Home > Blog > OpenAI Text Watermark

OpenAI Text Watermark: What the EU Rollout Means for Writers

Conceptual illustration of text token patterns under a magnifying glass with an EU emblem
Conceptual illustration of a statistical text watermark; not a detector screenshot.

Research updated October 11, 2026.

OpenAI’s text watermark is now an announced product rollout, rather than just a research proposal. On October 5, 2026, the company announced that eligible ChatGPT and Codex text in the European Union would receive invisible watermarks over the following weeks. The announcement covers all plans; it does not establish that every eligible account has already received the change. Read OpenAI’s launch announcement.

For writers, the useful question is what a result can actually establish. A watermark check, an AI-writing score, and a record of how an article was edited are different kinds of evidence. Treating them as interchangeable invites mistakes.

Who gets the OpenAI text watermark?

Product and location Announced launch position
Eligible ChatGPT and Codex text in the EU Phased rollout across all plans
ChatGPT and Codex outside the EU No global default at launch
OpenAI API worldwide Optional for selected models; disabled by default

These are the boundaries in the October 5 announcement, not a complete model compatibility list. Check current product documentation before making a claim about a particular account or output.

How textGrain works

OpenAI calls its method textGrain. Its technical report describes a statistical signal introduced while the model chooses tokens: words or parts of words. A secret key and preceding text influence the sampling process. Detection reconstructs the corresponding pattern from the passage using the key and matching configuration.

A useful analogy is a pattern spread across many choices, rather than a stamp on one sentence. That analogy is not the algorithm: spotting a particular phrase cannot reproduce the keyed statistical test.

The report also cautions that its idealized error calculation does not guarantee the same error rate for every deployed key or application. Mathematical guarantees under stated assumptions and performance on everyday documents are different claims.

It is not hidden punctuation

OpenAI’s provenance help page says textGrain adds no hidden characters, invisible spaces, or watermark-only tokens. Preserving the wording is expected to preserve the signal, although detection is not guaranteed.

That makes “paste as plain text” a formatting operation, not evidence that a textGrain watermark disappeared. Likewise, removing em dashes does not amount to a watermark test. For a separate discussion of stylistic clues, see our guide to signs of AI writing.

Can anyone check the watermark?

At launch, OpenAI’s text detector is restricted to approved research and expert organizations. Its public verification tools cover supported images and audio. The current access guidance also excludes academic-integrity applications such as checking student essays. Enabling API watermarking does not grant detector access.

Before trusting a service advertised as an “OpenAI watermark checker,” ask:

  1. What does it detect? Request an explicit distinction between a keyed watermark test and a general AI-text classifier.
  2. What supports the claim? Look for documented access, supported models, evaluation conditions, and known failure cases.
  3. What does its score mean? Ask which population and error rate the number refers to.
  4. What happens to uploaded text? Check retention and confidentiality before submitting an unpublished manuscript or client document.

A tool’s name is not evidence of a relationship with OpenAI. This checklist is a way to assess a claim, not a certification of any vendor.

How reliable is detection?

In OpenAI’s reported evaluations, detection varied with passage length, subject matter, and editing. For psychology-like content, a 1% false-positive target yielded roughly 80% detection at 200 tokens and 95% at 400. A separate synonym-editing evaluation fell from approximately 92% detection to 66% after 10% replacement and 17% after 25%. These are test-specific results, not universal accuracy figures. Source: OpenAI’s evaluation summary.

In particular, a 1% false-positive rate does not mean every positive result is 99% likely to be correct. That also depends on how common genuinely watermarked text is in the population being checked.

Consider an illustrative calculation, not an OpenAI test: among 10,000 passages, suppose only 100 are watermarked. At an assumed 80% detection rate, 80 would be correctly flagged. At an assumed 1% false-positive rate on the remaining 9,900, another 99 would be incorrectly flagged. Only about 45% of the 179 flags would then be true positives.

This is why an editor should ask about both error rates and the material being tested before acting on a flag.

What a result means for an author

OpenAI says its watermark does not identify the user, quantify human contribution, or establish accuracy and ownership. A missing signal also cannot establish human authorship. See its explanation of provenance results.

Use the following review approach:

What you receive A sensible next step
A claimed positive watermark result Establish which detector produced it and what that detector is authorized and designed to check. Then examine the writing process.
A negative result Continue ordinary source checking and editorial review; do not issue a “human-written” certificate.
A generic AI-detector score Ask for that tool’s methodology. Do not silently relabel its output as textGrain evidence.
A writer’s disclosure of AI editing Compare the disclosure with drafts, factual changes, and the publication’s own rules.

For example, imagine a writer who develops an argument and asks a model to improve transitions. The review should establish whether that assistance was allowed and accurately described. A percentage score cannot replace that conversation.

Why the EU rules matter—and what they do not decide

Article 50(2) of the EU AI Act concerns providers making synthetic output machine-readable and detectable, subject to technical feasibility and specified exceptions, including standard editing assistance. It does not prescribe textGrain by name.

A separate provision, Article 50(4), addresses disclosure for AI-generated or manipulated text published to inform the public on matters of public interest. Its exception includes human review or editorial control and a person or legal entity holding editorial responsibility. A provider’s invisible mark should therefore not be treated as a substitute for a publisher’s assessment of disclosure obligations.

The European Commission’s current FAQ gives August 2, 2026 as the general application date, with a limited transition to December 2, 2026 for the marking-and-detection obligation for systems placed on the market before August 2. That is more specific than saying every AI-related obligation began on the same date.

For an actual publishing decision, establish the type of content, your role, and the applicable exceptions rather than inferring compliance from a detector result.

A practical writing workflow

The most useful response to this rollout is a better record of your work:

  • Keep the starting material. Save the original draft, notes, and sources before requesting AI assistance.
  • Record the task. Distinguish brainstorming, proofreading, translation, rewriting, and full-draft generation.
  • Review changes for meaning. Check whether an edit introduced a new claim, altered a quotation, or removed a qualification.
  • Apply the relevant policy. Follow the publication, client, employer, or institution’s rules about permitted assistance and disclosure.
  • Keep the reviewed version. Preserve enough revision history to explain the final text without relying on a detector score.

If you use a humanizer or rewriting tool, judge its output by clarity, fidelity, and factual accuracy. A lower classifier score is not proof of watermark removal, and it says nothing by itself about permission to use the text.

For help with the editing itself, read our guide to humanizing AI content. Start with what the passage needs to communicate, preserve the evidence behind it, and make every final sentence something you can explain and stand behind.