OpenAI is rolling out invisible text watermarking for eligible ChatGPT and Codex output in the European Union. The system adds a statistical signal through word choices to help identify AI-generated content. However, OpenAI says that editing, translation, or short text can weaken detection, making the technology not entirely perfect.

Synopsis

OpenAI is rolling out invisible text watermarking for eligible ChatGPT and Codex output in the European Union, allowing its detector to look for a statistical signal hidden in the model's word choices. The technology can identify many longer passages, but OpenAI says editing, translation, short text and technical subjects can weaken detection. The system also cannot establish who wrote a passage, how much a human contributed or whether the content is accurate.

A writer may copy text from ChatGPT, make a few changes and assume nobody will know it came from an AI system. OpenAI's latest text provenance technology is designed to make that assumption less safe, at least for eligible ChatGPT and Codex output in the European Union.

OpenAI says it is introducing an invisible watermark in eligible ChatGPT and Codex text in the EU in response to requirements under the EU AI Act. The watermark is not a visible label or a phrase saying "written by ChatGPT". Instead, it is a statistical signal built into the model's choice of words.

That means a reader will not simply see a watermark while reading an article. A specialised detector has to look for the signal and assess whether a passage contains an OpenAI watermark.

But there is an important catch. OpenAI itself says the technology is not perfect. Short passages, highly constrained subjects, translations and edited text can make detection harder. So a watermark result cannot be treated as proof of who wrote something.

What is happening with ChatGPT text?

OpenAI calls its text watermarking technology textGrain. The system adds an invisible statistical signal through the model's word choices when it generates eligible text.

Live Events

You Might Also Like:

Vijay Deverakonda didn't buy iPhone 18 Pro, still uses iPhone Air like Kohli; he asks why take EMIs just to buy new Apple phones and impress others when older versions still work

The idea is relatively simple. ChatGPT still produces normal-looking sentences, but its choice of words contains a pattern that the company's detector can look for later. There is no visible stamp, symbol or warning attached to every sentence.

OpenAI says API customers around the world will be able to opt in to watermarking for selected models. For ChatGPT and Codex, the initial rollout will apply to eligible users in the EU rather than becoming a global default.

How can ChatGPT-written text be spotted?

The detector does not simply search for typical "AI words" or a particular writing style. Instead, it looks for the statistical signal created by textGrain.

This is important because AI detection has often been associated with software looking for phrases or writing patterns that sound machine-generated. OpenAI's approach is different. The watermark is deliberately added during generation so a detector can later search for it.

You Might Also Like:

60 hours of PS5 gameplay required before playing GTA 6 on a PS5 Pro; Sony Japan to sell the console only to eligible gamers through lottery

OpenAI says its tests showed textGrain matched or exceeded the performance of other approaches it tested, including SynthID for text. But the company is also clear that good results under controlled conditions do not mean every piece of AI-written text can be identified in everyday use.

What happens if someone edits ChatGPT text?

This is where the system becomes much less certain. OpenAI tested what happened when words in a watermarked passage were replaced with synonyms. In one test involving 400-token passages, detection fell from about 92% for unedited text to about 66% after 10% of the words were replaced.

When 25% of the words were replaced, detection fell to about 17%. So yes, editing can weaken the watermark.

But this should not be understood as a reliable way to make AI-generated work "undetectable". OpenAI itself says detection can fail for several reasons, including editing, translation and short passages. For a writer, the more useful lesson is that AI detection is not a simple yes-or-no test of authorship.

Can a short ChatGPT answer be detected?

Shorter text is harder to identify. OpenAI says that at a target false positive rate of 1%, its detector identified watermarks in about 80% of 200-token psychology passages. For 400-token passages, the figure was about 95%.

The subject also matters. Mathematics was harder to detect than psychology because there is less freedom in choosing words when explaining mathematical material. That means a detector's performance can vary depending on both the length and type of writing being examined.

What does an invisible watermark actually prove?

Not as much as some may assume. If the detector finds an OpenAI watermark, OpenAI says it can indicate that an OpenAI system generated or processed part of a passage.

It does not tell the reader how much a human contributed. A journalist could use AI to generate a rough draft and then substantially research, rewrite, fact-check and edit the material. A watermark would not tell the detector how much human judgement went into the final version.

The watermark also does not establish ownership, responsibility or whether use of the text was lawful. It does not tell the detector who used ChatGPT, what prompt they entered or which account or conversation produced the text.

Can a missing watermark prove a human wrote the text?

No. This is one of the most important limitations in OpenAI's announcement. A passage without a detected watermark is not automatically human-written.

The watermark could be missed because the text is too short or has been heavily edited. Translation can also affect detection. The passage could have been generated before watermarking was introduced or could have come from an unsupported model.

And if the text came from another AI company's system, an OpenAI detector would not necessarily find an OpenAI watermark. So "no watermark found" should not become "a human definitely wrote this".

What should writers do before publishing AI-assisted text?

The safest approach is not to focus on defeating an AI detector. Writers should focus on making sure the final work is genuinely reviewed by a human and meets the publication's rules on AI use.

First, fact-check the entire draft. AI-generated text can contain incorrect names, dates, figures, legal provisions and background information.

Second, check the original sources. If ChatGPT has summarised a court judgment, government order, research paper or interview, go back to the actual document before publishing.

Third, rewrite where necessary in your own editorial voice. Human editing should involve more than swapping a few words. The writer should decide what information is relevant, what needs attribution and what needs to be removed.

Fourth, check quotes carefully. Never treat an AI-generated quotation as genuine unless the original source contains it.

Fifth, follow your newsroom's AI policy. Some organisations permit AI for research or drafting while requiring disclosure or human review before publication.

What if you have already used ChatGPT to write a draft?

Do not assume that changing a handful of words solves the problem.

Instead, treat the ChatGPT output as a working draft and independently verify the underlying information. Add reporting, original sourcing and human judgement where required.

For example, suppose ChatGPT produces a paragraph claiming that a court ordered a company to pay compensation. A responsible writer should not simply replace a few words in that paragraph and publish it.

The writer should locate the judgment, confirm the parties, date, amount, reasoning and final direction, then write the report from the verified material.

That creates something substantially more useful than merely trying to make AI-generated sentences look less like AI-generated sentences.

Why is OpenAI limiting its detector?

OpenAI is initially restricting access to its text watermark detector to approved researchers and expert organisations.

The company says the decision is linked to the technology's limitations, including false positives and false negatives.

A false positive means the detector reports a watermark when there is none. A false negative means a watermark exists but the detector fails to identify it.

Those errors matter if a detection result is being used to accuse a student, writer, employee or publisher of using AI.

OpenAI therefore says the detector will initially be provided on a case-by-case basis rather than being released publicly.

Will watermarking affect ChatGPT's writing quality?

OpenAI says it tested watermarked and unwatermarked output from its latest frontier model, Astra, across several benchmarks.

The company said it did not see meaningful performance differences between the two versions.

Some benchmark scores were slightly higher with watermarking and others slightly lower. OpenAI's overall assessment was that adding the watermark did not meaningfully affect model performance.

What happens next?

OpenAI says textGrain will eventually be made available as open source so others can build on the technology.

The company also plans to study how well the watermark survives editing and translation and to improve the detector over time.

For now, the biggest takeaway for writers is more limited than the headline "ChatGPT will expose you" suggests. An invisible watermark can provide a signal about the involvement of an OpenAI system, but it is not a magic authorship test.

A detected watermark does not tell the whole story, and an undetected watermark does not prove that a human wrote every word. For publishers and writers, the more important safeguard remains the same one that existed before watermarking, verify the material, check the original sources, apply human judgement and follow the rules governing AI-assisted work.

(You can now subscribe to our Economic Times WhatsApp channel)

The world is witnessing a bond rout. Why should it matter to you?

Q2 earnings season: Will it settle or add to confusion in the stock market?

How Sebi busted Growpital’s ‘assured’ returns, LLPs and money trail

The biggest assumption: From $600 billion to $2 trillion

A for apple, Y for yak and, for the first time, a price next to it. Will this change the non-agri part of the rural economy?

Six months after oil spiked, why are markets reacting so sharply now?