AI News
AI News AgentPolicy & safetyOpenAI3 min read

OpenAI enables AI text watermarks in the EU

OpenAI will add invisible watermarks to eligible ChatGPT and Codex text in the European Union to comply with the AI Act. The technology can weaken with short texts, translations or edits, so access to the detector will initially be limited to researchers and specialized organizations.

OpenAI will begin adding an invisible watermark to text generated by ChatGPT and Codex in the European Union to comply with the AI Act's traceability rules. The rollout will arrive over the next few weeks and will not initially be enabled globally.

The measure is designed to make AI-generated text automatically identifiable, but OpenAI itself acknowledges that the technology still has important limitations. A watermark can provide a signal about a text's origin, but it does not show who wrote it, how much a person contributed or whether the content is true.

Three ways the measure will be applied

OpenAI has divided the rollout into several parts:

  • API customers worldwide will be able to voluntarily enable the watermark on some models. It will remain disabled by default.
  • ChatGPT and Codex will add the watermark to eligible texts for users in the European Union over the next few weeks.
  • Researchers and specialized organizations will be able to request access to the watermark detector. Approval will be granted individually, and access will not initially be available to the general public.

The company is also working with cloud service partners to bring the option to people who use OpenAI models through those platforms.

How textGrain works

The technology, called textGrain, introduces an invisible statistical signal into the model's choice of words. The detector then analyzes a text to check whether it finds that pattern.

OpenAI says textGrain matched or outperformed other evaluated methods, including SynthID for text. But a strong result under controlled conditions does not guarantee that the detector will work the same way on real-world documents.

In its tests, with a 1% false-positive rate, the system detected the watermark in approximately 80% of 200-token texts and roughly 95% of 400-token texts in areas such as psychology. Detection was considerably worse in mathematics, where there is less freedom to choose words.

Editing the text can also weaken the signal. In 400-token texts, replacing 10% of the words with synonyms reduced detection from around 92% to 66%. With 25% of the text changed, it fell to 17%.

What this means for you

If you use ChatGPT in the EU, some text generated by the service may carry an invisible signal that can be used to check whether an OpenAI system participated in its creation. That does not mean anyone can access your conversations or identify your account: the detector will only report whether it finds a watermark.

It will not be definitive proof of authorship either. Text without a watermark may have been generated by AI and then edited, translated or produced with an unsupported model. Similarly, detecting a watermark does not reveal how much human work went into the text.

The watermark also does not determine ownership of the text, legal responsibility for its use or the obligation to disclose that AI was used. Nor can it verify whether the information is accurate, misleading or harmful.

OpenAI says it has not observed meaningful differences in the quality of responses from its Astra model with and without a watermark in the benchmarks it uses. Even so, the company will initially limit access to the detector to study false positives and cases in which it fails to find an existing watermark.

The company plans to release the technology as open-source code and review its strategy as regulations, standards and available evidence evolve. The next key test will be whether these watermarks withstand common situations such as translation, rewriting or human editing. For now, they are a technical clue about a text's origin, not a certificate of authorship.