OpenAI to add invisible watermark to ChatGPT and Codex text in EU to comply with AI Act
Quick Look
- OpenAI will roll out an invisible text watermark for ChatGPT and Codex in the European Union to comply with the EU AI Act's transparency rules, which took effect on August 2.
- The watermark, called textGrain, shapes word choices to create a detectable pattern without affecting model performance.
- It will be available to eligible users in the EU over the coming weeks and to API developers worldwide starting today, though off by default.
AI-generated summary
Why It Matters
The EU AI Act’s transparency rules, which took effect on August 2, require AI companies to mark AI-generated content in a way other systems can identify. OpenAI had previously built a text watermark but delayed release over concerns users might switch to rivals that didn’t watermark.
OpenAI will start adding an invisible watermark to text generated by ChatGPT and Codex in the European Union to comply with the EU AI Act, the company said Monday in a blog post.
The EU AI Act’s transparency rules, which took effect on August 2, require AI companies to mark AI-generated content in a way other systems can identify.
OpenAI said the watermark will roll out over the coming weeks to eligible ChatGPT and Codex users on all plans, but only in the EU. Developers using OpenAI’s API anywhere in the world can turn it on for select models starting today; it’s off by default. OpenAI said it is not making text watermarking a global default at launch.
The watermark is not an actual symbol, but works by subtly shaping the model’s word choices, leaving a pattern readers can’t see, but a detector can pick up. Because it lives in the words themselves, it travels with the text when it’s copied and pasted. OpenAI said the watermark doesn’t identify the user, and that it saw no meaningful change in its models’ performance with it switched on.
OpenAI also published a technical report for its method, called textGrain, alongside the announcement. Co-written with researchers from the University of Pennsylvania and Yale, it walks through an example of using a secret key to sort next-word predictions to finish the sentence. Add hundreds of these nudges together, and the detector can spot AI-generated content using only the text and the key.
Can the watermark be removed by editing? OpenAI’s tests suggest yes. In one test, replacing 10% of words with synonyms dropped detection from about 92% to 66%. The company also said short passages, math answers, and translated text are harder to detect.
“These limitations contribute to our decision to provide initial detector access only to approved researchers and expert organizations, who can help us evaluate reliability and responsible uses,” said the company.
OpenAI also cautioned that a missing watermark “does not prove human authorship.” The text could be too short or too heavily edited, or it could come from another company’s AI.
“[Watermarks] can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it,” the company said.
The announcement comes two months after Anthropic said it would watermark text generated by Claude, a move it’s applying worldwide. That decision drew backlash from some Claude users, who argued they had supplied “the instructions, context, decisions” while Claude was just “the tool.”
OpenAI had built a text watermark before but held off on releasing it, partly over concerns that users would switch to rivals that didn’t watermark, The Wall Street Journal reported in 2024.
What to Watch
AI outlook — possibilities, not facts
More AI companies will adopt text watermarking to comply with evolving AI regulations globally
Likely · Within months
OpenAI may eventually expand the watermark beyond the EU if regulatory pressure increases or competitive risks decrease
Possible · Within months
Open Questions
- How will the watermark affect user adoption of OpenAI's services in the EU versus other regions?
- What specific safeguards will prevent misuse of the detector by unauthorized parties?
- How will OpenAI balance transparency with user concerns about perceived surveillance or control over AI output?






