NewsMacroOpenAI Embeds Invisible 'textGrain' Watermark in ChatGPT Outputs Across Europe to Comply With EU AI Act

OpenAI Embeds Invisible 'textGrain' Watermark in ChatGPT Outputs Across Europe to Comply With EU AI Act

Author: Blockonomi·

Key Takeaways

  • •OpenAI's textGrain watermark is mandatory by default for ChatGPT outputs in the EU, while API users globally can opt in and standard users outside the bloc have it disabled by default.
  • •The system embeds a statistical signature directly into word selection rather than hidden characters or spacing, so common evasion tactics like stripping invisible elements cannot remove it.
  • •OpenAI's internal evaluations showed detection rates of about 66% for unmodified 150-word responses and roughly 92% at 300 words, but replacing one in every four words with synonyms cut accuracy to just 17%.
  • •Access to the detector is limited to vetted researchers and specialized organizations, and OpenAI has not disclosed whether or when it will become publicly available.
  • •A negative detection result does not confirm human authorship, because brief, edited, or translated text and content from competing AI platforms can evade the system.
OpenAI Embeds Invisible 'textGrain' Watermark in ChatGPT Outputs Across Europe to Comply With EU AI Act

OpenAI has begun deploying an invisible statistical watermark, known as textGrain, across ChatGPT and Codex outputs in European Union territories. Announced on October 5, the rollout is framed by the company as a direct response to the transparency obligations imposed by the EU AI Act. The move also extends OpenAI's existing content provenance efforts, which already allow users to verify whether images and audio files were produced with its tools. The company detailed the initiative in an official announcement and a post on X:

We're expanding our approach to content provenance to include text in response to EU regulatory requirements, while recognizing the significant limitations of current text watermarking technology. Our tools already help verify whether an image or audio file was created with our…

— OpenAI (@OpenAI) October 5, 2026

How textGrain Works

The technology functions by subtly influencing the language model's word selection to create a concealed statistical signature. A companion detection application then analyzes text to identify that signature. According to OpenAI, the approach does not rely on hidden characters, invisible spacing, or unusual punctuation marks. As a result, typical evasion tactics — such as removing hidden characters from copied text — will not eliminate the watermark, because the signature is woven directly into the language patterns themselves.

How Resilient Is the Watermark Against Modification?

Detection effectiveness varies significantly based on content length. OpenAI quantifies text using tokens — word fragments that language models interpret with approximately one token equal to three-quarters of a standard English word. During internal evaluations, the detection system successfully identified roughly 66% of unmodified responses containing approximately 150 words. When content reached around 300 words, the success rate increased to approximately 92%.

Modifying content rapidly undermines the watermark's effectiveness. For passages of 300 words, substituting one in every 10 words with a synonym reduced detection accuracy from 92% to 66%. When one word in every four was replaced, detection plummeted to merely 17%. OpenAI's internal findings demonstrate that the system faces significant challenges once text undergoes editing, condensing, or paraphrasing — a constraint consistent with the "significant limitations of current text watermarking technology" the company itself acknowledged at launch.

The company additionally noted that watermark implementation had minimal impact on performance metrics for its newest model, GPT-6 Astra.

Why the Detection Tool Remains Private

OpenAI has chosen not to make the detector broadly available immediately. Access will instead be granted exclusively to vetted researchers and specialized organizations. The company clarifies that a positive detection result does not disclose user identity, input prompts, or conversation details.

A negative finding carries little certainty as well. Brief, modified, or translated content can evade the detector without triggering alerts. Content generated by competing AI platforms will likewise not activate the system, as it searches exclusively for OpenAI's proprietary signature. OpenAI explicitly stated that failing to detect a watermark does not confirm human authorship.

Visual and audio content follow a separate verification process. Users can already upload those file types to OpenAI's publicly accessible verification platform to scan for its SynthID watermark. Text outputs have no equivalent public check for now, as detector access remains confined to vetted organizations.

Regional Scope and Regulatory Context

For territories outside the European Union, the ChatGPT watermark remains disabled by default for standard users. API clients worldwide, however, can activate it for specific models through their project or organizational preferences. In practice, the watermark is mandatory for ChatGPT outputs within the EU, while API users globally can switch it on voluntarily through their settings — default-on for EU users, opt-in everywhere else.

The deployment follows the EU's enforcement of AI Act transparency provisions, which began in August. OpenAI positioned the watermark as an element of its continued response to regulatory requirements. The company also referenced broader industry data in its statement: TRM Labs research indicates that criminal exploitation of AI tools increased 40% year-over-year.

OpenAI has not disclosed whether or when the detection tool might become publicly available. How the system fares against real-world editing, condensing, and translation, and how widely API operators outside the EU opt in, remain open questions as the rollout proceeds. For now, the EU implementation and restricted access for approved research groups and expert institutions represent the existing scope of the initiative.

Source: Blockonomi