ChatGPT watermark plans are no longer hypothetical. On 5 October 2026, OpenAI said it will add an invisible watermark to text generated by ChatGPT and Codex for users in the European Union, to meet the transparency rules in the EU AI Act. The rollout will happen “over the coming weeks”, it applies to eligible users on all plans, and it is limited to the EU. Developers using the API anywhere in the world can switch the same watermark on for selected models from today, but it is off by default.

The announcement, first reported by TechCrunch, came with something more useful than a press line: OpenAI published its own detection numbers, a benchmark table and a technical report for its method, which it calls textGrain. Those figures show how well the ChatGPT watermark survives editing, how much length matters, and why the detector itself is not being released to the public.

This article walks through what OpenAI announced, how textGrain works, what the company’s own evaluations say, how the EU-only approach compares with Anthropic’s worldwide Claude watermark, and what UK and EU organisations should do before the rollout reaches their staff.

What OpenAI Announced About the ChatGPT Watermark

chatgpt watermark eu text openai textgrain b tabletop weaving loom with a diamond woven in

OpenAI framed the change as a phased response to the EU AI Act, which requires generative AI providers to make generated text identifiable in a machine-readable way. The company was candid that “text watermarking and detection remain early technologies with significant limitations”.

Three changes on three timelines

The announcement contains three separate moves, each with its own audience and start date. The table below sets them out.

ChangeWho it affectsWhenDefault
ChatGPT watermark on ChatGPT and Codex textEligible users on all plans, EU onlyOver the coming weeksOn
Opt-in watermarking in the APIAPI customers worldwide, select modelsFrom 5 October 2026Off
Watermark detectorApproved researchers and expert organisationsApplications open from 5 October 2026Not public
Cloud partner supportOpenAI’s models used via cloud providersIn the coming weeksNot stated

What stays the same for images and audio

The text changes sit alongside tools OpenAI already runs for other media. Its image and audio verification, through the openai.com/verify web tool and the Content Provenance API, stays publicly available. OpenAI also adds Content Credentials to supported images, says it is C2PA conformant, and embeds SynthID watermarks in supported images and audio.

Global default ruled out

OpenAI was explicit: “We are not making text watermarking a global default at launch.” A ChatGPT user in London, New York or Tokyo will not get watermarked output by default. The company says the regional approach “gives us room to learn from real-world use and feedback”.

How the ChatGPT Watermark Works: textGrain

chatgpt watermark eu text openai textgrain c halved onion showing its layered rings

The ChatGPT watermark is not a visible symbol, a hidden character or a line of metadata. It lives in the choice of words.

A nudge on every word choice

A language model writes one token (a word or part of a word) at a time, choosing each from a probability distribution. textGrain uses a secret key and the preceding few tokens to generate pseudorandom values, then gently couples the model’s choice to those values. In OpenAI’s words, it “adds an invisible statistical signal to the model’s word choices”.

A single nudge proves nothing. Hundreds of them, added together, create a pattern that the detector can test for using only the text and the key. A reader sees an ordinary paragraph.

Why it travels with copied text

Because the signal is in the words themselves, the ChatGPT watermark moves wherever the text goes. Copying a paragraph into an email, a slide or a document carries the pattern with it. Stripping formatting or metadata does nothing to it. The flip side is that rewriting the words weakens it, which the next section measures.

What the technical report adds

The textGrain technical report runs to 20 pages and lists nine authors from OpenAI, the University of Pennsylvania and Yale. It describes the method as an optimal transport problem with costs based on Gumbel random variables and a Kullback-Leibler penalty. The practical point is an “entropy budget”: a dial that sets how much randomness the watermark is allowed to remove from the model’s sampling.

The report also says the detector “does not need to know the budget used during generation”, and that textGrain works with speculative sampling, a common speed-up in production serving. This is applied natural language processing research, and OpenAI says it plans to release the technology as open source.

How Well Detection Works, by OpenAI's Own Numbers

chatgpt watermark eu text openai textgrain d ammonite fossil on the face of a split rock

OpenAI says textGrain “matched or exceeded” the other methods it tested, including Google’s SynthID for text. It then spent most of its post explaining why that is not enough.

Length matters

At a target false positive rate of 1%, the detector found the ChatGPT watermark in about 80% of 200-token passages and about 95% of 400-token passages, for content such as psychology. For mathematics, where there is less freedom in word choice, detection was “substantially lower”. Short answers, maths and translated text are all hard cases.

Editing erodes the signal

In a separate test on 400-token English passages, detection started at about 92%. Replacing 10% of the words with synonyms cut that to about 66%. Replacing 25% cut it to about 17%. The chart below shows both evaluations, all at a 1% target false positive rate.

ChatGPT watermark detection rate at a 1% target false positive rate (OpenAI evaluations)
400-token passages, psychology-style content about 95%
400-token passages, unedited (editing test baseline) about 92%
200-token passages, psychology-style content about 80%
400-token passages, 10% of words swapped for synonyms about 66%
400-token passages, 25% of words swapped for synonyms about 17%

The false positive arithmetic

A 1% false positive rate sounds small until it meets volume. If a university or employer checked 10,000 passages that were all written by people, a 1% rate would still flag about 100 of them (10,000 x 0.01). That is the core reason OpenAI is keeping the detector away from the public: a tool that is right most of the time can still accuse a lot of people.

Why the detector is gated

OpenAI said directly: “These limitations contribute to our decision to provide initial detector access only to approved researchers and expert organizations.” Approved applicants get a tool that reports whether it detects an OpenAI watermark, without identifying the user or revealing prompts. Teachers, HR teams and publishers cannot run ChatGPT watermark checks themselves at launch.

Does the ChatGPT Watermark Hurt Output Quality?

chatgpt watermark eu text openai textgrain e ice swan sculpture melting on a tray

One of the long-standing objections to text watermarking is that steering word choice could make answers worse. OpenAI tested this on Astra, which it describes as its latest frontier model, at maximum reasoning effort.

Eight benchmarks, with and without

The table compares watermarked and unwatermarked scores. The difference column is our own subtraction from OpenAI’s published figures.

BenchmarkUnwatermarkedWatermarkedDifference
Artificial Analysis Intelligence Index49.5749.76+0.19
AutomationBench34.09%34.86%+0.77
DeepSWE v1.172.80%71.68%-1.12
Terminal-Bench 4.053.90%56.06%+2.16
Terminal-Bench Science 0.156.90%60.00%+3.10
BrowseComp87.92%87.35%-0.57
HealthBench Professional64.27%64.60%+0.33
GPQA Diamond94.44%93.94%-0.50

Reading the result

Five of the eight scores went up with the ChatGPT watermark switched on and three went down. The largest moves, +3.10 and -1.12 points, run in opposite directions, which looks like ordinary run-to-run noise rather than a pattern. OpenAI’s own summary is that it does “not see meaningful performance differences”, and the table supports that.

What the table does not test

These are capability benchmarks. They do not measure style, tone or how natural a passage reads, which is what most writers care about. Anthropic made a similar claim for Claude, saying a watermarked response is “indistinguishable from an unwatermarked one”. Neither company has published a blind reader study.

What a ChatGPT Watermark Does Not Tell You

chatgpt watermark eu text openai textgrain f three shell game cups one tipped to show the ball

The most important part of OpenAI’s post is a list of things a detection result cannot prove. Anyone planning to act on a ChatGPT watermark check should read it first.

It does not measure human effort

OpenAI says a watermark “can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it”. A heavily researched report with one AI-polished paragraph and a pasted chatbot answer can both test positive.

It does not establish ownership or identity

A watermark “does not determine who owns the text, whether its use was lawful, whether disclosure was required, or who is responsible for it”. It also does not identify the user: it does not link a person, account, prompt or conversation to the text.

It does not verify accuracy

A detection result says nothing about whether a passage is true, misleading or harmful. A watermarked answer can be correct, and an unwatermarked one can be wrong.

Absence proves nothing

“The absence of a detected watermark does not prove human authorship.” The text may be too short, edited or translated. It may come from an unsupported model, predate the rollout, or come from another company’s tools. A negative ChatGPT watermark result is not a clean bill of health.

Why the ChatGPT Watermark Is EU-Only

The reason for the geography is the EU AI Act. Its Article 50 transparency rules became applicable on 2 August 2026, and they reach any provider whose output is intended to be used in the EU.

Article 50 in brief

Article 50(2) requires providers of generative AI systems to mark synthetic text, audio, images and video in a machine-readable format that is detectable as AI-generated. The Commission’s guidelines on transparency obligations and the Code of Practice on AI-generated content set out how. Systems already on the market before August have until 2 December 2026 to add the machine-readable marking.

The countdown

From OpenAI’s announcement on 5 October to that 2 December deadline is 58 days. A rollout “over the coming weeks” therefore lands inside the grace period, which explains the timing better than any change of heart. Fines for breaching the transparency rules can reach €15 million or 3% of worldwide annual turnover, whichever is higher.

The competitive worry

OpenAI had built a text watermark by 2024 and held it back. The Wall Street Journal reported in 2024 that one reason was concern that users would switch to rivals that did not watermark. Applying the ChatGPT watermark only where the law requires it, and only where rivals face the same law, limits that risk. Anthropic, Google, Meta, Microsoft and OpenAI have all committed to the EU code.

We covered the wider labelling regime, and the research on how labels can backfire, in our earlier analysis of the EU’s AI content label rules.

The Long Road to a ChatGPT Watermark

The ChatGPT watermark has been technically possible for years. What changed in 2026 was the law, and the fact that rivals moved first.

From shelved tool to legal requirement

The timeline below shows how the pieces fell into place. OpenAI’s announcement came 64 days after Article 50 began to apply (2 August to 5 October) and 55 days after Anthropic confirmed its own plan (11 August to 5 October).

DateEvent
August 2024The Wall Street Journal reports OpenAI has a working text watermark it has not released
23 October 2024Google releases SynthID Text so developers can watermark AI-generated text
10 June 2026EU Code of Practice on transparency of AI-generated content published
2 August 2026EU AI Act Article 50 transparency rules apply
11 August 2026Anthropic confirms Claude text will be watermarked
15 August 2026Anthropic explains its approach and plans a detection API
5 October 2026OpenAI announces textGrain, the EU rollout and API opt-in
2 December 2026Deadline for systems already on the market to add machine-readable marking

What held OpenAI back

The 2024 reporting described a tool that worked well in tests but carried two risks for OpenAI: false accusations against honest users, and customers drifting to services that did not watermark. Both worries are still visible in the 5 October post. The gated detector answers the first. Limiting the ChatGPT watermark to the EU, where every major rival faces the same rule, answers the second.

Why a common rule changes the maths

A watermark that only one company applies is a reason to switch. A ChatGPT watermark that sits alongside Claude’s, Google’s and other signatories’ marks in the same market is just the cost of operating there. That is why the EU code matters more than any single company’s announcement: it removes the first-mover penalty that kept text watermarks on the shelf.

ChatGPT Watermark vs Claude's Watermark

Anthropic moved first. On 11 August 2026, it confirmed in a support page that Claude’s text would be watermarked to comply with the same rules, and on 15 August it published a fuller explanation. The two approaches differ in ways that matter to businesses.

QuestionOpenAI (ChatGPT, Codex, API)Anthropic (Claude)
Where it appliesChatGPT and Codex in the EU onlyWorldwide, at model level
MethodtextGrain, OpenAI’s ownBased on the SynthID Text approach
APIOpt-in, off by defaultIncluded across Claude products and the API
Detector accessApproved researchers and expert organisationsDetection API planned
Stated weakness10% synonym swaps cut detection from 92% to 66%Light editing probably will not remove it; a full rewrite will
Announced5 October 202611 August 2026

The backlash Anthropic absorbed

Claude’s watermark drew an angry response from some users, who argued they had supplied “the instructions, context, decisions” while Claude was “the tool”. Business Insider reported that dozens of users on X said they had cancelled subscriptions. OpenAI’s narrower ChatGPT watermark avoids most of that exposure outside Europe.

The detection gap

Anthropic says it will offer a detection API. OpenAI is keeping its detector behind an application process. For an organisation trying to check incoming text, that means Claude output may be easier to test than ChatGPT output, at least at first. Google has offered SynthID verification for its own content, which we looked at in our SynthID verification guide.

What the ChatGPT Watermark Means for UK and EU Organisations

For most organisations, the practical effect of the ChatGPT watermark is not technical. It is about policy, honesty and what your people expect.

Staff in the EU

If you have employees in an EU member state using ChatGPT or Codex, their output will start to carry the ChatGPT watermark in the coming weeks. That includes text pasted into client reports, bids and marketing copy. A UK head office using the same account plan in London will not see the change by default.

Public-interest text and deployer duties

Article 50(4) puts a separate duty on deployers who publish AI-generated text to inform the public on matters of public interest, unless the text has had human review and someone holds editorial responsibility. The ChatGPT watermark does not discharge that duty for you. Disclosure is still a decision your organisation makes.

API builders have a choice

If you build products on the OpenAI API, the watermark is opt-in. If your users or outputs are in the EU, your own Article 50 position decides whether you should switch it on. Document the decision either way, since “we did not know” will not be a strong answer.

Never treat detection as proof

The watermark cannot identify a user, measure effort or prove authorship, and its absence proves nothing. Do not build disciplinary, academic or recruitment decisions on a ChatGPT watermark result, just as we argued against using AI detector scores as evidence in our piece on how US universities are shunning AI detectors.

Codex and code

OpenAI did not discuss code separately. Its finding that maths is much harder to detect points the same way as Anthropic’s explanation that code leaves little room for word choice, so watermarks in code are likely to sit mostly in comments and explanations. Development teams in the EU should still expect Codex output to carry the ChatGPT watermark where the model has freedom to choose its words, and should not rely on it, or its absence, in code review.

Update the AI use policy

A short paragraph is enough: when staff must disclose AI assistance, when watermarked output can be used as-is, and who signs off public-facing text. Our IT governance team helps organisations write and enforce that kind of rule.

ChatGPT Watermark: Frequently Asked Questions

Will my ChatGPT text be watermarked in the UK?

Not by default. OpenAI says the ChatGPT watermark rollout covers eligible ChatGPT and Codex users in the EU only. API customers anywhere can opt in.

Can the ChatGPT watermark be removed?

It can be weakened. In OpenAI’s tests on 400-token passages, swapping 10% of words for synonyms cut detection from about 92% to 66%, and swapping 25% cut it to about 17%.

Can I check whether text has a ChatGPT watermark?

Not yet, unless you are an approved researcher or expert organisation. OpenAI has opened applications for its detector but is not making it public at launch.

Does the watermark identify who wrote the text?

No. OpenAI says the watermark does not associate a person, organisation, account, prompt or conversation with the text.

Does the ChatGPT watermark make answers worse?

OpenAI’s benchmark table shows no meaningful difference: five scores rose slightly and three fell slightly across eight benchmarks.

References