OpenAI Adds the Invisible textGrain Watermark to ChatGPT Text in the EU: About 95% Detection at 400 Tokens, Under 20% Once a Quarter of the Words Change

On October 5 OpenAI announced that, to meet the transparency requirements in Article 50 of the EU AI Act, it will add an invisible watermark called textGrain to text generated by ChatGPT and Codex for EU users on all plans over the coming weeks; API customers anywhere can turn it on themselves, off by default, and it is not becoming a global default for now. When several words would fit equally well, textGrain uses a secret key to decide which one is chosen, inserting no hidden characters, so that over a long enough passage a detector holding the key can spot the pattern. In OpenAI's published tests, detection is about 95% at 400 tokens and about 80% at 200; replacing 10% of words with synonyms drops 400-token detection from about 92% to 66%, and replacing 25% pushes it below 20%. The detector is initially open only to approved researchers and expert organizations.

Who gets watermarked

The transparency rules in Article 50 of the EU AI Act took effect on August 2, requiring AI companies to mark AI-generated content in a machine-detectable way. On October 5 OpenAI announced that over the coming weeks it will add an invisible watermark called textGrain to text from ChatGPT and Codex for EU users on all plans. API customers anywhere can enable it per project, and it is off by default. OpenAI says it is not making it a global default for now.

That differs from Anthropic: as this site reported in August, Anthropic embeds a text watermark across Claude models released after August 2, with no opt-out in the API.

How it works, and how reliable it is

textGrain inserts no hidden characters. During generation, when several words would fit equally well, a secret key decides which one is used; no single word gives it away, but over a long enough passage a detector holding the key can recognize the pattern. OpenAI also published a technical report written with researchers from the University of Pennsylvania and Yale.

In OpenAI's published tests, under ideal conditions detection is about 95% for 400-token texts (about 300 English words) and about 80% at 200 tokens, and markedly lower for math. Editing matters a lot: replacing 10% of words with synonyms drops 400-token detection from about 92% to 66%, and replacing 25% pushes it below 20%. Translation, short passages, code and formal writing also weaken the signal. The detector is initially open, case by case, only to approved researchers and expert organizations.

What it means

OpenAI's own framing is restrained: a missing watermark does not prove human authorship, and a watermark cannot measure human contribution, establish ownership or verify accuracy. For teachers and platform moderators, that means it is not a substitute for an "AI detector," and light editing gets around it. Its real role is compliance and provenance at scale. Developers serving the EU should decide whether to enable it on the API side, and how to tell their users if they do.

via: OpenAI announcement, textGrain technical report, TechCrunch report, The Decoder report