AI news

OpenAI deploys textGrain watermarking for ChatGPT in the EU

OpenAI is rolling out invisible text watermarks for ChatGPT and Codex in the European Union to comply with the EU AI Act, using a method called textGrain.

A magnifying glass reveals invisible geometric patterns in typed text.
Illustration generated for this article

OpenAI has begun implementing an invisible watermarking system for text generated by its ChatGPT and Codex models within the European Union. This move, announced on Monday, aims to align the company’s operations with the transparency requirements of the EU AI Act, which became effective on August 2. The rollout will affect eligible users on all subscription plans in the region over the coming weeks.

What happened

The primary driver for this change is regulatory compliance. The EU AI Act mandates that providers of general-purpose AI models mark their outputs in a machine-readable format so that other systems can identify AI-generated content. OpenAI stated that it is not making this feature a global default at launch, citing different regulatory landscapes outside Europe. However, developers using the OpenAI API anywhere in the world can now enable the watermark for select models, though it remains off by default.

This decision follows a similar announcement from Anthropic two months prior, which introduced worldwide watermarking for its Claude model. That move sparked debate among users who felt their creative input was being misattributed to the AI. OpenAI had previously developed watermarking technology but delayed its release, reportedly due to fears that users might migrate to competitors who did not impose such markers. Now, alongside Anthropic, Google, Meta, and Microsoft, OpenAI has committed to the EU’s code of practice on AI-generated content.

How it works

The watermarking technique, detailed in a technical report co-authored with researchers from the University of Pennsylvania and Yale, is called textGrain. It does not insert visible symbols or metadata into the document. Instead, it subtly influences the model’s word selection during generation. By using a secret key to sort next-word predictions, the model makes specific, statistically detectable choices that form a pattern invisible to human readers.

Because the watermark is embedded in the linguistic structure of the text itself, it persists when the content is copied and pasted. A detector can identify the AI origin using only the text and the corresponding secret key. OpenAI reported that enabling textGrain resulted in no meaningful degradation in model performance or output quality. The system does not identify the specific user who generated the text, preserving anonymity while marking the source model.

Key details

  • The watermark rolls out to ChatGPT and Codex users in the EU over the coming weeks.
  • API developers globally can enable the feature for select models starting today, but it is off by default.
  • The method, named textGrain, uses a secret key to shape word choices without affecting readability.
  • Detection rates drop significantly with editing; replacing 10% of words with synonyms reduced detection from 92% to 66%.
  • Short passages, math answers, and translated text are currently harder for the detector to identify.
  • Access to the detector tool is initially restricted to approved researchers and expert organizations.

Why it matters

For engineering teams building products that integrate large language models, this shift introduces new considerations for content provenance and compliance. If your application serves users in the EU, you must account for the fact that outgoing text may carry these statistical markers. While the watermark does not impact performance, it changes the nature of the raw output. Developers need to understand that the text is no longer "neutral" but carries a signature that can be verified by third-party tools.

Furthermore, the limitations of textGrain highlight the fragility of current attribution technologies. The fact that minor edits can significantly reduce detection accuracy means that watermarks cannot serve as definitive proof of authorship or lack thereof. A missing watermark does not prove human creation, as the text could be too short, heavily edited, or generated by a non-watermarked model. This nuance is critical for teams designing moderation or verification pipelines, as relying solely on watermark detection may lead to false negatives.

What you can do

  • Review your data processing pipelines to determine if AI-generated text storage requires updates for EU compliance.
  • Test the API’s optional watermarking feature in staging environments to assess any edge cases in your specific use case.
  • Update user-facing documentation to clarify that AI-assisted content may contain invisible markers for identification.
  • Avoid relying exclusively on watermark detection for verifying human authorship in high-stakes moderation workflows.
  • Monitor the technical report on textGrain for updates on detection reliability and potential countermeasures.
  • Engage with legal counsel to ensure your product’s handling of AI-generated content meets the EU AI Act’s transparency rules.

Tools from the Bytechap store

$89

DocBento

Self-hosted document management that reads every scan and answers with page citations.

Live demo

Keep reading

All stories