OpenAI starts EU text-watermark rollout while limiting detector access
API customers can opt in worldwide, but ChatGPT and Codex marks will initially be introduced only for eligible EU users
OpenAI has begun a phased rollout of text watermarking, allowing API customers worldwide to opt in from Oct. 5 while preparing to watermark eligible ChatGPT and Codex text in the European Union in the coming weeks.
The API feature is off by default. OpenAI said it will introduce watermarking for eligible ChatGPT and Codex users in the EU on every plan, rather than make watermarking a global default at launch, so it can learn from real-world use and feedback.
The system, called textGrain, embeds an invisible statistical signal in a model’s word choices. A detector examines a passage for that signal to determine whether it contains an OpenAI watermark; it does not identify the user or disclose the underlying prompt or conversation.
OpenAI has opened applications for detector access, but will initially grant it only to approved researchers and expert organisations on a case-by-case basis. The company said it was not releasing a public detector because the technology can both miss watermarks and produce false positives. Its image and audio verification tools, including openai.com/verify and the Content Provenance API, remain public.
The phased launch comes after Article 50 transparency obligations of the EU AI Act took effect on Aug. 2. The law requires providers of systems that generate synthetic text to mark outputs in a machine-readable form that is detectable as artificially generated or manipulated, as far as technically feasible.
Article 50 separately requires deployers to disclose AI-generated or manipulated text published to inform the public on matters of public interest, subject to specified exceptions. The required transparency information must be clear and distinguishable no later than the first interaction or exposure.
The European Commission says Article 50’s requirements are legal obligations, while its Code of Practice on Transparency of AI-generated Content is voluntary. The Commission and AI Board have nevertheless recognised the code as an adequate voluntary tool for demonstrating compliance; about 190 organisations had signed it by the end of July.
A Morgan Lewis analysis says systems placed on the European Economic Area market before Aug. 2 have until Dec. 2 to meet the provider-side marking and detection obligation. Systems placed on the market on or after Aug. 2 must meet that obligation from the outset.
OpenAI plans to release textGrain as open source. Its technical report describes a system that couples token generation to keyed randomness while preserving relative probabilities within vocabulary blocks. Detection requires the text and a secret key, not the entropy budget used during generation.
The company reported that, at a 1% target false-positive rate, textGrain detected marks in about 80% of 200-token psychology passages and about 95% of 400-token passages. Those tests used watermarked English answers drawn from the ELI5 dataset, and performance was substantially lower for mathematics, where there is less flexibility in word choice.
Editing sharply reduced detection in one 400-token evaluation. Replacing 10% of words with synonyms cut detection from about 92% to 66%, while replacing 25% reduced it to 17%. OpenAI also cautioned that results under ideal conditions do not guarantee reliable everyday detection, and that short, edited or translated text can evade the system.
Across benchmarks used to assess Astra, OpenAI reported no meaningful difference between watermarked and unwatermarked output. The Artificial Analysis Intelligence Index score was 49.76 with watermarking and 49.57 without it; GPQA Diamond performance was 93.94% and 94.44%, respectively.
A detected watermark is not evidence of human contribution, ownership, responsibility, accuracy or contextual appropriateness, OpenAI said. Conversely, an absent mark does not prove that a passage was written by a human, since it may come from an unsupported model, predate the rollout or have been generated by another company’s tools.