OpenAI textGrain watermarks ChatGPT text under EU AI Act
OpenAI's textGrain watermark is opt-in for API users from October 5 and coming to ChatGPT and Codex in the EU. It flags 95% of 400-token passages.
4 min read

By the numbers
- of 400-token passages detected, at 1% false positives
- 95%
- of 200-token passages detected
- 80%
- detection once a quarter of the words are replaced
- 17%
- when the EU AI Act's Article 50 began to apply
- Aug 2, 2026
OpenAI has started adding an invisible watermark to text its models write. The system is called textGrain. From October 5, 2026, API customers anywhere can switch it on for their projects, and it stays off unless they do, Unite.AI reports. ChatGPT and Codex users in the European Union will get the watermark automatically in the coming weeks. The move answers an EU AI Act rule that makes AI-generated content identifiable by machines.
What OpenAI is switching on
The rollout comes in three parts, according to Unite.AI:
| Who | What changes | When |
|---|---|---|
| API customers, worldwide | Can opt in to watermarking; it is off by default | From October 5, 2026 |
| ChatGPT and Codex users in the EU | Watermarks added on every plan | In the coming weeks |
| Researchers and expert organizations | Can apply to use the detector, approved case by case | Applications opened October 5, 2026 |
Users outside the EU will not get watermarked ChatGPT or Codex text under this plan. Detector access runs under the EU's Code of Practice on transparency for AI-generated content, Unite.AI says. Crypto Briefing reports that OpenAI signed that code in June 2026.
How textGrain works
A text watermark hides a pattern in which words a model chooses. A reader cannot see it, but a detector can test a passage for it. Unite.AI says textGrain builds this statistical signal into the model's word selection.
How well detection works depends on the length of the text and how much it was changed. These are the figures Unite.AI reports, measured at a 1% false-positive rate:
| Test | Passages detected |
|---|---|
| 200-token passage | 80% |
| 400-token passage | 95% |
| 10% of words replaced | 66% |
| 25% of words replaced | 17% |
A token is a short chunk of text, often a whole word or part of one. A 1% false-positive rate means about one in 100 human-written passages would be wrongly flagged.
Edits are the weak point. "Text is easy to tweak, paraphrase or run through another tool, and each edit can weaken a watermark's signal," Crypto Briefing writes. OpenAI held back an earlier version for this reason. Crypto Briefing reports that a 2024 prototype was "about 99.9% effective," but OpenAI delayed its release over concerns about how robust it was.
What a watermark can and cannot prove
OpenAI lists clear limits, according to Unite.AI. A watermark cannot show that text is accurate, and it cannot establish who owns it. A missing watermark does not prove a human wrote the text. Detection is unreliable on short passages and on edited or translated text. It also fails on text from models the detector does not cover, including competitors' models.
Crypto Briefing raises a fairness concern too. People who write in a second language often use AI to polish their work, and watermarks could flag them.
Why now: Article 50 of the EU AI Act
Article 50 of the EU AI Act requires providers of generative AI to mark generated content in a machine-readable way. It has applied since August 2, 2026, and Crypto Briefing says it covers anyone serving EU users. City A.M. notes an exception: AI that only assists with editing, without substantially changing the original meaning, does not have to mark its output.
How rivals compare
OpenAI is not the first to watermark text. These reports describe the field:
| Company | Approach | Source |
|---|---|---|
| Anthropic | Invisible watermarks on Claude text worldwide since August 2, 2026 | City A.M., Crypto Briefing |
| SynthID-Text watermarking in Gemini since 2024 | Crypto Briefing | |
| xAI | Refused to sign the EU transparency code, though still bound by the AI Act | City A.M. |
City A.M. says Anthropic's marks survive copying and pasting, and that human-written text edited by Claude may carry them. Watermarks have drawn scrutiny before: SynthID's image watermark turned out to carry a 64-bit ID field, according to a research paper reported last month.
What this means for developers
If you build on OpenAI's API, decide whether to switch textGrain on. It is off by default. If your product serves EU users, ask your legal team whether Article 50 makes you responsible for marking AI output yourself. The API setting gives you one way to mark that output.
Do not treat the detector as a lie detector. Short or edited text slips through, and a missing watermark proves nothing. Any school, hiring or moderation tool that reads it as proof of human authorship will make mistakes.
If your team uses ChatGPT or Codex in the EU, expect text copied from them to carry the mark. Heavy editing weakens it, but light edits may not.
Watch who gets detector access. For now only approved researchers can test text. If OpenAI opens the detector wider, watermark checks could start appearing in publishing and education tools.
Sources
Related articles

OpenAI Agents API adds computer use in a hosted browser
OpenAI's Agents API, in public beta since September 10, gained computer use at DevDay on September 29, 2026: agents can drive an OpenAI-hosted browser.

GPT-6 Astra is generally available on Bedrock and Copilot
GPT-6 Astra is GA on Amazon Bedrock at $10 per million input tokens, and in GitHub Copilot for Pro+, Max, Business and Enterprise plans.

Pentagon adds ChatGPT Mil and Grok to GenAI.mil, with Anthropic absent
The Pentagon put ChatGPT Mil and Grok for Government on its GenAI.mil portal on August 31, 2026. Both cleared Impact Level 5. Anthropic is still missing.
The daily brief
Three to five stories a day, and what each one means for the people who build software. Free, no spam.