Tech Y Cluster AI What OpenAI text watermarking can and can’t prove

What OpenAI text watermarking can and can’t prove

0 Comment 10:30 pm

Illustration of a document with a faint hidden pattern in its text under a magnifying glass

Illustration of a document with a faint hidden pattern in its text under a magnifying glass
Photo: Niabot via Openverse, CC BY-SA

Key takeaways

  • OpenAI's textGrain hides a statistical pattern in the word choices of ChatGPT and Codex text, rolling out in the EU over the coming weeks, with opt-in API access worldwide.
  • In OpenAI's own tests on 400-token passages, detection fell from about 92% for unedited text to about 66% after 10% of words were swapped for synonyms.
  • A missing watermark does not mean a human wrote the text; it may be short, heavily edited or from another company's AI.
  • The detector is not public at launch, and OpenAI points to the chance of both misses and false alarms as a reason.

OpenAI announced textGrain on Monday, October 5, 2026. It is an invisible watermark for text from ChatGPT and Codex. It rolls out in the EU over the coming weeks, and API customers anywhere can opt in starting the same day.

If you are a student, teacher or writer, the question is whether this can get you wrongly flagged as AI. The short answer: a detected watermark points to OpenAI output, a missing one proves nothing, and OpenAI itself says a watermark can’t establish that a person wrote something.

What is textGrain, and who gets it?

textGrain nudges the word choices an OpenAI model makes with a hidden statistical pattern, and a detector checks for it. At launch it is limited to qualifying ChatGPT and Codex users in the EU, on any plan. API customers worldwide can opt in for select models, but it is off by default.

OpenAI also published a technical report, co-written with academics at the University of Pennsylvania and Yale. According to TechCrunch, it describes using a secret key to sort the model’s next-word predictions, so the detector needs only the text and the key. Because the signal lives in the words themselves, it stays when text is copied and pasted.

OpenAI says text watermarking will not be on by default worldwide at launch. The regional approach, it says, lets the company learn from real-world use and feedback. The trigger is regulatory: the EU AI Act’s transparency rules took effect August 2 and require AI providers to mark generated content so other systems can identify it. OpenAI is also working with cloud partners to offer watermarking for OpenAI model outputs on their services in the coming weeks, according to The Verge.

What can a textGrain detection actually tell you?

A positive result means the detector found an OpenAI watermark in the text. That is all. It does not name the user and does not reveal prompts or conversations. OpenAI says it also can’t confirm accuracy, show who owns or is responsible for the text, or gauge how much a person contributed.

That last point matters most for writers. Someone who drafted every idea and asked ChatGPT to tighten one paragraph could carry the same mark as someone who pasted in a one-line prompt. OpenAI says it will keep studying whether watermarks can tell AI assistance from AI authorship. That question is still open.

Anthropic ran into this argument. According to TechCrunch, some Claude users pushed back on Anthropic’s own watermark, arguing that they supplied the instructions, context and decisions and Claude was only the tool. The users were not named.

Does no watermark mean a human wrote it?

No. OpenAI says a detector coming up empty does not show a person wrote the text. It may be too short, heavily edited, or generated by another company’s AI. Most AI text will also never carry an OpenAI mark, since ChatGPT outside the EU is unwatermarked at launch and the API option is off by default.

Other vendors’ marks are separate. Per 9to5Mac, Anthropic’s Claude watermark uses an Anthropic-specific secret key, so its detector can only identify Claude text, not OpenAI’s or anyone else’s. The Verge reports that Anthropic’s approach is based on Google DeepMind’s SynthID for text. Only that outlet says so.

Our read: a watermark check can only ever be one clue. It can say this text came from a tool that marks its output. It cannot say nobody used AI.

How much does editing weaken the watermark?

A lot, at least in OpenAI’s own tests. On 400-token passages, detection was about 92% for unedited text. After 10% of words were replaced with synonyms it fell to about 66%. After 25% it fell to about 17%, a figure reported by 9to5Mac only.

  • Unedited: about 92%
  • 10% of words swapped: about 66%
  • 25% of words swapped: about 17%

Treat these numbers carefully. They come from OpenAI’s evaluation of one passage length and one kind of edit. No independent test has been reported. How the mark holds up against full paraphrasing or other editing tools is not yet reported.

The practical reading is that light human editing can already hide a large share of watermarked text from the detector. That cuts both ways. A mark that disappears under editing is a weak basis for accusing anyone, and it is also easy to lose by accident.

Which kinds of text are harder to detect?

Detection is weaker on three kinds of text: short passages, math answers and translations, according to 9to5Mac and TechCrunch. Math is harder because word choice is less flexible, which leaves less room for a hidden pattern. OpenAI says editing also weakens the signal.

Our read: the signal builds up across many word choices, so a few sentences give a detector little to work with. OpenAI says it will keep studying how well watermarks survive editing and translation.

Who can run the detector, and why isn’t it public?

The detector is not public at launch. Starting October 5, approved researchers and expert organizations can apply to use it, and OpenAI decides case by case under the EU Code of Practice. OpenAI points to the chance of missed marks and wrongful flags as a reason for keeping it closed.

That is a notable admission. OpenAI is saying that even its own detector can be wrong in both directions. It has not published a false-positive rate in the material we reviewed.

OpenAI also claims textGrain “matched or exceeded” approaches such as SynthID for text, and says watermarking caused no meaningful change in model quality. Those are OpenAI’s own results. Outlets differ slightly on benchmarks: The Verge describes similar scores for watermarked and unwatermarked text, while 9to5Mac and TechCrunch say watermarked output scored slightly higher on several.

Why it matters for you

Students and educators. A teacher acting alone cannot run a textGrain check at launch, since the detector is restricted. Even where one exists, OpenAI’s caveats mean a result is a clue, not proof. A clean result clears no one and a hit convicts no one. If you use AI for brainstorming or editing, keep your notes and drafts so you can show your process.

Writers and freelancers. If you use ChatGPT or Codex in the EU, your output may soon carry an invisible mark that survives copy-paste. Whether users will be told is not yet reported. Heavy rewriting weakens the mark, but do not count on that as protection.

Businesses and developers. API customers can opt in to watermarked output worldwide. Companies with EU transparency obligations may want to look at it, though which models support it is not yet reported.

Anyone judging text online. Treat the lack of a watermark as no information at all. The bigger point, in our view, is that watermarking is a compliance tool for marking AI output. It was not built to prove who wrote something.

What we don’t know yet

  • What counts as an eligible EU user, and whether users will be told when output is watermarked.
  • Which API models support watermarking at launch.
  • When OpenAI will release textGrain as open source, which it plans to do.
  • Whether OpenAI will expand watermarking beyond the EU, and what would trigger that.
  • Whether the detector will ever be public, and who gets approved for access.
  • How easily the watermark can be removed by paraphrasing, translation or other tools, beyond OpenAI’s own tests.
  • Whether detectors from different vendors can work together, or each provider needs its own.
  • Whether EU regulators accept this approach as meeting the AI Act, and whether users get any opt-out.

OpenAI says it will update the technical report with more detail in the coming weeks and expects to revisit its approach as technology, standards and evidence evolve. According to TechCrunch, citing a 2024 Wall Street Journal report, OpenAI built a text watermark earlier but held off releasing it, partly over fears users would switch to rivals without one.

Frequently asked questions

Is ChatGPT watermarking its text?

Yes, for qualifying users in the EU. Over the coming weeks, OpenAI is turning on textGrain for ChatGPT and Codex across all plans there. It isn't a worldwide default at launch, though API customers anywhere can opt in.

Can a textGrain check prove I used ChatGPT?

Not on its own. OpenAI says a watermark does not identify the user, verify accuracy, establish responsibility or measure human contribution. It only indicates the text carried an OpenAI watermark.

Does no watermark mean a human wrote the text?

No. Short text, heavy edits or another company's AI can all leave no OpenAI mark. Watermarking is also off by default in the API and not active for ChatGPT outside the EU.

Can anyone use the textGrain detector?

Not at launch. Approved researchers and expert organizations can apply for case-by-case access under the EU Code of Practice. OpenAI points to detection misses and false alarms as the reason for restricting it.

Get the next one in your inbox. One email a day with the tech stories that matter, explained in plain English. Subscribe free.

Sources

This article was compiled from reporting by the following outlets. Links go to the original reports.

  1. The Verge: OpenAI is adding text watermarking in ChatGPT and Codex
  2. 9to5Mac: OpenAI details new text watermarking system for ChatGPT, Codex, and the API
  3. TechCrunch: OpenAI will start watermarking ChatGPT’s text in the EU
  4. Neowin: ChatGPT will now show visual ads while you generate images
  5. BleepingComputer: OpenAI will show visual ads in ChatGPT while you generate images
  6. Engadget: OpenAI is testing more ads in ChatGPT

About the author
, Aerospace engineer & author

Sandeep Bandyopadhyay is a mechanical and aerospace engineer with more than 20 years in aircraft structures and composites, including work on Boeing's 777-9 wing and GE Aviation nacelle programs. He holds an MBA and a PMP, and is the author of "Aerospace Structures and Composite Materials with Artificial Intelligence" (2025). At TechyCluster he writes about AI, hardware and the technology decisions that affect engineers, businesses and everyday users.

How we report: this article was researched from the sources listed below and drafted with AI assistance under the editorial direction of Sandeep Bandyopadhyay. Facts are checked against the original reports; corrections are welcome at editor@techycluster.com.

Leave a Reply

Your email address will not be published. Required fields are marked *