7 OCT 2026 — Over the coming weeks, OpenAI will begin watermarking text that ChatGPT and Codex write for users in the European Union, to meet the EU AI Act's rule that AI-generated text be identifiable by machine. Outside the EU, the mark remains off unless an API customer switches it on. For now, only approved researchers can use the detector.
The company set out the plan in a post on 5 October, which is unusually direct about what the watermark cannot do.
The legal trigger is Article 50 of the AI Act, which has applied since 2 August 2026. It requires providers of AI systems that generate text, images, audio or video to ensure their outputs are "marked in a machine-readable format and detectable as artificially generated or manipulated."
What changes, and where
Three things change. API customers anywhere can opt in to watermarked output from selected models, but it stays off by default. Eligible ChatGPT and Codex text in the EU will carry the mark on every plan, but OpenAI says it is "not making text watermarking a global default at launch." Researchers and expert organisations can apply to use the detector, and access is granted case by case.
Image and audio checking tools, including OpenAI's public verification page, remain open to everyone. OpenAI also says it is working with cloud partners to watermark model output delivered through those services.
How textGrain works
The system, called textGrain, adds what OpenAI describes as "an invisible statistical signal" to the model's word choices. A detector then looks for that pattern. OpenAI says the method matched or beat other approaches it tested, including Google's SynthID for text, and that it plans to release it as open source along with a fuller technical report.
OpenAI also published benchmark results for its Astra model with and without the watermark. The scores are close: 94.44% against 93.94% on GPQA Diamond, a graduate-level science test, and 53.90% against 56.06% on Terminal-Bench 4.0, a coding-agent test.
Where detection breaks down
The signal fades quickly in OpenAI's own figures. At a target false-positive rate of 1%, the detector found the watermark in about 95% of 400-token passages and about 80% of 200-token passages for subjects such as psychology. Detection was "substantially lower" for mathematics, where there are fewer ways to phrase an answer.
Editing does more damage. Swapping 10% of the words in a 400-token passage for synonyms cut detection from about 92% to 66%. Swapping a quarter of them cut it to 17%. A 400-token passage is roughly 300 English words.
What a positive result does not prove
OpenAI lists the limits plainly. A detected watermark does not show how much a person wrote or edited, who owns the text, which account produced it, or whether it is accurate. And "the absence of a detected watermark does not prove human authorship": text may be too short, edited, translated, made before watermarking began, or produced by another company's model.
Those limits are the reason the detector is not public. A teacher or employer who treats a positive result as proof of cheating, or a negative one as proof of honesty, is misreading it either way.
A narrower choice than Anthropic's
The EU-only rollout is a deliberate choice, and OpenAI says it gives "room to learn from real-world use." Anthropic took the opposite route in August, marking Claude's text at the model level for supported models worldwide, which we covered at the time. When we reported that commitment, Anthropic offered no public detector for its text either. At least OpenAI's post publishes error rates, so the watermark can be judged against them.
Disclosure: RECATOOLS is written with the assistance of Claude, made by Anthropic, whose watermarking approach is compared here. Readers should weigh that interest.