OpenAI announced on Monday that it will begin adding invisible watermarks to text generated by ChatGPT and Codex within the European Union. The move is a direct response to the transparency requirements of the EU AI Act, which took effect on August 2. The company stated in a blog post that the feature will roll out over the coming weeks to eligible users on all plans in the region.
How the OpenAI watermark works
The watermark is not a visible symbol or a hidden tag attached to the file. Instead, it operates by subtly shaping the model’s word choices. This creates a statistical pattern that is invisible to human readers but detectable by specialized software. Because the pattern is embedded in the text itself, it remains present even if the content is copied and pasted into another document or application.

OpenAI clarified that the watermark does not identify the specific user who requested the text. The company also reported that enabling the feature caused no meaningful change in the performance of its models. Alongside the announcement, OpenAI published a technical report detailing the method, which it calls textGrain. The report, co-written with researchers from the University of Pennsylvania and Yale, explains how a secret key is used to sort next-word predictions to finish a sentence. When hundreds of these small nudges are combined, a detector can identify AI-generated content using only the text and the key.
Limitations and detector access
OpenAI acknowledged that the watermark is not foolproof. In internal tests, replacing just 10% of words with synonyms dropped the detection rate from approximately 92% to 66%. The company also noted that short passages, mathematical answers, and translated text are harder to detect reliably. Consequently, OpenAI is restricting initial access to its detector to approved researchers and expert organizations. These groups will help evaluate the reliability of the tool and identify responsible uses.

The company cautioned that the absence of a watermark does not prove that a text was written by a human. A passage might be too short to trigger detection, heavily edited by a user, or generated by a different AI company. “Watermarks can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it,” the company said.
Developers using OpenAI’s API anywhere in the world can enable the watermark for select models starting today, though it is turned off by default. OpenAI stated it is not making text watermarking a global default at this launch. This decision follows a similar move by Anthropic, which began watermarking text generated by its Claude model worldwide two months ago. That decision drew backlash from some users who argued they provided the instructions and context, making Claude merely a tool.

OpenAI had previously built a text watermark but delayed its release. Reports from 2024 suggested the company held back partly due to concerns that users might switch to rival services that did not watermark their outputs. Major tech firms including Anthropic, Google, Meta, and Microsoft have committed to following the EU’s code of practice on AI-generated content.
Source: TechCrunch

