What changed
On Monday, OpenAI announced it will start watermarking the text that comes out of ChatGPT and Codex — invisibly, and only in the European Union. The move puts the company into compliance with the EU AI Act's transparency rules, which have required machine-identifiable AI content since August 2. Rollout happens over the coming weeks, across all plans, to eligible EU users. Everywhere else, nothing changes: OpenAI is not making watermarking a global default at launch.
How textGrain works
There is no visible mark. textGrain, the technique OpenAI described in a technical report co-written with researchers from the University of Pennsylvania and Yale, nudges the model's word choices as it generates — a statistical pattern, keyed by a secret, that a detector can pick up later. Because the pattern lives in the words themselves, it survives copying and pasting. OpenAI says the watermark does not identify the user and that it saw no meaningful change in model performance with it on. The company says it intends to release the technology as open source.
The scrubbing problem
OpenAI published the weak points alongside the announcement, which is more candor than most watermark launches get. In its tests, replacing 10% of the words in a 400-token passage with synonyms dropped detection from about 92% to 66%. Replacing 25% dropped it to 17%. Short passages, math answers, and translated text are harder to detect — math is the worst case, because there is little room to vary word choice. The watermark survives a casual copy-paste. It does not survive an editor with a thesaurus.
Regulation did this
Credit where it is due: this exists because a law required it. The EU AI Act's transparency obligations forced every major lab to ship provenance tooling, and OpenAI is following Anthropic, which introduced invisible watermarking for Claude in August. Google DeepMind has watermarked its outputs for years — though in August it moved the other way, letting users remove watermarks on images, video, and songs in countries where it is not required. That reversal is worth keeping in mind: watermarking is only as strong as the companies' willingness to keep it on.
The verdict
A watermark that survives copy-paste but dies to paraphrase is not provenance infrastructure. It is a compliance artifact — real enough to satisfy a regulator, fragile enough that no one should treat detection as proof of anything. OpenAI knows this: detector access goes only to approved researchers and expert organizations, case by case, because of false-positive risk, and the company says a watermark cannot show how much of a text was machine-generated versus edited by a human. The honest version of this story is a milestone and a shrug: the first large-scale text watermarking regime is here, and its own numbers say a determined rewrite defeats it.
Sources
- [1] TechCrunch — “OpenAI will start watermarking ChatGPT's text in the EU” (Oct 5, 2026)Read source
- [2] BleepingComputer — “OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU” (Oct 5, 2026)Read source
- [3] Gizmodo — “OpenAI Is Adding Text Watermarks in the EU Because Regulation Works” (Oct 5, 2026)Read source
- [4] B&T — “OpenAI Follows Anthropic With Invisible Watermarks On ChatGPT Text” (Oct 5, 2026)Read source