On October 5, OpenAI announced that ChatGPT and Codex will start putting an invisible watermark in the text they write, beginning in the European Union. It’s called textGrain. It is not a visible label, it doesn’t add hidden characters, and nobody can check your text for it yet, because the detector is not public.
The headlines made it sound like every ChatGPT answer on Earth is now fingerprinted. That’s not what OpenAI said. This post walks through what the company actually announced, who is affected, whether your own writing is marked, how easily the mark disappears (OpenAI published the numbers itself), and what a sensible person should do about it, whether you’re a student, a writer, a job-seeker or someone who just uses ChatGPT for work emails.
I built this from OpenAI’s announcement and its Help Center article, TechCrunch’s coverage, a Perplexity deep-research pass that read several hundred sources including the EU AI Act text and academic watermark studies, and two rounds of reaction on X. Where something is confirmed, I’ll say so. Where OpenAI hasn’t said, I’ll say that too, because a lot of what’s circulating online is guesswork stated as fact.
What textGrain actually is
A watermark in text sounds like it should be something you can see or select. This isn’t. OpenAI’s Help Center describes it as “an invisible change to the randomness used in the model’s word choices.”
Here’s the plain-English version. When ChatGPT writes a sentence, it’s constantly choosing between words that would all work. “Begin” or “start.” “Big” or “large.” “However” or “But.” Most of those choices are close to a coin flip. textGrain nudges those coin flips using a secret key, so that across a few hundred words the choices form a statistical pattern. A detector that knows the key can look for the pattern. A human reader sees ordinary text.
Three things follow from that design, and they explain almost everything else in this post:
- The mark lives in the wording, not in hidden characters. OpenAI’s Help Center says it doesn’t add hidden characters, invisible spaces or unusual punctuation. So copy-pasting the text into Word or Google Docs doesn’t strip it, and a “remove invisible characters” tool does nothing.
- It needs length. One short sentence has too few word choices to build a pattern. A few hundred words has plenty.
- Changing the words changes the evidence. If you rewrite the passage, you’re replacing the very choices the pattern is made of.
Images and audio from OpenAI already carry watermarks (SynthID, from Google DeepMind) and Content Credentials metadata, and OpenAI runs a public checker at openai.com/verify for those. Text is the new addition, and it’s the first one where the checker is deliberately not public.
What OpenAI announced on October 5 (the confirmed facts)
Everything in this table comes from OpenAI’s own announcement page and Help Center article, with TechCrunch’s report as a cross-check.
| Question | What OpenAI said |
|---|---|
| Who gets watermarked text by default? | “Eligible ChatGPT and Codex text output in the European Union” (across all plans) |
| When? | “Over the coming weeks.” No exact date. It may not be live in your account today |
| Is it global? | No. OpenAI says it is “not making text watermarking a global default at launch” |
| What about the API? | Developers anywhere can opt in for “select models,” starting October 5. Off by default |
| Where’s the API switch? | In project or organization settings, per the Help Center |
| Can I check text for it? | Not yet. Detector access is limited to “approved researchers and expert organizations” who apply |
| Does it identify me? | No. OpenAI says it doesn’t link text to a person, account, prompt or conversation |
| Does it hurt quality? | OpenAI reports no meaningful difference on its benchmarks (examples below) |
| Will it be open source? | OpenAI says it plans to release the technology as open source |
| Why now? | EU AI Act transparency rules, which became applicable August 2, 2026 |
A few details worth pausing on.
It’s EU-only for ChatGPT. OpenAI’s phrase is that it is “not making text watermarking a global default at launch” and that the regional approach “gives us room to learn from real-world use and feedback.” If you open ChatGPT in the US, nothing in the announcement says your text gets marked by default. The exception is text produced through an app built on OpenAI’s API by a developer who turned the option on.
The detector isn’t a product. OpenAI is accepting applications from researchers and organizations that can help evaluate it. The Help Center names some partners already working with it: John Thickstun (Cornell), Martin Vechev (ETH Zurich and INSAIT) and researchers at the Kempelen Institute. A teacher, an editor, an HR department or a curious student cannot run a check today.
OpenAI published the weak spots itself. That’s unusual and worth giving credit for. It also means we don’t have to guess how fragile the mark is.
How well does it work? OpenAI’s own numbers
OpenAI tested textGrain at a target false positive rate of 1%, meaning the detector is tuned so that it wrongly flags unmarked text about 1% of the time. At that setting:
- Around 95% of 400-token passages (roughly 300 words) were detected for content like psychology answers.
- Around 80% of 200-token passages (roughly 150 words) were detected.
- For mathematics, where there’s little freedom in word choice, detection was “substantially lower.” Reading the chart OpenAI published, the math line runs from roughly 37% at 200 tokens to roughly 61% at 400.
Then comes the part that matters for anyone who edits their writing, which is nearly everyone. In a test on 400-token passages:
- Unedited: about 92% detected.
- Replace 10% of the words with synonyms: detection drops to about 66%.
- Replace 25% of the words: detection drops to about 17%.
OpenAI also says translated text is harder to detect and that substantial paraphrasing can make the watermark undetectable, though it didn’t publish a number for translation. A widely shared post on X made the same point: nobody has given a translation figure yet.
On quality, OpenAI compared its newest model (Astra) with and without the watermark across several benchmarks. A few examples from its table: the Artificial Analysis Intelligence Index scored 49.57 unwatermarked and 49.76 watermarked; GPQA Diamond scored 94.44% versus 93.94%; BrowseComp scored 87.92% versus 87.35%. Differences of that size move in both directions, which is what “no meaningful difference” looks like in practice.
One more claim worth noting, because people will repeat it: OpenAI says that in its tests textGrain “matched or exceeded” other approaches it tried, including SynthID for text. That is OpenAI’s own evaluation. TechCrunch reported the same. No independent group had published a test of textGrain at the time of writing, the day after launch.
The worked example: what this means for one real piece of writing
Numbers like “92%” and “66%” are slippery, so let’s carry one ordinary document through them. Take a 300-word cover letter. At the usual rule of thumb of about 0.75 words per token, that’s roughly 400 tokens, exactly the size OpenAI tested.
Scenario A: you paste ChatGPT’s draft in unchanged. In OpenAI’s test, a detector would flag about 92 out of 100 such passages. For this letter, the chance of detection is high, if someone had access to a detector, which almost nobody does.
Scenario B: you swap about one word in ten. That’s roughly 30 words in a 300-word letter. Detection falls to about 66 out of 100. You’ve done real editing, and the signal is still more likely than not to be present.
Scenario C: you rewrite about one word in four. Roughly 75 words. Detection falls to about 17 out of 100. Most people who “make it sound like me” change at least this much.
Scenario D: you write the letter yourself, then ask ChatGPT only to fix three commas. Here the headline numbers don’t apply at all. The model returned your text with light edits, so very little of the wording came from its random choices. OpenAI’s own Help Center cautions that a watermark “does not indicate the extent to which an OpenAI model was involved.” It can say a model processed text. It cannot say who did the thinking.
Now the flip side, which is the fairness problem that worries people most. OpenAI’s detector is tuned to wrongly flag unmarked text about 1% of the time. If a department ever ran 300 genuinely handwritten essays through a detector like that, it would expect around three false alarms (1% of 300). Three students accused of something they didn’t do. That’s why OpenAI says in its announcement that, given “the risk of missed watermarks and false positives,” it isn’t releasing the detector publicly, and why no serious reading of this announcement turns a detector hit into proof of misconduct.
How to tell whether your text is marked (a step-by-step)
There’s no checker, so “tell if it’s marked” really means “work out whether it could be.” Here’s the sequence, with what you should see at each step.
Step 1: Ask where the text was generated.
- Through ChatGPT or Codex, with an account used from inside the EU: this is the group OpenAI says will be watermarked “over the coming weeks.”
- Through ChatGPT from the US or elsewhere outside the EU: OpenAI announced no default watermark for you.
- Through an app or website built on OpenAI’s API: marked only if the developer turned it on, and only for “select models.”
- Through Claude, Gemini or another tool: different rules. Anthropic said its Claude watermark applies worldwide to supported new models (we covered it in Is Claude AI Detectable?), and Google’s SynthID is already in Gemini.
Expected result: you can sort most of your recent writing into “could be marked” and “almost certainly not.”
Step 2: Check the timing. OpenAI said “over the coming weeks,” not “today.” Text written before the rollout reaches your account isn’t marked, and OpenAI says text that “predates watermarking” can’t be detected.
Step 3: Check the length. Under about 100 to 150 words, there’s often too little signal to detect. Over 300 words of unedited model output, there’s plenty.
Step 4: Check how much you changed it. If more than a quarter of the words are yours, OpenAI’s own numbers say a detector would catch it only about one time in six. If you only changed punctuation, it’s essentially unchanged.
Step 5: Accept that you can’t verify it, and ignore sites that claim otherwise. Detector access is limited to approved applicants. A website offering to “check your text for the ChatGPT watermark” this week is not using OpenAI’s detector. Treat those like the “watermark remover” tools flooding search results: nothing you can verify is happening behind the button.
Why the EU, and what the law actually requires
The reason this is happening is a single article of the EU AI Act.
Article 50(2) requires providers of generative AI systems to mark synthetic output (text, images, audio, video) in a machine-readable way, so it can be detected as artificially generated. Article 50 became generally applicable on August 2, 2026. There’s an exception for systems that perform “standard assistive editing” or don’t substantially change the input they receive, which is part of why text that you wrote and the model only lightly edited is a gray zone.
Two dates are worth knowing:
- August 2, 2026: Article 50 applies. New systems were expected to launch with marking built in. This is why Anthropic switched on its Claude watermark that day.
- December 2, 2026: a transition the EU’s “Digital Omnibus” package added for the machine-readable marking duty only, for generative systems already on the market before August 2. That’s the legal runway that explains OpenAI rolling textGrain out “over the coming weeks” rather than overnight.
On top of the law sits a voluntary Code of Practice on Transparency of AI-Generated Content, published by the European Commission on June 10, 2026. The Commission published a first list of around 190 signatories on July 31, including OpenAI, Anthropic, Google, Microsoft, Meta and Mistral. OpenAI’s Help Center says its text watermarking is “in line with our commitments under the EU Code of Practice.”
Two things this does not do. It doesn’t require every AI-assisted document to carry a visible “written by AI” banner. And it doesn’t make a watermark hit legal proof that a student cheated or a candidate lied. Those are separate questions that schools and employers answer with their own rules.
textGrain, Claude and Gemini side by side
All three big assistants now use a version of the same idea, but they differ on who gets it and who can check it.
| OpenAI (ChatGPT, Codex) | Anthropic (Claude) | Google (Gemini) | |
|---|---|---|---|
| Technique | textGrain (statistical watermark in word choices) | A version of Google’s SynthID-Text, per Anthropic | SynthID-Text |
| Where it applies | EU ChatGPT and Codex by default, “coming weeks”; API opt-in worldwide | Worldwide on supported new models, from August 2 | Already deployed in Gemini |
| Default or opt-in | Default in the EU, off by default in the API | On by default | On by default |
| Public detector? | No. Researchers and expert organizations only | A detector API was announced as forthcoming | Google has offered a reference detector to developers |
| Published weak spots | Yes: 92% to 66% to 17% under edits | Anthropic warned presence or absence isn’t proof | Google warns rewriting or translation reduces confidence |
So “OpenAI is now watermarking” is true only in a narrower sense than the posts suggest. Claude’s mark is the more sweeping one. OpenAI’s is the more cautious, regional, and detector-limited one, and it’s the only one where the vendor published edit-robustness numbers on launch day.
What independent research says about the limits
Because textGrain is a day old, there’s no independent test of it yet. But watermarking research is older than this announcement, and the same weaknesses show up across schemes.
- Paraphrasing hurts a lot. In one benchmark (MarkMyWords), a strong paraphrase attack removed the better watermarks about half the time. A 2025 robustness study reported that a single ChatGPT paraphrase pushed all the tested schemes below 30% detection. These studies tested other watermarks, not textGrain, so treat them as evidence about the technique, not the product.
- Long text can fight back. Research from John Thickstun’s group at Cornell reported that even a strong human paraphrase can leave a detectable trace if the document is long enough (on the order of 800 tokens, at a very strict false-positive setting). That’s very different from a 150-word email.
- Attackers can learn the rules. ETH Zurich researchers, including Martin Vechev’s group, showed in “watermark stealing” work that querying a watermarked model can reveal enough about its hidden rules to scrub a mark or fake one, with over 80% average success at a cost under $50 in the tested setups. Faking is the scarier half: if someone can make unrelated text look watermarked, a positive result stops being safe evidence.
- False positives need real calibration. One 2026 preprint reported a 5.4% false-positive rate for its tested SynthID setup, well above a nominal 1%. That’s specific to its corpus and implementation, but it’s a reminder that a vendor’s stated rate isn’t automatically the real-world rate for every language and text type.
- Don’t confuse watermarks with “AI detectors.” The famous finding that detectors wrongly flagged more than 60% of TOEFL essays by non-native English writers was about old statistical classifiers that guess whether writing “sounds like AI.” A keyed watermark works differently, which is why it can in principle be far more precise. But it creates a different fairness issue: if the model rewrote more of a non-native speaker’s draft, more of their text carries the mark, even if both writers followed the same rules.
If you’ve read our guide on whether AI detectors actually work, the short version is that a watermark is a better tool than those classifiers, and still not a lie detector.
What this means for you
Seven situations, each with a recommendation and one concrete first move.
If you’re a student in the EU. Your ChatGPT text may start carrying a mark in the coming weeks, but no school can check it today, and OpenAI says a hit proves only that a model processed the text. The risk isn’t the watermark. It’s presenting model-written work as your own when your course forbids it. First action: reread your course’s AI policy this week and write down what you’re allowed to use AI for, so you’re working from the rules rather than from rumors.
If you’re a student outside the EU. You’re not in the default rollout. Don’t assume that means you’re invisible: Claude and Gemini already mark text, and API-based study apps may opt in. First action: keep dated drafts and notes for anything you submit, the same habit that protects you if a detector ever misfires. Our guide on what to do if you’re falsely accused of using AI has the evidence checklist.
If you’re a teacher or professor. You can’t run this detector, and a hit wouldn’t settle a case anyway. The sturdier move is process: assignments that show thinking over time. First action: use the 15-minute syllabus approach in our AI policy guide for professors and try one prompt that makes an assignment harder to outsource.
If you write for a living (freelancer, marketer, content lead). Clients may ask whether your work is AI-generated. A watermark can’t answer “who did the thinking,” and OpenAI says so itself. First action: decide your disclosure line now (the template in the next section), so you answer calmly rather than defensively.
If you’re a job-seeker. A CV or cover letter made with ChatGPT isn’t legally required to carry a label, no recruiter can check for textGrain today, and edited text mostly sheds the mark anyway. What actually hurts applications is generic, un-edited AI writing, not a hidden pattern. First action: rewrite at least a quarter of your AI-drafted letter in your own words, add one specific story only you can tell, and keep your own draft file. Our ChatGPT résumé prompts show a faster edit workflow.
If you’re a developer or run an app on OpenAI’s API. You get a choice the ChatGPT user doesn’t. The option is off by default and you can turn it on from project or organization settings for supported models. First action: decide whether your product’s users need provenance (compliance, publishers, regulated sectors) and test the option on a staging project before you tell customers anything.
If you publish text to the public or work in HR. In the EU, publishing AI-generated text on matters of public interest can trigger a disclosure duty under Article 50(4), unless a human reviewed it and someone takes editorial responsibility. For HR, the EU’s hiring rules are a separate and bigger deadline (see what moved and what’s live in the EU AI Act hiring rules). First action: write one sentence of editorial responsibility into your process, and never reject a candidate on a watermark result alone.
A simple disclosure and process template
The healthiest response to watermarks isn’t fighting them. It’s keeping a clean record of how you used AI, so a detector result, right or wrong, never has to be your only evidence. Copy this and adapt it.
AI-use note (keep with the final file)
Document: [title]
Date: [date]
Tool(s) used: [ChatGPT / Claude / Gemini / none]
What AI did: [brainstormed outline | fixed grammar | drafted sections 2 and 4 | translated | none]
What I did myself: [ideas, structure, examples, final edits, fact-checking]
Where the drafts live: [Google Docs version history / Word file / folder path]
Sources I checked myself: [list]
Save it in the same folder as your drafts. If anyone ever asks, you can show a dated process trail instead of arguing about a statistic.
Edge cases and troubleshooting
These are the questions and problems people were actually raising in the first 24 hours.
“Can I avoid it with a VPN?” Plenty of people asked. OpenAI hasn’t said how it decides who counts as being in the EU, and the only answers circulating are an AI chatbot’s guess that it’s probably location-based. Don’t plan around that. Even if it worked, OpenAI says the regional approach is temporary, “we expect to revisit each part of this approach.” And dodging the mark doesn’t change your school’s or employer’s rules.
“Does text I wrote and only had ChatGPT polish carry the mark?” Possibly, in part. A model that rewrites your sentences uses its own word choices for those sentences. But OpenAI says a hit says nothing about how much a human contributed, which is why “I wrote it and asked for grammar fixes” can look the same as “ChatGPT wrote it” in a detector’s eyes. If that distinction matters to you, the AI-use note above is how you prove it.
“Does copy-pasting into Word or Google Docs remove it?” No. The mark is in the word choices, not in invisible characters. The Help Center lists copy and paste among the changes textGrain is designed to survive. Retyping every sentence in your own words is what weakens it, because it replaces the choices.
“What about translating the text?” OpenAI says translated text is harder to detect and that translation can make the watermark undetectable. It hasn’t published how much. Treat “translated, therefore unmarked” as likely but unproven, and disclose translation help where your rules require it.
“Does it mark code written by Codex?” OpenAI says watermarking covers eligible Codex text, but code has very little wording freedom, and OpenAI’s own chart shows low-flexibility content (like math) is much harder to detect. Expect weak signals in code, stronger ones in comments and documentation. How well it survives a code formatter hasn’t been published.
“A website says it can check my text for the ChatGPT watermark.” It can’t be using OpenAI’s detector, which isn’t public. Treat it as a classifier that guesses, or as a lead-capture page. Don’t paste confidential text into it.
“A ‘humanizer’ or ‘remover’ tool says it strips the watermark.” Some may reduce it, because heavy rewriting does. But you can’t verify the result, and the same rewriting can degrade your text or introduce errors. If your goal is writing that sounds like you, editing it yourself by hand is both the cheaper and the safer route. We cover the honest version in our guide to AI text humanizers.
“My text was flagged by a detector and I wrote it.” Keep calm and ask for specifics: which detector, what threshold, what length, what evidence besides the score. A watermark result is a clue, not a verdict, and OpenAI’s own page says so. Bring your drafts and version history. The steps in falsely accused of using AI apply directly.
What this can’t do
Be clear-eyed about the limits, because they’re the real story.
- It can’t prove a human wrote something. OpenAI is explicit: “the absence of a detected watermark does not prove human authorship.” Text can be too short, edited, translated, from another company’s tool, or from before the rollout.
- It can’t tell you who did the thinking. A watermark doesn’t measure human contribution. A student who drafted every idea and asked for grammar fixes and a student who pasted a prompt look alike.
- It can’t identify you. OpenAI says the watermark doesn’t link text to a person, account, prompt or conversation. A detector tells you whether a mark is present, nothing more.
- It can’t survive determined editing. Replace a quarter of the words and OpenAI’s own detection drops to 17%. Anyone motivated to evade it can.
- It can’t be treated as proof in a dispute. False positives exist (about 1% at the tested setting), spoofing attacks have been demonstrated against other watermark schemes, and the detector isn’t independently validated yet.
What it can do: help platforms and researchers spot large volumes of unedited machine text, such as spam, bot farms and mass-produced posts, where nobody bothers to edit. That’s closer to what regulators are after than catching an individual’s essay.
FAQ
Is ChatGPT watermarking all my text now? No. OpenAI says it will add an invisible watermark to eligible ChatGPT and Codex text in the EU, over the coming weeks. It is not a global default, and API customers worldwide can opt in on select models, off by default.
What is textGrain? It’s OpenAI’s text watermarking method. It subtly adjusts the random choices the model makes between similar words so that a detector with a secret key can later find a statistical pattern. It doesn’t add visible marks or hidden characters.
Can anyone check whether my text has the watermark? Not today. OpenAI is giving detector access only to approved researchers and expert organizations at launch. Websites claiming to check for textGrain aren’t using OpenAI’s detector.
Does the watermark identify me or reveal my prompts? OpenAI says no. The watermark doesn’t link text to a person, organization, account, prompt or conversation, and the detector only reports whether it found an OpenAI watermark.
Can I turn it off? OpenAI’s announcement doesn’t describe a user setting for ChatGPT in the EU. It says that “when possible” it wants to give people a choice, and API customers can switch it on or off in their project or organization settings. Claims that it “can’t be turned off” aren’t something OpenAI’s pages state either way.
Does editing the text remove the watermark? It weakens it. OpenAI’s test on 400-token passages found detection fell from about 92% to about 66% when 10% of words were swapped and to about 17% at 25%. Substantial paraphrasing or translation can make it undetectable.
Will a teacher or employer be able to catch me? Not with OpenAI’s watermark detector, which they can’t access. And even if they could, OpenAI says a result can’t show how much of the text was human, who owns it, or whether any rule was broken.
Is Claude’s watermark different? Yes. Anthropic said its watermark, a version of Google’s SynthID-Text, applies worldwide on supported new Claude models, not only in the EU. OpenAI’s is regional and its detector is limited. Our Claude watermark explainer has the details.
Why is this happening in the EU first? Because Article 50(2) of the EU AI Act, applicable since August 2, 2026, requires providers to mark synthetic text in a machine-readable way. A Digital Omnibus transition runs to December 2, 2026 for systems already on the market, which is why the rollout is phased.
Should I stop using ChatGPT for writing? No. The practical risk isn’t the watermark, it’s pretending AI help was your own work where your rules forbid it. Use AI, edit it so it’s genuinely yours, keep your drafts, and follow your school’s or employer’s policy.
The bottom line
textGrain is a real change, but a smaller and more cautious one than the headlines suggested. ChatGPT and Codex text in the EU will carry an invisible, statistical mark over the coming weeks. Outside the EU you’re not in the default rollout. Nobody outside a small group of approved researchers can check for it. And OpenAI’s own numbers show it fading quickly once text is edited, with detection down to about 17% after a quarter of the words change.
So don’t panic, and don’t try to game it. Understand it, follow the rules you’re actually bound by, and keep a clean trail of how you used AI. A short AI-use note and a folder of dated drafts are worth more than any watermark result, for you or against you.
If you want to use AI at work or school with confidence, our AI Fundamentals course covers what these tools do and don’t do, ChatGPT vs Claude compares the two assistants side by side (including how each handles things like this), and Writing Better with AI shows how to edit AI drafts so they genuinely sound like you.
Sources
- OpenAI, “Our approach to EU text provenance rules” (Oct 5, 2026)
- OpenAI Help Center, “Provenance signals in OpenAI-generated content”
- OpenAI, textGrain technical report: “Entropy-calibrated watermarking for language model text”
- TechCrunch, “OpenAI will start watermarking ChatGPT’s text in the EU” (Oct 5, 2026)
- The Verge, “OpenAI is adding text watermarking in ChatGPT and Codex”
- PCMag, “OpenAI to add watermarks on ChatGPT’s text, but only in the EU”
- European Commission, Code of Practice on Transparency of AI-Generated Content (published June 10, 2026), via Council of Europe summary
- Cloud Security Alliance, EU AI Act Article 50 watermarking deadline note (Dec 2, 2026 transition)
- EU AI Act, Article 50: transparency obligations
- Ars Technica, on Anthropic’s Claude watermark
- The Next Web, Anthropic watermarks Claude output under EU AI Act Article 50
- Google DeepMind, SynthID Text (Nature)
- Jovanović, Staab and Vechev, “Watermark Stealing in Large Language Models” (arXiv)
- Piet et al., “Mark My Words: Analyzing and Evaluating Language Model Watermarks” (arXiv)
- Liang et al., “GPT detectors are biased against non-native English writers” (Patterns, 2023)