Skip to content

OpenAI starts EU rollout of textGrain watermarking for ChatGPT and Codex

The system changes statistical patterns in word choices, but OpenAI says editing and short passages can lower detection rates.

OpenAI has begun rolling out textGrain, an invisible text-watermarking system that alters a model’s word-selection process so a detector can assess whether a passage contains an OpenAI watermark. API customers worldwide have been able to opt in for select models since Oct. 5, while eligible ChatGPT and Codex users in the European Union are due to receive watermarked output in the coming weeks. The feature will not be a global default at launch. Watermarking remains off by default for API users, and OpenAI is limiting the ChatGPT and Codex rollout to the EU across all plans. As we reported on Oct. 5, the company is also initially restricting detector access to approved researchers and expert organizations, which can apply case by case. TextGrain places a statistical signal in token choices rather than inserting hidden characters or symbols. The detector uses the passage and a secret key to reconstruct the signal, without requiring access to the generating model or the setting used to control watermark strength. That design means the mark can persist when text is copied and pasted. OpenAI’s technical report describes the system as entropy-calibrated watermarking. It couples token selection to keyed pseudorandomness while using an entropy budget intended to limit the loss of variation in generated prose. The company said its Astra benchmarks showed no meaningful performance difference between watermarked and unwatermarked text. The company nevertheless described watermarking and detection as early technologies with significant limitations. In its evaluations, at a 1% target false-positive rate, the detector found marks in about 80% of 200-token psychology passages and 95% of 400-token passages. Results were weaker for mathematical text, where there is less freedom in word choice. Editing also sharply reduced detection. In a test of 400-token passages, replacing 10% of words with synonyms cut detection from about 92% to 66%; replacing 25% cut it to 17%. A missing watermark therefore does not prove that writing is human-authored, OpenAI said, since text may be short, edited, translated, made by an unsupported or pre-watermark model, or produced with another company’s tools. Nor does a detected watermark settle a passage’s provenance. It can show that an OpenAI system generated or processed some of the text, but it does not identify a user, establish ownership or responsibility, measure human contribution, or verify accuracy and context. OpenAI said it was withholding public detector access at launch because of the risks of missed marks and false positives. The rollout comes as generative-AI providers face EU requirements to make generated text identifiable in machine-readable form. OpenAI said textGrain matched or exceeded other approaches it tested, including Google DeepMind’s SynthID for text, while planning to make its system open source. Anthropic has separately said that supported Claude models launched in the EU from Aug. 2 carry machine-readable markings, with detector access also limited to eligible organizations in private preview.