Invisible Ink, Statistical Signature: OpenAI's textGrain Watermark Comes to EU ChatGPT Text
OpenAI's textGrain embeds an invisible statistical watermark in EU ChatGPT and Codex output to comply with the EU AI Act — strong on long prose, fragile under editing, and unlike Anthropic, optional for API users worldwide.
On October 5, 2026, OpenAI published “Our approach to EU text provenance rules,” quietly launching one of the most consequential provenance experiments in the company’s history. The post introduced textGrain, an invisible statistical watermark that will be embedded in eligible ChatGPT and Codex text generated in the European Union over the coming weeks — with a worldwide API opt-in available from day one. The move is OpenAI’s answer to Article 50 of the EU AI Act, whose transparency rules for synthetic media began applying on August 2, 2026, and it arrives with an unusually candid appendix of limitations attached.
What textGrain actually is
textGrain is not a visible tag, a hidden character, or metadata glued onto the end of a response. It belongs to the family of statistical watermarks — the same conceptual lineage as Google’s open-source SynthID for text, which Anthropic adopted for Claude’s watermark earlier this year.
The mechanism exploits a simple property of language models: at almost every position in a sentence, several words would fit equally well. A secret key, combined with the preceding words, quietly biases which of those near-equivalent candidates the model picks. No single word looks odd to a reader. But across a long enough passage, the accumulated pattern of choices becomes statistically measurable. A detector holding the same key re-derives the preferred candidates at each position, counts how often the text followed them, and compares that rate against pure chance. A large enough gap means the text very likely came from the watermarked model.
Two consequences follow directly from the math, and OpenAI has been more forthright about them than most vendors:
- Length matters. Statistical confidence grows with token count. A two-line email carries almost no signal; a multi-page report carries a lot.
- Entropy matters. Where the next word is nearly forced — boilerplate, code syntax, quoted material — there is nothing to bias, so no signal gets embedded.
The numbers: strong on prose, fragile under editing
OpenAI’s internal benchmarks, run with the detector tuned to a 1 percent false-positive rate, show a steep dependence on both length and subject matter. At 400 tokens (roughly 300 words), the detector identified watermarks in about 95 percent of psychology passages — but only about 60 percent of math content, where the model has less freedom in word choice. At 200 tokens, psychology detection fell to roughly 80 percent. OpenAI says textGrain matched or beat alternative approaches in internal comparisons, including Google’s SynthID for text.
Editing is the softer spot. Swapping just 10 percent of words for synonyms cut detection on 400-token passages from roughly 92 percent to 66 percent. Replace a quarter of the words, and detection collapses to 17 percent — a rate low enough that the watermark functions more as a compliance tool for cooperative settings than as a forensic instrument against adversarial paraphrasing. Translation, which rewrites every word choice entirely, likely destroys the signal altogether. OpenAI has not published data on longer passages, so whether extra length compensates for light editing remains an open question.
On quality, OpenAI reports no significant differences with watermarking on or off across eight benchmarks — including GPQA Diamond, BrowseComp, and DeepSWE — tested on its frontier model Astra. Those benchmarks measure reasoning and task performance, though, not prose quality; critics have raised the same caveat about Claude’s watermark.
Where it applies — and the Anthropic contrast
The rollout is deliberately regional and asymmetric:
- ChatGPT and Codex in the EU: watermarking turns on by default for eligible text, phased in over the coming weeks, across all plans.
- API worldwide: strictly opt-in from October 5, off by default, for select models — with availability through cloud partners such as Microsoft Azure “in the coming weeks.”
That opt-in design is the sharpest divergence from Anthropic, whose Claude watermark applies globally regardless of how users access the model. OpenAI is betting that a lighter touch outside regulated jurisdictions will blunt the incentive for users to defect to open-weight models — a real concern, since anyone determined to avoid detection can already run unwatermarked open models locally, or simply paraphrase watermarked output past the point of detectability.
The legal driver is Article 50 of the EU AI Act, which requires providers of generative systems to mark synthetic text in a machine-readable, detectable way. OpenAI frames the phased approach as a reflection of both the legal timetable and the technology’s genuine limits. Gizmodo’s coverage put it bluntly: this is regulation working as designed — the reason the EU gets watermarks first is that the EU demanded them.
What the watermark can’t do
The most useful section of OpenAI’s post is its list of explicit limits. A detected textGrain signal indicates only that an OpenAI system generated or processed the text. It cannot:
- reveal who the user was
- measure how much a human contributed
- determine ownership or copyright
- verify that the content is accurate
And critically, the absence of a watermark “does not prove that a person wrote it” — the passage may be too short, edited, translated, or from an unsupported model. The word “processed” carries its own caveat: text that an OpenAI model merely rewrote or polished may also carry the signal, so a positive result means an OpenAI system touched the passage, not that it wrote every word.
That nuance should be pinned above every classroom, newsroom, and HR workflow tempted to treat the detector as a verdict.
Restricted detection, open-sourced technology
For now, almost nobody can run the detector. Access is limited to approved researchers and specialist organizations, granted case by case under the EU’s Code of Practice — mirroring Anthropic’s gated detection API for Claude. The tool reports only whether an OpenAI watermark was found; it does not identify users, prompts, or conversations. OpenAI says the gate exists precisely because the detector can flag unmarked text or miss marks on edited content, and it plans to expand access only “when we believe results can be interpreted responsibly.” No timeline was given.
At the same time, OpenAI says it plans to release textGrain as open source, so other developers can build on and audit the approach — a meaningful transparency gesture that stands in contrast to the closed detection tooling.
Existing verification tools for images and audio remain publicly available, including openai.com/verify and the Content Provenance API. textGrain extends the provenance posture to text, the hardest modality to mark.
What this means for builders
For anyone shipping on the OpenAI API, the practical checklist is short:
- Determine scope. If your product serves EU users or publishes content there, clarify with counsel whether Article 50 obligations fall on you, on OpenAI, or both.
- Test the opt-in on a staging key. The setting is off by default and model-limited; verify support before assuming coverage.
- Run your own quality evals. Vendor averages across reasoning benchmarks say little about your specific writing use case.
- Don’t post-process aggressively. Synonym replacement, paraphrase pipelines, and translation will erase the mark — if your pipeline rewrites model output, the watermark may not survive.
- Never promise detection to customers. With a restricted detector and these detection curves, “we can prove this was AI-generated” is a liability, not a feature.
- Log provenance yourself. Model, version, timestamp, and prompt hashes form a stronger evidentiary record than any watermark — and they work for short text and code, where statistical marks are weakest.
Codex’s inclusion is worth noting for developer workflows: code itself is low-entropy and will carry weak signal, but the natural-language layers around it — comments, commit messages, documentation — are exactly where the mark will land.
The bigger picture
Every major lab has now converged on the same position: text provenance is a compliance and provenance tool for cooperative ecosystems, not a lie detector for adversarial ones. Google built SynthID across modalities; Anthropic shipped a mandatory global watermark with gated detection; OpenAI had already moved on images with C2PA metadata and now extends the posture to text with a regionally-scoped, API-optional approach.
The differences in strategy — mandatory versus opt-in, global versus regional, closed versus open-sourced — will matter less than the shared trajectory. Regulation set the deadline, the technology met it with honest caveats, and the burden of interpretation now falls on the institutions that choose to use these detectors. OpenAI’s own framing is the right one: a watermark is evidence, not a verdict — and its absence proves nothing at all.
Sources
- [1] https://openai.com/index/eu-text-provenance/
- [2] https://the-decoder.com/openai-will-watermark-chatgpt-text-in-the-eu-but-makes-it-optional-for-api-users-worldwide/
- [3] https://techcrunch.com/2026/10/05/openai-will-start-watermarking-chatgpts-text-in-the-eu/
- [4] https://www.explainx.ai/blog/openai-textgrain-text-watermark-eu-chatgpt-codex-api-opt-in-2026
- [5] https://www.unite.ai/openai-begins-phased-text-watermarking-under-eu-ai-act-rules/
- [6] https://gizmodo.com/openai-is-adding-text-watermarks-in-the-eu-because-regulation-works-2000821852