OpenAI will watermark Codex and ChatGPT text in the EU

OpenAI will add invisible statistical watermarks to eligible ChatGPT and Codex text in the EU, while API customers worldwide can opt in for select models.

OpenAI will add invisible statistical watermarks to eligible ChatGPT and Codex text in the European Union on all plans. OpenAI's 2026-10-05 announcement did not give an exact EU rollout date. It did say that API customers worldwide could opt in to watermarked output for select models from 2026-10-05, with the API setting off by default.

Key facts about OpenAI textGrain

  • OpenAI announced on 2026-10-05 that it would add textGrain to eligible ChatGPT and Codex text in the EU across all plans.
  • OpenAI is not making text watermarking a global ChatGPT or Codex default at launch.
  • API customers worldwide can opt in to watermarked output for select models from 2026-10-05. The API setting remains off by default.
  • textGrain adds an invisible statistical signal to the model's word choices. It does not identify a user, account, prompt, or conversation.
  • Detector applications opened on 2026-10-05. OpenAI said access would be limited to approved researchers and expert organizations on a case-by-case basis.
  • OpenAI plans to release textGrain as open-source software.

How OpenAI textGrain embeds the signal

When a language model generates text, it samples each next token from a probability distribution conditioned on the preceding text. The textGrain technical report says the watermark changes this sampling with pseudorandom values derived from a secret key and the preceding context.

The method formulates the change as an entropy-constrained optimal transport problem. Gumbel random variables supply the costs, while Kullback-Leibler regularization limits the departure from ordinary sampling. The report defines the strength parameter as an entropy budget, so it measures the average sampling randomness exchanged for the watermark signal.

TextGrain applies transport to keyed vocabulary blocks. Tokens keep their relative probabilities inside each block, which reduces the optimization size. The detector needs the generated text and secret key. It does not need the original prompt, model weights, or generation-time entropy budget.

How OpenAI textGrain performs on detection tests

OpenAI tested detection at a 1% target false-positive rate. For psychology answers from the ELI5 dataset, detection was about 80% for 200-token passages and about 95% for 400-token passages. More constrained subjects, such as mathematics, produced lower detection rates because they offer fewer word choices.

Editing weakens the signal quickly:

Evaluation

Detection rate

200-token psychology passage

about 80%

400-token psychology passage

about 95%

400-token passage after replacing 10% of words with synonyms

about 66%, down from about 92%

400-token passage after replacing 25% of words with synonyms

17%, down from about 92%

OpenAI also compared its Astra frontier model with and without watermarking. The Artificial Analysis Intelligence Index score was 49.57 unwatermarked and 49.76 watermarked. GPQA Diamond was 94.44% unwatermarked and 93.94% watermarked. OpenAI reported no meaningful performance difference across the benchmark set it used.

What an OpenAI text watermark can prove

A positive signal can indicate that an OpenAI system generated or processed part of a passage. It cannot measure human contribution, establish ownership or responsibility, identify the user, or verify accuracy. A negative result does not prove human authorship. The text may be too short, edited, translated, generated by an unsupported model, or produced before watermarking began.

OpenAI says the EU rollout responds to the EU AI Act requirement that generated text be identifiable in a machine-readable way. The company is keeping the detector out of public access while it evaluates false positives, false negatives, and responsible uses. Its image and audio verification tools remain public.

Sources

Last verified: 2026-10-06.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.