OpenAI's Text Watermark Rolls Out in the EU – While the Detector Stays Locked
On October 5, 2026, OpenAI announced that its textGrain system will watermark AI-generated text for ChatGPT and Codex users in the EU – but only there, and only for "eligible" text. At the same time, the company is opening voluntary watermarking via the API globally, alongside a detector available only to approved researchers. The numbers OpenAI itself presents show why: detection works poorly on short texts and degrades sharply when text is edited.
What Is Changing
The announcement came on October 5, 2026: over the coming weeks, text watermarking will be introduced for "eligible ChatGPT and Codex users across all plan types, in the EU only," as The Verge reports, quoting OpenAI's own words from the announcement (The Verge, source 786a9021). OpenAI stresses that it is "not making text watermarking a global default at launch," and justifies the regional approach on the grounds that it leaves room to learn from real-world use and feedback.
The rollout has three parts:
-
The EU as the default for consumer products. Watermarked text will roll out to eligible ChatGPT and Codex users on all plans in the EU over the coming weeks (786a9021). It is worth noting that OpenAI itself uses the word "eligible" without defining exactly which texts are covered – the scope of "eligible" text is therefore unclear. Some outlets, such as Gizmodo, have described the watermark in stronger terms than OpenAI's own wording (Gizmodo, source 445c9262).
-
The API becomes opt-in globally. From the day of the announcement, API customers worldwide can opt in to watermarked text output for select models, and OpenAI is working with cloud partners to make watermarking available through their services in the weeks ahead (786a9021). Outside the EU, then, watermarking is off by default – customers decide for themselves, with reference to their own "transparency obligations."
-
The detector stays locked. Approved researchers and expert organizations can apply for access as of the day of the announcement. Under the Code of Practice, access will initially be granted case by case. The tool only reports whether it detects an OpenAI watermark, without identifying the user or exposing texts or conversations. OpenAI justifies keeping the detector out of public hands by citing the risks of missed watermarks and false positives (786a9021).
Why Now
The timing is no coincidence. The EU AI Act has been phasing in gradually since 2025, and most of its articles – including the transparency and marking obligations – became applicable on August 2, 2026 (Mashable, source 26fbc6b4). The regulation requires, among other things, machine-readable markings of AI-generated text, and watermarking is a technical solution to that requirement.
There is also a competitive dimension: Anthropic was the first major AI company to announce its approach to AI Act compliance, using Google's SynthID-Text algorithm – and doing so globally, not just in the EU (The Register, source e9103443). SynthID-Text is also the basis for the watermarking Anthropic announced in August (786a9021). OpenAI says that textGrain, in its internal evaluations, "matched or exceeded" other approaches it tested, including SynthID for text (786a9021; MSN syndication, source a92a605e) – but these are OpenAI's own, not independently verified results from controlled tests, and the company itself cautions that such results do not guarantee reliability in the real world (a92a605e).
How It Works
Text watermarking builds on the fact that language models choose among many possible words at each position. textGrain influences this choice by having the model look not only at the preceding text, but also at pseudorandom values determined by a secret key (26fbc6b4). The result is that the word choices in the generated text carry a slight statistical bias that is impossible to notice when reading, but that a detector with the right key can search for. Because the signal resides in the text's word choices themselves, the watermark survives copying and pasting elsewhere (b9740f8b, citing TechCrunch, which describes textGrain as sorting candidate words based on a secret key).
How Well Does Detection Work – According to OpenAI Itself
OpenAI's own test figures, relayed by Mashable and The Register, paint a nuanced picture:
- Short texts are a weakness. In OpenAI's testing, the detector caught the watermark in roughly 80 percent of 200-word AI-generated texts, and the detection rate was even lower for texts on topics with rigid vocabulary, such as mathematics (26fbc6b4). For 400-word texts, detection was around 95 percent (e9103443, citing OpenAI's textGrain paper). The target for false positives is approximately one percent (e9103443).
- Functional text is harder. In texts about mathematics or code, results are worse, because word substitution there more easily introduces errors (e9103443).
- Paraphrasing largely breaks detection. In a 400-word text, editing 10 percent of the words lowered detection to 66 percent – and editing 25 percent brought it down to 17 percent (26fbc6b4). In other words: someone who asks another model to rewrite the text, or makes a few edits themselves, can in practice remove the statistical trace.
OpenAI itself frames the limitations in the announcement: "Text watermarking and detection remain early technologies with significant limitations, and views on the benefits and responsible use are still developing" (26fbc6b4). The company also stresses that the absence of a watermark does not prove a text is human-written.
It is worth keeping in mind that all of these performance figures come from OpenAI itself, relayed through secondary press – there is no independent verification.
Who This Affects
- EU users of ChatGPT and Codex, on all subscription types, will receive watermarked text by default in the coming weeks (786a9021). The text they copy out will therefore in principle carry a statistical trace – though traceability is limited by the detection figures above.
- API customers globally get a choice: watermarking is available but off by default, for select models (b9740f8b; 786a9021). For companies with their own transparency obligations – for instance under the AI Act – this is a tool, not a mandate.
- Researchers and expert organizations can apply for detector access, case by case, and the tool will only answer whether an OpenAI watermark is present – not who wrote the text or what was prompted (786a9021).
- Everyone else – teachers, editors, employers – gets no public access to detection. A watermark you cannot check for has limited practical value.
This regionally split model stands in contrast to Anthropic, which applies SynthID-Text globally (e9103443). In the US and other markets, OpenAI's text thus remains unwatermarked unless the customer actively opts in via the API. At the same time, a survey by the Rainey Center, relayed by Gizmodo, shows that nearly eight in ten Americans support requirements for AI watermarking, including 82 percent of Democrats and 75 percent of Republicans (445c9262) – an indication that pressure may also come from consumers, not just regulators.
Open Questions
Several questions remain unanswered in what is available:
- What does "eligible" text mean? OpenAI does not specify which outputs are covered. Whether the watermark applies to all text output, specific models, or specific user surfaces is not defined in the available sources.
- Does a closed detector satisfy Article 50? The AI Act's transparency obligations require machine-readable marking. It is not documented how the Commission will assess whether a detector available only to approved researchers on a case-by-case basis meets the requirement that AI-generated text be identifiable (786a9021; 26fbc6b4). This could become a test case for how the entire industry's compliance approaches are judged.
- How robust is the technology in practice? With 80 percent detection on 200-word texts and 17 percent after 25 percent editing (26fbc6b4; e9103443), it is explicitly a technology with "significant limitations," according to OpenAI itself. Whether the figures improve with experience from the EU rollout – the rationale OpenAI gives for the regional approach – remains to be seen (786a9021).
For an industry now confronting applicable AI law for the first time, textGrain is a concrete answer – but it is an answer that confirms as much as it resolves: watermarking text is possible, but reliable evidence of who wrote what remains a long way off.

