OpenAI says it will add an invisible watermark to eligible text and code produced by ChatGPT and Codex in the European Union, a move designed to meet the EU’s incoming generative-AI transparency requirements. The system, called textGrain, is intended to let an authorized detector identify whether material carries a statistical signal associated with AI output.
This is not a visible label pasted at the top of a response, a signature in a code comment, or a record that tells a reader who used a tool. It is a machine-readable signal embedded through the model’s selections among possible words. The distinction matters: textGrain is meant to make generated material detectable by a compatible system, rather than make every individual passage instantly obvious to a human reader.
That ambition comes with important limits that OpenAI itself has acknowledged. Detection is less dependable for short text, content involving mathematics, and text that has been edited after generation. The company cites roughly an 80 percent success rate for shorter material, and cautions that strong results in ideal conditions should not be mistaken for guaranteed performance in ordinary use.
What textGrain is designed to do
Generative AI models generally have more than one plausible next word available when writing a response. A statistical watermark works by making carefully controlled choices among those plausible alternatives. Across a sufficiently substantial piece of output, those choices can form a pattern that a detector is trained to recognize.
In practical terms, the watermark is not a secret sentence hidden between the lines. It is a pattern in word-choice probabilities. That is why OpenAI describes textGrain as adding an invisible statistical signal to a model’s word choices. A compatible detector examines the output and determines whether the pattern is present at a meaningful level.
This approach has an immediate advantage over a conspicuous disclaimer: it can travel with the generated wording without changing the presentation for ordinary readers. But it also creates a different challenge. The detector needs enough relevant text to separate a real watermark signal from normal variation in language. Very short answers simply offer less material from which to draw a confident conclusion.
OpenAI says textGrain matched or exceeded the performance of alternative approaches, including SynthID for text, in its evaluations. That comparison should be read carefully. It describes comparative performance in the company’s testing, not a promise that the system can reliably resolve every real-world dispute over authorship or AI use.
Why the EU rollout is different
The default position described by OpenAI is narrow. Watermarking will not be switched on by default across all output everywhere. The stated exception is eligible ChatGPT and Codex text output in the European Union. Customers elsewhere may be able to opt in for select models, although the company has not said which models will be offered or when broader choices will arrive.
Codex is particularly notable in this context because the policy applies to code as well as ordinary prose. Code can be brief, heavily revised, reformatted, merged with human-written work, or composed largely of mathematical and symbolic notation. Those are exactly the kinds of conditions that make a text-based statistical signal more complicated to detect or interpret. The announcement establishes the direction of travel, but it does not claim that every code snippet will remain identifiable after ordinary development work.
The EU-specific implementation is tied to Article 50 of the EU AI Act. That provision requires providers of generative AI systems to make generated text identifiable in a machine-readable way. New companies entering the market are already covered, while pre-existing organizations have until December 2 to comply. The obligation reaches beyond one AI provider: established firms including Anthropic, Microsoft, Google and Meta are among the companies affected by the same broader regulatory framework.
Anthropic made a comparable move earlier in the year. The growing adoption of watermarking reflects a regulatory demand for a technical means of identification, rather than evidence that the industry has solved the much larger question of proving exactly how any given document was made.
A detector is not an authorship verdict
The most useful way to understand textGrain is as a signal for review, not an all-purpose lie detector. A detector may indicate that text contains a watermark, but the system is not described as identifying a user, exposing a prompt, or revealing a conversation. OpenAI says its detector will not provide any of those things.
That limitation is significant for schools, workplaces, game communities, publishers, and moderation teams. If a detector finds a watermark, it may establish that a particular eligible model’s output contributed to the text being examined. It does not, by itself, establish intent, the proportion of material written by a person, whether permissible assistance was involved, or who submitted the final document.
Conversely, a failure to find a watermark should not be treated as proof that no AI was used. The signal may be absent because the content came from a non-watermarked system, because it was created outside the eligible EU scenario, because there was not enough text, or because editing reduced detection performance. That asymmetry is central: a positive result and a negative result have different meanings, and neither should be stretched beyond the technology’s stated scope.
The same caution applies to automated enforcement. A system that flags suspicious output can be useful for prioritizing a closer look, but it should not be confused with a machine that has independently determined wrongdoing. That distinction is also relevant in gaming contexts, where detection tools are often discussed as if their results settle every question; as with a recent tool built to flag suspicious in-game gold, a flag is not the same thing as a final judgment.
The weak points are part of the story
OpenAI’s disclosed caveats are not minor footnotes. They explain the practical boundary of this sort of watermarking.
- Short outputs: A small amount of text gives the detector less statistical evidence. OpenAI places the success rate for short text at around 80 percent, which means meaningful uncertainty remains.
- Mathematics: Mathematical material has constrained notation and fewer natural language choices. A watermark based on word selection has less room to operate in such content.
- Editing: Revision can weaken the pattern. Rephrasing, trimming, restructuring, or mixing output with other writing may all affect the detector’s ability to spot the original signal.
- Coverage: The initial default deployment concerns eligible ChatGPT and Codex output in the EU, not an assertion that all AI text on the internet will carry the same marker.
These constraints do not make the system pointless. Machine-readable identification can still offer a useful compliance mechanism and an additional clue in situations where provenance matters. The problem would come from expecting it to perform a job it does not claim to perform: delivering flawless detection across every language, document length, format, revision history, and AI platform.
Restricted access and an open-source goal
OpenAI plans to make the watermarking technology available in open source, which could give outside parties the opportunity to inspect, adapt, and improve the underlying approach. At the same time, access to the detection software will initially be restricted to approved researchers and expert organizations.
Those two choices point in different but compatible directions. Open-sourcing the watermarking technology could encourage scrutiny and technical development. Restricting detector access, at least initially, may reduce the immediate risk of widespread misuse or attempts to optimize around a publicly accessible detection service. The announcement does not provide a timetable for either broader detector access or the planned open-source release, so those details remain unresolved.
For ordinary users, the immediate takeaway is modest. EU users receiving eligible ChatGPT or Codex text may be using output that contains an invisible, machine-readable signal. They should not assume the watermark will survive every edit, nor assume a detector can reconstruct private prompts, identify the account behind the output, or provide a complete history of how a finished document was assembled.
For organizations, the sensible interpretation is equally measured: treat a watermark result as one relevant technical indicator, build review processes that account for uncertainty, and avoid converting a probabilistic detection tool into an automatic penalty system. Article 50 asks providers to make outputs identifiable in a machine-readable form. textGrain is OpenAI’s proposed answer to that requirement—not a definitive solution to every question of AI provenance.







