Back to Global Impact

OpenAI will add an invisible watermark to ChatGPT's text in the EU to meet new AI rules

OpenAI illustration of a picture frame with a check mark, titled "Advancing content provenance for a safer, more transparent AI ecosystem"
Illustration: OpenAI

OpenAI says that over the coming weeks it will put an invisible watermark in text that ChatGPT and Codex write for users in the European Union, to meet an EU AI Act rule that AI-made text be identifiable by machines. At first only approved researchers and expert organizations can use the tool that detects it. OpenAI's own tests show that editing the text can weaken the mark sharply, and it is not yet clear how EU regulators will judge that.

OpenAI said on Monday, Oct. 5, that over the coming weeks it will add an invisible watermark to the text that ChatGPT and Codex write for eligible users on every plan in the European Union. The EU's AI Act requires companies that build generative AI to make the text it produces identifiable by machines, and the European Commission says those rules have applied since Aug. 2, 2026. For now, OpenAI is not making the watermark a default anywhere else.

The watermark, which OpenAI calls textGrain, is a hidden statistical pattern in the words the AI chooses. A reader cannot see it, but OpenAI's detector can look for it and judge whether a passage carries the mark. Since Monday, businesses and developers that use OpenAI's API, a connection that lets developers plug a service into their own apps, can switch watermarking on for some models anywhere in the world; it stays off unless they do. OpenAI says the watermark made no meaningful difference to the quality of answers from Astra, its newest model, in its own tests.

OpenAI says text watermarking is still an early technology with significant limitations. In its tests, set so that about 1 in 100 unmarked passages would be wrongly flagged, the detector found the watermark in about 80 percent of shorter passages on topics such as psychology, and about 95 percent of passages twice as long. It did much worse on math answers, where there are fewer ways to word things. Editing weakened it further. In longer passages, swapping one word in ten for a synonym cut detection from about 92 percent to 66 percent, and swapping a quarter of the words cut it to 17 percent.

Because of those gaps, OpenAI will not release the detector to the public at first. Researchers and expert organizations can apply for access now, and OpenAI will grant it case by case, which it says follows the EU's Code of Practice on marking AI-made content. The Commission says that code was drawn up by independent experts and is voluntary, though the marking rules themselves are law, and about 190 organizations had signed it by the end of July. Companies that sign it can point to it to show they follow the law; those that do not must show national regulators that their own methods are good enough. OpenAI's post does not say whether it has signed. The detector will say whether it finds a watermark without identifying the user or revealing their conversations.

OpenAI also warns that a watermark cannot show how much a person contributed, who owns the text or whether it is accurate. Finding no watermark does not prove a person wrote something, the company says, since the text may be too short, edited, translated or made with another company's tools.

It is not yet clear how EU regulators will judge a mark that rewording can weaken this much, or when people outside the research program will be able to check text themselves. OpenAI has not said which users or answers count as eligible. OpenAI says it plans to release the technology as open source and will revisit its approach as standards and evidence change.

More on OpenAI