textGrain is OpenAI's invisible watermark for text. On October 5, 2026, OpenAI published its approach to EU text provenance rules, announcing that eligible ChatGPT and Codex text output in the European Union will be watermarked with textGrain over the coming weeks, to meet the EU AI Act's requirement that generated content carry machine-readable marking. API customers worldwide can opt in for select models starting today, can leave it off, and will also be able to access it through cloud partners such as Microsoft Azure in the coming weeks.
The mark hides in word choices, not in characters
textGrain does not insert hidden characters or add a visible label at the end of a paragraph. As the model generates text, it adjusts word choices so an invisible statistical signal is embedded in how words combine; a matching detector then reads a passage and judges whether it carries that OpenAI signal. OpenAI is explicit about what the signal can and cannot establish: it does not identify an author, organization, account, or the conversation a text came from, and detecting a watermark does not mean the text is accurate, nor can it settle questions of ownership.
OpenAI's own test data: length matters, edits erode it
In OpenAI's published tests, with the detector set to a 1% false-positive target, watermarks were identified in about 95% of psychology passages of roughly 400 tokens; at 200 tokens, detection fell to about 80%. Subject matter matters just as much: math content leaves the model far less freedom in word choice, and detection at the same length was only about 60%. Editing is the bigger variable — replacing 10% of the words in a 400-token passage with synonyms cut detection from about 92% to 66%, and replacing a quarter of the words left just 17%. OpenAI says textGrain matched or beat Google's SynthID text watermark in internal testing and plans to open-source the technology. On its frontier model Astra, enabling the watermark produced no significant performance differences across eight benchmarks including GPQA Diamond, BrowseComp, and DeepSWE, and did not affect generation speed or readability.
The detector is, for now, only for approved researchers
The first group allowed to check for the watermark is approved researchers and specialist organizations, who must apply and are reviewed case by case under the EU's General-Purpose AI Code of Practice. OpenAI's stated reason is straightforward: the detector can flag text that carries no watermark and can miss text that does, so until results can be interpreted responsibly, it will not be opened to the public. The tool itself answers a single question — whether an OpenAI watermark was detected — and reveals neither user identities nor prompts or conversation content.
The approach contrasts sharply with its peers. Anthropic applies a mandatory, global watermark to Claude that cannot be switched off, while OpenAI confines the mandate to its EU consumer products and makes API watermarking voluntary worldwide. Under regulatory pressure, everyone is now marking text; who gets to check, and whether it can be turned off, is where they differ. California's SB 574 rules for AI follow the same logic: require verifiability first, then argue about responsibility. For everyday users, the practical expectation is this: longer passages copied out of ChatGPT and Codex in the EU may soon test positive for an AI mark — while short, translated, or rewritten text testing negative is equally normal, because no detection never proved a human wrote it.