OpenAI has unveiled its approach to text watermarking in response to the EU AI Act. The company will add an invisible signal to eligible ChatGPT and Codex output in the European Union. Meanwhile, developers worldwide can now opt in through the API. As a result, OpenAI text watermarking is moving from the lab into real-world use.
However, the company is urging caution. In its announcement on EU text provenance, OpenAI admits that “Text watermarking and detection remain early technologies with significant limitations.”
A Phased Rollout Under the EU AI Act
The EU AI Act requires generative AI providers to make generated text identifiable in a machine-readable way. OpenAI is responding with a phased plan. First, API customers can enable watermarking for select models today. Notably, the feature stays off by default.
Second, eligible ChatGPT and Codex users in the EU will see watermarks over the coming weeks. Finally, approved researchers and expert organizations can apply for detector access. OpenAI says this regional approach “gives us room to learn from real-world use and feedback.” In addition, the company is working with cloud partners to bring the feature to their platforms.
How textGrain Works
The technology behind OpenAI text watermarking is called textGrain. It adds an invisible statistical signal to the model’s word choices. A detector then scans a passage for that signal. According to OpenAI, textGrain matched or beat other tested methods, including SynthID for text. Moreover, the company plans to release the technology as open source.
Importantly, watermarking does not seem to hurt output quality. Benchmarks for Astra, OpenAI’s latest frontier model, showed no meaningful gaps. For example, GPQA Diamond scored 94.44% without watermarks and 93.94% with them.
Detection Has Real Limits
Still, the test results reveal clear weaknesses. At a 1% false positive rate, the detector caught about 80% of 200-token passages. By contrast, it caught about 95% of 400-token passages on psychology topics. Math content proved much harder because it offers less flexibility in word choice.
Editing also erodes the signal. Swapping 10% of words for synonyms cut detection from about 92% to 66%. Furthermore, replacing 25% of words dropped it to just 17%. For this reason, OpenAI will not make the detector public at launch.
What a Watermark Cannot Prove
OpenAI also warns against overreading results. A watermark does not identify the user or measure human effort. Likewise, it does not verify accuracy or establish ownership. In OpenAI’s words, “The absence of a detected watermark does not prove human authorship.”
Part of a Broader Provenance Strategy
Text is only one layer of OpenAI’s provenance work. The company already adds Content Credentials to images. It also embeds SynthID watermarks in supported images and audio. Additionally, its openai.com/verify tool remains open to the public for image and audio checks.
Overall, OpenAI text watermarking reflects a careful balance between regulation and technical reality. As the company puts it, “No single provenance technique is enough on its own.” For security teams, educators, and regulators, the takeaway is simple. Treat a watermark result as one signal, not final proof.
Support Our Threat Intelligence
Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!