AI Affairs, home

Monday 5 October 2026

Government

OpenAI plans EU text watermarks for ChatGPT and Codex, with API opt-in

The company is limiting access to its text detector as its tests find that replacing words with synonyms sharply reduces the chance of detecting a watermark.

OpenAI’s former headquarters at 1515 Third Street, seen across a wire-crossed intersection.
Photo: Coolcaesar, CC BY 4.0, via Wikimedia Commons (cropped)

OpenAI announced on 5 October 2026 that it would add invisible watermarks to eligible ChatGPT and Codex text output in the European Union over the coming weeks, Unite.AI reported. The company also opened an opt-in setting for API customers worldwide on 5 October. OpenAI presented the rollout as its response to the EU AI Act’s requirement that text generated by AI systems be identifiable in a machine-readable way.

Key points

  • OpenAI plans to watermark eligible ChatGPT and Codex text for EU users across all plans in the coming weeks.
  • API customers worldwide can opt in for selected models; watermarking is off by default.
  • Access to OpenAI’s text watermark detector will initially be limited to approved researchers and expert organisations.
  • In OpenAI’s tests, replacing 25% of words with synonyms reduced detection to 17%.

ChatGPT and Codex take the EU route

OpenAI’s planned watermarking covers eligible users of ChatGPT and Codex across all subscription plans in the EU. The company said it would begin there rather than make watermarking the default globally at launch, so that it could learn from use and feedback. The timetable for those products is the coming weeks. OpenAI made the API setting available on 5 October for selected models, Unite.AI reported.

API customers must choose to switch the feature on. OpenAI said that arrangement lets customers decide how watermarking fits their own transparency obligations and the experience they provide to users. The company is also working with cloud partners to make watermarking available for output from OpenAI models accessed through their services in the coming weeks.

The announcement concerns text. OpenAI said its existing verification tools for images and audio, including its web verification tool and Content Provenance API, remain publicly accessible. That differs from the access plan for text: applications for the text detector opened on 5 October, but OpenAI plans initially to admit approved researchers and expert organisations case by case, under the EU’s Code of Practice on transparency of AI-generated content.

textGrain depends on word selection

OpenAI calls its method textGrain. It alters the statistical pattern of words selected during generation, leaving a signal that its detector can test for without changing how the text appears to a reader. The company says the detector needs the passage and a secret key. A technical report dated 5 October describes a method for limiting how much the watermark changes the model’s choices, while making the signal detectable across a passage.

Passage length matters in OpenAI’s reported evaluations. At a target false positive rate of 1%, its detector found the watermark in about 80% of 200-token passages and about 95% of 400-token passages for material such as psychology, Unite.AI reported. OpenAI reported substantially lower detection for material such as mathematics, where the model has less flexibility in its choice of words. The evaluations used watermarked English answers to questions from the ELI5 dataset.

Editing had a larger effect in OpenAI’s test of 400-token passages. Detection stood at about 92% before words were replaced with synonyms, fell to 66% when 10% were replaced and reached 17% when 25% were replaced. OpenAI said those limitations contributed to its decision to restrict initial detector access. It also reported no meaningful difference with and without watermarking across the benchmarks it uses to assess its Astra model.

The detector is intended to indicate whether it finds an OpenAI watermark, rather than identify a user or reveal a prompt or conversation, Seeking Alpha reported. OpenAI said a watermark cannot determine how much of a passage a person wrote or edited, who owns it, who bears responsibility for it or whether its contents are accurate. It also said that an unmarked passage does not prove human authorship.

Article 50 reaches text providers

The transparency obligations in Article 50 of the EU AI Act took effect in early August 2026. They require AI providers to label generated content in a machine-readable way, Trending Topics reported. Providers that breach the transparency obligations face fines of up to 15 million euros or 3% of global annual revenue. OpenAI’s EU product rollout will therefore follow the start of those obligations, while its worldwide API setting remains a choice for customers.

OpenAI plans to release its watermarking technology as open-source software and to revise its approach as the technology and regulatory requirements develop, Seeking Alpha reported. For now, the company’s restricted text detector means that access to its test for a watermark depends on approval, even where the watermark is applied automatically to eligible EU product output.

Anthropic has marked text across its Claude products worldwide since early August, rather than limiting the rollout to EU users, Trending Topics reported. Its coverage includes the chat application, API and Claude Code, including access through cloud partners. Anthropic’s text detection API is in a closed preview for authorities, media organisations, fact-checkers, researchers and educational institutions.

Sources

Topics: Foundation models, Regulation, Safety