OpenAI watermarks EU text under the AI Act — API customers must opt in themselves
On October 5, 2026, OpenAI launched its approach to text watermarking under the EU AI Act: invisible watermarks in eligible ChatGPT and Codex text for European users in the coming weeks, while API customers worldwide can opt in to watermarked text from the same day. The company is open about the fact that the technology has significant weaknesses — and it is precisely these weaknesses that make the rollout as much a compromise as a technology launch.
What was announced
OpenAI announced on October 5, 2026 that invisible watermarks will be added to eligible text output from ChatGPT and Codex in the EU over the coming weeks, according to Unite.AI's coverage of the announcement (Unite.AI). According to AI Weekly, the watermarking applies to users on all subscription tiers in the EU (AI Weekly).
The same day, the company opened up for API customers globally to opt in to watermarked text for select models. The setting is off by default — customers must activate it themselves (AI Weekly). The rollout diverges from competitors: unlike Anthropic and Google, OpenAI is launching — for now — default watermarking only in the EU, not globally, as commentator Andrew Curran noted (X).
The rollout is happening under regulatory time pressure. Article 50 of the AI Act's transparency rules took effect on August 2, 2026, with a transition deadline of December 2, 2026 for existing systems (CryptoBriefing). Anthropic introduced invisible text watermarks in new Claude models the same day (CryptoBriefing).
How textGrain works
The technology is named textGrain. It embeds an invisible statistical signature in the words the model chooses, and OpenAI's detector tests a text for this signature to judge whether it carries an OpenAI watermark, according to Unite.AI's summary of the company's technical report (Unite.AI). Detection requires a secret key, meaning detector access is in practice controlled by OpenAI — not by anyone who wants to test a text.
What OpenAI's own results show
OpenAI has itself published the evaluation results, and they paint a nuanced picture. At a target rate of 1% false positives, the detector identified watermarks in roughly 80% of passages of 200 tokens and roughly 95% of passages of 400 tokens for content like psychology — that is, text where word choice has great flexibility. For content like mathematics, where word choice is far less flexible, the rates are substantially lower (Unite.AI).
The most revealing figure, however, concerns paraphrasing. Replacing 10% of the words in a text drops the detection rate to 66%; at 25% replacement it falls to 17% (AI Weekly). In other words: even a relatively light rewrite can in practice remove the watermark.
At the same time, OpenAI claims the watermarking does not measurably affect text quality. According to the company's published table, 49.57 points are reported for unwatermarked text versus 49.76 for watermarked text on the Artificial Analysis Intelligence Index, and 94.44% versus 93.94% on GPQA Diamond (Unite.AI). These figures are company-reported and not independently verified.
Restricted detector access
The same day the rollout was announced, OpenAI opened applications for access to the text watermark detector. Access will initially be limited to approved researchers and expert organizations, assessed case by case under the EU Code of Practice on transparency of AI-generated content, with the goal of supporting the evaluation and improvement of text provenance (Unite.AI).
OpenAI justified both the technology's limitations and the restrictive detector access by the risk of unreliable detection in practice. The company described text watermarking and detection as early technologies with significant limitations, and said the phased approach reflects both the legal requirements and these limitations (Unite.AI).
What a watermark does not mean
OpenAI is explicit about what the watermark does not tell you: "A watermark does not measure human contribution, does not establish ownership or responsibility, does not identify the user, and does not verify accuracy," the company wrote (AI Weekly). This is an important clarification in a context where watermarks are easily misunderstood as a reliable AI detector — something OpenAI's own paraphrasing figures clearly contradict.
Open questions
Several significant details remain unresolved. It has not been defined what "eligible" ChatGPT and Codex output entails, or which specific API models support textGrain at launch. Perhaps most importantly: the legal basis is still in motion — according to CryptoBriefing, "many implementation details are still being clarified, including how regulators will assess opt-in tools versus default watermarks as the December 2, 2026 transition deadline approaches" (CryptoBriefing).
OpenAI has also said the company plans to make the technology available as open source so others can build on it, and that the report will be updated with more details in the coming weeks (Unite.AI). It remains to be seen whether that resolves any of the open questions — or creates new ones.
All figures and quotations in this story come from OpenAI's announcement and technical report as reported by Unite.AI, AI Weekly and CryptoBriefing. OpenAI's own announcement has not been directly reviewed by AIMag.

