On Monday, OpenAI announced via a blog post that it will begin placing an unseen watermark on text produced by ChatGPT and Codex within the European Union, in line with the EU AI Act. The decision comes after pressure from regulators and competitors. However, the company has attached a significant caveat: the watermark can be broken.
On August 2, the EU AI Act’s transparency requirements went into force, obliging AI firms to attach labels that other systems can detect to their machine-generated material. OpenAI has announced that the watermark will start appearing for eligible ChatGPT and Codex users across all subscription tiers over the next few weeks, though the deployment is restricted to the EU. The company also confirmed that OpenAI’s API anywhere in the world can turn it on for select models starting today; it’s will remain switched off by default for developers. OpenAI made clear that it does not plan to make text watermarking a universal default setting when the feature launches.
What appears as a watermark is not a visible mark at all. Instead, it shapes the model’s word choices, leaving a pattern readers can’t way that a detector can catch, even though the human eye cannot. Since it exists within the words themselves, it moves along with the text when it’s copied and pasted. OpenAI said the watermark doesn’t detect it, and it also found that the models performed just as well whether the watermark was turned on or off.
How TextGrain Works
A technical report accompanying the announcement details OpenAI’s method, textGrain, which was co-authored by researchers from the University of Pennsylvania and Yale. It demonstrates an example of applying a secret key to rank next-word predictions in order to complete a sentence. By accumulating hundreds of such adjustments, the detector can identify AI-generated content based solely on the text and the key.
The technique depends on small changes in word selection that build up through an entire passage. A detector built from the secret key can identify the sequence, even though the human eye notices no irregularity. OpenAI likened the procedure to a digital signature embedded within the text itself.
Testing the Limits
OpenAI’s own testing shows that its watermark isn’t entirely reliable. One trial found that substituting 10% of words for synonyms cut detection from roughly 92% to 66%. The company added that brief passages, mathematical answers, and translated text are particularly difficult to identify.
The rollout depends on these restrictions, with OpenAI saying it will first make the detector available only to approved researchers and expert organizations, so they can help test reliability and responsible uses.
“[Watermarks] can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it,” the company said.
What the Watermark Actually Says
The announcement comes two months after Anthropic said it would watermark text generated by Claude, a move it’s applying worldwide. That decision drew backlash from some Claude users, who argued they had supplied “the instructions, context, decisions” while Claude was just “the tool.”
OpenAI’s approach differs in a key way. The watermark does not measure human contribution. It only flags that OpenAI’s system was involved somewhere in the chain. A passage marked with a watermark could still be heavily edited by a human afterward, and the mark travels with the text regardless.
OpenAI’s caution on this point is explicit. A missing watermark “does not prove human authorship,” the company said. The text could be too short or too heavily edited, or it could come from another company’s AI.
The History Behind It
Before now, OpenAI had developed a watermark for text but chose not to release it, according to The Wall Street Journal’s report in 2024, citing worries that people might move to competing services that did not include such a mark.
Regulation has changed the timing. The EU AI Act has created a compliance requirement, and OpenAI is moving to meet it. The company’s announcement frames the rollout as a response to regulation, not a marketing stunt.
Who Else Is Watermarking
A number of tech firms have pledged to abide by the EU’s code of practice for AI-generated content, with Anthropic, Google, Meta, Microsoft and OpenAI among those who have signed on.
The terrain is thick with travelers, and the routes diverge widely. OpenAI’s course falls between releasing access to developers at once and delaying the switch-on by default across the globe.
The Hard Problem
Putting it another way, the challenge at hand is straightforward to describe yet difficult to overcome. The goal is a watermark that remains undetectable by human eyes while still being reliably detected. OpenAI’s own testing demonstrates just how wide the gap between those two requirements actually is.
Here is where the story lands:
- The watermark is real and coming soon in the EU.
- It is not a global default at launch.
- It can be stripped by editing.
- OpenAI is not claiming it measures human effort.
The company has released the feature while openly admitting the gap instead of hiding it. Its success will depend on how far the watermark spreads and how simple it becomes to take it off.
Tests from OpenAI itself reveal that the watermark can be undone through editing, and the company admits that brief passages, math answers, and translated text are more difficult to spot. These weaknesses are part of the reason it is offering early detector access only to approved researchers and expert groups, which will allow them to assess how reliable the tool is and what careful uses it should have.
The firm presents its watermark as a detection aid rather than a warranty of trustworthiness. It shows that an OpenAI system took part in generating or working on a passage, but it says nothing about how much human judgment, editing, or originality went into it.
The announcement carries the weight of regulatory pressure and competitive precedent. Anthropic’s decision to watermark Claude worldwide drew backlash from some users, who argued they had supplied the instructions, context, and decisions while Claude was just the tool. OpenAI’s approach differs in a key way: the watermark does not measure human contribution. It only flags that OpenAI’s system was involved somewhere in the chain.
The company has admitted that its watermark can be removed through editing, which means people could post watermarked text while presenting it as human-written work. Its own tests reveal a real difference between how invisible the watermark is and how reliably it performs. OpenAI chose to put the feature out there with that difference acknowledged instead of kept hidden.
Source material: “OpenAI will start watermarking ChatGPT’s text in the EU,” TechCrunch.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

