ChatGPT watermark plans are no longer hypothetical. On 5 October 2026, OpenAI said it will add an invisible watermark to text generated by ChatGPT and Codex for users in the European Union, to meet the transparency rules in the EU AI Act. The rollout will happen “over the coming weeks”, it applies to eligible users on all plans, and it is limited to the EU. Developers using the API anywhere in the world can switch the same watermark on for selected models from today, but it is off by default.
The announcement, first reported by TechCrunch, came with something more useful than a press line: OpenAI published its own detection numbers, a benchmark table and a technical report for its method, which it calls textGrain. Those figures show how well the ChatGPT watermark survives editing, how much length matters, and why the detector itself is not being released to the public.
This article walks through what OpenAI announced, how textGrain works, what the company’s own evaluations say, how the EU-only approach compares with Anthropic’s worldwide Claude watermark, and what UK and EU organisations should do before the rollout reaches their staff.
Table of contents
- What OpenAI Announced About the ChatGPT Watermark
- How the ChatGPT Watermark Works: textGrain
- How Well Detection Works, by OpenAI’s Own Numbers
- Does the ChatGPT Watermark Hurt Output Quality?
- What a ChatGPT Watermark Does Not Tell You
- Why the ChatGPT Watermark Is EU-Only
- The Long Road to a ChatGPT Watermark
- ChatGPT Watermark vs Claude’s Watermark
- What the ChatGPT Watermark Means for UK and EU Organisations
- ChatGPT Watermark: Frequently Asked Questions
- References
What OpenAI Announced About the ChatGPT Watermark
OpenAI framed the change as a phased response to the EU AI Act, which requires generative AI providers to make generated text identifiable in a machine-readable way. The company was candid that “text watermarking and detection remain early technologies with significant limitations”.
Three changes on three timelines
The announcement contains three separate moves, each with its own audience and start date. The table below sets them out.
| Change | Who it affects | When | Default |
|---|---|---|---|
| ChatGPT watermark on ChatGPT and Codex text | Eligible users on all plans, EU only | Over the coming weeks | On |
| Opt-in watermarking in the API | API customers worldwide, select models | From 5 October 2026 | Off |
| Watermark detector | Approved researchers and expert organisations | Applications open from 5 October 2026 | Not public |
| Cloud partner support | OpenAI’s models used via cloud providers | In the coming weeks | Not stated |
What stays the same for images and audio
The text changes sit alongside tools OpenAI already runs for other media. Its image and audio verification, through the openai.com/verify web tool and the Content Provenance API, stays publicly available. OpenAI also adds Content Credentials to supported images, says it is C2PA conformant, and embeds SynthID watermarks in supported images and audio.
Global default ruled out
OpenAI was explicit: “We are not making text watermarking a global default at launch.” A ChatGPT user in London, New York or Tokyo will not get watermarked output by default. The company says the regional approach “gives us room to learn from real-world use and feedback”.
How the ChatGPT Watermark Works: textGrain
The ChatGPT watermark is not a visible symbol, a hidden character or a line of metadata. It lives in the choice of words.
A nudge on every word choice
A language model writes one token (a word or part of a word) at a time, choosing each from a probability distribution. textGrain uses a secret key and the preceding few tokens to generate pseudorandom values, then gently couples the model’s choice to those values. In OpenAI’s words, it “adds an invisible statistical signal to the model’s word choices”.
A single nudge proves nothing. Hundreds of them, added together, create a pattern that the detector can test for using only the text and the key. A reader sees an ordinary paragraph.
Why it travels with copied text
Because the signal is in the words themselves, the ChatGPT watermark moves wherever the text goes. Copying a paragraph into an email, a slide or a document carries the pattern with it. Stripping formatting or metadata does nothing to it. The flip side is that rewriting the words weakens it, which the next section measures.
What the technical report adds
The textGrain technical report runs to 20 pages and lists nine authors from OpenAI, the University of Pennsylvania and Yale. It describes the method as an optimal transport problem with costs based on Gumbel random variables and a Kullback-Leibler penalty. The practical point is an “entropy budget”: a dial that sets how much randomness the watermark is allowed to remove from the model’s sampling.
The report also says the detector “does not need to know the budget used during generation”, and that textGrain works with speculative sampling, a common speed-up in production serving. This is applied natural language processing research, and OpenAI says it plans to release the technology as open source.
How Well Detection Works, by OpenAI's Own Numbers
OpenAI says textGrain “matched or exceeded” the other methods it tested, including Google’s SynthID for text. It then spent most of its post explaining why that is not enough.
Length matters
At a target false positive rate of 1%, the detector found the ChatGPT watermark in about 80% of 200-token passages and about 95% of 400-token passages, for content such as psychology. For mathematics, where there is less freedom in word choice, detection was “substantially lower”. Short answers, maths and translated text are all hard cases.
Editing erodes the signal
In a separate test on 400-token English passages, detection started at about 92%. Replacing 10% of the words with synonyms cut that to about 66%. Replacing 25% cut it to about 17%. The chart below shows both evaluations, all at a 1% target false positive rate.
The false positive arithmetic
A 1% false positive rate sounds small until it meets volume. If a university or employer checked 10,000 passages that were all written by people, a 1% rate would still flag about 100 of them (10,000 x 0.01). That is the core reason OpenAI is keeping the detector away from the public: a tool that is right most of the time can still accuse a lot of people.
Why the detector is gated
OpenAI said directly: “These limitations contribute to our decision to provide initial detector access only to approved researchers and expert organizations.” Approved applicants get a tool that reports whether it detects an OpenAI watermark, without identifying the user or revealing prompts. Teachers, HR teams and publishers cannot run ChatGPT watermark checks themselves at launch.
Does the ChatGPT Watermark Hurt Output Quality?
One of the long-standing objections to text watermarking is that steering word choice could make answers worse. OpenAI tested this on Astra, which it describes as its latest frontier model, at maximum reasoning effort.
Eight benchmarks, with and without
The table compares watermarked and unwatermarked scores. The difference column is our own subtraction from OpenAI’s published figures.
| Benchmark | Unwatermarked | Watermarked | Difference |
|---|---|---|---|
| Artificial Analysis Intelligence Index | 49.57 | 49.76 | +0.19 |
| AutomationBench | 34.09% | 34.86% | +0.77 |
| DeepSWE v1.1 | 72.80% | 71.68% | -1.12 |
| Terminal-Bench 4.0 | 53.90% | 56.06% | +2.16 |
| Terminal-Bench Science 0.1 | 56.90% | 60.00% | +3.10 |
| BrowseComp | 87.92% | 87.35% | -0.57 |
| HealthBench Professional | 64.27% | 64.60% | +0.33 |
| GPQA Diamond | 94.44% | 93.94% | -0.50 |
Reading the result
Five of the eight scores went up with the ChatGPT watermark switched on and three went down. The largest moves, +3.10 and -1.12 points, run in opposite directions, which looks like ordinary run-to-run noise rather than a pattern. OpenAI’s own summary is that it does “not see meaningful performance differences”, and the table supports that.
What the table does not test
These are capability benchmarks. They do not measure style, tone or how natural a passage reads, which is what most writers care about. Anthropic made a similar claim for Claude, saying a watermarked response is “indistinguishable from an unwatermarked one”. Neither company has published a blind reader study.
What a ChatGPT Watermark Does Not Tell You
The most important part of OpenAI’s post is a list of things a detection result cannot prove. Anyone planning to act on a ChatGPT watermark check should read it first.
It does not measure human effort
OpenAI says a watermark “can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it”. A heavily researched report with one AI-polished paragraph and a pasted chatbot answer can both test positive.
It does not establish ownership or identity
A watermark “does not determine who owns the text, whether its use was lawful, whether disclosure was required, or who is responsible for it”. It also does not identify the user: it does not link a person, account, prompt or conversation to the text.
It does not verify accuracy
A detection result says nothing about whether a passage is true, misleading or harmful. A watermarked answer can be correct, and an unwatermarked one can be wrong.
Absence proves nothing
“The absence of a detected watermark does not prove human authorship.” The text may be too short, edited or translated. It may come from an unsupported model, predate the rollout, or come from another company’s tools. A negative ChatGPT watermark result is not a clean bill of health.
Why the ChatGPT Watermark Is EU-Only
The reason for the geography is the EU AI Act. Its Article 50 transparency rules became applicable on 2 August 2026, and they reach any provider whose output is intended to be used in the EU.
Article 50 in brief
Article 50(2) requires providers of generative AI systems to mark synthetic text, audio, images and video in a machine-readable format that is detectable as AI-generated. The Commission’s guidelines on transparency obligations and the Code of Practice on AI-generated content set out how. Systems already on the market before August have until 2 December 2026 to add the machine-readable marking.
The countdown
From OpenAI’s announcement on 5 October to that 2 December deadline is 58 days. A rollout “over the coming weeks” therefore lands inside the grace period, which explains the timing better than any change of heart. Fines for breaching the transparency rules can reach €15 million or 3% of worldwide annual turnover, whichever is higher.
The competitive worry
OpenAI had built a text watermark by 2024 and held it back. The Wall Street Journal reported in 2024 that one reason was concern that users would switch to rivals that did not watermark. Applying the ChatGPT watermark only where the law requires it, and only where rivals face the same law, limits that risk. Anthropic, Google, Meta, Microsoft and OpenAI have all committed to the EU code.
We covered the wider labelling regime, and the research on how labels can backfire, in our earlier analysis of the EU’s AI content label rules.
The Long Road to a ChatGPT Watermark
The ChatGPT watermark has been technically possible for years. What changed in 2026 was the law, and the fact that rivals moved first.
From shelved tool to legal requirement
The timeline below shows how the pieces fell into place. OpenAI’s announcement came 64 days after Article 50 began to apply (2 August to 5 October) and 55 days after Anthropic confirmed its own plan (11 August to 5 October).
| Date | Event |
|---|---|
| August 2024 | The Wall Street Journal reports OpenAI has a working text watermark it has not released |
| 23 October 2024 | Google releases SynthID Text so developers can watermark AI-generated text |
| 10 June 2026 | EU Code of Practice on transparency of AI-generated content published |
| 2 August 2026 | EU AI Act Article 50 transparency rules apply |
| 11 August 2026 | Anthropic confirms Claude text will be watermarked |
| 15 August 2026 | Anthropic explains its approach and plans a detection API |
| 5 October 2026 | OpenAI announces textGrain, the EU rollout and API opt-in |
| 2 December 2026 | Deadline for systems already on the market to add machine-readable marking |
What held OpenAI back
The 2024 reporting described a tool that worked well in tests but carried two risks for OpenAI: false accusations against honest users, and customers drifting to services that did not watermark. Both worries are still visible in the 5 October post. The gated detector answers the first. Limiting the ChatGPT watermark to the EU, where every major rival faces the same rule, answers the second.
Why a common rule changes the maths
A watermark that only one company applies is a reason to switch. A ChatGPT watermark that sits alongside Claude’s, Google’s and other signatories’ marks in the same market is just the cost of operating there. That is why the EU code matters more than any single company’s announcement: it removes the first-mover penalty that kept text watermarks on the shelf.
ChatGPT Watermark vs Claude's Watermark
Anthropic moved first. On 11 August 2026, it confirmed in a support page that Claude’s text would be watermarked to comply with the same rules, and on 15 August it published a fuller explanation. The two approaches differ in ways that matter to businesses.
| Question | OpenAI (ChatGPT, Codex, API) | Anthropic (Claude) |
|---|---|---|
| Where it applies | ChatGPT and Codex in the EU only | Worldwide, at model level |
| Method | textGrain, OpenAI’s own | Based on the SynthID Text approach |
| API | Opt-in, off by default | Included across Claude products and the API |
| Detector access | Approved researchers and expert organisations | Detection API planned |
| Stated weakness | 10% synonym swaps cut detection from 92% to 66% | Light editing probably will not remove it; a full rewrite will |
| Announced | 5 October 2026 | 11 August 2026 |
The backlash Anthropic absorbed
Claude’s watermark drew an angry response from some users, who argued they had supplied “the instructions, context, decisions” while Claude was “the tool”. Business Insider reported that dozens of users on X said they had cancelled subscriptions. OpenAI’s narrower ChatGPT watermark avoids most of that exposure outside Europe.
The detection gap
Anthropic says it will offer a detection API. OpenAI is keeping its detector behind an application process. For an organisation trying to check incoming text, that means Claude output may be easier to test than ChatGPT output, at least at first. Google has offered SynthID verification for its own content, which we looked at in our SynthID verification guide.
What the ChatGPT Watermark Means for UK and EU Organisations
For most organisations, the practical effect of the ChatGPT watermark is not technical. It is about policy, honesty and what your people expect.
Staff in the EU
If you have employees in an EU member state using ChatGPT or Codex, their output will start to carry the ChatGPT watermark in the coming weeks. That includes text pasted into client reports, bids and marketing copy. A UK head office using the same account plan in London will not see the change by default.
Public-interest text and deployer duties
Article 50(4) puts a separate duty on deployers who publish AI-generated text to inform the public on matters of public interest, unless the text has had human review and someone holds editorial responsibility. The ChatGPT watermark does not discharge that duty for you. Disclosure is still a decision your organisation makes.
API builders have a choice
If you build products on the OpenAI API, the watermark is opt-in. If your users or outputs are in the EU, your own Article 50 position decides whether you should switch it on. Document the decision either way, since “we did not know” will not be a strong answer.
Never treat detection as proof
The watermark cannot identify a user, measure effort or prove authorship, and its absence proves nothing. Do not build disciplinary, academic or recruitment decisions on a ChatGPT watermark result, just as we argued against using AI detector scores as evidence in our piece on how US universities are shunning AI detectors.
Codex and code
OpenAI did not discuss code separately. Its finding that maths is much harder to detect points the same way as Anthropic’s explanation that code leaves little room for word choice, so watermarks in code are likely to sit mostly in comments and explanations. Development teams in the EU should still expect Codex output to carry the ChatGPT watermark where the model has freedom to choose its words, and should not rely on it, or its absence, in code review.
Update the AI use policy
A short paragraph is enough: when staff must disclose AI assistance, when watermarked output can be used as-is, and who signs off public-facing text. Our IT governance team helps organisations write and enforce that kind of rule.
ChatGPT Watermark: Frequently Asked Questions
Will my ChatGPT text be watermarked in the UK?
Not by default. OpenAI says the ChatGPT watermark rollout covers eligible ChatGPT and Codex users in the EU only. API customers anywhere can opt in.
Can the ChatGPT watermark be removed?
It can be weakened. In OpenAI’s tests on 400-token passages, swapping 10% of words for synonyms cut detection from about 92% to 66%, and swapping 25% cut it to about 17%.
Can I check whether text has a ChatGPT watermark?
Not yet, unless you are an approved researcher or expert organisation. OpenAI has opened applications for its detector but is not making it public at launch.
Does the watermark identify who wrote the text?
No. OpenAI says the watermark does not associate a person, organisation, account, prompt or conversation with the text.
Does the ChatGPT watermark make answers worse?
OpenAI’s benchmark table shows no meaningful difference: five scores rose slightly and three fell slightly across eight benchmarks.
References
Our approach to EU text provenance rules (OpenAI)
textGrain: Entropy-Calibrated Watermarking for Language Model Text (technical report)
OpenAI will start watermarking ChatGPT’s text in the EU (TechCrunch)
Anthropic says it will watermark text generated by its AI models (TechCrunch)
Anthropic shares more details about how Claude’s new watermarks will work (TechCrunch)
Article 50: Transparency obligations (EU AI Act)
Guidelines on AI transparency obligations (European Commission)
Strong backing for the Code of Practice on AI-generated content (European Commission)
More AI coverage: explore Progressive Robot's AI Models, Tools & Releases hub — hands-on reviews, setup guides and benchmarks in one place.