OpenAI Launches textGrain Watermarking for ChatGPT in the EU
OpenAI is rolling out invisible text watermarking in the European Union to comply with the EU AI Act while offering global API users an opt-in toggle.

Key takeaways
- OpenAI announced textGrain, an invisible statistical watermarking system for ChatGPT, Codex, and API text outputs.
- The watermark will be enabled automatically only for eligible ChatGPT and Codex users in the EU, while API users globally can opt in.
- Internal tests on the Astra model show negligible benchmark performance drops, though editing text significantly weakens detection rates.
- Detector access is currently restricted to approved researchers and expert organizations via an application process.
OpenAI announced on October 5, 2026, that it is implementing an invisible text watermarking system called textGrain for ChatGPT and Codex in response to the European Union's regulatory requirements. The rollout applies automatically to eligible ChatGPT and Codex text outputs across all tiers in the European Union over the coming weeks, as detailed in OpenAI's official announcement. Developers using the OpenAI API worldwide will also be able to opt in to watermarking on select models, where the feature remains disabled by default.
The move comes under Article 50 of the EU AI Act, which requires providers of generative AI systems to make artificial text outputs identifiable in a machine-readable format. While transparency regulations took effect on August 2, existing market entities have until December 2 to meet compliance obligations, as reported by Engadget.

How the textGrain Watermarking System Works
Unlike metadata that can be removed, textGrain alters the underlying generation process. The system embeds an invisible statistical signal directly into the model's word choices using a secret key to sort next-word predictions, according to TechCrunch. The technical report supporting the release was co-authored with researchers from Yale University and the University of Pennsylvania, and OpenAI stated it plans to release the technology as open source so third parties can build upon it.
OpenAI claims that textGrain matched or exceeded the performance of other approaches in internal testing, including Google DeepMind's SynthID for text. Because the signal is embedded into the syntax itself, the watermark persists when text is copied and pasted.
To ensure the statistical alterations do not degrade intelligence or reasoning, OpenAI evaluated textGrain across eight benchmarks on its frontier model, Astra. The results showed virtually identical scores across both conditions:
- GPQA Diamond: 94.44% unwatermarked vs. 93.94% watermarked
- BrowseComp: 87.92% unwatermarked vs. 87.35% watermarked
- DeepSWE v1.1: 72.80% unwatermarked vs. 71.68% watermarked
- Terminal-Bench 4.0: 53.90% unwatermarked vs. 56.06% watermarked
- Terminal-Bench Science 0.1: 56.90% unwatermarked vs. 60.00% watermarked
- Artificial Analysis Intelligence Index: 49.57 points unwatermarked vs. 49.76 points watermarked
- HealthBench Professional: 64.27% unwatermarked vs. 64.60% watermarked
- AutomationBench: 34.09% unwatermarked vs. 34.86% watermarked

Evasion, Editing, and Detection Limitations
Despite baseline benchmark parity, OpenAI emphasized that text watermarking remains an early technology with substantial limitations. Detection reliability drops significantly depending on length, domain flexibility, and subsequent human editing.
At a fixed false-positive rate target of 1%, textGrain's detector recognized watermarked 400-token passages in open-ended fields like psychology roughly 95% of the time. When passage length fell to 200 tokens, accuracy dropped to about 80%, as noted by The Decoder. In structured domains with constrained vocabulary, such as mathematics, detection rates fell sharply—reaching roughly 60% on 400-token passages.
Manual rewriting easily disrupts the statistical pattern. In tests using 400-token passages from the ELI5 dataset:
- Replacing 10% of words with synonyms lowered detection accuracy from 92% to 66%.
- Replacing 25% of words reduced detection accuracy to 17%.
OpenAI highlighted several key caveats regarding what textGrain results mean. A watermark does not measure human contribution, establish copyright ownership, reveal user identities, or verify factual accuracy. Conversely, the absence of a detected watermark does not prove human authorship, as text may have been translated, shortened, heavily modified, or generated by competing models.
Restricted Detector Access and Global Rollout
Because of the risks associated with false positives and evasion, OpenAI is not releasing the detection tool to the general public, according to 9to5Mac. Instead, access is restricted to approved researchers and expert organizations that apply under the EU Code of Practice framework. When queried, the detector only reports whether an OpenAI watermark is present and does not expose user accounts, prompts, or conversation history.

This regional rollout contrasts with Anthropic, which implemented mandatory global watermarking for Claude earlier this year using SynthID, drawing criticism from users who did not want their writing watermarked, as reported by PCMag. OpenAI noted that restricting default watermarking to the EU allows it to evaluate real-world usage before considering wider deployments, while cloud partners like Microsoft Azure will support opt-in watermarking for OpenAI models in the coming weeks.
Frequently asked questions
What is textGrain?
textGrain is an invisible watermarking technology developed by OpenAI that embeds a statistical pattern into a model's word choices, allowing detectors to identify AI-generated text.
Will all ChatGPT users have their text watermarked?
No. The text watermark is enabled automatically only for eligible ChatGPT and Codex users located in the European Union. API customers globally can choose to opt in, but it remains off by default.
Can textGrain watermarks be removed by editing?
Yes. OpenAI's evaluations showed that replacing 10% of words with synonyms reduces detection accuracy to 66%, while replacing 25% of words drops detection to 17%.
Who gets access to OpenAI's watermark detector tool?
Access is currently restricted to approved researchers and expert organizations that apply through an official evaluation process in line with the EU Code of Practice.
Sources
- Our approach to EU text provenance rulesOpenAI · Official
- OpenAI Will Add A Digital Watermark To Text And Code Generated In The EUEngadget · Oct 5, 2026
- OpenAI details new text watermarking system for ChatGPT, Codex, and the API9to5Mac · Oct 5, 2026
- OpenAI will watermark ChatGPT text in the EU but makes it optional for API users worldwideThe Decoder · Oct 5, 2026
- OpenAI is adding text watermarking in ChatGPT and CodexThe Verge · Oct 5, 2026
- OpenAI will start watermarking ChatGPT’s text in the EUTechCrunch · Oct 5, 2026
- OpenAI to Add Watermarks on ChatGPT's Text Outputs, But Only in the EUPCMag · Oct 5, 2026
How this story was made: the newsroom picked it up from Techmeme, Google News and the-decoder.com, gathered the full text of the sources above, and drafted it with AI assistance. Every factual claim was then checked against those sources before publishing (22 claims checked). Illustrations marked as AI-generated are not photographs. Spotted an error? Tell us.
Published October 6, 2026 at 00:10 UTC


