Skip to main content

Command Palette

Search for a command to run...

OpenAI Is Putting an Invisible Watermark on ChatGPT Text in the EU

OpenAI will add an invisible watermark to ChatGPT and Codex text in the EU. Here is what it does, how well it works, and what it can't tell you.

Updated
•5 min read•View as Markdown
OpenAI Is Putting an Invisible Watermark on ChatGPT Text in the EU
Z
One platform to write, cross-post to Dev.to, Medium, WordPress, Hashnode, and Bluesky, and protect your SEO with canonical links. Zero paywalls and full content ownership.

Soon, text written by ChatGPT for people in the EU will carry a mark you can't see.

OpenAI is adding an invisible watermark to text from ChatGPT and Codex for eligible users across the European Union. The rollout starts over the next few weeks, with no exact date given. It's the first time ChatGPT's text will carry a built-in mark. OpenAI has had a text watermarking method in the works since at least 2024 and held it back. What changed is the law.

Why now

The EU AI Act requires providers of generative AI to make their output identifiable by machines. That duty sits in Article 50, which started applying on August 2. Services that were already on the EU market before that date get until December 2 to start marking their output. Newer systems had to comply from launch.

OpenAI says the watermark is its response to the law. It doesn't point to a specific deadline.

It isn't the first to do this. Anthropic began marking text from its newer models in early August, and Google already ships SynthID for text. Until now, ChatGPT shipped without one.

What changes for you

If you use ChatGPT or Codex in the EU, on any plan, eligible text you generate will start carrying the mark. You won't notice anything. The words and formatting look the same.

If you're outside the EU, ChatGPT stays as it is for now. OpenAI says it isn't making watermarking a global default at launch and wants to learn from the EU rollout first.

For developers, API customers anywhere can switch watermarking on for select models starting now. It's off by default. OpenAI is also working with cloud partners to offer it through their platforms in the coming weeks.

How it works

OpenAI calls its method textGrain. A language model picks each word from a range of reasonable options. textGrain nudges those choices in a statistical pattern, and a matching detector looks for that pattern later.

The signal lives in the word choices themselves, not in hidden characters or file metadata. Copying and pasting the text won't remove it. Changing the words can.

OpenAI also says the watermark doesn't hurt quality. On its latest model, Astra, benchmark scores with and without the mark stayed within a few points of each other, some slightly up and some slightly down. On GPQA Diamond, for example, it scored 94.44% unmarked and 93.94% marked.

The limits

OpenAI is fairly direct about where this falls short.

Length matters. With the detector tuned to wrongly flag about 1% of unmarked text, it caught the watermark in roughly 80% of 200-token passages and 95% of 400-token passages (about 150 and 300 words). Those were explanatory answers on psychology. On math, where there's less freedom in word choice, detection was much lower.

Editing hurts more. On 400-token passages, swapping 10% of the words for synonyms dropped detection from about 92% to 66%. Swapping 25% dropped it to 17%. Translated text is also harder to detect.

So a missing watermark tells you very little. OpenAI says so itself: no detected watermark doesn't prove a human wrote the text. It could be short, edited, translated, from an older or unsupported model, or from another company's tool.

A watermark that is present has limits too. It can show that an OpenAI system generated or processed part of a passage. It can't tell you how much a person contributed, who owns the text, who is responsible for it, or whether it's accurate. It doesn't identify the user, and it isn't tied to any account, prompt or conversation.

Who can check for it

Not you, at least for now. The detector isn't public. OpenAI opened applications for approved researchers and expert organizations, and will grant access case by case. The tool reports whether it finds an OpenAI watermark, without identifying the user or revealing prompts.

OpenAI says it will widen access once results can be interpreted responsibly, and plans to release the technology as open source so others can build on it. Images and audio are different. OpenAI's verification tools for those are already public.

Why OpenAI waited

In 2024, the Wall Street Journal reported that OpenAI had a text watermark ready but hadn't launched it. OpenAI replied that the method worked well on unedited text but could be beaten by translation or by having another model reword the passage. It also worried about stigmatizing non-native English speakers who use AI as a writing aid. A survey reported at the time found about 30% of ChatGPT users said they'd use it less if it watermarked text.

The new announcement shows the same caution. The EU-only rollout follows the law, and the detector is locked down because of the reliability gaps above.

What to take from this

  • Users in the EU: nothing to do. Just don't read a watermark result, or its absence, as proof of who wrote something.

  • Teachers and editors: you can't run the detector, and OpenAI says a result wouldn't measure how much a person contributed anyway.

  • Businesses publishing for EU audiences: machine-readable provenance for text is now something to plan around.

  • Developers: the opt-in is available today. Decide whether your own transparency duties call for it.

A few things are still open: the exact EU rollout date, the updated technical report and open-source release, and whether OpenAI extends the mark beyond Europe. For now it's a first step, with limits spelled out, from a company that spent years deciding whether to ship it.


Published via ZyVOP — Write once in Markdown, auto-backup to GitHub, and syndicate to Dev.to, Medium & Hashnode in 1 click.