Tech News

OpenAI to Add Invisible Watermarking to ChatGPT and Codex Texts in the EU

Within a few weeks, texts generated by ChatGPT or Codex will include an invisible watermark, embedded directly into the text through word choice. OpenAI made this decision to comply with the EU AI Act, applying the same approach as Anthropic with Claude. Here’s what you need to know.

On October 5, 2026, OpenAI explained how it will make it possible to identify the origin of texts in order to comply with European regulations. This will happen as follows:

  • ChatGPT and Codex in the EU : an invisible watermark will be added to text outputs, for all plans. The rollout planned for the coming weeks applies only to the European Union. So this will not be a global default setting, at least for now.
  • API as an option : since October 5, API customers worldwide can enable watermarking on certain models. It remains disabled by default. OpenAI also plans to offer it through its cloud partners.
  • A text detector : applications for access to the detection tool are open, but access is initially limited to researchers and expert organizations, approved on a case-by-case basis.

For the record, Article 50 of the AI Act requires providers of generative AI systems to mark their content in a machine-readable format so it can be detected as artificially generated. These obligations have applied since August 2, 2026, and the European Commission supported them with a code of practice on transparency for AI-generated content, published on June 10, 2026.

However, OpenAI is not behind schedule. Generative AI systems already on the market before August 2 get a little more time: until December 2, 2026. OpenAI is therefore on time, and it is better to be, because a violation of Article 50 can cost up to 15 million euros or 3% of annual global revenue.

textGrain: a hidden statistical signal in word choice

No visible mention, and no hidden characters to remove with find-and-replace. OpenAI’s technology, called textGrain, slightly alters the words chosen by the model to embed a statistical signal. OpenAI’s AI text detector knows the “key,” so it can look for this pattern to estimate whether an OpenAI mark is present. A technical report describes the method for anyone interested.

It works on the same principle as the technology Anthropic uses to mark text generated with Claude. The same goes for Google with SynthID for text.

That said, it is not foolproof. OpenAI also provides a few figures:

  • Length matters : with a target false-positive rate of 1%, the detector identifies the watermark in about 80% of 200-token passages, compared with 95% for 400 tokens, on psychology-style answers.
  • The topic matters too : on mathematical content, where the model has less freedom in word choice, detection is significantly weaker.
  • Editing erases the trace : on 400-token passages, replacing 10% of words with synonyms drops detection from about 92% to 66%. At 25% replaced words, it falls to 17%.

Even so, OpenAI believes there is no significant gap in the quality of the responses provided. According to benchmarks for GPT-6 Astra, its latest frontier model, here are the results: 94.44% on GPQA Diamond without watermarking, compared with 93.94% with it enabled.

What the watermark does not tell you

With this kind of marking technology, a fairly heavy rewrite is enough to muddy the waters. Conversely, a text written by a human but lightly polished with AI could easily look like it was AI-generated. In reality, AI did not do the bulk of the work. Not a simple topic.

OpenAI also stresses that the watermark does not measure the amount of human work involved. But the reverse is equally true.... "The absence of a watermark does not prove that a human authored it," OpenAI warns. The text may be too short, edited, translated, generated by an unsupported model, created before watermarking was introduced, or produced by a competing tool.... In that case, it is better that the detection tool not be public, because it is not foolproof.

Another important point: it does not establish ownership or responsibility for a text, and it does not verify its accuracy. Above all, it does not identify the user: no account, prompt, or conversation is associated with the text. The detector simply indicates whether it finds an OpenAI mark or not.

What do you think?

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.