OpenAI said on 5 October 2026 that, starting that day, API customers worldwide can opt in to text watermarking for select models, and that over the coming weeks it is adding an invisible watermark to eligible ChatGPT and Codex text output in the European Union. OpenAI calls the technology textGrain, says it stays off by default in the API, and says it is not a global default at launch.
What OpenAI Announced
OpenAI describes a phased approach in response to the EU AI Act, which it says “requires generative AI providers to make generated text identifiable in a machine-readable way.” It also says text watermarking and detection “remain early technologies with significant limitations.”
The first step is the API. OpenAI says API customers around the world can opt in to watermarked text for select models from 5 October. Its help center says customers can switch it on for a project or for a whole organization in their settings, and choose which models receive it.
The second step is ChatGPT and Codex. OpenAI says it is introducing the watermark to eligible users “across all plans in the EU only” over the coming weeks, and adds: “We are not making text watermarking a global default at launch.”
The third step is the detector. OpenAI says approved researchers and expert organizations can apply for access from 5 October, case by case. It says it is not making the detector public at launch, “given the risk of missed watermarks and false positives.”
Its help center names researchers it says it is already working with: John Thickstun of Cornell University, Martin Vechev of ETH Zurich and INSAIT, and researchers at the Kempelen Institute of Intelligent Technologies. OpenAI also says it is working with cloud partners on watermarking for model outputs reached through their services, and plans to release textGrain as open source.
OpenAI says the announcement covers text only. For supported images it says it adds Content Credentials and embeds invisible SynthID watermarks, for supported audio it embeds SynthID watermarks, and it says its verification tools for images and audio, including openai.com/verify and its Content Provenance API, stay publicly accessible.

Business Pill · A HIDDEN MARK, BUILT IN AS IT IS MADE
A one-minute explainer of the idea behind this story: a watermark. It teaches the concept, not this story’s figures.
The key insight: OpenAI reports its detection figures from separate evaluations with different conditions: about 80% of 200-token passages and about 95% of 400-token passages in one, and, in another, about 92% of 400-token passages falling to 66% and then 17% as 10% and 25% of the words are replaced. OpenAI also says that the absence of a detected watermark does not prove human authorship.
How textGrain Works, in OpenAI’s Description
OpenAI says textGrain “adds an invisible statistical signal to the model’s word choices,” and that its detector looks for that signal. The help center says the watermark does not add hidden characters, invisible spaces or unusual punctuation, and that copying and pasting the text does not introduce hidden material.
The help center gives the mechanism in steps. At each step the model assigns a likelihood to every possible next word or word piece. The system builds several adjusted sets of those likelihoods, each favoring different choices according to a secret key, balanced so that averaged together they match the model’s original likelihoods.
The key picks which set to use, and the model then makes a fresh random choice from that set. OpenAI says a detector holding the same key and matching settings can check whether a text follows the secret pattern more often than chance would explain.
OpenAI says this depends on the model having different ways to say something. It says there is less room when an answer must be very factual or precise, such as a math answer, or when the model is asked to reproduce supplied text unchanged, and that short passages and code are also harder.
The help center says the EU Code of Practice on the Transparency of AI-Generated Content does not require watermarks in outputs shorter than 200 tokens, about 150 words in English, or in code snippets.
What OpenAI Reports on Detection
OpenAI says “strong performance under ideal conditions does not guarantee reliable detection in everyday use,” and shows evaluations that illustrate the limits. It reports its length and language figures at a target false positive rate of 1%.
On length, OpenAI says its detector identified watermarks in about 80% of 200-token passages and about 95% of 400-token passages for content such as psychology. It says detection was substantially lower for content such as mathematics, where there is less flexibility in word choice.
On editing, OpenAI says that in an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%, and replacing 25% of words reduced it to 17%. OpenAI says these limits contribute to its decision to give initial detector access only to approved researchers and expert organizations.
On language, the help center reports a test across all 24 official EU languages: 500 synthetic English prompts, translated into the other 23. At a 1% false positive rate, it says Spanish had the highest detection rate (69.0%) and Romanian the lowest (42.2%).
OpenAI says the watermark has an adjustable strength setting, and that it raised the strength for languages with detection rates below 60%. The help center says the light blue portions of the chart’s bars show the resulting gains; it does not give those gains as numbers in the text this publication read.
What OpenAI Reports on Quality and Speed
OpenAI says that across the benchmarks it uses to assess Astra, its latest frontier model, it does not see meaningful performance differences with and without watermarking. Its post lists eight benchmarks; for GPQA Diamond it reports 94.44% unwatermarked and 93.94% watermarked, and for Terminal-Bench 4.0, 53.90% and 56.06%.
The help center says the differences fall within the noise OpenAI typically sees across evaluation runs, that earlier tests in ChatGPT showed no change in thumbs-down rates or other product measures, and that the impact on model speed is negligible.
What OpenAI Says a Watermark Does Not Tell You
OpenAI sets out several limits. It says a watermark does not measure human contribution: it can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment or editing went into it. It says a watermark does not establish ownership or responsibility, and does not identify the user.
It also says a watermark does not verify accuracy. And it says “the absence of a detected watermark does not prove human authorship”: text may be too short, edited or translated, may come from an unsupported model, may predate watermarking, or may come from another company’s tools.
The help center adds that watermarks do not replace visible labels or other disclosures, and that OpenAI cannot advise customers on their specific legal obligations.
What the Technical Report Adds
The 20-page report, written by authors from the University of Pennsylvania, Yale and OpenAI, says it provides “the mathematical details” of textGrain. Its abstract says the method couples token generation to keyed randomness through an optimal transport problem, and explains how to set a budget for the sampling entropy lost in exchange for a watermark signal.
The report says the detector “requires only the generated text and the secret key and does not need to know the budget used during generation.”
The report is also explicit about its own assumptions. It states that the conditional false positive rate is the chosen level “under these assumptions,” and that a fixed deployed key and finite precision arithmetic “require empirical calibration checks; the idealized null calculation does not by itself guarantee the same error rate for every key or application.”
OpenAI says the report will be updated with additional details in the coming weeks.
The Structural Read
The announcement gives three audiences three different settings. API customers choose, per project or organization, and OpenAI says the watermark is off by default. Eligible ChatGPT and Codex users across all plans in the EU are covered by what OpenAI says it is introducing over the coming weeks. Detector access goes first to approved researchers and expert organizations.
OpenAI pairs each capability with a limit. It says detection depends on text length and on how much room the text leaves for word choice, that editing weakens the signal, and that a watermark does not measure human contribution, establish ownership, identify the user or verify accuracy.
The technical report states its own assumptions. It says its false positive calculation is idealized and that a fixed deployed key and finite precision arithmetic require empirical calibration checks. OpenAI says the report will be updated with additional details in the coming weeks.
OpenAI — Our approach to EU text provenance rules, 5 October 2026
“The absence of a detected watermark does not prove human authorship.”
Three Implications
TEXT AND IMAGES ARE HANDLED DIFFERENTLY OpenAI says its verification tools for images and audio stay publicly accessible, while the text detector is limited at launch to approved researchers and expert organizations. It gives the risk of missed watermarks and false positives as its reason.
THE CHOICE SITS WITH API CUSTOMERS OpenAI says the API opt-in lets customers decide “how watermarking fits their transparency obligations and the experiences they provide to users.” Its help center adds that watermarks do not replace visible labels or other disclosures, and that OpenAI cannot advise customers on their legal obligations.
WHAT REMAINS UNKNOWN This publication found no independent replication of OpenAI’s figures in the three documents, and OpenAI gives no date for the EU rollout beyond the coming weeks, nor for cloud-partner availability or the open-source release. This publication did not test the detector.
What Is Not Established
Every performance figure above comes from OpenAI’s own evaluations. This publication found no independent replication in the three documents. OpenAI says detector access is initially limited to approved researchers and expert organizations, and that it is not making the detector public at launch.
OpenAI says textGrain matched or exceeded the other approaches it tested. The post gives no figures for that comparison, and this publication does not assess it.
OpenAI gives no date for the EU rollout beyond “the coming weeks,” none for cloud-partner availability, and none for the open-source release. The help center says availability may vary by output and by partner.
This publication read the three OpenAI documents only. It did not test the detector, read the text of the EU AI Act or the Code of Practice, or seek a response from OpenAI, so the descriptions of those texts are OpenAI’s own.
The Bottom Line
OpenAI says it is opening text watermarking as an API opt-in worldwide from 5 October and adding it to ChatGPT and Codex in the EU over the coming weeks, with the detector limited to approved researchers. Its own figures show detection falling with shorter text and with edits, and it says the absence of a detected watermark does not prove human authorship. This publication verified none of it independently.
91,000+ executives read Business Engineer for the AI strategy frameworks cited by ChatGPT, Claude, and Perplexity.
A note on sourcing. We worked from OpenAI’s post, help-center article, and technical report of 5 October 2026 and read nothing beyond those three documents. We did not test the detector, did not consult the text of the EU AI Act or the EU Code of Practice, and did not seek a response from OpenAI. The results and capabilities described are OpenAI’s own unverified claims, not findings we checked ourselves. Nothing here constitutes a forecast, legal guidance, or investment advice.
Sources: OpenAI post ‘Our approach to EU text provenance rules’









