OpenAI to Watermark ChatGPT and Codex Output in the EU - Opt-In and Off by Default in the API, Detector Restricted to Researchers and Expert Bodies
On October 5, 2026, OpenAI published how it will meet the EU AI Act's text provenance rules. Eligible ChatGPT and Codex text in the EU will carry an invisible watermark within weeks, API customers worldwide can switch it on per project or per organization (it stays off unless enabled), and the detector is initially reserved for approved researchers and expert bodies.
On October 5, 2026, OpenAI set out how it will comply with the AI Act’s rules on text provenance in Europe1. The plan has three parts. In the API, customers anywhere can now choose to watermark text from some models; nothing changes unless they turn it on. In the EU, ChatGPT and Codex will start embedding an invisible watermark in eligible text within the next few weeks. And the detector that reads the watermark will, for now, be open only to researchers and specialist organizations that OpenAI approves.
The AI Act obliges companies offering generative AI to mark their generated text so that software can recognize it. OpenAI describes text watermarking and detection as early-stage technology with “significant limitations,” and says its staged rollout is meant to satisfy the law while staying within what the technology can actually do1.
EU users of ChatGPT and Codex: all plans, EU only
According to OpenAI, the watermark will reach users of ChatGPT and Codex within the EU, where their output is eligible, over the next few weeks, whatever plan they are on. It will apply to the EU alone, and OpenAI is not turning it on worldwide at launch. The company says limiting it to one region leaves room to learn from how it works in practice and from feedback1.
The announcement does not spell out which outputs count as “eligible.” The help center offers one reference point: under the EU’s transparency Code of Practice for AI-generated content, watermarks are not expected on outputs under 200 tokens (roughly 150 English words) or on code snippets2. That is a description of what the Code requires, though, and the help center does not say OpenAI uses it as its own exclusion rule.
In the API, switch it on per project or per organization
The setup steps are in the help center2. An organization-wide default lives under “Organization settings → Data controls → Text provenance,” and a per-project override under “Project Settings → Text provenance.” In either place you enable “Allow text watermarking,” pick the models, and save. Model selection is available at both levels. Once a supported model is enabled, OpenAI inserts the watermark at generation time, so developers do not have to mark each response themselves.
The settings screens show which models are currently supported; the help center itself does not name them. It says support will expand to all legacy models in the coming weeks2. For OpenAI models used through cloud providers, OpenAI says it is working with those partners to offer watermarking on a similar timeline1.
OpenAI explains that it leaves the API choice to customers so each can work out where watermarking belongs given its own transparency duties and the experience it gives its users1.
One point to note: enabling the watermark does not give you the detector. According to the help center, only approved organizations doing research or academic work can use the text detector at present. It also says watermarks and C2PA metadata are machine-readable signals and do not stand in for any visible labels, banners or notices that may be required, and that OpenAI cannot give advice on a customer’s specific legal duties, which their own legal team should assess2.
textGrain detection depends heavily on length, subject and editing
OpenAI’s watermarking method is called textGrain. It places a statistical signal, invisible to readers, in the model’s choice of words1. A technical report is available; OpenAI plans to expand it in the coming weeks and to release the technology as open source. The help center adds that the method adds no hidden characters and no tokens that exist only for the watermark2. According to TechCrunch, the report’s co-authors include academics at Yale and the University of Pennsylvania3.
On performance, OpenAI says its own tests found textGrain equal to or better than the other methods it tried, SynthID for text among them. It also cautions that good results under ideal conditions are no guarantee of dependable detection in ordinary use. The published figures were all measured with the false positive rate targeted at 1%1:
- On subjects such as psychology, the detector flagged roughly 80% of watermarked passages at a length of 200 tokens, rising to roughly 95% at 400 tokens. On subjects such as mathematics, where wording is less flexible, rates were much lower
- For 400-token passages, swapping 10% of the words for synonyms cut the detection rate from about 92% to 66%; swapping 25% cut it to 17%
Language matters too. The help center describes a test covering every one of the EU’s 24 official languages, built from 500 synthetic English prompts translated into the other 23. At a 1% false positive rate, Spanish scored highest at 69.0% and Romanian lowest at 42.2%2. For languages under 60%, OpenAI says it raised the watermark’s strength to improve results.
OpenAI reports little cost to quality or speed. On the benchmarks it uses for Astra, which it calls its latest frontier model, it saw no meaningful difference with the watermark on or off, and it publishes an eight-row comparison table1. The help center describes the speed impact as negligible2.
Why the detector is not public, and what a watermark cannot show
OpenAI says these limitations are part of why it is starting with researchers and expert organizations only. Because it can produce both false negatives and false positives, the detector will not be public at launch. Applications will be reviewed one at a time, following the Code of Practice, and the tool only reports whether an OpenAI watermark was found, without revealing the user, their prompts or their conversations. For images and audio, verification through openai.com/verify and the Content Provenance API stays publicly available1.
The announcement also devotes a section to the limits of what a watermark means1. A detected watermark can suggest that an OpenAI system wrote or handled some of the text, but it cannot tell you the size of the human share. It does not settle ownership or responsibility, it does not point to a user, and it offers no judgment on whether what the text says is true. A negative result is not proof of human writing either: the passage may be brief, it may have been edited or translated, or it may have originated with a model that isn’t supported, from the period before watermarking started, or from another company’s AI.
Claude watermarks worldwide; OpenAI limits it to the EU and an API opt-in
Text watermarking has been moving along the track set by the transparency obligations in Article 50 of the EU AI Act. On July 20 the European Commission published guidelines on those obligations, which have applied since August 2, 2026. Systems already on the market before that date were given until December 2, 2026 to meet requirements such as labeling.
Anthropic announced its approach in August, putting an invisible watermark into Claude’s generated text and applying it, including on the Claude Platform API, wherever Claude is offered. In its explanation of how the watermark works, the company said it applies the mark globally because there is not yet a durable way to restrict it by region. On the detection side, in September it opened a private preview of a watermark detection API limited to organizations that meet EU legal requirements, such as regulators, law enforcement, media, fact-checkers, independent researchers, educational institutions and EU civil society groups.
OpenAI draws these lines differently. Automatic watermarking covers only the EU versions of ChatGPT and Codex, while API customers decide for themselves and nothing is marked unless they opt in. For the detector, OpenAI names researchers and expert organizations, which is worded differently from the list in our earlier Anthropic coverage. OpenAI says it will revisit each element as technology, standards and evidence develop1, so the regional scope and defaults may change.
API defaults to check, and the view from the receiving side
For businesses calling OpenAI models through the API, the first thing to check is the default: without a settings change, no watermark is added. Services that deliver generated text to users in the EU will need to weigh their own transparency obligations and decide whether to enable it organization-wide or only in EU-facing projects. Since the watermark does not replace visible labeling, whether a label is needed is a separate question.
Organizations using ChatGPT or Codex in the EU will see watermarked output begin to appear over the coming weeks. The help center expects the signal to survive when the wording is reused as is, but says heavy rewriting, paraphrasing or translation makes detection less reliable2.
For anyone on the receiving end, OpenAI’s text detector is not publicly available, so there is no way to check a document for an OpenAI watermark yourself. Even if that changes, the detection rates OpenAI has published, and its own point that failing to find a watermark does not show a human wrote the text, suggest that judging job applications or student papers on the watermark alone would be hard to justify.
Sources
- Our approach to EU text provenance rules - OpenAI (October 5, 2026)
- Provenance signals in OpenAI-generated content - OpenAI Help Center (API setup and detection rates by language)
- OpenAI will start watermarking ChatGPT’s text in the EU - TechCrunch (October 5, 2026)
Was this article helpful?
Thank you!
Received. Thank you!