OpenAI says it will begin adding an invisible watermark to eligible text produced by ChatGPT and Codex for users in the European Union in the coming weeks. The company describes the feature as a way to help determine whether text likely originated from one of its AI systems.
The technology, called textGrain, does not insert visible labels, metadata, or special characters into generated content. Instead, it subtly influences word selection to create a statistical signature that an authorized detector can attempt to identify later. Readers and users copying the output should not see a difference in the text, according to OpenAI.
The rollout is limited geographically for now. API customers globally will be able to choose watermarking for supported models, but the setting will be disabled by default. OpenAI is also accepting applications for access to its detection tool, initially limiting availability to approved researchers and specialist organizations.
Detection can be weakened by edits
OpenAI acknowledged that the watermark is not a definitive method for establishing authorship. In company testing using 400-token passages, replacing 10% of words with synonyms reduced detection rates from roughly 92% to 66%. When 25% of words were changed, detection fell to about 17%.
Performance also varied based on the length and type of content. At a 1% false-positive threshold, OpenAI reported detection in about 80% of 200-token psychology responses and approximately 95% of 400-token responses. Mathematical text was more difficult to watermark because there are fewer interchangeable word choices without changing meaning.
- A missing watermark does not demonstrate that content was written by a human.
- Short passages, translation, and post-generation editing can prevent reliable detection.
- A detected watermark does not identify the user, account, prompt, or conversation associated with the output.
- The signal cannot determine how much of a final document was written or revised by a person.
OpenAI said enabling textGrain did not meaningfully affect quality benchmarks for its GPT-6 Astra model. The initiative arrives as policymakers, educators, publishers, and security teams continue to assess methods for identifying synthetic content while avoiding overreliance on tools that can be evaded through routine editing.
