OpenAI Ships textGrain to Invisibly Watermark AI Text for EU Compliance

OpenAI is rolling out textGrain, an invisible statistical watermark for ChatGPT and Codex output in the EU, with opt-in API access worldwide.

·
·
·
OpenAI Ships textGrain to Invisibly Watermark AI Text for EU Compliance
  • OpenAI launches textGrain, an invisible statistical watermark for ChatGPT and Codex, driven by EU AI Act Article 50.
  • EU ChatGPT and Codex users get watermarked output in coming weeks; global API customers can opt in today, off by default.
  • Detection hits ~95% on 400-token passages but drops to 17% after replacing 25% of words with synonyms.
  • Benchmarks on Astra show no meaningful quality or speed difference between watermarked and unwatermarked output.
  • Detector access limited to approved researchers via an application form; OpenAI plans to open-source textGrain later.
  • Follows Anthropic's August 2026 SynthID-Text rollout for Claude, making watermarking a de facto industry standard in the EU.

OpenAI brings text watermarking to its API and EU products

OpenAI will begin deploying textGrain, a text-watermarking system that embeds an invisible statistical pattern in model output. A dedicated detector can analyze that pattern and estimate whether a passage came from an OpenAI model.

The rollout responds to Article 50 of the EU AI Act, which requires generative AI providers to mark synthetic output in a machine-readable format. TextGrain gives developers a low-cost provenance control, although OpenAI’s tests show that paraphrasing, translation, short passages, code, and formal text can weaken or erase the signal.

Rollout starts with opt-in access

  • Global API access: Beginning October 5, 2026, API customers worldwide can enable watermarking for select models. The setting remains off by default.
  • EU product rollout: OpenAI plans to add watermarking for eligible ChatGPT and Codex users across all plans in the European Union. The company gave no exact launch date, describing the timing as “the coming weeks.”
  • Restricted detector: Access will initially be granted case by case under the EU Code of Practice on AI-generated content. OpenAI cites the risks of false positives and missed watermarks.
  • Cloud support: OpenAI is working with cloud partners to watermark model output delivered through their services.
  • Future open source release: OpenAI says it intends to publish the technology eventually, without committing to a date.

OpenAI will offer watermarking as a no-cost toggle, with existing API pricing unchanged. Coverage depends on model eligibility, and the announcement describes API support only as applying to “select models.”

Sampling carries the watermark

TextGrain embeds its signal through the model’s ordinary token choices. During generation, the sampler slightly favors selected words or word pieces among several plausible options, producing a statistical pattern that the detector can measure across a passage.

The technical paper describes the method as entropy-calibrated. In plain terms, the system applies a stronger bias when the model has many plausible next tokens and reduces the bias when wording is constrained. Free-form prose provides more opportunities to encode the pattern than mathematics, code, tables, or other structured output.

Quality shifts stay small

In tests of Astra, OpenAI reports no meaningful overall quality loss from watermarking. Scores moved in mixed directions across the company’s benchmark suite, with no consistent decline:

OpenAI’s reported Astra benchmark scores. Delta is watermarked minus unwatermarked; “pp” means percentage points.
Benchmark Unwatermarked Watermarked Delta
Artificial Analysis Intelligence Index 49.57 49.76 +0.19
GPQA Diamond 94.44% 93.94% -0.50 pp
Terminal-Bench 4.0 53.90% 56.06% +2.16 pp
DeepSWE v1.1 72.80% 71.68% -1.12 pp
HealthBench Professional 64.27% 64.60% +0.33 pp

Detection needs length and flexibility

At a threshold calibrated for a 1% false-positive rate, roughly one unwatermarked passage in 100 could trigger the detector under test conditions. For flexible content such as psychology prose, OpenAI recovered the watermark in about 80% of 200-token passages and about 95% of 400-token passages.

Detection rates were substantially lower for mathematics, where rigid notation and limited wording leave fewer choices for encoding a signal. The same constraint applies to Codex output: short snippets, repetitive syntax, configuration files, and formal code provide little statistical room for a reliable watermark.

Edits can erase the pattern

OpenAI’s evaluation found that modest rewriting sharply reduced detection. In 400-token passages, replacing 10% of words with synonyms lowered detection from about 92% to 66%. Replacing 25% lowered it to 17%, while translation could remove the signal entirely.

Paraphrasing with another language model can produce similar results, making textGrain unsuitable as standalone forensic evidence. These failure modes also explain OpenAI’s restricted detector access and its caution around high-stakes attribution.

A detector result has narrow meaning

  • Positive result: The passage contains a statistical pattern consistent with watermarked OpenAI output at the detector’s configured threshold.
  • Attribution: The detector reveals no user, account, prompt, author, owner, or responsible party.
  • Accuracy: Detection provides no evidence that the passage is factual or trustworthy.
  • Negative result: The finding remains inconclusive because short, edited, translated, structured, or older output may evade detection.

Google and Anthropic chose similar methods

OpenAI joins Google and Anthropic in deploying statistical text watermarks. Anthropic announced in August 2026 that new Claude models would embed an invisible watermark derived from SynthID-Text, with detector access initially limited to regulators, researchers, media organizations, and other eligible groups.

Google already uses SynthID-Text in Gemini. Its evaluation of nearly 20 million watermarked and unwatermarked responses found no statistically significant quality difference. Across all three systems, paraphrasing and translation remain central technical limitations.

Article 50 explains the common direction: providers need a machine-readable way to identify synthetic output. Statistical watermarking can satisfy that operational requirement in cooperating pipelines, while real-world robustness depends on preserving the original wording.

Best fit: intact prose pipelines

Use case Practical guidance Reason
EU-facing API output Use watermarking as one control in a broader transparency program. It adds machine-readable provenance with no reported pricing change.
Long-form publishing workflows Preserve the original text until verification is complete. Longer, flexible prose produces stronger detection rates.
Code and mathematical output Treat detector results as weak supporting evidence. Constrained syntax leaves little room to encode the signal.
Translated or paraphrased content Expect low detection reliability. Rewording can sharply reduce or erase the watermark.
Academic, employment, or enforcement decisions Require independent corroborating evidence. The detector cannot establish authorship, intent, or responsibility.

Teams enabling textGrain should record the model version and watermark setting, retain original output for audits, and avoid translation or paraphrasing before verification. They also need approved detector access, since downstream parties cannot independently test the watermark at launch.

Trending
  • No trending articles

Comments

avatar

Next Reads