OpenAI starts opt-in text watermarking as it prepares an EU ChatGPT rollout

OpenAI is rolling out textGrain watermarking in the EU and as an opt-in API feature, while warning that detection cannot prove authorship or accuracy.

Mason Reed

OpenAI has started offering opt-in text watermarking to API customers around the world and says eligible ChatGPT and Codex text in the European Union will gain an invisible watermark over the coming weeks.

The October 5 change is part of OpenAI’s response to the EU AI Act’s transparency requirements for generated text. It is also a useful reminder that a watermark is a provenance signal, not a digital lie detector or a reliable answer to the question “who wrote this?”

API customers can opt in now

OpenAI says global API customers can enable text watermarking for select models starting October 5. It remains off by default in the API, so the change does not silently apply to every API response.

For ChatGPT and Codex, the initial product rollout is narrower. OpenAI says eligible text generated in the EU will receive an invisible watermark over the coming weeks, across eligible plans. The company is not making text watermarking a global default at launch.

OpenAI calls the technology textGrain. Rather than inserting visible labels or hidden characters, it changes the statistical pattern of word or token choices so a detector can look for a signal across a passage.

The Verge reports that the EU rollout is tied to AI Act compliance and notes that detection is not guaranteed, particularly after editing or in text where there is limited room for varied wording.

Detection access is deliberately restricted

OpenAI is also opening applications for access to its text-watermark detector, but the detector is not being released as a general public tool at launch.

Access will initially be limited to approved researchers and expert organisations. OpenAI says the detector can report whether it detects an OpenAI watermark without identifying the user or exposing prompts and conversations.

That restricted rollout matters because the company acknowledges both missed detections and false positives. A public detector that people treated as definitive could easily turn an imperfect technical signal into an accusation about authorship.

A watermark proves much less than it sounds like

OpenAI is explicit about the limits. A detected watermark does not identify the person who used the model. It does not reveal how much human editing happened afterwards. It does not establish ownership, responsibility or whether the text is factually correct.

The reverse is equally important: failing to detect a watermark does not prove that a human wrote the text. The passage may have been substantially rewritten or translated, may be too short for reliable detection, may come from an unsupported model, or may predate the watermarking system.

OpenAI’s existing public verification tools for supported images and audio are not being withdrawn; the restricted-access rule applies specifically to the new text detector.

For users and organisations, the practical takeaway is less dramatic than “AI text can now be identified.” OpenAI is adding another machine-readable provenance signal, beginning with opt-in API use and a regional ChatGPT/Codex rollout. The company’s own documentation says that signal should be treated as evidence with limits, not proof of authorship.

Sources

More from Xarmo News