OpenAI will watermark ChatGPT and Codex text in the EU

OpenAI said in a blog post on Monday that it will start adding an invisible watermark to text generated by ChatGPT and Codex in the European Union, to comply with the EU AI Act. The Act's transparency rules took effect on August 2 and require AI companies to mark AI-generated content in a way other systems can identify.
The watermark will roll out over the coming weeks to eligible ChatGPT and Codex users on all plans, but only in the EU. Developers using OpenAI's API anywhere in the world can turn it on for select models starting today; it is off by default. OpenAI said it is not making text watermarking a global default at launch.
The watermark is not an actual symbol. It works by subtly shaping the model's word choices, leaving a pattern readers cannot see but a detector can pick up. Because it lives in the words themselves, it travels with the text when it is copied and pasted. OpenAI said the watermark does not identify the user, and that it saw no meaningful change in its models' performance with it switched on.
Alongside the announcement, OpenAI published a technical report on the method, called textGrain, co-written with researchers from the University of Pennsylvania and Yale. It walks through an example of using a secret key to sort next-word predictions to finish a sentence. Add hundreds of these nudges together, and a detector can spot AI-generated content using only the text and the key.
The watermark can be weakened by editing. In one OpenAI test, replacing 10% of words with synonyms dropped detection from about 92% to 66%. The company also said short passages, math answers and translated text are harder to detect. Because of these limitations, OpenAI is giving initial detector access only to approved researchers and expert organizations, who can help it evaluate reliability and responsible uses.
OpenAI also cautioned that a missing watermark does not prove human authorship. The text could be too short or too heavily edited, or it could come from another company's AI. Watermarks, it said, can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing or creativity went into it.
The announcement comes two months after Anthropic said it would watermark text generated by Claude, a move it is applying worldwide. That decision drew backlash from some Claude users, who argued they had supplied the instructions, context and decisions while Claude was just the tool. The Wall Street Journal reported in 2024 that OpenAI had built a text watermark before but held off releasing it, partly over concerns that users would switch to rivals that did not watermark. Anthropic, Google, Meta, Microsoft and OpenAI are among the companies that have committed to following the EU's code of practice on AI-generated content.
Key facts
- OpenAI will add an invisible watermark to ChatGPT and Codex text in the EU over the coming weeks, for eligible users on all plans, to comply with the EU AI Act transparency rules that took effect on August 2.
- API developers anywhere can switch the watermark on for select models starting now; it is off by default, and OpenAI is not making it a global default at launch.
- The method, textGrain, was published in a technical report co-written with researchers from the University of Pennsylvania and Yale; it shapes word choices using a secret key.
- In one OpenAI test, replacing 10% of words with synonyms cut detection from about 92% to 66%; short passages, math answers and translated text are harder to detect.
- Detector access starts with approved researchers and expert organizations only, and a missing watermark does not prove human authorship.
Why it matters
OpenAI is putting a text watermark into a mass-market chatbot, driven by a legal requirement rather than a product choice. The EU AI Act's transparency rules, in force since August 2, require AI companies to mark AI-generated content in a way other systems can identify. OpenAI had built a text watermark before but held off, partly over worry that users would move to rivals that did not watermark, according to a 2024 Wall Street Journal report. The move follows Anthropic's announcement two months earlier that Claude text would be watermarked worldwide.
Who it affects
Eligible ChatGPT and Codex users on all plans in the EU will get watermarked text over the coming weeks. Developers using OpenAI's API anywhere in the world can opt in on select models. Researchers and expert organizations that OpenAI approves will get the first access to the detector. Claude users are also in the picture: Anthropic applies its watermark worldwide, and some users objected, arguing they supplied the instructions, context and decisions while Claude was only the tool.
How to use it
In ChatGPT and Codex in the EU there is nothing to switch on; the watermark will arrive for eligible users on all plans over the coming weeks. API developers can turn it on for select models starting today, and it is off by default. OpenAI says the watermark does not identify the user and that it saw no meaningful change in model performance with it enabled. The detector is not public: initial access is limited to approved researchers and expert organizations.
How solid is it
The core claims come from OpenAI's own blog post and technical report, as relayed by TechCrunch. The method, textGrain, was co-written with researchers from the University of Pennsylvania and Yale, and it works by using a secret key to sort next-word predictions, with hundreds of small nudges adding up to a signal a detector can read from the text and the key alone. The robustness figure is a single OpenAI test: replacing 10% of words with synonyms dropped detection from about 92% to 66%. The article does not give the test setup or false-positive rates.
Risks and caveats
The watermark is not robust to editing. In OpenAI's test, a 10% synonym swap cut detection from about 92% to 66%, and short passages, math answers and translated text are harder to detect. A missing watermark proves nothing: the text may be too short or too heavily edited, or may come from another company's AI. A watermark can show that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing or creativity went into it. OpenAI cites these limits as a reason to restrict initial detector access. The article does not say whether OpenAI will extend the watermark beyond the EU later.
“[Watermarks] can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it”
— OpenAI, in its announcement, as reported by TechCrunch