Products·3 min read
By BitsMindsSource: OpenAI

OpenAI Watermarks ChatGPT Text in the EU With textGrain

OpenAI is adding an invisible watermark called textGrain to ChatGPT and Codex text in the European Union to meet the AI Act’s labelling rule. It catches about 95% of untouched 400-token passages, but only 17% once a quarter of the words are swapped for synonyms. API customers elsewhere can opt in.

A hidden watermark in ChatGPT text A printed page of text lies on an EU-blue desk ringed by faint gold stars. A round detector lens over the page shows the same lines as a coloured grain of marked words, with the OpenAI logo surfacing inside the lens. TEXTGRAIN EU · AI ACT BITSMINDS.COM
Share:

Text written by ChatGPT in the European Union will soon carry a hidden signature. In a post on Monday, OpenAI said it is rolling out textGrain, an invisible watermark for text from ChatGPT and Codex, across every plan in the EU “over the coming weeks”. The trigger is Article 50(2) of the AI Act, which requires AI-generated output to be marked in a machine-readable way and detectable as artificial. Systems already on the market have until 2 December to comply.

textGrain does not insert hidden characters. Where several words would fit a sentence equally well, a secret key combined with the preceding words nudges the model towards one of them. No single choice gives anything away, but over a long enough passage the pattern becomes statistically detectable by anyone holding the key. Following the EU Code of Practice, passages under 200 tokens are left out, and OpenAI says it saw no meaningful difference across eight benchmarks with the watermark switched on.

Easy to weaken

OpenAI’s own numbers, reported by ActuIA, show how fragile text watermarks remain. At a 1% false-positive rate, the detector catches about 80% of 200-token passages and about 95% of 400-token ones in its English test set. Swap one word in ten for a synonym and detection falls to as low as 66%; swap one in four and it drops to 17%. Maths scores around 60% even untouched, and other EU languages trail English, from 42% for Romanian to 69% for Spanish. Heavy paraphrasing or translation removes the signal altogether.

The company is explicit about what a hit does and does not mean. According to CellCog, the post says the watermark “does not measure human contribution” and that its absence “does not prove human authorship”, a caveat aimed at teachers and employers hoping for a reliable AI detector.

Who can check it

For now, very few people. Access to the detector is limited to approved researchers and partner institutions, with Cornell, ETH Zurich and the Slovak institute KInIT named, although the Code of Practice expects it to reach regulators, law enforcement, media and fact-checkers eventually. Outside the EU, the watermark is optional: API customers anywhere can switch on “Text provenance” in their organisation or project settings for selected models from 5 October. It is off by default, and there is no per-request parameter yet.

The rival labs have split on scope. Anthropic chose to watermark Claude’s text worldwide in August, arguing there was no durable way to fence a watermark to one region, while Google open-sourced SynthID Text back in 2024. OpenAI has gone the narrowest route the law allows, which means a ChatGPT answer written in Paris will carry the mark and the same answer written in Boston will not.

More on ChatGPT

Evergreen coverage we keep current — start here.

Want AI news before everyone else?

The morning's most important AI stories, straight to your inbox. No fluff.

Related Articles