On 5 October 2026 OpenAI said it will start adding an invisible statistical watermark to text from ChatGPT and Codex in the European Union, to comply with the EU AI Act's transparency rules.
The mark is built into word choice, so it travels with copied text, but OpenAI's own tests show it weakens under editing, and the detector is restricted to approved researchers. That gap is the whole story for anyone running a check.
This piece separates what OpenAI has published from what nobody outside OpenAI can currently verify, and says plainly what a third-party checker, this one included, can and cannot tell you.
- 01The watermark applies to ChatGPT and Codex for eligible users on all plans, in the EU only, rolling out over the coming weeks. API developers anywhere can opt in for select models; it is off by default and not a global default.
- 02OpenAI's method, textGrain, nudges the model's next-word choices using a secret key. The mark lives in the words, so copy and paste preserves it, and OpenAI says it does not identify the user.
- 03OpenAI's own test: replacing 10% of words with synonyms cut detection from about 92% to 66%. Short passages, math answers and translated text are harder to detect.
- 04Detector access is limited to approved researchers and expert organisations at launch. No public detector, and no public key, exists.
- 05A missing watermark does not prove human authorship, in OpenAI's own words.
What OpenAI Announced
OpenAI's announcement covers two surfaces. In ChatGPT and Codex, the watermark rolls out to eligible users on every plan, but only in the EU. Through the API, developers anywhere in the world can switch it on for select models from the day of the announcement, with it off by default.
OpenAI was explicit that it is not making text watermarking a global default at launch. That makes this a regional compliance measure, not a change to how ChatGPT behaves everywhere, and it is the main difference from Anthropic's approach, which the company said it is applying worldwide.
The trigger is the EU AI Act's transparency rules, which took effect on 2 August 2026 and require providers to mark AI-generated content in a way other systems can identify. Anthropic, Google, Meta, Microsoft and OpenAI are among the companies that have committed to the EU's code of practice on AI-generated content.
How textGrain Works
OpenAI's technical report, co-written with researchers at the University of Pennsylvania and Yale, describes textGrain as entropy-calibrated watermarking. In plain terms, a secret key is used to sort the model's candidate next words, and the model is gently steered toward one side of that sort when finishing a sentence.
Any single nudge is meaningless. Hundreds of them add up to a pattern a detector holding the key can find using only the text and the key. This is the same family of idea as the green-list scheme published by Kirchenbauer et al. in 2023, which our guide on provenance marks explains step by step.
Because the signal sits in the choice of words rather than in any file attribute, it survives copying, pasting and reformatting. OpenAI also says the watermark does not identify the person who prompted the model, and that it saw no meaningful change in model performance with it switched on.
What OpenAI's Own Tests Say About Editing
OpenAI's robustness figure is the most useful number in the announcement. Replacing 10% of words with synonyms dropped detection from about 92% to 66%. The company also said short passages, math answers and translated text are harder to detect.
That is the expected behaviour of any scheme that lives in word choice: each replaced word is one fewer position carrying the signal. It is also why OpenAI cautions that a missing watermark can mean the text was too short, too heavily edited, or produced by another company's AI.
The unit matters. OpenAI states robustness as a share of words changed, so WatermarkRemoverPro's rewrite now reports the same unit on every result: the percentage of your original words that did not survive. It is a measure of how much your wording moved, not a measurement of OpenAI's mark, which we cannot read.
Who Can Actually Detect It
For now, almost nobody outside OpenAI. The company is giving initial detector access only to approved researchers and expert organisations, to help evaluate reliability and responsible use. There is no public key and no public detector.
That is consistent with how keyed marks work, and with what we have said about Anthropic's mark: a third-party tool can only test keys it holds. WatermarkRemoverPro holds an open reference key for self-testing and accepts vendor or institution keys through configuration, and every result names the keys it tested. It does not hold OpenAI's, and any tool claiming to detect textGrain without that key is not doing what it says.
What a checker can still do honestly is report an independent, key-free AI-style likelihood, run named statistical tests, and state its own limits. See the guide on the ChatGPT watermark for the full breakdown.
What It Means for Writers and Publishers
If you are in the EU and use ChatGPT, text you copy out may now carry a mark you cannot see. Whether anyone can read it depends on who holds the detector, and today that is a short list.
OpenAI's own caution cuts both ways. A mark can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing or creativity went into it. A clean result is not proof of human authorship, and a detected mark is not proof of a lazy one.
Practically, the evidence that holds up is still process evidence: version history, drafts, notes. A documented check on your exact file, with its limits stated, is supporting material, not a verdict.
| Item | What OpenAI said | What it means |
|---|---|---|
| Where | ChatGPT and Codex in the EU; API opt-in worldwide for select models | Regional by default, not a global default |
| Method | textGrain, a secret-key bias on next-word choice | Signal lives in the words and survives copy-paste |
| 10% synonym replacement | Detection fell from about 92% to 66% | Editing weakens the mark in proportion to words changed |
| Harder cases | Short passages, math answers, translated text | Absence of a mark proves little |
| Detector access | Approved researchers and expert organisations only | No public detector or key exists |
“A watermark tells you a system touched a passage. It tells you nothing about how much of the thinking was yours, which is the question everyone actually wants answered.”
Common pitfalls
- Assuming ChatGPT text everywhere is now watermarked, when the ChatGPT rollout is EU-only and the API mark is opt-in.
- Treating a tool that claims to detect the OpenAI watermark as credible without asking which key it holds.
- Reading a clean result as proof of human authorship, which OpenAI itself says it is not.
- Treating a word-change percentage as a guarantee. It describes your edit, not the outcome of a detector you cannot run.
A detected mark is not proof of authorship, and an absent mark is not proof of human authorship. WatermarkRemoverPro's on-device rewrite can reduce detectable evidence but cannot guarantee defeating a vendor's undisclosed watermark, on any tier.
On WatermarkRemoverPro