ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI compliance
ChatGPT Text Watermarks Are Here: Mandatory in the EU, Off by Default in the API

ChatGPT Text Watermarks Are Here: Mandatory in the EU, Off by Default in the API

AI compliance • Admin • • 3 views

ChatGPT text watermarking, called textGrain, has arrived: OpenAI announced the system on October 5, 2026, and over the coming weeks eligible ChatGPT and Codex text output in the European Union will automatically carry an invisible statistical mark. From the same day, API customers worldwide can switch the same feature on for select models, but it stays off by default. What pushed this step was not a product preference. The transparency provisions of the EU AI Act now apply, so the very same paragraph is a compliance duty inside the EU and, for now, only an option outside it.

Three moves at once — do not conflate them

First, the EU consumer rollout is mandatory. OpenAI says the watermark will cover eligible output across plans in the EU, with no opt-out. Second, the API side is opt-in. Organizations can turn on text provenance at organization or project level, for selected supported models only, at no change in price. Third, the detector is not public. For now only approved researchers and expert organizations can apply, case by case; teachers, employers and publishers cannot get it yet. Keeping these apart matters: being marked does not mean anyone can test the text, and being able to test it would not make a result sufficient grounds for discipline.

textGrain works by slightly shifting the model's choices among several plausible words during generation, leaving a statistical pattern readers cannot see and copy-paste does not remove. It relies neither on hidden characters nor on file metadata. Researchers from the University of Pennsylvania and Yale took part in the technical report OpenAI published alongside the announcement, and the company says it plans to open-source the technology later, without giving a date.

The legal basis is European — do not export it

This rollout answers the transparency duties in Article 50 of the AI Act. According to the European Commission, those duties have applied since August 2, 2026, and require providers of generative AI to make synthetic content identifiable in a machine-readable way. Systems already on the market before August 2, 2026 get a transition period for this marking and detection duty specifically, and must comply by December 2, 2026 — the deadline OpenAI's schedule is aimed at.

Two layers of responsibility must stay separate. A watermark covers the provider-side machine-readable marking; it does not replace deployer-side disclosure. In the EU, an organization that publishes AI-generated text on matters of public interest without substantive human review still has to tell readers, visibly, that the content is AI-generated. A mark hidden in word choices and a notice placed in front of readers are not interchangeable. The United States has no equivalent federal text-watermark rule, so OpenAI's different defaults in the US and the EU trace the geographic border of this law quite precisely. EU enforcement checks on high-risk AI have already begun, with hiring and credit scoring among the first areas examined; this time the track in question covers transparency for generated text in general.

Strong detection numbers, with a hard ceiling on what they prove

OpenAI's published test figures must be read with their conditions attached. At a target false-positive rate of 1%, a flexible, roughly 400-token passage on a psychology topic was detected about 95% of the time; at about 200 tokens that fell to about 80%. Yet swapping just 10% of the words in a 400-token passage for synonyms cut detection from about 92% to 66%, and swapping 25% left only 17%. Translation can largely erase the signal, and constrained writing such as mathematics and code is inherently harder to detect; according to OpenAI's help center, outputs shorter than 200 tokens and code snippets are not the focus of this transparency regime in the first place.

So the meaning of a result has to be pinned down. A positive result only shows a statistical pattern consistent with an OpenAI watermark. It does not identify a user, account, prompt or organization, and it says nothing about whether the text is accurate or who owns it. A negative result does not prove human authorship either: text that is too short, rewritten, translated, older, or produced by another model will also come back negative. Using such a result on its own for dismissal, discipline or an academic-misconduct finding holds up neither technically nor as compliance practice.

Who should act: EU users, API organizations and publishers

Individual ChatGPT and Codex users in the EU have little to do; the mark has no visible effect on reading or editing. The workflow changes fall on organizations. API customers serving the EU should inventory now which models and scenarios count as EU business, enable watermarking for those projects in settings, and log model versions and toggle states. They should also keep the original generated text until any verification is finished, because translating or paraphrasing first destroys the reference value of a later check.

For publishers, schools and employers the right move is restraint. While the detector is not open to you and false positives and missed detections are officially acknowledged, do not buy third-party verdicts marketed as substitutes for the official detector, and do not write any single detection score into a disciplinary process. If a dispute has to be resolved, process evidence — drafts, version history, how the work was made — is more reliable than a probability figure.

Finally, the scope: mandatory watermarking covers only eligible ChatGPT and Codex output in the EU, and elsewhere the API switch remains the customer's own choice. Teams operating in the United States, China or other markets can treat this as advance preparation for EU compliance, but Article 50 must not be described as a rule that has already taken effect uniformly worldwide.

Recommended Tools

More