Back

OpenAI Is Watermarking ChatGPT Text in the EU: How textGrain Works and What It Can't Prove

On October 5, 2026, OpenAI said it will add an invisible text watermark called textGrain to eligible ChatGPT and Codex output in the European Union to meet the EU AI Act, let API customers worldwide opt in for select models, and open its detector to approved researchers only.

OpenAI Is Watermarking ChatGPT Text in the EU: How textGrain Works and What It Can't Prove
Written by
BSH Technologies
Published on2026-10-06

What OpenAI announced

On October 5, 2026, OpenAI published Our approach to EU text provenance rules, explaining how it will make text generated by its models identifiable under the EU AI Act. The plan is phased:

  • ChatGPT and Codex in the EU: over the coming weeks, an invisible watermark will be added to eligible text output for users on all plans, in the EU only.
  • API, worldwide: starting October 5, API customers anywhere can opt in to watermarked text for select models. It stays off by default.
  • Detector: applications are open, but access is initially limited to approved researchers and expert organizations, granted case by case.
  • Not a global default: OpenAI says it is not making text watermarking a global default at launch.

This page is the long-form briefing behind the BSH Technologies Instagram carousel.

Why now: the EU AI Act

The AI Act requires generative AI providers to make generated text identifiable in a machine-readable way. According to TechCrunch, the Act's transparency rules took effect on August 2. OpenAI's Help Center says the rollout is also in line with its commitments under the EU Code of Practice on Transparency of AI-Generated Content, which several major AI providers have signed. That Code does not require watermarks in outputs shorter than 200 tokens (about 150 words in English) or in code snippets.

How textGrain works

OpenAI's method, textGrain, adds an invisible statistical signal to the model's word choices, and a detector looks for that signal. The Help Center is explicit that it does not add hidden characters, invisible spaces or unusual punctuation: the watermark is part of the wording itself. As TechCrunch explains, a technical report co-written with researchers from the University of Pennsylvania and Yale describes using a secret key to sort next-word predictions; add up hundreds of these nudges and a detector can spot the pattern using only the text and the key. Because the signal lives in the words, it travels with the text when it is copied and pasted.

OpenAI says textGrain matched or exceeded other approaches it tested, including Google DeepMind's SynthID for text, and plans to make the technology available in open source. Across benchmarks for its frontier model Astra, OpenAI reports no meaningful performance difference with watermarking switched on.

Where detection breaks down

OpenAI is unusually direct about the limits:

  • Length matters. At a target false positive rate of 1%, the detector found watermarks in about 95% of 400-token passages but about 80% of 200-token passages (for content such as psychology). Detection was substantially lower for mathematics, where word choice is less flexible.
  • Editing weakens it. On 400-token passages, replacing 10% of words with synonyms cut detection from about 92% to 66%; replacing 25% cut it to 17%.
  • Translation and short answers are also harder to detect, according to TechCrunch.

These limits are why OpenAI is not making the detector publicly available at launch.

What a watermark can't tell you

  • Human contribution: it can show an OpenAI system generated or processed part of a passage, not how much human judgment, editing or creativity went into it.
  • Ownership or responsibility: it does not decide who owns the text, whether its use was lawful, or whether disclosure was required.
  • Identity: it does not associate a person, account, prompt or conversation with the text.
  • Accuracy: it says nothing about whether a passage is true or misleading.
  • No mark is not proof: text may be too short, edited, translated, from an unsupported model, or written by another company's AI.

The wider picture

The Verge notes that Anthropic announced watermarking for Claude in August, also to meet the AI Act, and that not every user welcomed it. TechCrunch adds that Anthropic is applying its watermark worldwide, while OpenAI is starting in the EU only. For images and audio, OpenAI already adds C2PA Content Credentials and SynthID watermarks and keeps its openai.com/verify tool and Content Provenance API public. OpenAI's Developer Community announcement summarizes the same rollout for developers.

What teams should do now

  • EU users and teams: expect ChatGPT and Codex text to carry the mark in the coming weeks; it does not change what you see.
  • API builders: decide whether opting in fits your own transparency obligations under the AI Act; it is off unless you turn it on.
  • Educators and reviewers: do not treat a detection result, or its absence, as proof of authorship.
  • Compliance leads: map where generated text leaves your systems, and keep human review where provenance matters.

Primary sources

  • OpenAI: Our approach to EU text provenance rules (Oct 5, 2026)
  • OpenAI Help Center: Provenance signals in OpenAI-generated content
  • OpenAI Developer Community: OpenAI's approach to EU text provenance rules (Oct 5, 2026)
  • TechCrunch: OpenAI will start watermarking ChatGPT's text in the EU (Oct 5, 2026)
  • The Verge: OpenAI is adding text watermarking in ChatGPT and Codex (Oct 5, 2026)

How BSH can help

At BSH Technologies we help teams ship AI features that hold up under the EU AI Act and similar rules: provenance and disclosure flows, opt-in watermarking decisions for API products, and human review where it matters. If your product sends generated text to EU users, our Thrissur engineers can turn this briefing into a compliance checklist.

Frequently asked questions

What is textGrain?

textGrain is OpenAI's text watermarking technology. It adds an invisible statistical signal to the model's word choices that a detector can look for. It does not add hidden characters or unusual punctuation.

Who gets watermarked ChatGPT text?

Eligible ChatGPT and Codex users on all plans in the European Union, rolling out over the coming weeks from October 5, 2026. API customers worldwide can opt in for select models; it is off by default.

Can anyone check text for an OpenAI watermark?

Not yet. Detector access is initially limited to approved researchers and expert organizations, because short or edited text can cause missed watermarks and false positives.

Related Topics

#OpenAI#ChatGPT#Codex#textGrain#Watermarking#EU AI Act#AI Provenance

From the blog

View all posts
Google Pauses Its Open-Source Bug Bounty After a Flood of AI Bug Reports
blog.categories.ai

Google Pauses Its Open-Source Bug Bounty After a Flood of AI Bug Reports

On October 1, 2026, Google stopped accepting new product vulnerability reports to its Open Source Software Vulnerability Reward Program (OSS VRP), citing a significant rise in automated submissions, the vast majority of which are not valid. Supply chain reports and reports already filed are unaffected, and Google promises an update in Q1 2027.

BSH Technologies
BSH Technologies · 2026-10-05
Apple Tightens macOS Full Disk Access as AI Agents Rise
blog.categories.ai

Apple Tightens macOS Full Disk Access as AI Agents Rise

On October 2, 2026, Apple said macOS Full Disk Access will require very explicit user action. The company warns that some apps use the backup-era permission in ways that can expose files, mail, messages, and browsing history — risks that grow as autonomous AI agents become more capable.

BSH Technologies
BSH Technologies · 2026-10-04