs served through their platforms in the coming weeks. Its verification tools for images and audio, including the public verify web tool and its Content Provenance API, stay open to everyone; the new restrictions apply only to text.
According to TechCrunch, the AI Act’s transparency rules took effect on 2 August and require AI companies to mark generated content in a way other systems can identify. TechCrunch also noted that Anthropic, Google, Meta, Microsoft and OpenAI are among the companies that have committed to the EU’s code of practice on AI-generated content. PromptCrates has tracked how the bloc switched on its AI Act enforcement powers, and OpenAI’s move is a concrete example of the law reshaping a mainstream consumer product.
How textGrain hides a signal in word choices
OpenAI’s method is called textGrain. Instead of inserting hidden characters, invisible spaces or odd punctuation, it nudges how the model chooses between plausible next words, so that a passage carries a statistical pattern a detector holding a secret key can find. The OpenAI Help Center article on provenance signals says the company built its own technique to gain more control than SynthID or TextSeal over the balance between detectability and response variety, and that it plans to release textGrain as open-source technology.
The accompanying textGrain technical report, dated 5 October and co-written with researchers from the University of Pennsylvania and Yale University, says the detector needs only the generated text and the key. It treats watermark strength as a budget of sampling entropy traded away for the signal, which gives operators a dial between how detectable the mark is and how varied the writing remains.
On quality, OpenAI reports no meaningful difference with watermarking switched on across the benchmarks it uses for Astra, its latest frontier model. GPQA Diamond moved from 94.44% to 93.94%, BrowseComp from 87.92% to 87.35%, and Terminal-Bench 4.0 actually rose from 53.90% to 56.06%.
Where the watermark falls short in testing
The company is unusually direct about the weaknesses. At a target false positive rate of 1%, its detector found watermarks in about 80% of 200-token passages and about 95% of 400-token passages for psychology-style answers, with substantially lower rates for mathematics, where word choice is tightly constrained. Editing hurts even more: replacing 10% of words with synonyms dropped detection to about 66%, and replacing 25% dropped it to 17%.
Those numbers explain why the detector is not public. OpenAI says the risk of missed watermarks and false positives is too high for open access at launch, and it spells out what a detection result cannot tell anyone. A watermark does not measure how much a person contributed, does not establish ownership or legal responsibility, does not identify the user and does not verify accuracy. A missing watermark does not prove human authorship either, because text may be too short, edited, translated, produced by an unsupported model, written before watermarking began, or generated with another company’s tools.
That caveat matters for schools, publishers and employers tempted to treat a detector as an authorship test. By OpenAI’s own framing, a positive result means an OpenAI system generated or processed part of a passage, and very little beyond that.
What the change means for EU users and developers
For ChatGPT and Codex users in the EU, everyday output should look the same, since the signal is invisible and OpenAI reports no quality loss. The practical difference is that their text now carries a statistical fingerprint that approved detectors can test for, and OpenAI’s help center says the mark is designed to survive light edits and copying and pasting. TechCrunch reported that OpenAI says the watermark does not identify the user.
OpenAI is following rather than leading here. TechCrunch noted that Anthropic said two months ago it would watermark Claude text worldwide, a decision that drew pushback from some users; PromptCrates explained what Claude’s invisible watermark means for prompt users when it went live. Google took a different route for media, as we reported when Google let users hide the sparkle but not the invisible watermark.
Developers serving EU customers now have a direct compliance lever. The help center says API customers can enable watermarking for a single project or across an entire organization and choose which models receive it, without marking each response themselves, while teams outside Europe can leave it off. What to watch next is whether OpenAI ships the promised open-source release and updated technical details, how quickly cloud partners add support, and whether EU regulators accept a detector that only vetted researchers can use as meeting the Act’s machine-readable marking rule.
- OpenAI: Our approach to EU text provenance rules
- OpenAI: textGrain technical report
- OpenAI Help Center: Provenance signals in OpenAI-generated content
- TechCrunch: OpenAI will start watermarking ChatGPT’s text in the EU
- PromptCrates: EU AI Act enforcement powers now active
- PromptCrates: Claude’s invisible watermark is live
- PromptCrates: Google lets you hide the sparkle, not the invisible watermark


