OpenAI said on 5 October 2026 that ChatGPT and Codex will add an invisible watermark, called textGrain, to the text they write for users in the European Union. It covers every plan and rolls out over the coming weeks, to meet the EU AI Act’s rule that AI output must be machine-detectable. OpenAI’s own tests show the mark is fragile: replace a quarter of the words and detection falls from 92% to 17%.
Rewording a quarter of the text drops detection to 17%
textGrain works through word choice. Each time the model picks its next word, a secret key nudges it towards some options over others. You read normal text; a detector that holds the key sees a statistical pattern. There are no hidden characters to strip out.
That design has a clear weak spot, and OpenAI’s figures show where it is. Every rate below assumes the detector wrongly flags 1% of human text. A token is a chunk of text, about three quarters of an English word.
| Test (1% false alarm rate) | Watermarked text detected |
|---|---|
| 400 tokens, unedited | About 95% |
| 200 tokens, unedited | About 80% |
| 400 tokens, 10% of words swapped for synonyms | 66% (from 92%) |
| 400 tokens, 25% of words replaced | 17% |
| Maths answers | Substantially lower than prose |
| Other EU languages (translated prompts) | 42.2% (Romanian) to 69.0% (Spanish) |
The English and editing figures are OpenAI’s own, from its announcement and help pages, and no outside lab has checked them yet. The language range comes from OpenAI’s help centre as reported by ActuIA; we found no figure for Dutch. OpenAI says it saw no meaningful quality difference on its benchmarks with the watermark on.
Teachers, editors and HR teams cannot check for the mark
Only approved researchers and expert organisations can apply for the detector. OpenAI grants access case by case, as the EU Code of Practice for marking AI content describes. ActuIA names Cornell, ETH Zurich and the Slovak institute KInIT among the first. OpenAI held back a public tool because of missed marks and false alarms. An open-source release is planned, without a date.
OpenAI is also clear about the limits of a result. A watermark can show that an OpenAI system wrote or processed part of a passage. It says nothing about how much a person edited it, and a missing mark does not prove a human wrote the text. If you hoped to catch AI-written essays or application letters, nothing changes yet.
OpenAI marks only what the law requires, while Anthropic marks everything
The scope is narrow by design. Article 50 of the AI Act has required providers of generative AI to mark output in a machine-readable way since 2 August 2026. Systems that were already on the market before then get a grace period until 2 December 2026. Breaches can cost up to €15 million or 3% of worldwide turnover. For the wider rules and risk classes, read our explainer on the EU AI Act and what it means for your business.
Anthropic went the other way. Since 2 August it has watermarked Claude text in every region, its API included, Euronews reported. OpenAI limits the default to EU users of ChatGPT and Codex and makes the API opt-in everywhere.
What changes, and what OpenAI leaves open:
- ChatGPT and Codex: watermarked text for EU users on all plans, rolling out over the coming weeks
- Opt-out for ChatGPT users: OpenAI does not say whether there is one
- API: opt-in worldwide since 5 October, off by default, switched on per organisation or project
- API models covered: “select models”, not named
- Detector: by application, for researchers and expert organisations only
- Norway, Iceland and Liechtenstein: not mentioned, as OpenAI only names the EU
Set your own rules for AI text, because ChatGPT’s mark proves little either way
For most organisations this is OpenAI’s compliance step, not a new task for you. Staff keep using ChatGPT as before, and their texts will carry a mark that almost nobody can read. Two groups should act now.
The first is any team that builds its own text tools on the OpenAI API. If you offer a generative system under your own name, the Article 50 marking duty may sit with you, and OpenAI leaves the watermark off unless you enable it. Check your role with legal counsel before 2 December. Then turn the setting on in a test project and compare output quality on your own tasks.
The second is communication and editorial teams. Article 50 also asks deployers to disclose AI-generated text published to inform the public on matters of public interest, unless a person reviews it and someone holds editorial responsibility. A watermark does not meet that duty for you. Write down who reviews AI drafts and when you label them. Our guide to AI watermarks and provenance shows how to test whether your publishing workflow keeps or strips these signals.
For more information, visit the official announcement of textGrain on the OpenAI blog.