"Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union," OpenAI explained.
OpenAI's textGrain technique
OpenAI says the watermark will be invisible to readers and will not appear when you copy text. The company calls the method textGrain: it "slightly changes the model's word choices to create a statistical pattern that can later be detected." In practice, OpenAI is embedding a probabilistic signature in generated language rather than adding overt metadata or visible marks.
EU rollout, API opt-in, and detector access
The rollout is initially geographic and limited. OpenAI plans to enable the invisible watermark for eligible ChatGPT and Codex outputs in the European Union, and the company is "not making this a global default yet." Separately, API developers worldwide can opt in to watermarking for supported models starting immediately, but the option "remains disabled by default." OpenAI is also opening applications for its watermark detector; initial access will be restricted to "approved researchers and expert organizations."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDetection performance and failure modes
OpenAI is candid about the technique's limits. Company testing shows that relatively modest edits reduce detector performance: in evaluations of 400‑token passages, replacing 10% of words with synonyms lowered detection from about 92% to 66%, and replacing 25% of words reduced detection to 17%. Length matters too: with a 1% false‑positive target, OpenAI detected the watermark in about 80% of 200‑token psychology responses, compared with roughly 95% when passages reached 400 tokens.
Performance varies by subject. Detection was "even worse for subjects such as mathematics," where the model has less flexibility to alter wording and thus less capacity to generate the statistical pattern textGrain depends on. OpenAI warns that "the absence of a detected watermark does not prove human authorship" because generated text may be too short, edited, or translated for detection to work reliably.
OpenAI also emphasizes the detector's limits in attribution: when a watermark is detected, it "does not reveal who generated the text, their account, prompt, or conversation, and it cannot tell how much of the final work was written or edited by a human."
Effect on model quality: GPT-6 Astra
OpenAI reports that enabling textGrain "does not meaningfully affect the quality of GPT-6 Astra," saying benchmark results are "broadly similar" with watermarking turned on. That claim frames textGrain as a minimally invasive change to model output quality for at least one named model version.
What this means for technologists and security teams, policymakers and end users
- Technologists and security teams: The detector's sensitivity to editing and to short or mathematically constrained outputs means tools that rely on watermark detection will face frequent false negatives. Those groups are likely to seek access to the detector itself—OpenAI says applications are open, but access is initially limited to approved researchers and expert organizations.
- Policymakers and regulators: The EU‑focused rollout and the clarification that a detected watermark does not reveal account or prompt information will matter to regulatory discussions about provenance, accountability, and data privacy. The company’s decision not to enable watermarking globally by default also leaves room for regional policy differences to shape adoption.
- End users and API customers: Users should note the watermark is invisible in everyday use and can be erased or weakened by normal editing: simple synonym replacement and shortening materially reduce detection rates. API developers worldwide can opt in to watermarking, but it is not mandatory; organizations will need to decide whether to enable it for their own deployments.
OpenAI's approach is a practical experiment in embedding statistical signatures in language rather than stamping outputs with visible marks. The company discloses meaningful technical caveats: editing, short passages, and certain subject areas undercut detection, and the detector will be available only to approved external parties at first. Whether textGrain will be expanded beyond the EU, hardened against editing, or opened more widely to external verification remains unanswered by OpenAI's announcement.




