OpenAI Is Watermarking ChatGPT Text in the EU Ahead of the AI Act's December 2 Deadline
The company is rolling out textGrain watermarking to ChatGPT and Codex users in the EU over the coming weeks, barely two months before the EU AI Act's compliance deadline. Globally, the feature is voluntary via the API, and the detector stays closed to ordinary users.
OpenAI announced on October 5, 2026 that it will begin watermarking text from ChatGPT and Codex — but only for users in the EU. "In the coming weeks, we will introduce text watermarking for eligible ChatGPT and Codex users across all plans, in the EU only. We are not making text watermarking a global standard at launch," the company's statement says, as reported by The Verge. The company justified the regional approach as giving it "room to learn from real-world use and feedback."
The announcement comes barely two months before the December 2 deadline for established providers under the EU AI Act, and two months after Anthropic went global with watermarking of Claude text — a move that met significant user resistance. It makes this a clear example of regulation, rather than voluntary initiative, determining when and where watermarking becomes reality.
The details of the rollout
The rollout has three parts. First, watermarking by default for eligible ChatGPT and Codex users in the EU, on all subscription tiers. Second: from October 5, API customers worldwide can opt in to watermarked text output for select models — OpenAI has not specified which models, as Engadget notes. Third, a separate detector, which does not automatically accompany the watermarking. Approved researchers and subject-matter expert organizations can apply for access as of the announcement date, and according to the company, access will "initially be granted on a case-by-case basis" in line with a Code of Practice, to support the evaluation and improvement of text provenance.
OpenAI cites two problems in justifying the closed detector: missed watermarks and false positives. In other words, even though the watermark is meant to serve as provenance infrastructure, in practice almost no one — neither users nor platforms — can actually check a text against it during the launch phase.
Why now: Article 50 and December 2
The regulatory driver is Article 50 of the EU AI Act, which requires providers of generative AI to make text outputs identifiable in a machine-readable way. The transparency rules took effect on August 2 and already apply to new market entrants, while established companies — including OpenAI, Anthropic, Microsoft, Google and Meta — face a December 2 deadline, Engadget reports.
In the US, there is no comparable federal requirement, and that is precisely where AJ Dellinger at Gizmodo finds the explanation for the geographic split. "Without requirements for frontier AI companies to include a watermark that helps users and platforms quickly identify AI-generated content, there is really no motivation for OpenAI to proactively comply with a law that doesn't exist," he writes. That is analytical interpretation, not reporting, but the chronology supports the reading: OpenAI built a text watermark years ago and held it back, partly out of fear that users would switch to competitors that did not watermark, according to a 2024 Wall Street Journal report, as recounted by TechCrunch.
How textGrain works
The method, which OpenAI has named textGrain, is described in a technical report written together with researchers from the University of Pennsylvania and Yale. It is published as a technical report, not a peer-reviewed paper, and uses, among other things, optimal transport theory to balance detectability against variation in the output.
Unlike what the name "watermark" might suggest, it does not involve hidden characters, invisible spaces, or metadata. Instead, the model slightly adjusts the probabilities for which word or word fragment it selects as the next token, governed by a secret key and the preceding context. The adjustments are per token too small to notice, but collectively they set a statistical imprint across the entire text, as XenoSpectrum describes.
The detector reconstructs the grouping with the same secret key and settings, and checks whether the actually chosen tokens show the expected bias more often than chance would allow. That detail has practical significance: detection requires neither the original prompt nor the model that generated the text — only the text itself and the key. Since the key is not publicly available, detection in practice must go through OpenAI or others granted access.
How vulnerable is the watermark?
OpenAI's own tests show the method is genuinely detectable, but not robust. According to TechCrunch, the detection rate fell from around 92 percent to 66 percent when 10 percent of words were replaced with synonyms. The company also says that short passages, math answers, and translated text are harder to detect.
The numbers vary across coverage and cannot be reconciled from the available sources: XenoSpectrum cites "around 95 percent detection under given conditions," TechCrunch reports 92 percent, and Engadget says around 80 percent for shorter text. The conditions behind each figure are not specified precisely enough to combine them into a single benchmark — readers should bear that in mind.
OpenAI does not sell the method as impenetrable. The company itself warns that "strong performance under ideal conditions does not guarantee reliable detection in everyday use," according to Engadget. And the company qualifies what a watermark actually proves: "[Watermarks] can indicate that an OpenAI system has generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it," the company tells TechCrunch. The absence of a watermark, correspondingly, proves nothing — the text may be AI-generated and merely sufficiently rewritten.
The company's own quality claims
The most common counterargument to watermarking has been that it can degrade text quality, since it constrains the model's choices. OpenAI claims that textGrain "matched or exceeded" other approaches, such as Google's SynthID for text, and that the quality loss is absent: "Across the benchmarks we use to evaluate Astra, our latest frontier model, we do not see meaningful performance differences with and without watermarking," the company tells PCMag.
Both claims are the company's own, not independent findings, and the technical report behind the method has not been peer-reviewed.
The context: Anthropic went first, globally
OpenAI is not first. Anthropic introduced watermarking of Claude-generated text worldwide in August, without a comparable legal requirement, and met significant user protest. The contrast is instructive: Anthropic voluntarily chose what OpenAI is now doing only where the law requires it, and was met with resistance from its users for it. The 2024 WSJ report that OpenAI waited out of fear of competitive disadvantage suggests the company has long seen the same risk.
Another detail worth noting: according to XenoSpectrum, citing the EU Commission's FAQ, source code falls outside the AI Act's marking requirement — even though Engadget alone reports plans to open-source the technology. That claim is single-source and unconfirmed by other outlets in the case.
What remains unresolved
Several questions remain open. Which API models support watermarking at launch has not been specified. It is uncertain whether the regional model will spread — whether OpenAI will roll out watermarking globally if more jurisdictions introduce similar requirements, or whether the US remains without standard marking. And it is highly unclear how the restricted access to the detector will work in practice: how many researchers and organizations will gain access, for what use, and whether access will ever expand to the platforms that actually confront AI-generated content at scale.
Until those are answered, the conclusion is limited but concrete: the EU has now shown it can get the largest AI companies to deliver text provenance infrastructure — but the defense of the watermark's reliability under editing, and access to verification itself, still rest entirely with the company that owns the key.
Note: All facts in this article are reported through secondary outlets reproducing OpenAI's announcement and technical report; the primary documents were not reviewed directly.

