Regulation & Policy

OpenAI Will Add Invisible Text Watermarks to ChatGPT in the EU

OpenAI will watermark eligible ChatGPT and Codex text in the EU, but restricted detector access and editing-related limitations complicate the promise of identifying AI writing.

By Marcus Lee Edited by Samantha Reed Published: Updated:
OpenAI Will Add Invisible Text Watermarks to ChatGPT in the EU
OpenAI will add invisible text watermarks to eligible ChatGPT and Codex output in the EU as detection access remains restricted. Photo: Lukasz Kobus / European Commission

Key Notes

  • Eligible ChatGPT and Codex text across EU plans will receive watermarks over the coming weeks.
  • The watermark is embedded in word choices, without hidden characters or user identifiers.
  • Detector access starts with approved organizations, and editing can weaken the signal.

OpenAI will add invisible text watermarks to eligible ChatGPT and Codex output across all plans in the European Union over the coming weeks. The company announced the regional rollout on October 5, alongside a worldwide API option that remains off by default.

The change introduces a machine-readable signal into generated wording, but its launch comes with a significant qualification: OpenAI’s text detector will initially be available only to approved researchers and expert organizations. The announcement therefore does not create an instant public test for every passage copied from ChatGPT.

The Watermark Lives in Word Choices

Called textGrain, the system works through the statistical choices a model makes while writing. OpenAI’s technical report describes linking token generation to randomness derived from a secret key and the preceding text. A detector can later use that key to look for evidence of the embedded pattern.

For a reader, the result remains ordinary prose. OpenAI’s provenance guidance says the method adds no hidden characters, invisible spaces or watermark-only tokens. The signal belongs to the wording itself, so preserving those words through copying and pasting can preserve the pattern.

That is a different approach from attaching a label to a document or asking an outside classifier whether a passage sounds machine-written. The detector checks for a signal created during generation. Its usefulness depends on both the signal surviving and the system interpreting it reliably.

Editing Can Weaken Detection

OpenAI’s announcement illustrates the limits with an English-language editing evaluation: replacing 10% of words with synonyms reduced detection in 400-token passages from about 92% to 66%. Replacing 25% reduced it to 17%. Those figures describe a particular evaluation, rather than a universal removal threshold.

Manual synonym replacement is therefore not the only way a signal can become harder to detect. The company’s guidance also identifies substantial paraphrasing and translation as potential causes. Short answers, code and tightly constrained factual text give watermarking less flexibility, which can make detection less reliable even without extensive editing.

A failed check cannot establish that a person wrote the text. Equally, a detected signal does not show how much human work went into a passage, identify its user or determine ownership. These limits matter when a system might be used to assess a student’s assignment, a job application or a published article.

Claude Has Already Taken a Different Rollout Approach

Anthropic explained its own watermarking approach in August. It uses a version of Google DeepMind’s SynthID-Text and says the signal does not affect readability, add tokens or carry identifying information. Its detection API is in private preview for eligible organizations.

We previously covered the Claude watermark rollout. Anthropic says it applies watermarking globally because it does not yet have a durable way to scope the system by region. OpenAI is choosing an EU-only default for eligible consumer output, while allowing API customers elsewhere to opt in.

EU Transparency Rules Set the Direction

The European Commission’s transparency code supports compliance with AI Act Article 50 obligations, applicable from August 2, 2026. The code is voluntary; the underlying legal requirements are not. Providers are expected to make generated content machine-readable and detectable, within technical limits.

The Commission separately addresses disclosures by organizations using AI, including deepfakes and certain public-interest text publications. Its framework recognizes human review and editorial responsibility in the latter context. An embedded watermark and a visible disclosure consequently serve different functions.

For EU users, the practical change will be a provenance signal in supported output. For institutions checking that output, the harder task is interpreting evidence without treating detection as a verdict. Clear rules for access, uncertainty and human review will be as consequential as the watermark’s technical performance.

Disclaimer: AIstify is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and insights on artificial intelligence, emerging technologies, automation, and related industries. NuvexMedia LLC invests in and collaborates with companies across the AI, technology, software, and digital innovation sectors. These relationships do not influence AIstify’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2026 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

AI & Machine Learning, Consumer Tech, News, Regulation & Policy