OpenAI will add an invisible watermark to ChatGPT text in the EU to follow the AI Act. The company said the rollout happens over coming weeks for all plans. This technology, called textGrain, adds a signal to word choices. From October 5, API customers worldwide can also use this feature.
OpenAI will begin adding an invisible watermark to eligible text generated by ChatGPT and Codex in the European Union (EU), as the company moves to comply with transparency requirements under the EU’s AI Act.
The company said the rollout would take place over the coming weeks and apply to eligible users across all ChatGPT and Codex plans in the EU. It said it was not making text watermarking a global default at launch.
Separately, from October 5, API customers worldwide can opt in to text watermarking for select models, OpenAI said.
The mandate
The move comes as Article 50(2) of the EU AI Act requires providers of generative AI systems to ensure that AI-generated or manipulated content, including text, is marked in a machine-readable format and detectable as artificially-generated or manipulated.
The European Commission says the technical measures must be effective, interoperable, robust and reliable “as far as technically feasible”, taking into account the limitations of different types of content. The transparency obligations have applied since August 2, 2026.
The law does not specifically require companies to use a watermark. The European Commission has also developed a voluntary Code of Practice on Transparency of AI-generated Content, which sets out practical measures for providers to comply with the Article 50 requirements.
Section 1 of the Code deals with the marking and detection of AI-generated content by providers and Anthropic, Google, Meta, Microsoft, Mistral and OpenAI have signed this section of the Code.
Technology: textGrain
OpenAI said its text watermarking technology, called textGrain, adds an invisible statistical signal to the model’s choice of words. It does not insert hidden characters or additional watermark-specific tokens. Instead, the statistical pattern in the model’s word choices can subsequently be analysed by a detector.
A technical paper published by OpenAI alongside the announcement explains that the watermark is created during generation by subtly influencing token selection using a secret key and the preceding context. The detector can later use the generated text and secret key to look for the statistical signal.
Limitations
OpenAI said its detector identified watermarks in about 80% of 200-token passages and about 95% of 400-token passages in psychology-related content, at a target false-positive rate of 1% (meaning it would wrongly flag about one in 100 texts without the watermark). Detection was substantially lower for mathematics, where there is less flexibility in word choice.
Editing also significantly weakened the signal. In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%, while replacing 25% of words reduced detection to about 17%, according to OpenAI.
The company, therefore, said it would initially restrict access to its text-watermark detector to approved researchers and expert organisations.
It said the detector would report whether an OpenAI watermark was detected but would not identify the user or reveal prompts or conversations. OpenAI said the decision reflected the risks of false positives and missed watermarks.
The limitations are significant because the watermark is intended as a provenance signal rather than a definitive AI-authorship test.
The frontier AI company said a watermark cannot determine how much human judgment, editing or creativity went into a passage. It said it also cannot establish ownership or responsibility, identify the person or organisation that generated the text, or determine whether the text is accurate.
Conversely, the absence of a detected watermark does not establish that a human wrote the text. OpenAI said detection may fail because content is too short, has been edited or translated, comes from an unsupported model, predates watermarking or was generated by another AI system.
Separately, EU rules require deployers to clearly label certain AI-generated or manipulated text published to inform the public about matters of public interest.
OpenAI plans to make textGrain available as open-source technology, saying this could allow others to build on the approach and help improve text watermarking.
The company said it is also trying to make text watermarking as one part of a broader provenance system. For images and audio, OpenAI uses technologies including Content Credentials based on C2PA and invisible SynthID watermarks, alongside verification tools. It said no single provenance technique was sufficient on its own.