OpenAI Plans Default AI Text Watermarks for ChatGPT and Codex in the EU

OpenAI plans default textGrain watermarking for ChatGPT and Codex in the EU, with reported detection limits when text is edited.

OpenAI Plans Default AI Text Watermarks for ChatGPT and Codex in the EU
AI

Illustrative image generated with AI

OpenAI is preparing to add detectable patterns to text produced through its ChatGPT and Codex apps in the European Union, making the watermarking system active by default for EU users.

The change was reported on October 6, 2026. OpenAI says deployment will begin “in the coming weeks,” but it has not provided an exact rollout date.

The company calls the proprietary technique textGrain. Rather than adding visible labels or metadata, it is designed to modify patterns of word selection in ways that a specialized detector can recognize.

OpenAI presents the move as part of its response to the EU AI Act. However, the available report attributes both the compliance rationale and the system’s performance figures to the company. The supplied information does not include independent testing of textGrain.

EU deployment will differ from other regions

Watermarking will be enabled automatically for text generated in the ChatGPT and Codex apps when used in the European Union. Users elsewhere will also have access to the feature, according to the report, but it will be disabled by default.

The report tentatively describes a similar arrangement for OpenAI’s API: textGrain would be optionally available but remain off unless enabled. That API detail is less definitive than the announced default for the EU apps.

This geographic split has a direct operational consequence. Text from the same OpenAI product family may or may not contain the watermark depending on the user’s region, application and configuration. A detector’s failure to find textGrain therefore would not, by itself, establish that a passage was written without an OpenAI model.

OpenAI links the EU default to rules under the EU AI Act requiring AI-produced content to be marked in a form that another tool can detect, as characterized in the report. The article says the legislation took effect in August, but does not specify the year. No year should therefore be inferred for that event.

The policy contrasts with the approach attributed to Anthropic. According to the same reporting, Anthropic introduced text watermarking in August and enabled it globally. Again, the year is not specified. OpenAI instead plans to make automatic marking dependent on geography, with the EU receiving the default-enabled configuration.

textGrain alters word-selection patterns

OpenAI describes textGrain as a statistical watermark embedded through word choices. The intended patterns are not supposed to be apparent to a person reading the output, and the company says they do not materially reduce its general quality.

Detection requires a dedicated tool and a key capable of identifying those patterns. This differs from a visible disclosure such as a label placed above a generated passage. It also differs from ordinary metadata, which can be lost when text is copied into another document or messaging service.

The available account does not provide the underlying algorithm, key-management design or other implementation details. It says OpenAI has published a technical paper, but no link to that paper is included in the supplied material.

Detector access will initially be restricted. OpenAI plans to provide it to a limited group of researchers and organizations, while allowing other parties to apply for approval. Consequently, ordinary readers will not necessarily be able to submit arbitrary text and check it themselves.

That access model concentrates verification among approved organizations. Depending on who receives the detector, potential users could include researchers studying synthetic content or organizations assessing material submitted through their systems. OpenAI has not demonstrated those specific uses in the information supplied, so they remain possible applications rather than confirmed deployments.

Reported accuracy falls when text is modified

In OpenAI’s reported best-case testing, textGrain reached a 92% successful detection rate. That result is a company-reported test outcome, not an independently reproduced performance benchmark in the available material.

The reported figures also show substantial sensitivity to editing:

  • Changing 10% of a passage reduced successful detection by almost 30%.
  • Changing 20% could reduce successful detection by almost 75%.
  • Detection generally performed worse on shorter passages.
  • Translated text was harder to identify than longer, unmodified text.

The report does not clarify whether the reductions of almost 30% and almost 75% refer to relative decreases or percentage-point changes. They therefore cannot be reliably converted into final detection rates.

For example, it would be unsupported to subtract those values directly from the best-case 92% result. It would be equally unsupported to assume that every type of rewriting produces the same effect. The figures describe OpenAI’s reported tests under conditions that are not detailed in the supplied account.

These limitations matter because generated text is frequently edited before publication. A person may shorten an answer, reorganize it, translate it or combine it with independently written material. Those ordinary transformations could weaken detection even without a deliberate attempt to remove the watermark.

Conversely, a positive detector result would indicate that the tool found the expected pattern. The supplied reporting does not establish how such a result should be treated as evidence in academic, workplace or legal decision-making.

Watermarks are signals, not durable proof of origin

Ars Technica assesses existing watermarking systems, including Google’s SynthID and the C2PA project, as relatively easy to circumvent for someone with basic knowledge. The publication expects textGrain to face a comparable problem.

That is Ars Technica’s assessment. The supplied material does not contain an independent demonstration that textGrain has been defeated, nor does it document an active bypass method against OpenAI’s system.

OpenAI’s own reported editing results nevertheless show why watermark detection has practical boundaries. A hidden statistical pattern must survive rewriting, translation and reduction while remaining unobtrusive to readers. Improving resilience in one area could potentially affect text quality or predictability, although the available information does not document those trade-offs for textGrain.

The result is better understood as an attribution signal than as conclusive proof. Detection may help an approved organization identify some unmodified or lightly modified OpenAI-generated text. Failure to detect the pattern may have several explanations, including editing, translation, short length, use outside the EU or generation through a channel where watermarking was not enabled.

What changes for users and organizations

EU users of the ChatGPT and Codex apps should expect watermarking to activate automatically once the rollout reaches them. OpenAI has not described a user-side remediation process, workaround or security mitigation because this is a product and compliance change, not a vulnerability or breach.

Users outside the EU should not assume their outputs are marked merely because textGrain is available. The reported default remains off in those regions. API customers likewise need to verify the eventual product configuration rather than assuming that API-generated text contains the watermark.

Organizations planning to use detection should account for the published limitations before building policies around it. Short passages, translations and edited material are specifically associated with weaker detection in the reported tests. Access to the detector will also depend on selection by OpenAI or approval through its request process.

No security incident, CVE, affected-person count or conventional severity rating is associated with the announcement. The immediate change is narrower: OpenAI intends to make machine-detectable text patterns standard for its EU consumer-facing apps while keeping watermarking optional elsewhere.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →