OpenAI announced on October 5 that it will begin adding invisible watermarks to text generated by ChatGPT and Codex for users in the European Union, its concrete response to the EU AI Act's text provenance rules. In a blog post titled "Our approach to EU text provenance rules," the company said the watermarking will roll out "over the coming weeks" for eligible output in the bloc, a plan reported the same day by TechCrunch, The Verge, BleepingComputer, Engadget and other outlets.

The technology behind the change is called textGrain. Rather than embedding a visible mark, textGrain works by subtly steering the model's word choices so the resulting text carries a statistical pattern that can be detected later. Readers will notice nothing when consuming or copying AI-generated text; detection requires access to OpenAI's detector, which is not available to the general public. For a wider look at how regulators and labs are colliding over AI rules, follow our ongoing AI policy coverage.

How textGrain Watermarking Works

OpenAI's approach modifies the token selection process during generation. The company says textGrain "slightly changes the model's word choices to create a statistical pattern that can later be detected," according to reporting by BleepingComputer. The watermark is invisible when the text is read or copied, and OpenAI claims it does not degrade output quality.

The detection side is deliberately restricted. Alongside the watermark launch, OpenAI is opening applications for its watermark detector, but access will initially be limited to approved researchers and expert organizations. That design keeps detection capability out of the hands of anyone hoping to weaponize it, but it also means publishers, teachers and employers cannot independently verify whether a piece of text is watermarked.

API Access Is Opt-In Worldwide

The EU mandate applies to ChatGPT and Codex output in the bloc, but OpenAI is simultaneously giving developers everywhere a choice. Starting October 5, API developers worldwide can opt in to text watermarking for supported models. The feature remains disabled by default on the API, a decision The New Stack highlighted as a contrast with Anthropic's approach, which turned provenance marking on for EU traffic earlier this year in its own response to the same rules.

That opt-in posture will reassure developers worried about unforeseen side effects. Statistical watermarking changes how tokens are sampled, and any modification to generation carries at least a theoretical risk of shifting behavior on edge cases. By making watermarking a flag rather than a default, OpenAI transfers the compliance decision to the companies building on its models.

Why the EU AI Act Forced This

The EU AI Act's transparency provisions require that AI-generated text be identifiable as machine-generated, an obligation that pushed both OpenAI and Anthropic toward statistical watermarking schemes. OpenAI's blog post frames textGrain as its implementation of those provenance requirements, and PYMNTS reported the rollout as OpenAI meeting "EU AI Act mandates" directly.

The timing is notable. The watermark announcement lands amid an unusually turbulent stretch for OpenAI's public posture: the same news cycle brought the departure of safety leader David Robinson, an FTC investigation into consumer risks at major AI labs, and a shareholder lawsuit atmosphere that has kept the company under scrutiny. Watermarking is one of the few regulatory demands OpenAI can satisfy fully with infrastructure rather than product changes, which may explain why it shipped first.

The Catch: Watermarks Break Under Editing

OpenAI itself concedes the fundamental limitation. The company admits its watermark can disappear when the text is edited, and decades of research on linguistic steganography back that concern: paraphrasing, translation or even modest rewriting can destroy statistical watermarks. Anyone determined to launder AI text through a "humanizer" tool will likely succeed.

That weakness has not stopped regulators from requiring watermarking, and it has not stopped labs from shipping it. The realistic goal is not tamper-proof provenance but raising the cost of casual deception at scale, the same logic that governs currency watermarks. Critics, including some AI safety groups who have been skeptical of voluntary industry measures, argue that detectors accessible only to approved organizations do little for teachers, editors or platforms trying to enforce their own AI-content policies.

What It Means for Users and Developers

For ChatGPT and Codex users inside the EU, nothing will visibly change. Text will look and feel the same, and no label will appear on outputs. The watermark will simply be there, detectable in principle by OpenAI's approved partners.

For developers, the API flag arrives immediately and is worth evaluating carefully: turning it on means accepting subtle changes to token sampling across every completion, even for non-EU users, since the API setting is global. Teams with strict latency or quality budgets may want to benchmark watermarked generation against their current setup before flipping the switch.

OpenAI says more detail on eligible models and the detector application process will arrive in the coming weeks. As other labs face the same EU obligations, textGrain is unlikely to be the last watermarking scheme the industry deploys this year.

Stay Ahead of AI

Regulation is reshaping how AI products work under the hood. Get the latest AI developments on AI Buzz Wire, with policy analysis and model news updated throughout the day.

Read more AI news here.