← All insights

News analysisLens: United States5 min read

OpenAI starts watermarking text for the EU. A watermark is evidence, not a verdict

OpenAI's textGrain is opt-in for API customers worldwide and coming to ChatGPT and Codex in the EU. OpenAI's own tests show why detection cannot decide authorship on its own.

Listen to this article · 7 min

AI-generated narration of the full article.

An inked fingerprint on textured paper, in La Madre duotone, beside the words A signal, not proof
Photo: rawpixel (CC0)

On October 5, OpenAI explained how it will meet the EU AI Act’s requirement to make generated text machine-readable as AI output. The answer is a statistical watermark called textGrain, and the most useful part of the announcement is the section where OpenAI lists what a watermark cannot tell you. Anyone tempted to wire a detector into HR, compliance or fraud decisions should read that section first.

What OpenAI is shipping, and where

  • API, worldwide, opt-in. Starting October 5, API customers anywhere can opt in to watermarked text on select models. Watermarking stays off by default in the API.
  • ChatGPT and Codex, EU only. Over the coming weeks, eligible text output for users on all plans in the European Union gets an invisible watermark. OpenAI says it is deliberately not making this a global default at launch.
  • Detector, restricted. Approved researchers and expert organizations can apply for access, granted case by case. The detector is not publicly available, and it reports only whether it finds an OpenAI watermark, without identifying the user or revealing prompts.
  • Cloud partners later. OpenAI says it is working with cloud partners to offer watermarking for its models accessed through their services “in the coming weeks.” If your company consumes OpenAI models through Azure, do not assume the option exists there today.

textGrain adds an invisible statistical signal to the model’s word choices. OpenAI reports no meaningful benchmark difference with and without watermarking on its current frontier model, says textGrain matched or beat other approaches it tested, including SynthID for text, and plans to open-source the technology.

What OpenAI’s own numbers say

At a target false positive rate of 1%, the detector found the watermark in about 80% of 200-token passages and about 95% of 400-token passages for content like psychology answers. For mathematics, where word choice is constrained, detection was substantially lower. Editing hurts more: replacing 10% of words with synonyms in 400-token passages cut detection from about 92% to 66%; replacing 25% cut it to 17%.

Then the list that matters. A watermark does not measure how much a person contributed. It does not establish ownership or responsibility. It does not identify the user. It does not verify accuracy. And the absence of a detected watermark does not prove human authorship: the text may be short, edited, translated, from another model or another company’s tool.

What a detection result can and cannot tell you

Six questions people will ask a watermark01Did an OpenAImodelgenerate partof this?02How much dida personcontribute?03Who wrote orsent it?04Who owns it,who isresponsible?05Is itaccurate?06No markfound: is ithuman?A probabilistic signal, at bestNeeds other evidence
  1. Did an OpenAI model generate part of this?
  2. How much did a person contribute?
  3. Who wrote or sent it?
  4. Who owns it, who is responsible?
  5. Is it accurate?
  6. No mark found: is it human?

A probabilistic signal, at bestNeeds other evidence

Only the first question is in scope, and even that answer carries error rates that grow with short or edited text.

What this changes for enterprise teams

Provenance becomes a pipeline setting. If your company offers a generative AI feature to users in the EU, the Article 50 marking duty may sit with you as the provider of that system, not only with OpenAI. Article 50 has been enforceable since August 2, 2026, with a grace period until December 2, 2026 for systems already on the market, according to Baker Botts’ summary. Opting in on the API is one way to get a machine-readable mark on text. Decide it per product and per market, with counsel, and record the decision.

Your pipeline may erase the mark. Enterprise content flows edit, translate, summarize and template generated text. Each step weakens the signal. If marking matters for a product, test detection on output as it actually leaves your system, not as it left the model. You cannot run that test yourself yet, since the detector is restricted, which is a reason to keep your own records.

Your logs are the stronger provenance. The watermark says little; your application logs can say who requested what, which model and version answered, which template and human edits followed. That record answers the questions a watermark cannot, and it is under your control. Treat it with the same retention and access rules as other business records.

Never let a detector decide about a person. At a 1% false positive target, a check across 100,000 documents flags around a thousand that no model marked, and misses edited AI text. In HR investigations, vendor disputes or fraud reviews, a detection result is one piece of evidence for a human reviewer, never an automated outcome. This is the same rule we argued for in our analysis of controls that produce evidence: evidence feeds a decision; it does not replace it.

For U.S. teams the regulatory pull is weaker but not zero. California’s AI Transparency Act, operative since August 2, 2026, requires covered providers to offer detection tools and latent disclosures for image, video and audio, not text. Text provenance is therefore mostly a contractual and EU question for now, which fits what we described in our piece on buyers becoming the regulator.

What to do now

  1. List the products that generate text for EU users and decide, with counsel, whether you are the provider for Article 50.
  2. Decide API watermarking per product, and document why it is on or off.
  3. Test where your pipeline transforms text (editing, translation, templating) before relying on any mark.
  4. Strengthen your own provenance logs: request, model and version, template, human edits.
  5. Write a policy that forbids automated decisions on detection results in HR, academic, vendor and fraud processes.
  6. Ask your cloud provider when watermarking reaches OpenAI models on its platform.

The bottom line

OpenAI has been unusually candid: text watermarking is a weak, probabilistic signal that degrades with editing and says nothing about who, how much, or whether it is true. Turn it on where the law asks for it, keep better records of your own, and never let the absence or presence of a mark decide something about a person.

Have an AI use case stuck between prototype and production?

Tell us what you’re trying to ship. We’ll reply with honest next steps.

Discuss a use case