AERIOXFLUX
← Frontier Labs
Frontier Labs · openai

OpenAI Will Watermark ChatGPT Text in the EU, and Says It Breaks

textGrain hides a statistical signature in ChatGPT and Codex output for European users. OpenAI's own numbers show how quickly light editing erases it.

Flux Desk·2026-10-10·5 min read

OpenAI is about to start marking the words ChatGPT writes, but only for some of its users, and with a frank warning attached about how little the mark survives.

The company said on October 5 that it will add an invisible watermark to text generated by ChatGPT and Codex for users in the European Union, rolling out "in the coming weeks" across plans there. The technique is called textGrain. It is not a global default. Outside the EU, developers anywhere can opt in through the API for supported models, but it ships switched off.

How textGrain works

There is no hidden character, no metadata tag and no invisible Unicode. textGrain nudges the model's word choices, using a secret key, so that the output carries a statistical pattern a detector can later look for. A reader sees ordinary prose. Copying and pasting carries the pattern with it, because the pattern is the words.

OpenAI is explicit about what the mark does not do. A detected watermark does not reveal who generated the text, which account, what prompt or what conversation. It is not a tracking code tied to identity. It also cannot tell anyone how much of a finished piece a human wrote or edited.

Detector access is narrow at the start. OpenAI is taking applications and will initially limit the detector to approved researchers and expert organizations. Schools, publishers and employers will not be pasting essays into a public checker on day one.

The numbers OpenAI published against itself

The most useful part of the announcement is the part that undercuts it. In OpenAI's own evaluation on 400-token passages, detection ran at about 92%. Replacing 10% of the words with synonyms dropped that to about 66%. Replacing 25% dropped it to 17%.

Length matters too. At a 1% false-positive target, detection was about 80% for 200-token psychology answers versus about 95% for 400-token ones. Math answers were harder to mark, because a model has less freedom in word choice when the right answer constrains the wording. The tests drew on the ELI5 dataset of math and psychology questions.

OpenAI also says the absence of a watermark proves nothing. Text can be too short, edited or translated for reliable detection. In practice, that makes textGrain a one-way signal: a positive result is meaningful; a negative one is not evidence of human authorship.

On quality, OpenAI says the watermark does not meaningfully affect GPT-6 Astra, with benchmark results broadly similar when it is enabled.

Why Europe, and why now

The EU-only scope reads as regulatory rather than philosophical. The bloc's AI rules push providers toward marking machine-generated content, and a company that rolls out a mark in one jurisdiction while keeping it optional elsewhere is telling you where the pressure comes from. BleepingComputer's report on the announcement does not tie it to a specific article or deadline, and OpenAI framed it as a transparency step, so treat the exact legal trigger as inferred rather than stated.

Some details remain unsettled in the coverage. It is not yet clear whether EU users will be able to turn the watermark off on their own accounts, and the announcement does not list which API models support the opt-in.

What this changes

For most EU users, very little they will notice. Their ChatGPT answers will read the same. The change sits downstream, with the institutions that eventually get detector access.

That is where the published numbers matter. A detector that catches unedited, longer passages with high confidence but loses most of its signal after a quarter of the words are swapped will catch careless use, not determined use. Anyone paraphrasing, translating or running output through another model will mostly fall outside it. And because math and other constrained outputs are harder to mark, the watermark is weakest exactly where cheating on problem sets would be tempting.

It is still a meaningful precedent. A frontier lab is shipping text watermarking at production scale, publishing its failure rates and keeping identity out of the signal. That is a more defensible design than the AI-text detectors already sold to schools, which guess from style and have no key to check against.

The bigger picture

Provenance for AI images has moved toward metadata and signed credentials. Text never had that option; a paragraph has no file header. Statistical watermarking is the only real lever, and OpenAI's own data shows how short that lever is.

The honest framing is the one OpenAI chose: textGrain is a partial signal, not a lie detector. The open questions are who gets the detector, how they are told to read a negative result, and whether "the watermark wasn't found" becomes a claim people make in disputes it cannot settle. OpenAI has already said it cannot settle them. The test is whether the people holding the detector listen.

#openai#watermarking#textgrain#eu#ai-detection

The state of AI, in flux.

The directory + magazine for AI tools and the workflows people use to make money with them.

🔥 The Sauce Drop

The week's highest-earning AI workflows, in your inbox.

Some outbound links are affiliate links — Flux may earn a commission at no cost to you; this never affects rankings. Earnings figures are self-reported and not guarantees of income; most people earn less, some earn nothing.