OpenAI Begins Text Watermarking Rollout, With Detection Restricted to Experts
Developers can opt in worldwide, while eligible EU app outputs will gain invisible signals over the coming weeks. OpenAI’s tests show how easily editing can weaken detection.
OpenAI is rolling out textGrain, a statistical watermark for eligible ChatGPT and Codex text in the EU, while keeping its detector limited to approved researchers and expert organizations. Developers worldwide can opt in through the API, but support is limited to select models and the feature is off by default. The signal is not a reliable authorship test: detection varies by passage length and subject, and even modest synonym edits can sharply weaken it.
01
OpenAI opened applications for detector access on October 5 and says it will approve requests case by case.
02
At a 1% target false-positive rate, OpenAI detected about 80% of watermarks in 200-token psychology passages and 95% in 400-token passages.
03
In 400-token tests, replacing 10% of words with synonyms cut detection from about 92% to 66%; replacing 25% cut it to 17%.
Eligible ChatGPT and Codex text in the European Union will soon carry an invisible signal of OpenAI’s involvement—but the public will not get access to the detector at launch. OpenAI’s October 5 announcement starts a phased rollout, with worldwide developer opt-in available immediately and EU app coverage coming over the next few weeks.
A regional default, a developer choice
The EU rollout covers eligible outputs across all ChatGPT and Codex plans. OpenAI is not making watermarking a global default. For developers using its API, watermarking remains off unless they enable it, and only select models support the option.
OpenAI ties the change to the EU AI Act, which it says requires providers to make generated text identifiable in a machine-readable form. Applications for detector access opened October 5, initially for approved researchers and expert organizations. Access will be granted case by case to help evaluate reliability and responsible uses.
The signal depends on the wording surviving
The technology, called textGrain, embeds a statistical pattern in the model’s word choices. A detector searches a passage for that pattern rather than checking a visible label. OpenAI says its benchmarks for Astra showed no meaningful performance difference between watermarked and unwatermarked output.
Detection is less consistent. In OpenAI’s evaluations, at a target false-positive rate of 1%, the detector found about 80% of watermarks in 200-token psychology passages, versus about 95% in 400-token passages. Mathematics performed substantially worse because there was less flexibility in word choice. These are company test results, not a guarantee of everyday reliability.
Editing also erodes the signal. OpenAI tested synonym substitutions in watermarked English passages of 400 tokens; even changing a minority of words sharply reduced detection.
An origin signal is not an authorship verdict
OpenAI cites both false positives—finding a watermark where none exists—and missed watermarks as reasons to restrict detector access. It also draws firm boundaries around what a positive result means:
It cannot measure how much human judgment, editing or creativity contributed.
It does not establish ownership, lawful use or responsibility for the text.
It does not identify the user or reveal their prompts or conversations.
It does not verify whether the passage is accurate.
Nor does a negative result prove human authorship. OpenAI-generated text may be too short, edited or translated to detect, or come from an unsupported model or predate watermarking. Text from another provider would not carry OpenAI’s signal.
OpenAI plans to release the technology as open source and is working with cloud partners on watermarking access in the coming weeks. Broader detector access remains conditional: the company says it will expand availability when it believes results can be interpreted responsibly.
Sources
openai.comOur approach to EU text provenance rules
Reader comments
Newest comments first. Replies stay oldest first.