Building with AI

OpenAI launches optional textGrain watermarking for API text generation

OpenAI introduces textGrain, an opt-in statistical watermarking system for API text. Detection rates vary by content type and editing, with code posing significant challenges.

A magnifying glass examining digital text to reveal a hidden watermark pattern.
Illustration generated for this article

OpenAI has released textGrain, a new watermarking system that allows API customers to embed detectable statistical signals into generated text. Launched on October 5, 2026, the feature is available globally as an opt-in tool for supported models, marking a shift in how the company handles content provenance for textual output.

What happened

The new system enables developers to choose whether their API-generated text carries a hidden identifier. Unlike previous image and audio watermarking efforts, textGrain is off by default for API users. This approach gives customers control over how they meet transparency obligations and manage user experiences. OpenAI stated that this flexibility allows organizations to decide how watermarking fits their specific needs.

In the coming weeks, the company will begin automatically watermarking eligible text produced by ChatGPT and Codex within the European Union. This move aligns with new transparency requirements under the EU AI Act. While API users must actively enable the feature, consumer-facing products in the EU will have it applied by default to comply with regional regulations.

This strategy contrasts with Anthropic’s approach announced in August. Anthropic applies watermarking globally to all supported Claude models, including API outputs, without an opt-out for developers. Anthropic cited technical limitations in restricting the technology by region as the reason for its blanket application. OpenAI’s method provides more granular control, allowing activation at the project or organization level without requiring changes to individual API requests.

How it works

textGrain embeds a statistical signal into text by subtly influencing word selection. When a model generates text, it often faces multiple suitable word choices for a given context. The system favors one valid option over another based on a hidden pattern. Over a long passage, these micro-decisions create a detectable signature that OpenAI’s detector can identify.

OpenAI developed textGrain internally rather than adopting existing standards like Google’s SynthID or Meta’s TextSeal. The company claims this custom approach offers better control over the balance between detectability and response variety. Internal testing suggests textGrain matches or exceeds SynthID’s detection performance. OpenAI plans to open-source the technology to encourage external improvements and broader adoption in the field of text provenance.

Key details

  • textGrain is opt-in for API customers globally but will be automatic for ChatGPT and Codex in the EU soon.
  • Detection rates reach approximately 80% for 200-token passages and 95% for 400-token passages in domains like psychology.
  • The system targets a false-positive rate of 1%, ensuring high confidence in positive detections.
  • Editing significantly weakens the signal; replacing 10% of words drops detection from 92% to 66%, while 25% replacement reduces it to 17%.
  • Code generation is harder to watermark due to fewer plausible token choices, though OpenAI reports no meaningful performance drop in coding benchmarks.
  • Detector access is currently restricted to approved research and academic organizations studying provenance and detection reliability.

Why it matters

For software engineers building AI applications, understanding the limitations of text watermarking is crucial. The technology is not a silver bullet for content authentication. Detection reliability depends heavily on text length and domain. Short passages may lack sufficient data for reliable identification, and constrained domains like mathematics offer fewer opportunities for the model to embed the statistical signal without altering meaning.

The fragility of the watermark against editing poses challenges for workflows involving human-in-the-loop refinement. If a developer or user edits a significant portion of the generated text, the watermark may become undetectable. This limits its utility for verifying the origin of collaboratively edited documents. Additionally, the restriction on detector access means most commercial API users cannot verify watermarks themselves, relying instead on OpenAI’s internal tools or future public releases.

The distinction between prose and code is particularly relevant for teams using Codex. Since code syntax is rigid, there are fewer synonyms or structural variations available for embedding signals. While OpenAI asserts that performance remains stable, the ability to detect watermarks in generated code remains uncertain. Developers should not assume that all AI-generated code can be reliably traced back to its source using this method.

What you can do

  • Evaluate whether your application requires content provenance and enable textGrain at the project or organization level if needed.
  • Test detection reliability with your specific use cases, noting that shorter texts and technical domains may have lower success rates.
  • Inform users about watermarking policies, especially if you operate in the EU where automatic watermarking will soon apply.
  • Monitor OpenAI’s announcements regarding detector access expansion if you need to verify watermarks independently.
  • Consider the impact of post-generation editing on watermark integrity when designing workflows that involve human review.
  • Keep an eye on the upcoming open-source release of textGrain to potentially integrate detection capabilities into your own systems.

Tools from the Bytechap store

$89

DocBento

Self-hosted document management that reads every scan and answers with page citations.

Live demo

Keep reading

All stories