OpenAI Begins Watermarking ChatGPT and Codex Text for EU Users

OpenAI is adding an invisible machine-readable mark to text from ChatGPT and Codex, starting with users in the European Union.

The news

OpenAI will apply its TextGrain watermark to outputs from ChatGPT and Codex for users located in the EU. The move is intended to satisfy obligations under the EU AI Act. The watermark remains invisible to readers but can be read by detection tools.

The company states that TextGrain matched or exceeded the performance of earlier systems, including Google DeepMind’s SynthID for text. Anthropic adopted a similar approach in August for the same regulatory reason. OpenAI supplied benchmark scores showing that watermarked text produces results comparable to unwatermarked text on standard evaluations.

Context

Until now, OpenAI’s consumer and developer products returned plain text with no embedded signals. The EU AI Act introduces requirements for transparency in AI-generated content, prompting several providers to add detection mechanisms. OpenAI and Anthropic have both framed their watermarking work as a direct response to those rules.

The watermark is described as machine-readable rather than human-visible. OpenAI notes that heavy editing of the output can reduce the reliability of detection. It also states that the system does not guarantee identification in every case. The rollout begins with accounts tied to EU addresses or IP locations, leaving users elsewhere unaffected for the time being.

Details

TextGrain is being rolled out first to accounts with EU addresses or IP locations. The same marking applies to both general ChatGPT responses and Codex code completions. OpenAI has not announced a timeline for expansion beyond the EU.

Benchmark data released by the company shows that the presence of the watermark produces no measurable drop in standard task performance. The system is positioned as an incremental technical step rather than a change to model behavior or training. Because the mark is embedded at generation time, any downstream copy of the text carries the signal unless the text is substantially rewritten.

OpenAI has not published the exact technical method used to embed the mark. The decision to withhold those details stems from a desire to keep detection robust against removal attempts. The company has confirmed only that the approach builds on prior work such as SynthID and that it performs at least as well on the benchmarks it released.

Reactions / counterpoints

Some users and observers expressed dissatisfaction when the addition was announced. OpenAI has not published details on the exact technical method used to embed the mark, citing the need to keep detection robust against removal attempts. The absence of public technical specifications has left some developers questioning how durable the watermark will prove once adversaries attempt to strip it.

The sources note that not everyone welcomed the change. Concerns center on the added signal itself rather than any performance cost, since the benchmarks show no measurable difference. No public statements from competing labs beyond Anthropic’s earlier announcement appear in the reporting.

Why it matters

For developers and teams that rely on ChatGPT or Codex inside the EU, every generated string will now carry a persistent signal that downstream tools can read. The requirement applies only to EU users at present, creating a split experience based on geography. Because editing can weaken detection and the company offers no absolute guarantee, the practical effect on content provenance remains limited to cases where the output is left largely intact.

Teams that operate across regions will need to track which outputs carry the mark and which do not. Workflows that involve heavy post-editing or translation will see reduced effectiveness of the signal. Over time, the same pressure that produced TextGrain in the EU may push similar changes in other regions that adopt comparable rules. The current implementation therefore functions as a narrow compliance measure rather than a universal provenance solution.

---

Sources:

No comments yet