OpenAI begins phased rollout of text watermarking for EU rules

OpenAI has outlined a phased text-watermarking programme in response to the EU AI Act. API customers worldwide can now opt in to watermarking for select models, while eligible ChatGPT and Codex text outputs in the European Union will receive an invisible watermark over the coming weeks.
The company is keeping API watermarking off by default and limiting initial access to its detector to approved researchers and expert organizations. OpenAI says this scope reflects both the legal requirement for machine-readable identification of generated text and the current limits of detection technology.
textGrain embeds a statistical signal
OpenAI’s system, called textGrain, changes model word choices to add an invisible statistical signal. Its detector assesses whether a passage contains an OpenAI watermark. The company plans to update its technical report with more detail and says it intends to release the technology as open source.
In evaluations, OpenAI said textGrain matched or exceeded other approaches it tested, including SynthID for text. The company also said watermarking did not produce meaningful performance differences across the benchmarks it uses for Astra, its latest frontier model. For example, the Artificial Analysis Intelligence Index result was 49.57 points without watermarking and 49.76 with it.
Detection depends on length, content and editing
OpenAI cautioned that strong performance in controlled tests does not ensure reliable results in routine use. At a target false-positive rate of 1%, its detector found watermarks in about 80% of 200-token passages and about 95% of 400-token passages for material such as psychology. Detection was substantially lower for mathematics, where there is less flexibility in word choice.
Editing can also weaken the signal sharply. In tests of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% reduced it to 17%. Short passages, translations, content from unsupported models and material created before watermarking may likewise fail to produce a detectable result.
Provenance is not proof of authorship or accuracy
A detected watermark can indicate that an OpenAI system generated or processed part of a passage, but it does not quantify human contribution. It does not establish ownership, legality, responsibility, the identity of a user, account, prompt or conversation, and it does not determine whether the text is accurate or harmful.
OpenAI will report only whether its detector finds an OpenAI watermark; it will not reveal users, prompts or conversations. The company is also working with cloud partners to extend watermarking to OpenAI model outputs accessed through their services.
The text effort sits within OpenAI’s broader provenance programme, which includes Content Credentials for supported images, C2PA conformance, SynthID watermarks for supported images and audio, and verification tools for those media. For businesses, the immediate implication is to treat a text watermark as one limited evidence signal, rather than as a standalone basis for authorship, compliance, accuracy or accountability decisions.

