Analysis

OpenAI will watermark ChatGPT and Codex text in the EU: what textGrain means for enterprises

1AYM is an OpenAI Select Partner.

Published . Vendor facts checked on against each vendor’s own pages, listed at the end. Plans, prices and availability change. Neither OpenAI nor Anthropic has reviewed this analysis.

The short version

The sections below take the EU rollout, the API opt-in and the detector and its limits in turn, each with what to check before you rely on any of it.

The EU rollout in ChatGPT and Codex
Over the coming weeks, eligible ChatGPT and Codex text generated in the EU will carry a statistical watermark, on all plans. It is not a global default.
The API opt-in
From 5 October 2026, API customers anywhere can switch on watermarked text for select models. It is off by default, so a product serving EU users has a decision to make.
The detector and its limits
Only approved researchers and expert organisations can apply for the detector. In OpenAI's tests, replacing 10% of words cut detection from about 92% to 66%, and 25% cut it to 17%.

ChatGPT and Codex text in the EU gets an invisible watermark

What was announced

OpenAI published its approach to the EU's text provenance rules on 5 October 2026. Over the coming weeks it will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union, for users across all plans, in the EU only. OpenAI says it is not making text watermarking a global default at launch, and that the regional approach gives it room to learn from real use.

The technology is called textGrain. OpenAI describes it as an invisible statistical signal added to the model's word choices, which a detector can then look for. It has published a technical report, says it will update it in the coming weeks and plans to release the technology as open source.

OpenAI ties the change to the EU AI Act, which it says requires generative AI providers to make generated text identifiable in a machine-readable way. The European Commission's guidance on Article 50 says providers must mark AI-generated audio, image, video and text in a machine-readable format so that it can be detected as artificially generated. Article 50 has applied since 2 August 2026. For systems placed on the market before that date, the marking and detection obligation applies from 2 December 2026.

What it means for enterprises

A company with staff on both sides of the EU border will now produce two kinds of ChatGPT text: marked where it was generated in the EU, unmarked elsewhere. Nothing visible changes for the person typing, and OpenAI describes no setting for it in its announcement. The practical effect is that documents, emails and code comments written with ChatGPT in an EU office can later be tested for an OpenAI watermark by whoever holds detector access.

OpenAI is clear about what the mark does not carry. It says a watermark does not identify the user, and does not associate a person, organisation, account, prompt or conversation with the text. On OpenAI's account, that limits the privacy concern, and it also means the mark cannot be used to trace a leak to an employee.

On quality, OpenAI reports no meaningful performance difference with and without watermarking across the benchmarks it uses for its Astra model, and publishes the paired scores. Those are OpenAI's own evaluations. A team with a sensitive workload, such as structured output or code, can run its own comparison before assuming the same.

Before you switch it on

Where your users are
List which teams use ChatGPT and Codex from inside the EU. Their output is the output that will be marked.
Staff notice
Tell EU staff that text they generate will carry a machine-readable mark, and what it does and does not reveal.
Policies that assume no mark
Review any rule or contract that treats AI-assisted text as indistinguishable from human text. In the EU that assumption is weakening.
Quality on your own work
If output quality matters to a workflow, test it before and after the rollout reaches your workspace.

Sources: [1] [2]

On the API it is opt-in, worldwide, and the decision is the customer's

What was announced

From 5 October 2026, API customers around the world can opt in to watermarked text outputs for select models. Text watermarking remains off by default in the API. OpenAI says this lets customers decide how watermarking fits their own transparency obligations and the experiences they provide to users.

OpenAI also says it is working with cloud partners to make watermarking available for OpenAI model outputs accessed through their services in the coming weeks.

What it means for enterprises

This is the part that lands on businesses. A company that builds an assistant, a drafting tool or a support bot on the API and offers it under its own name is the one that decides whether its text is marked. The Commission's guidance defines a provider as a body that develops an AI system, or has one developed, and places it on the EU market or puts it into service under its own name or trademark, wherever that body is established. A UK or US company whose product's output is used in the EU can fall within that.

The same guidance sets out exceptions and a narrow exemption: for example where the system only assists with standard editing, and for outputs used in business-to-business or industrial contexts where the conditions in the Commission's guidelines are met. Whether a given product is in scope is a legal question. OpenAI's switch is one way to meet a marking obligation where there is one, and the dates above set the timetable. By our count, 2 December 2026 is under eight weeks from the date of this post.

The Commission also describes a voluntary Code of Practice on Transparency of AI-generated Content, which it and the AI Board have assessed as adequate for showing compliance, and says about 190 companies and organisations had signed it by the end of July 2026. Companies that comply by other means have to show those means are adequate. The guidance says fines can reach 15 million euros or 3% of total worldwide turnover.

None of this is legal advice. It is a prompt to put the question to counsel now, with the product list in hand.

Before you switch it on

Products with EU users
List every product or internal tool on the OpenAI API whose text reaches people in the EU.
Provider or deployer
Ask counsel which role you hold for each one under Article 50, and whether an exception applies.
Supported models
Check whether the models you use are among the select models that support the opt-in. OpenAI's announcement does not list them.
Access through a cloud provider
If you reach OpenAI models through a cloud provider, ask that provider when the watermark option arrives.
A second model vendor
If a product uses more than one model vendor, ask each how its text is marked. One vendor's mark does not cover another's output.

Sources: [1] [2] [3]

The detector is restricted, and the mark fades when text is short or edited

What was announced

OpenAI has opened applications for access to its text watermark detector. Access is at first limited to approved researchers and expert organisations, granted case by case. The tool reports whether it detects an OpenAI watermark, without identifying the user or revealing prompts or conversations. OpenAI says that, given the risk of missed watermarks and false positives, it is not making the detector public at launch.

It publishes the reasons. At a target false positive rate of 1%, its detector found the watermark in about 80% of 200-token passages and about 95% of 400-token passages for content such as psychology, with substantially lower rates for content such as mathematics, where there is less freedom in word choice. In a test on 400-token passages, replacing 10% of the words with synonyms cut detection from about 92% to 66%, and replacing 25% cut it to 17%.

OpenAI lists what a detection result cannot show. A watermark does not measure how much a person contributed, establish ownership or responsibility, identify the user or verify accuracy. And a missing watermark does not prove a person wrote the text: it may be too short, edited or translated, come from an unsupported model, predate watermarking or come from another company's tools.

What it means for enterprises

For an employer, a university or a publisher, the conclusion follows from OpenAI's own numbers. A result that falls from about 92% to 17% after a quarter of the words are swapped is unlikely to carry a disciplinary case, an academic misconduct finding or a contract dispute. OpenAI's decision to withhold the detector from the public is consistent with that.

It also means a business cannot check its own suppliers' or candidates' text for an OpenAI watermark today. Organisations that have bought third-party AI text detectors should note that the announcement does not give those tools access to the detector.

What the watermark does do is let a provider show a regulator that its output is marked. That is a compliance function. It is a different thing from a tool for deciding who wrote a document, and policies are safer when they keep the two apart.

Before you switch it on

HR and academic policies
Do not treat a watermark result, or the lack of one, as proof of authorship. Write that into the policy.
Detector vendors
Ask any AI text detection supplier what signal their product reads, and what their false positive rate is on edited text.
Disclosure by rule
Where it matters that readers know AI was used, require a visible statement. A hidden mark few can read does not inform a reader.
Research access
If your organisation evaluates provenance tools, OpenAI's announcement links the application form for detector access.

Sources: [1]

Where the market is heading: marking by region, and labels that people can see

OpenAI already marks images and audio and offers public verification for them. Text is the hard case, because it is so easily rewritten, and OpenAI says its approach has to reflect the practical limits of current technology. A regional rollout with a restricted detector is what a provider does when the law requires a mark and the technique is not yet reliable enough to hand to everyone.

For buyers, the practical effect is that provenance now varies by geography and by vendor. The same model can produce marked text in one country and unmarked text in another, and each vendor's mark is its own. A company running more than one assistant will be dealing with more than one scheme.

The machine-readable mark is also only one of the Article 50 duties. The Commission's guidance says deployers must clearly label AI-generated or manipulated text published to inform the public on matters of public interest, unless it has had human review or editorial control, and that spell-checking or other formal checks do not count as review. That duty sits with the organisation publishing the text, and no vendor's hidden mark discharges it.

Sources: [1] [2] [3]

What is not known yet

The facts above come from OpenAI's announcement of 5 October 2026 and the European Commission's pages on Article 50 and the Code of Practice. They leave these points open.

The rollout date
OpenAI says the coming weeks. It gives no date, and does not say whether the EU rollout has begun.
What counts as eligible
The announcement does not define eligible ChatGPT and Codex text, or say how being in the EU is determined for a travelling user or a multinational workspace.
Which API models
It says select models and does not list them, or name the setting that switches the watermark on.
Enterprise controls
It does not say whether a ChatGPT Enterprise administrator in the EU can change the default, or one outside the EU can switch it on.
Translation and code
OpenAI says translated text may not be detected reliably and that it is still studying editing and translation. It gives no detection figures for code.
Independent tests
Every detection and quality figure is OpenAI's own. No independent evaluation is cited.

Sources: [1] [2]

For engineers: how the signal behaves, and what to test before switching it on

A statistical signal in word choice

textGrain biases the model's word choices to carry a signal that a detector scores afterwards. Detection therefore depends on how much text there is and how much freedom the model had. OpenAI's figures at a 1% target false positive rate are about 80% for 200-token passages and about 95% for 400 tokens on psychology questions, and substantially lower on mathematics. Short, constrained outputs such as labels, extracted fields and formulae are the weakest case.

Sources: [1]

Anything downstream that rewrites the text weakens it

Synonym replacement of 10% of words took detection on 400-token passages from about 92% to 66%, and 25% took it to 17%. A pipeline that post-processes model output, by summarising, translating, templating or passing it through a second model, should be assumed to degrade the mark. If marking is a requirement, apply it at the last generation step and test what survives your own post-processing.

Sources: [1]

Evaluate before opting in

OpenAI reports paired benchmark scores for its Astra model with and without watermarking and no meaningful difference between them: for example 72.80% unwatermarked against 71.68% watermarked on DeepSWE v1.1, and 53.90% against 56.06% on Terminal-Bench 4.0. Run your own evaluation set both ways, particularly for structured output, and make the watermark a configuration value per region or tenant so that EU and non-EU traffic can differ.

Sources: [1]

Record the decision

Log which requests were made with watermarking on, by product and model, and keep the reasoning for each product's setting with its risk assessment. That record is what a compliance team will ask for, since the detector itself is not available to check after the fact.

Where 1AYM fits

Setting up and rolling out ChatGPT Enterprise is core 1AYM work, and 1AYM is an OpenAI Select Partner. For a workspace with EU staff, this change belongs in the same place as any other after launch day: the note to staff, the policy line and the training that explains what the mark is.

For a product built on the API, the decision and the evidence behind it are part of running AI in production, which is what our Production AI systems work is for: the inventory of what serves EU users, the evaluation with the watermark on and off, the configuration and the record. It does not need a large engagement: 1AYM takes small fixed-scope statements of work as well as larger builds.

Sources

  1. [1]OpenAI, Our approach to EU text provenance rules, 5 October 2026 (checked 9 October 2026)
  2. [2]European Commission, Transparency obligations under Article 50 of the AI Act, last updated 24 July 2026 (checked 9 October 2026)
  3. [3]European Commission, Code of Practice on Transparency of AI-generated Content (checked 9 October 2026)

Frequently asked questions

Is OpenAI watermarking ChatGPT text?

In the European Union, yes, over the weeks following 5 October 2026: eligible ChatGPT and Codex text will carry an invisible watermark on all plans. OpenAI says it is not making this a global default at launch.

What is textGrain?

OpenAI's text watermarking technology. It adds an invisible statistical signal to the model's word choices, and a detector looks for that signal to assess whether a passage contains an OpenAI watermark.

Is OpenAI API output watermarked?

Only if the customer switches it on. From 5 October 2026 API customers worldwide can opt in for select models, and watermarking stays off by default.

Can anyone check whether text has an OpenAI watermark?

No. Detector access is at first limited to approved researchers and expert organisations, case by case. OpenAI cites the risk of missed watermarks and false positives.

Does a watermark prove who wrote a piece of text?

No. OpenAI says it does not identify the user or measure human contribution, and that a missing watermark does not prove human authorship. In its tests, replacing 25% of words cut detection to 17%.

When do the EU marking rules apply?

The European Commission says Article 50 of the AI Act has applied since 2 August 2026. For AI systems placed on the market before that date, the marking and detection obligation applies from 2 December 2026.

Further

A product or a workspace with EU users?

Half an hour is enough to list what is affected, what to ask counsel and what to test first.

Last reviewed · 1AYM