What Is an AI Text Watermark? textGrain, SynthID & Claude (2026)

An AI text watermark is an invisible pattern a model leaves in its word choices. How it works, who uses one, and why editing erases it, with real numbers.

TL;DR. An AI text watermark is an invisible statistical pattern a model leaves in its own word choices so a detector holding a secret key can later recognize the text. OpenAI reports 92% detection on unedited 400-token text, falling to 17% after 25% of words change. Caveat: a missing watermark never proves a human wrote it (OpenAI).

Last reviewed: October 6, 2026. Reviewed quarterly.

On October 5, 2026, OpenAI announced that ChatGPT and Codex would start putting an invisible watermark in the text they write, beginning in the European Union. Anthropic had done something similar for Claude two months earlier, and Google has had a version running in Gemini since 2024. Within a day, people were asking whether their cover letters, essays and client emails now carry a fingerprint.

An AI text watermark is an invisible statistical pattern that a language model leaves in its own word choices, so that a detector holding a secret key can later estimate whether a passage came from that model. In plain terms: it isn’t a stamp you can see or a hidden character you can delete. It’s a faint habit in which words the model chooses, and it only shows up if you know the key and the text is long enough. FindSkill.ai tracks it because the same technique is now showing up in the three most-used AI assistants, and most of what’s being said about it online is wrong.

Why AI text watermarks matter now

AI text watermarks matter now because a law pushed every major AI company to ship one within weeks of each other. According to the EU AI Act’s Article 50, providers of generative AI systems must mark synthetic output in a machine-readable way, and the article became generally applicable on August 2, 2026. Search interest followed: Google Ads data pulled through DataForSEO on October 6, 2026 shows “ai watermark” at about 2,400 searches a month and “chatgpt watermark” at about 2,900.

  • June 10, 2026: the European Commission published the voluntary Code of Practice on Transparency of AI-Generated Content, and around 190 organizations, including OpenAI, Anthropic, Google, Microsoft, Meta and Mistral, appeared on the first signatory list, per the Council of Europe’s MERLIN summary.
  • August 2, 2026: Anthropic began watermarking supported new Claude models worldwide, using a version of Google’s SynthID-Text, according to The Next Web.
  • October 5, 2026: OpenAI announced textGrain for ChatGPT and Codex text in the EU, with opt-in for API customers anywhere, according to OpenAI.
  • December 2, 2026: the end of a four-month transition the EU’s Digital Omnibus package gave to generative systems already on the market before August 2, for the machine-readable marking duty only, according to the Cloud Security Alliance.

Here is the part the headlines skip. These watermarks are built to satisfy a compliance rule and to help platforms and researchers spot large volumes of unedited machine text. They were not designed to catch an individual student or job applicant, and the companies say so.

How fast editing erases OpenAI's textGrain watermark
Share of 400-token passages detected at a 1% false-positive rate (OpenAI, October 2026)
%!f(uint64=92)% 46% 0%
92%
Unedited
66%
10% of words swapped
17%
25% of words swapped
Unedited text is detected about 92% of the time. Swap one word in ten and it drops to about 66%. Swap one in four and it is about 17%. Source: OpenAI, Our approach to EU text provenance rules.

How an AI text watermark actually works

An AI text watermark works by nudging the model’s word choices with a secret key while it writes. A language model picks each next word from a list of plausible options. The watermark makes that pick follow a hidden pattern tied to the preceding words and the key. Over a few hundred words, the pattern adds up to a signal a detector can measure.

OpenAI’s Help Center describes textGrain in exactly these terms: it “subtly adjusts how the model randomly chooses between possible words or word pieces as it writes” and “does not add hidden characters, invisible spaces, or unusual punctuation.” That detail matters because it kills two popular myths at once. Copy-pasting does not strip an AI text watermark, and a “remove invisible characters” tool does nothing, because the mark is in the wording itself.

From prompt to detection
Model picks each next word from several plausible options
Secret key nudges the pick a hidden pattern, not a visible mark
Text looks normal no characters added
Detector re-reads the words same key, same pattern test
Score, not proof 'likely from this model'
A statistical text watermark is added while the model writes and checked later with the same secret key.

The technical version: the signal accumulates across many word positions and is strongest where the model had many reasonable choices. It is weakest in short answers, exact facts, mathematics and tightly constrained code, because there is little freedom to nudge. OpenAI’s own chart shows that for mathematics, detection runs from roughly 37% at 200 tokens to roughly 61% at 400, versus about 80% to 95% for psychology answers, according to OpenAI (October 2026). A token is roughly three-quarters of an English word, so 400 tokens is about 300 words.

An AI text watermark also has a built-in false-positive setting. OpenAI evaluated textGrain at a 1% target false-positive rate, which means the detector is tuned to wrongly flag unmarked text about 1 time in 100. Run 300 genuinely human essays through such a detector and you’d expect about three false alarms. That’s one reason OpenAI is not releasing its detector publicly.

What OpenAI, Anthropic and Google actually publish today

The three companies publish different things about their AI text watermark, and the differences decide who is affected. As of October 6, 2026, Claude’s mark is the most widely applied, Gemini’s is the oldest, and OpenAI’s is the narrowest in reach but the most open about its weak spots.

OpenAI (textGrain)Anthropic (Claude)Google (SynthID-Text)
AnnouncedOctober 5, 2026August 2, 20262024 (Nature paper)
Where it appliesChatGPT and Codex text in the EU, “over the coming weeks”; API opt-in worldwide for select modelsSupported new Claude models, worldwideGemini
DefaultOn in the EU, off by default in the APIOnOn
Public detectorNo. Approved researchers and expert organizations onlyAnnounced as forthcomingReference detector offered to developers
Published weak spotsYes: detection numbers under edits and by lengthAnthropic warns a result is not proof of authorshipGoogle says heavy rewriting or translation reduces confidence

Two clarifications. First, OpenAI says it is “not making text watermarking a global default at launch,” so a ChatGPT user in the US is not in the default rollout, per OpenAI’s announcement. Second, OpenAI says it plans to release the technology as open source, which would let others build on it, but it has not given a date. For the Google-specific details, see our guide to SynthID; for the Claude angle, see Is Claude AI Detectable?.

AI text watermark vs AI detector vs C2PA

An AI text watermark, an AI detector and C2PA are three different tools that people constantly confuse. A watermark looks for a hidden pattern a model deliberately inserted. A detector guesses from style. C2PA is a signed record attached to a file. Only the first one can be precise about text, and only for text from a model that applies it.

AI text watermarkAI detectorC2PA Content Credentials
How it worksHidden pattern in word choices, checked with a secret keyStatistical guess from predictability and variationCryptographically signed metadata about a file’s origin
Works onText from models that apply a watermarkAny text, with errorsImages, audio and video files (text has no file to attach to)
Main riskEdits and translation erase it; spoofing attacks existFalse positives, which fall hardest on non-native writersMetadata is lost when you screenshot or convert a file
Who can check itMostly nobody yet (detectors are restricted)Anyone, through commercial toolsAnyone, through public verifiers

The best-known detector failure is the Stanford study that found seven detectors wrongly flagged 61.3% of TOEFL essays by non-native English writers as AI-written, according to Stanford researchers Liang et al. (2023). That figure describes style-guessing classifiers, not keyed watermarks, so it should not be quoted as a watermark’s error rate. For more on detectors, read What Is an AI Detector? and our test of whether AI detectors actually work. For file provenance, see C2PA.

What an AI text watermark can and can’t tell you

An AI text watermark can tell you that a particular company’s model probably generated or processed some text. It can’t tell you who did the thinking, how much a person edited, who owns the text, or whether anyone broke a rule. OpenAI states each of these limits in its own announcement.

  • It does not measure human contribution. OpenAI: a watermark “can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it.”
  • It does not identify the user. It does not associate a person, account, prompt or conversation with the text.
  • A miss proves nothing. OpenAI: “The absence of a detected watermark does not prove human authorship.” Text may be too short, edited, translated, from an unsupported model, from before watermarking started, or from another company’s tool.
  • Attackers can learn the rules. Researchers at ETH Zurich showed that querying a watermarked model can reveal enough of its hidden rules to scrub a mark or fake one, with over 80% average success at a cost under $50 in the tested setups, according to Jovanović, Staab and Vechev (2024). Faking is the worrying half, because it makes a positive hit less safe as evidence. Those experiments tested other watermark schemes, not textGrain.
  • Paraphrasing is the weak point. A benchmark of watermark robustness found that a strong paraphrase attack removed the better schemes about half the time, according to the MarkMyWords benchmark by Piet et al. (2023). Again, that is evidence about the technique, not a test of OpenAI’s product, which independent researchers had not yet evaluated on launch day.

What this means for teachers and professors

An AI text watermark gives teachers almost nothing they can use today, because the detectors are not available to schools and the mark fades when a student edits. OpenAI is giving detector access to approved researchers and expert organizations at launch, not to classrooms. What still works is process evidence: drafts, version history and a conversation about the work.

If you teach in the EU, your students’ ChatGPT text may start carrying a mark in the coming weeks, and that changes nothing about how you should handle a suspected case. A hit would show a model processed some text, not that the student cheated. The sturdier habit is to design assignments that show thinking over time and to write an AI policy students can follow. The AI for Teachers: Your First Week Back course walks through exactly that, and our 15-minute syllabus policy guide gives you the wording. See also Learn AI for Teachers.

What this means for students

For students, an AI text watermark is a reason to keep a clear record of how you used AI, not a reason to panic. Nobody outside a small group of researchers can check for it, and OpenAI’s own numbers show it weakens fast when text is edited. The real risk is breaking your course’s AI rules, which no watermark is needed to discover.

Keep dated drafts and version history for anything you submit, write down what AI did and what you did, and follow your instructor’s policy rather than assuming the law decides what is allowed. If a detector ever misfires on your work, the evidence of your process is what resolves it. The Falsely Flagged by an AI Detector course is a calm playbook for that situation, and What to do if you’re falsely accused of using AI is the short version.

What this means for writers and marketers

For writers and marketers, an AI text watermark matters mainly as a disclosure question. In the EU, publishing AI-generated text on matters of public interest can trigger a disclosure duty under Article 50(4), unless a person reviewed it and someone takes editorial responsibility, according to the Article 50 text. A watermark does not answer who wrote a piece. Your process does.

Decide your disclosure line before a client asks. Describe what AI did (outline, first draft, translation, grammar) and what you did (ideas, examples, edits, fact-checking), and keep the drafts. Be careful with tools that promise to strip watermarks: you can’t verify the result, and heavy rewriting can add errors. The AI for Writers course covers voice and the ethics of AI-assisted publishing, and our guide to AI slop explains why unedited machine text gets ignored regardless of any hidden mark.

What this means for job-seekers and recruiters

For job-seekers, an AI text watermark is very unlikely to be the thing that sinks an application. No recruiter can check for OpenAI’s mark today, and a cover letter you’ve edited sheds most of it anyway. What actually hurts applications is generic, unedited AI writing that sounds like everyone else.

Rewrite at least a quarter of any AI-drafted letter in your own words, add one specific story only you can tell, and keep your own draft. Recruiters should not reject candidates on a watermark result: it can’t show how much a person contributed, and the EU’s hiring rules add separate obligations, covered in what moved and what’s live in the EU AI Act hiring rules. The Resume Writing course shows a faster edit workflow.

What this means for developers and product teams

For developers, an AI text watermark is a setting. OpenAI says API customers anywhere can turn on text watermarking for select models from their project or organization settings, and that it is off by default. It is also working with cloud partners to offer watermarking for OpenAI models accessed through their services in the coming weeks, per OpenAI’s announcement.

If your product shows model-written text to the public, decide whether your users need provenance, for instance for compliance or publishing, and test the option on a staging project first. Do not promise customers that marked text can be reliably detected: short text, code, math and edited text are weak cases. The Prompt Engineering for Developers course covers building with model APIs, and The EU AI Act for Non-Lawyers covers the rules behind the requirement.

Common misconceptions about AI text watermarks

“A watermark is a hidden character I can delete.”

An AI text watermark is not a hidden character. OpenAI’s Help Center says textGrain adds no hidden characters, invisible spaces or unusual punctuation. The mark is a pattern in which words the model picked, so a “clean invisible characters” tool cannot find it or remove it.

“If no watermark is found, a human wrote it.”

A missing AI text watermark proves nothing about authorship. OpenAI lists the reasons directly: the text may be too short, edited, translated, from an unsupported model, from before watermarking, or from another company’s tool. Treating a clean result as proof of human writing is as unreliable as treating a hit as proof of cheating.

“ChatGPT now watermarks everything everywhere.”

OpenAI’s AI text watermark is not a global default. It applies to eligible ChatGPT and Codex text in the EU, with API opt-in elsewhere. Claude’s is the one that applies worldwide on supported models. Posts claiming every ChatGPT answer on Earth is now fingerprinted overstate what OpenAI announced.

“A watermark detector will catch cheaters.”

An AI text watermark detector mostly catches unedited machine text, because editing erodes the signal quickly. A student who pastes a full answer unchanged is the likeliest to be caught; one who rewrites in their own words is not. That makes it a poor fairness tool, and it is why OpenAI is keeping its detector restricted.

“Watermarks make AI detectors obsolete.”

An AI text watermark does not replace AI detectors, and the two fail differently. A watermark can only identify text from models that apply one, while detectors guess at any text but wrongly flag human writing. Neither is reliable enough to carry an accusation alone, which is why process evidence still wins.

An AI text watermark sits in a cluster of terms about proving where content came from and whether a machine wrote it. These neighbors are the closest in meaning to an AI text watermark, and each has its own plain-language guide, so you can follow whichever idea you need next without rereading this page.

  • SynthID: Google DeepMind’s invisible watermark, the family Claude’s mark comes from.
  • AI detector: style-guessing tools, a different method with a different failure pattern.
  • C2PA: signed Content Credentials for image, audio and video files.
  • AI slop: the flood of low-quality machine content that provenance rules partly target.
  • AEDT: automated employment decision tools, the hiring-side rules that sit next to this one.

See also

This section collects the courses, glossary terms and articles most closely related to an AI text watermark, grouped by type so you can jump straight to what matches your situation, whether that is a classroom policy, a job application, a publishing workflow or a developer setting.

Courses

Related terms

Blog posts

Profession hubs

The bottom line

An AI text watermark is a quiet, statistical signal that three of the biggest AI assistants now build into their text, driven by EU law. It can suggest that a company’s model processed a passage. It cannot say who wrote it, how much a person changed it, or whether anyone broke a rule, and OpenAI’s own numbers show it fading to about 17% once a quarter of the words change.

So treat an AI text watermark as a compliance tool, not a lie detector. Keep a clean record of how you used AI, follow the rules you are actually bound by, and never let a single score carry an accusation. The AI Fundamentals course on FindSkill.ai is a good place to learn how these tools behave, and our full walkthrough of OpenAI’s announcement is in Is ChatGPT Watermarking Your Writing?.

Frequently asked questions

What is an AI text watermark? An AI text watermark is an invisible statistical pattern a language model leaves in its own word choices. A detector with a secret key can later check for the pattern. It is not a visible label and it does not add hidden characters, so copying and pasting the text does not remove it.

Does ChatGPT watermark its text? Since October 5, 2026, OpenAI says it will add an invisible watermark called textGrain to eligible ChatGPT and Codex text in the EU over the coming weeks. It is not a global default. API customers worldwide can opt in on select models, and the detector is limited to approved researchers and expert organizations.

Does Claude watermark its text? Yes. Anthropic began watermarking supported new Claude models on August 2, 2026, using a version of Google’s SynthID-Text. Anthropic applied it worldwide rather than only in the EU, and says a detection result shows probable Claude involvement, not who wrote the text.

Can an AI text watermark prove I used AI? No. A watermark can suggest a model generated or processed some text, but it cannot show how much a human contributed, who owns the text, or whether any rule was broken. OpenAI says the absence of a watermark does not prove human authorship either.

How do you remove an AI text watermark? You do not need special tools. Editing weakens the pattern because it replaces the word choices that carry it. OpenAI reports detection falling from about 92% to 66% when 10% of words are swapped and to 17% at 25%. Translation and heavy paraphrasing can make it undetectable.

Is an AI text watermark the same as an AI detector? No. An AI detector guesses from writing style, such as predictability, and can wrongly flag human writing. A watermark checks for a hidden pattern that the model deliberately inserted, using a secret key. Watermarks can be more precise, but they only work on text from models that apply them.

Sources

Build Real AI Skills

Step-by-step courses with quizzes and certificates for your resume