OpenAI announced on Monday that it will begin implementing invisible watermarking for text generated by ChatGPT and its Codex model within the European Union. This move is a direct response to the regulatory requirements of the European Union AI Act, which mandates that AI companies clearly identify content generated by artificial intelligence.
The new system, based on a method called textGrain, will roll out to eligible ChatGPT and Codex users across all subscription plans in the EU over the coming weeks. While standard users in other regions will not see the change yet, developers using OpenAI's API globally can choose to enable the watermarking feature for specific models starting immediately.
The regulatory landscape
The primary driver behind this deployment is the EU AI Act, which officially took effect on August 2. The act includes strict transparency rules designed to ensure that users are aware when they are interacting with or consuming content created by an AI system. Under these rules, providers of general purpose AI models must mark their outputs in a format that other systems and detectors can recognize.
OpenAI is among several major technology companies, including Google, Meta, and Microsoft, that have pledged to follow the European Union's code of practice regarding the transparency of AI generated content. By introducing these watermarks, OpenAI is positioning itself to remain compliant with the evolving legal framework of one of its largest markets.
How the textGrain technology works
Unlike a digital watermark on a photo or a logo on a video, text watermarking does not involve a visible symbol. Instead, the process occurs during the generation of the text itself. OpenAI developed the textGrain method in collaboration with researchers from the University of Pennsylvania and Yale University.
The technology works by subtly influencing the mathematical probability of the next word chosen by the model. When ChatGPT predicts the next word in a sentence, the watermarking algorithm uses a secret key to nudge the model toward specific word choices. While these changes are imperceptible to a human reader, they create a specific statistical pattern that a detector can identify.
Because the watermark is embedded in the word choices rather than the file metadata, it remains attached to the content even when it is copied and pasted into a different document or application. OpenAI claims that this method does not result in any meaningful change to the performance or quality of the model's output.
Deployment and availability
The rollout of text watermarking is currently limited in scope. For the general ChatGPT interface, it is restricted to users located within the European Union. OpenAI has not committed to making the feature a global default for all users at this time.
For professional users and engineers, the situation is slightly different. Developers using the OpenAI API can now toggle the feature on for selected models, regardless of their geographic location. This allows businesses to voluntarily comply with transparency standards or provide verifiable AI provenance for their own products. OpenAI noted that for API users, the feature is turned off by default.
Limitations and vulnerabilities
Despite the sophisticated nature of the textGrain method, OpenAI has been transparent about its limitations. The watermark is not a foolproof solution for identifying AI content, and its effectiveness can be degraded through manual editing.
In testing, OpenAI found that even minor modifications could significantly impact detection rates. For example, replacing just 10 percent of the words in a generated passage with synonyms caused the detection accuracy to drop from approximately 92 percent to 66 percent. The company also acknowledged that certain types of content are much harder to watermark effectively, including:
- Very short passages of text
- Mathematical formulas and answers
- Translated text
- Highly technical or structured data
OpenAI also warned that the absence of a watermark is not definitive proof of human authorship. A passage might lack a watermark because it was generated by a different AI model, because it was heavily edited, or because it was too short to sustain the statistical pattern required for detection.
Furthermore, the company is not yet releasing a public detection tool. Access to the detector is currently restricted to approved researchers and expert organizations. This controlled release is intended to allow for further evaluation of the tool's reliability and to prevent bad actors from finding ways to circumvent the system.
The challenge of user retention
The decision to limit the initial rollout to the European Union may be influenced by competitive pressures. In 2024, reports indicated that OpenAI had developed text watermarking technology but delayed its release due to concerns that users might migrate to rival platforms that do not use such markers.
The fear within the industry is that users, particularly students or content creators, may view watermarking as a restrictive feature that could lead to their work being unfairly flagged. When Anthropic recently announced that it would watermark text generated by its Claude models globally, the move faced significant pushback from users who argued that the AI is a tool and that the final output is the result of human instruction and creative decision making.
OpenAI appears to be walking a fine line between regulatory compliance and user satisfaction. By implementing the feature only where legally required, the company can satisfy EU regulators while maintaining a standard experience for its global user base.
What this means for the industry
The introduction of textGrain marks a significant step in the ongoing effort to create a standard for AI provenance. As AI generated text becomes indistinguishable from human writing, the ability to trace the origin of information becomes a critical issue for educators, journalists, and government agencies.
OpenAI stressed that while watermarks can indicate that a system generated a portion of a text, they cannot determine the level of human judgment or editing that occurred after the fact. The watermark essentially acts as a "processed by" label rather than a definitive statement on the creative origin of an entire piece of work.
As the EU AI Act continues to be phased in, other AI providers will likely follow suit with their own regional or global watermarking solutions. The success of these technologies will ultimately depend on whether they can remain robust against editing and whether the industry can agree on a shared standard for detection.
Filed under: AI, TechNews, Software, OpenAI, ChatGPT, EUAIAct, ProductLaunches