TLDR
- OpenAI is deploying textGrain, an invisible watermarking system, for ChatGPT and Codex content across EU territories.
- The deployment fulfills transparency obligations mandated by the European Union’s AI Act.
- Internal testing reveals that replacing just 25% of words with synonyms reduces detection success to merely 17%.
- Access to the detection tool remains limited to vetted researchers and specialized institutions.
- While mandatory only in the EU, API users globally can enable the watermarking feature through settings.
On October 5, OpenAI revealed plans to implement an invisible watermarking mechanism for ChatGPT and Codex-generated content throughout the European Union. The initiative directly addresses compliance obligations outlined in the EU AI Act’s transparency provisions.
The watermarking technology, known as textGrain, operates by subtly influencing the language model’s lexical selections to embed a concealed statistical signature.
A companion detection application scans written material for this embedded pattern. According to OpenAI, the approach introduces no concealed characters, imperceptible spacing, or irregular punctuation marks.
This design choice means traditional evasion techniques, such as removing hidden characters from documents, prove ineffective against the watermark. The identifier exists within the actual word selection pattern rather than as discrete hidden elements.
Watermark Detection Rates and Limitations
The system’s effectiveness varies significantly based on content length. OpenAI measures content in tokensālinguistic fragments processed by AI systems. Approximately four tokens equal three English words.
During internal evaluations, the detector successfully identified approximately 66% of unmodified responses containing roughly 150 words. When content length increased to around 300 words, identification rates improved to approximately 92%.
However, even minor modifications dramatically compromise watermark integrity. For 300-word samples, substituting just 10% of words with synonyms reduced detection accuracy from 92% to 66%.
When researchers replaced 25% of words, detection plummeted to a mere 17%. OpenAI’s published data demonstrates clear vulnerability when text undergoes editing, condensation, or reformulation.
The organization also noted that watermark implementation produced minimal impact on performance benchmarks for its newest model, GPT-6 Astra.
Limited Detector Availability Raises Questions
Rather than making the detection tool publicly available, OpenAI plans to distribute access exclusively to vetted research institutions and specialized organizations.
According to the company, a positive identification reveals nothing about user identity, input prompts, or conversation details.
Conversely, negative results carry little evidentiary weight. Brief content, modified passages, or translated material can evade detection without triggering alerts.
Content generated by competing AI platforms will not activate the system, as it exclusively identifies OpenAI’s proprietary signature. The company explicitly stated that watermark absence cannot definitively establish human authorship.
Visual and audio content follows different protocols. Users can already submit these file types to OpenAI’s publicly accessible verification platform to check for its SynthID watermark.
For users outside European Union jurisdictions, ChatGPT watermarking remains disabled by default. However, API customers worldwide can activate the feature for supported models through project or organizational configuration panels.
The implementation follows the EU’s enforcement of AI Act transparency requirements that began in August. OpenAI positioned the watermark as an element of its continuing compliance response.
The announcement also referenced broader security trends. Research from TRM Labs indicates criminal exploitation of AI systems increased 40% year-over-year.
OpenAI has not announced whether or when the detection tool will become available to general users. Currently, EU deployment and restricted researcher access represent the full scope of the program.





