OpenAI brings invisible text watermarking to ChatGPT and Codex in EU
OpenAI will add invisible text watermarks to eligible ChatGPT and Codex output in the EU, while API customers worldwide can opt in for select models.
OpenAI will add an invisible statistical watermark to eligible ChatGPT and Codex text output in the European Union over the coming weeks. The regional rollout covers all plans, while API customers worldwide can opt in for select models starting now; API watermarking remains off by default.
The change is OpenAI's response to the EU AI Act's machine-readable identification requirements for generated text. It gives developers a new provenance option, but it does not turn AI-text detection into a reliable authorship test.
OpenAI's EU rollout covers ChatGPT and Codex
According to OpenAI's announcement, eligible ChatGPT and Codex users across all plans in the EU will receive watermarking over the coming weeks. OpenAI is not enabling it as a global default at launch.
API customers can opt in globally for supported models. OpenAI also says it is working with cloud partners to offer watermarked OpenAI model output through their services in the coming weeks, though it does not name partners or provide a firm date.
Detector access is narrower. Applications are open, but the first users will be approved researchers and expert organizations rather than the general public. OpenAI says this controlled access is intended to test reliability and responsible uses before any broader release.
textGrain changes word choices, not visible formatting
The system, called textGrain, embeds a statistical signal by influencing a model's word choices. A detector looks for that pattern in the resulting passage. The mark is invisible and remains in copied text because it is carried by the wording rather than by file metadata.
OpenAI reports no meaningful performance difference across its cited Astra benchmarks with watermarking enabled. That claim comes from the company's own evaluation, not independent product testing. TechCrunch independently confirmed the rollout details and noted that the technical report was co-written with researchers from the University of Pennsylvania and Yale.
Editing can sharply reduce detection
The limitations matter more than the label. In OpenAI's test of 400-token passages, replacing 10% of words with synonyms cut detection from about 92% to 66%. Replacing 25% reduced it to 17%. Short passages, constrained material such as mathematics, and translated or heavily edited text are also harder to identify.
A positive result only suggests that an OpenAI system generated or processed part of a passage. It does not identify a user, measure human contribution, establish ownership, prove wrongdoing, or verify factual accuracy. A negative result does not prove human authorship.
Those caveats make textGrain a provenance signal, not a plagiarism detector or disciplinary shortcut. Schools, publishers, and employers should not treat one detector result as decisive evidence.
What developers and EU users should expect
Developers with disclosure obligations can evaluate the API opt-in now, but should test how editing, translation, passage length, and their own content format affect detection. They should also explain to users what the watermark can and cannot establish.
EU ChatGPT and Codex users do not need to enable the regional rollout themselves, according to OpenAI's description. The practical checkpoints are which outputs qualify, which models support the signal, and when the rollout reaches each account. Teams building automated content pipelines can also review LinkLoot's AI workflow automation guide while deciding where provenance records belong in their process.
The next meaningful milestone is operational evidence: model coverage, cloud-partner availability, detector access beyond selected experts, and real-world false-positive and false-negative rates after routine editing.
Try the related loot
Rowan: evidence-led security scanning for AI applications
