ChatGPT watermark: what OpenAI's textGrain means

/ OpenAI will hide an invisible watermark in ChatGPT and Codex text in the EU. How textGrain works, who can detect it, how editing breaks it, and what it means.
by Hozefa Khety
· 7 min read
OpenAI is about to hide an invisible watermark inside the text ChatGPT writes, but only in the European Union for now. In a blog post on Monday, October 5, 2026, the company said eligible ChatGPT and Codex text output in the EU will start carrying a watermark "over the coming weeks", on every plan. Developers anywhere in the world can switch the same watermark on in the API from today, and OpenAI is opening a detector, but only to approved researchers and expert organisations. The system is called textGrain. Below: what changes, who gets it, how it works in plain English, how easily it breaks, and what it does and doesn't prove. We re-checked OpenAI's announcement on October 6, 2026 at about 13:40 UTC (19:10 IST), and the rollout details were unchanged.

What OpenAI announced
OpenAI's post, titled "Our approach to EU text provenance rules", lists three changes. First, from October 5, API customers worldwide can opt in to watermarked text for select models; it stays off by default. Second, over the coming weeks OpenAI will add an invisible watermark to eligible ChatGPT and Codex text in the EU, across all plans. Third, approved researchers and expert organisations can now apply for access to OpenAI's text watermark detector.
OpenAI is clear that this is not a worldwide switch-on. "We are not making text watermarking a global default at launch," the company wrote, adding that the regional approach "gives us room to learn from real-world use and feedback." It is also working with cloud partners to bring the watermark to OpenAI models sold through their services in the coming weeks. Images and audio are a separate story: OpenAI already adds Content Credentials (the C2PA standard) and invisible SynthID watermarks to supported images and audio, and its public openai.com/verify tool for those files stays open to everyone.
Who gets the ChatGPT watermark, and when
If you use ChatGPT or Codex in the EU: your eligible text output will start carrying the watermark over the coming weeks, whatever plan you are on. OpenAI has not given an exact date or said which outputs count as "eligible". If you use ChatGPT outside the EU, including the US, UK and India: nothing changes at launch, because OpenAI says it is not making watermarking a global default. If you build on the OpenAI API: you can turn watermarking on now for select models, anywhere in the world, but it is off unless you opt in. OpenAI has not said it will charge extra for it.
How textGrain works, in plain English
A chatbot writes one word (strictly, one token) at a time, and at many points several words would work equally well. A watermark uses those low-stakes choices. textGrain lets a secret key nudge which of the acceptable words the model picks, so across hundreds of words a statistical pattern builds up. A reader cannot see it: it is not a symbol or extra character added to the text, just a pattern in the word choices. A detector holding the key can check whether the word choices fit the pattern. Because the signal lives in the words themselves, TechCrunch notes, it travels with the text when it is copied and pasted.

OpenAI published a 20-page technical report alongside the post, written with researchers from the University of Pennsylvania and Yale. It describes how the method keeps the model's word choices random on average while tying them to the key, and says the detector needs only the text and the secret key. OpenAI also says it plans to release the technology as open source so others can build on it, and that in its tests textGrain "matched or exceeded" other approaches it tried, including Google DeepMind's SynthID for text.
Does it make ChatGPT's answers worse? OpenAI says it saw no meaningful difference on the benchmarks it uses for Astra, its latest frontier model. A few of its published scores, without and then with the watermark: GPQA Diamond 94.44% vs 93.94%, BrowseComp 87.92% vs 87.35%, DeepSWE v1.1 72.80% vs 71.68%, and the Artificial Analysis Intelligence Index 49.57 vs 49.76 points.
How reliable is it? Editing weakens it fast
OpenAI's own numbers show the limits. Length matters: at a target false-positive rate of 1%, its detector found the watermark in about 80% of 200-token passages and about 95% of 400-token passages for subjects like psychology. (A token is roughly three-quarters of an English word, so 400 tokens is about 300 words.) Subject matters too: detection was "substantially lower" for maths, where there are fewer ways to word an answer.
Editing matters most. In a test on 400-token passages, swapping 10% of the words for synonyms cut detection from about 92% to 66%, and swapping 25% cut it to 17%. OpenAI also says text can escape detection if it is too short, edited, translated, made by an unsupported model, written before watermarking began, or produced by another company's AI. Its conclusion: "strong performance under ideal conditions does not guarantee reliable detection in everyday use."
Can a teacher or employer check if you used ChatGPT?
Not with OpenAI's detector, at least not yet. Because of the risk of missed watermarks and false positives, OpenAI says it is "not making it publicly available at launch". Access starts case by case for approved researchers and expert organisations, in line with the EU's Code of Practice. The detector reports only whether it finds an OpenAI watermark; OpenAI says it does not identify the user or reveal prompts or conversations.

OpenAI also spells out what a positive result does not mean. A watermark does not measure how much a person contributed, does not show who owns the text or who is responsible for it, does not identify the user, and does not say whether the content is true. And a missing watermark "does not prove human authorship." That matters for schools and workplaces: a watermark is evidence that an OpenAI system generated or processed part of a passage, not proof of cheating, and no watermark is not proof of innocence either.
Why now: the EU AI Act
The trigger is Article 50 of the EU AI Act. According to the European Commission, its transparency obligations have applied since August 2, 2026, and they require providers of generative AI to mark audio, image, video and text output in a machine-readable way so it can be detected as AI-generated. The Commission's voluntary Code of Practice on Transparency of AI-generated Content, finalised in June, gives companies a recognised way to show they comply; the Commission says about 190 organisations had signed it by the end of July. TechCrunch reports that Anthropic, Google, Meta, Microsoft and OpenAI are among those committed to it.
OpenAI is not first. Anthropic said on August 14, 2026 that future Claude models would carry a text watermark based on Google DeepMind's SynthID-Text method, and that it is applying it globally because it does not yet have a durable way to limit it by region. Anthropic's detection API is in private preview for eligible organisations. TechCrunch reports that Anthropic's decision drew backlash from some Claude users, who argued they had supplied the instructions and decisions while Claude was just the tool. TechCrunch also points to a 2024 Wall Street Journal report that OpenAI had built a text watermark earlier but held off, partly over worries that users would switch to rivals.
What this means for you
For most people outside the EU, nothing changes today. For EU users, ChatGPT will look and read the same, but its text will carry a hidden signal that approved detectors may be able to find, especially in longer, lightly edited passages. For developers, the API switch lets you watermark your own app's output if you have EU transparency duties. And for anyone judging someone else's writing, OpenAI's message is that a watermark check is one clue, not a verdict. OpenAI says it will revisit every part of the approach as the technology, standards and evidence develop, and will widen detector access only when it believes results can be interpreted responsibly.
Frequently asked questions
Does ChatGPT have a watermark now?
Not everywhere. OpenAI said on October 5, 2026 that it will add an invisible watermark to eligible ChatGPT and Codex text in the European Union over the coming weeks, on all plans. It is not a global default at launch, so users outside the EU are not affected for now.
What is textGrain?
textGrain is OpenAI's text watermarking technology. It uses a secret key to nudge which of several acceptable words the model picks, leaving a statistical pattern that readers cannot see but a detector with the key can check. OpenAI published a technical report on it and says it plans to open-source the technology.
Can I check if text was written by ChatGPT?
Not with OpenAI's detector yet. At launch, access is limited to approved researchers and expert organisations, who can apply now. OpenAI says it is not making the detector public because of the risk of false positives and missed watermarks.
Can the ChatGPT watermark be removed?
Editing weakens it a lot. In OpenAI's tests on 400-token passages, replacing 10% of words with synonyms cut detection from about 92% to 66%, and replacing 25% cut it to 17%. Short passages, maths answers and translated text are also harder to detect.
Does the watermark identify me?
No, according to OpenAI. It says a text watermark does not identify the user and the detector does not associate a person, account, prompt or conversation with the text. It only reports whether an OpenAI watermark is detected.
Does the watermark make ChatGPT worse?
OpenAI says it saw no meaningful performance difference on the benchmarks it uses for its Astra model. For example, GPQA Diamond scored 94.44% without the watermark and 93.94% with it.
Why is OpenAI watermarking text only in the EU?
The EU AI Act's transparency rules, which apply from August 2, 2026, require generative AI providers to make AI-generated content machine-readable and detectable. OpenAI says starting in the EU only lets it learn from real-world use before considering anything wider.
Do other AI chatbots watermark text?
Yes. Anthropic said in August 2026 that future Claude models would watermark text worldwide, using a version of Google DeepMind's SynthID-Text method, with a detection API in private preview for eligible organisations.



