US Edition
Your source for latest news
TechnologyArtificial Intelligence

OpenAI to watermark ChatGPT text for European users, bowing to new EU transparency law

The company's new system, called textGrain, invisibly marks AI-written text as the EU's AI Act transparency rules take hold — a reversal after years of resisting the technology that rivals Anthropic and Google adopted first.

PT
By PressTemps Technology DeskPublished Today, 06:40 ET · 6 min read
OpenAI to watermark ChatGPT text for European users, bowing to new EU transparency law
OpenAI's former San Francisco headquarters building at 1515 Third Street in the Mission Bay neighborhood. Illustrative image of the company; not a photo from the announcement itself. Photo: Coolcaesar / Wikimedia Commons, CC BY 4.0.
What to know
OpenAI will begin automatically watermarking ChatGPT and Codex text for EU users within weeks, using a method called textGrain developed with University of Pennsylvania and Yale researchers.
The watermark detector is roughly 80-95% accurate on unmodified text but drops to as low as 17% accuracy once a quarter of the words are swapped for synonyms.
The move complies with Article 50 of the EU's AI Act, in effect since August 2, 2026, and follows similar moves by Anthropic (global) and Google; OpenAI's rollout stays EU-only by default, with a worldwide opt-in for API developers.

OpenAI said Monday that it will begin embedding an invisible watermark in text generated by ChatGPT and its Codex coding assistant for users in the European Union, reversing a years-long reluctance to deploy the technology and framing the move as a direct response to a new European transparency law. The watermarking method, which OpenAI calls textGrain, alters the statistical pattern of word choices the model makes as it writes, leaving a signal that is invisible to readers but recoverable by a detector that holds a matching key.

The announcement, posted to OpenAI's company blog, came as enforcement of Article 50 of the European Union's AI Act moved into effect this summer, requiring providers of general-purpose AI systems to mark synthetic text, audio, image and video output in ways that can be detected by machine. OpenAI is the last of the major American AI labs to commit to a production text watermark; Anthropic and Google had already shipped theirs, a contrast first reported by TechCrunch.

The numbers behind textGrain

OpenAI, working with researchers from the University of Pennsylvania and Yale, built textGrain around a cryptographic key that biases the randomness a language model uses when selecting between similarly likely words or sub-word tokens. According to the company's own figures, the detector identifies a watermark correctly in roughly 80 percent of 200-token passages — a few sentences of ordinary prose — and in about 95 percent of passages twice that length. The signal is fragile against tampering: replacing one word in ten with a synonym cut detection accuracy from about 92 percent to 66 percent, and replacing one in four pushed it down to roughly 17 percent.

OpenAI says the rollout to ChatGPT and Codex users inside the EU will happen automatically "in the coming weeks" and will apply across all subscription tiers, free and paid alike. Separately, developers building on OpenAI's API, anywhere in the world, can switch the watermark on for a subset of models starting October 5; it ships off by default. The company says it intends to open-source detector access for outside researchers, a detail an OpenAI researcher involved in the project, Weijie Su, described on social media the day the work went public.

"Announcing our work textGrain, OpenAI's text watermark in response to the EU AI Act. OpenAI is rolling out textGrain in the EU and opening detector access to researchers. We'll open-source it so the community can build on top." — Weijie Su, OpenAI researcher and University of Pennsylvania statistics professor

A rule written for deepfakes, aimed at chatbots too

The obligation OpenAI is responding to sits inside Article 50 of the EU's AI Act, the bloc's sweeping artificial-intelligence law. Transparency duties under that article took effect on August 2, 2026, requiring that providers of generative AI systems mark their synthetic output "using machine-readable solutions that are effective, interoperable, robust and reliable, as far as technically feasible," according to the European Commission's own guidance on the accompanying Code of Practice. Systems already on the market before that date get a transition window running to December 2, 2026. Noncompliance with the Act's obligations falls into a penalty tier that can reach into the tens of millions of euros or a percentage of a company's global revenue, whichever is larger.

OpenAI had long resisted shipping a text watermark even though, as the company has previously acknowledged, it had a working version for years. Earlier internal testing, some of it reported by the Wall Street Journal, found the technique could be defeated by paraphrasing or translation and raised fairness concerns because it risked flagging the writing of non-native English speakers at higher rates. Those trade-offs are reflected in OpenAI's own numbers this time around: the system is far more reliable against unaltered text than against text that has been lightly edited or run back through another model.

OpenAI's rivals moved first. Anthropic began weaving a watermark into everything its Claude models generate in August, applying it globally rather than only in Europe because, the company has said, it has no durable way to restrict the feature by region once text leaves the model. Google already marks text from its Gemini models using its SynthID system, which Anthropic's approach adapts. OpenAI itself has used outside provenance tools for two years, attaching C2PA Content Credentials metadata to ChatGPT-generated images and licensing Google DeepMind's SynthID for audio. Text had remained the missing piece.

Who the change reaches

The most immediate effect falls on ChatGPT's European user base, the largest regulated market OpenAI operates in, along with developers using Codex for coding assistance there. Because the feature stays off by default outside the EU and is opt-in for API customers, most ChatGPT users in the United States and elsewhere will not notice any difference in the near term. That split mirrors a broader industry debate over whether an EU-specific rule should become a de facto global one, as Anthropic concluded it had to, or whether a company can keep a lighter touch outside the jurisdiction that wrote the rule, which is the path OpenAI has chosen for now.

Educators, publishers and plagiarism-detection vendors — who have spent three years asking AI companies for better tools to flag machine-written text — are a secondary audience. OpenAI's own disclosure that light paraphrasing collapses detection accuracy to well below a coin flip suggests the watermark will do little to settle disputes over whether a given student essay or news article was AI-generated, a limitation the company has acknowledged rather than overstated. Policy teams at other large AI providers, meanwhile, now have one fewer holdout to point to in future conversations with EU regulators about whether the industry is complying in good faith with Article 50.

What happens next

OpenAI has not given an exact date for the EU rollout beyond "coming weeks," and it has not said whether or when it might extend automatic watermarking to ChatGPT users outside Europe, the way Anthropic did. The European Commission's AI Office, which oversees compliance with the Code of Practice, is expected to continue monitoring how providers implement Article 50 as the December transition deadline approaches for systems that predate the August enforcement date. OpenAI says it plans to publish its detection methodology and open access to outside researchers, a step that would let independent groups test textGrain's resilience against the kind of circumvention — paraphrasing, translation, re-generation through a different model — that the company's own benchmarks show remains its biggest weakness.

More on this story

All Technology