OpenAI adds EU text watermarks to ChatGPT and Codex

OpenAI will watermark ChatGPT and Codex text for EU users under the AI Act, and lets API customers worldwide opt in to its textGrain method.
What it means for founders
- ChatGPT and Codex text made in the EU will carry the mark. Over the coming weeks, drafts and docs your EU staff generate there will be watermarked, while API output stays unmarked unless you opt in. Light editing weakens the signal, so do not count on it either way.
- The API opt-in is a compliance decision, not a default. If you resell OpenAI text to EU users, you may carry your own AI Act transparency duties. Turning the watermark on is a cheap signal of good faith; leaving it off avoids friction with users who dislike being marked, a tension Anthropic has already met.
- There is an opening in verification. With no public detector and weak results on short or edited text, tools that combine provenance signals, disclosure workflows and audit logs have room to grow. Watch for OpenAI's updated technical report and the open source release.
- Do not build products that treat detection as proof. Hiring, grading or moderation tools that read a missing watermark as human work will be wrong often enough to create liability.
The story
OpenAI said on Monday, October 5, that it will start embedding an invisible watermark in text produced by ChatGPT and Codex for people in the European Union, its answer to the EU AI Act's rule that generated text be machine readable as AI output. Developers on the OpenAI API anywhere can switch the same text watermarking on for some models as of Monday, though it ships disabled.
How OpenAI's textGrain watermark works
The method, called textGrain, leans on the model's word selection rather than adding any visible mark. A secret key tilts which next word gets picked, and across hundreds of those small tilts a detector holding the key can spot the pattern from the text alone. Because the signal sits in the wording, it survives copy and paste. OpenAI says the mark carries no information about who the user is.
In its announcement, OpenAI says textGrain performed at least as well as SynthID, the text watermark from Google DeepMind, in its own tests, and that scores across eight benchmarks run on its Astra model barely moved with the watermark on. It also plans to open source the technique.
Detection is fragile
With the detector tuned to a 1 percent false positive target:
- Roughly 95 percent of psychology answers 400 tokens long were flagged, falling to roughly 80 percent at 200 tokens.
- Math answers scored far lower, since there are fewer ways to phrase them.
- Swapping 10 percent of words for synonyms dropped the hit rate from roughly 92 to 66 percent; swapping a quarter cut it to 17 percent.
For that reason the detector is not public. Approved researchers and expert groups can apply, with OpenAI granting access one case at a time as the EU Code of Practice sets out. A clean result proves nothing about human authorship, the company stresses: the text may be short, edited, translated or from another vendor.
The EU transparency rules took effect on August 2, TechCrunch notes. Anthropic announced in August that it would watermark Claude text worldwide, which drew complaints from some users. The Decoder reports that Anthropic applies its mark however customers reach Claude, so OpenAI's opt-in API is the real difference.
What we don't know yet
- Which API models support the watermark, and when cloud partners will offer it.
- When, or whether, the detector opens to the public.
- Whether OpenAI extends the default beyond the EU after its regional trial.
Sources
Primary sources
Reporting
Enki Daily
Get stories like this every weekday morning.
The day's AI stories for founders, each with what it means for your company. Free.
Tools in this story
We may earn a commission if you sign up through our links. It never affects our ratings or which stories we cover.
OpenAI's all-purpose AI assistant
OpenAI's coding agent, included with ChatGPT
More in Policy & Safety
- Wikimedia finds rogue OpenAI agents on its wikis

For founders: Sampled analytics can hide agent traffic. Wikimedia's own defences missed a scraper because rate rules came from a small sample.
The Verge · 17h ago - Ousted New Jersey official cites 59 chatbot answers to dispute harassment findings

For founders: Expect more people to treat chatbot output as proof in disputes with employers, courts and regulators.
The Verge · 1d ago - Rural data centers could win a new federal tax break starting January 1

For founders: For data center developers, GPU cloud providers and energy startups building in rural areas, the program could meaningfully lower the cost of capital.
WIRED · 2d ago - Trump names Jay Clayton to lead a new Super Intelligence Force

For founders: Federal policy is leaning toward coordination and promotion, not new rules.
TechCrunch · 1d ago - Google pauses its open source bug bounty after a flood of invalid AI reports

For founders: If you run a bounty or a public security inbox, expect the same flood.
TechCrunch · 1d ago