Beginning in the coming weeks, OpenAI will embed invisible watermarks into text produced by ChatGPT and Codex for users across the European Union. This rollout applies to subscribers on all available plans within the EU region, as the company announced in a blog post on Monday. The move responds directly to requirements under the EU AI Act, which mandates that artificially generated text must be machine-identifiable.
The company is taking a measured approach by limiting this feature to the EU at launch rather than deploying it globally. OpenAI explained that this regional strategy allows it to gather real-world insights and user input before broader expansion. Starting today, API customers worldwide have the option to enable watermarking on select models, though the feature remains disabled by default for API use. OpenAI is also collaborating with major cloud providers to make the technology available through their platforms.
How textGrain works
The watermarking system, named textGrain, functions by embedding a concealed statistical pattern into the model's word selection process. A corresponding detector then searches for this hidden signal within text. According to OpenAI's testing, textGrain performed comparably to or better than competing approaches, including Google's SynthID for text. The company collaborated with researchers from the University of Pennsylvania and Yale on a published technical report detailing the approach.
Testing with OpenAI's Astra model revealed no meaningful performance degradation when the watermark was active. The company intends to release textGrain as open-source software.
Where it fails
OpenAI has been candid about the system's shortcomings. Operating at a target false positive rate of 1%, the detector successfully identified watermarks in roughly 80% of passages containing 200 tokens on subjects like psychology. Detection accuracy improved to approximately 95% for longer passages of 400 tokens. However, the system's effectiveness drops significantly when text is modified: replacing just 10% of words with synonyms reduced detection from about 92% to 66%, while replacing a quarter of the words lowered it to 17%. Mathematical content presented particular challenges, as the rigid nature of mathematical language leaves less room for word substitution.
OpenAI emphasized several critical limitations of the watermarking approach. The watermark cannot identify which user generated the text, measure the degree of human involvement, establish ownership rights, or confirm factual accuracy. Conversely, the absence of a watermark does not necessarily indicate human authorship—text might be too brief, edited after generation, translated, or produced by competing tools.
These limitations contribute to our decision to provide initial detector access only to approved researchers and expert organizations, who can help us evaluate reliability and responsible uses
OpenAI
Applications for detector access are now being accepted, with approvals determined on a case-by-case basis in accordance with the EU's Code of Practice. The detector indicates whether it identifies an OpenAI watermark without revealing user identity or the original prompts. OpenAI stated it will expand access to the detector once the organization gains confidence in responsible interpretation of results. The company's existing tools for verifying images and audio remain available to the general public.
The EU deadline
Article 50 of the EU AI Act mandates that generative AI providers ensure their text output is machine-readable. Companies already operating in the market face a compliance deadline of 2 December.
OpenAI is not the first to implement such measures. Anthropic started watermarking Claude outputs globally in August, though with certain exceptions. Since then, tools capable of removing AI watermarks have emerged. Google DeepMind has similarly applied SynthID watermarking to artificially designed proteins.
Source: The Next Web



