ChatGPT users in Europe will soon be producing text with a hidden fingerprint. Over the coming weeks, OpenAI plans to add an invisible watermark to eligible ChatGPT and Codex output across all plans in the European Union. It’s a direct response to the EU AI Act, which requires generative AI providers to make machine-written text identifiable in a machine-readable way. Users outside the bloc won’t see the change by default for now.
The system, which OpenAI calls textGrain, works by subtly biasing the model’s word choices to leave a statistical pattern a detector can later spot. OpenAI says it performed as well as or better than the alternatives it tested, including Google’s SynthID for text. It also says it plans to release the technology as open source. The company also claims watermarking had no meaningful effect on output quality, pointing to near-identical scores for its GPT-6 Astra model across benchmarks with the feature on and off.
The more revealing part is how openly OpenAI admits what the technology can’t do. Its own figures show the watermark is fragile. At a 1% false positive rate, detection hit about 95% for 400-token passages on a subject like psychology. That fell to roughly 80% for 200-token passages, and it was much worse for mathematical text, where there are fewer ways to phrase things. Light editing hurts it badly. Swapping just 10% of words for synonyms cut detection from about 92% to 66%, and swapping a quarter of them dropped it to 17%. Anyone with a thesaurus, or another chatbot, can largely remove it.
That is why the detector itself is not going public. Access will initially be limited to approved researchers and expert organisations, granted case by case. OpenAI is clear that a positive result only signals that one of its systems touched the text. It says nothing about authorship, ownership, accuracy or who the user was. A negative result proves even less, since the text could be short, edited, translated or produced by a competing model.
This matters most to the people who would want such a tool, such as teachers, publishers and platforms trying to spot AI-written content. They aren’t getting a reliable answer. OpenAI held back on releasing text watermarking for years, and this rollout reads more like regulatory compliance than a solution. Developers worldwide can opt in through the API, where the feature stays off by default. Meanwhile, OpenAI’s image and audio verification tools, built on C2PA Content Credentials and SynthID, remain publicly available. Text was always the harder problem, and the EU has now made it OpenAI’s problem to solve in public.
