In short
OpenAI is introducing invisible text watermarking for ChatGPT and Codex, starting with an EU-only rollout while keeping the feature optional for API users worldwide. The company says the tool supports text provenance, but it is not fully reliable and will not be a global default at launch.
- OpenAI is rolling out invisible text watermarking for ChatGPT and Codex.
- The first consumer launch is limited to users in the European Union.
- API customers worldwide can opt in for selected models.
- OpenAI says the detector will not be publicly available at launch.
- The company stresses that watermarking is useful for provenance, not proof of authorship or accuracy.
OpenAI is beginning to add invisible text watermarking to ChatGPT and Codex, with the first rollout limited to users in the European Union and the feature not yet set as a worldwide default. The change matters because it puts OpenAI on a path toward AI-content provenance tools required by Europe’s new rules while highlighting how uncertain text watermarking still is as a detection method.
The company says the system, called textGrain, is designed to embed a machine-readable signal in text generated by its models. OpenAI is also making the feature available as an opt-in setting for API customers globally and is opening detector access to approved researchers and expert organisations under a case-by-case review process.
The move places OpenAI alongside other major AI developers that have recently embraced similar provenance tools, including Google DeepMind and Anthropic, as the industry adjusts to the compliance demands and transparency expectations of the European Union AI Act.
What OpenAI is launching and why it matters
OpenAI is rolling out invisible text watermarking for ChatGPT and Codex so generated text can be identified later, at least in some cases, without changing how users see the output. That matters because the spread of highly fluent AI text has made it harder for platforms, regulators, researchers and users to tell where a passage came from, even when the content itself looks polished and credible.
The new system is intended to help with text provenance, not to solve every trust problem attached to AI-generated content. OpenAI says the watermark can be detected by approved tools, but it also acknowledges that the method is not fully reliable and should not be treated as proof of authorship or accuracy.
OpenAI says the rollout is intended to begin with the EU, where it can learn from real-world use before deciding whether to expand watermarking more broadly, and that API customers will be able to choose whether to turn on watermarked outputs for eligible models.
How the watermarking rollout works
The company is taking a phased approach. For ordinary ChatGPT and Codex users in the European Union, watermarking will arrive over the coming weeks across all eligible plans. For API users around the world, the feature is already available as an opt-in for select models. OpenAI also says it is working with cloud partners to make watermarking available for model outputs accessed through those services in the near future.
This structure gives OpenAI room to collect feedback and test how the system performs in the wild rather than forcing a one-size-fits-all release. It also lets enterprise and developer customers decide whether watermarking fits their own transparency and compliance needs.
Why start in the EU first?
OpenAI is starting in the EU first because Europe’s AI Act and related transparency expectations are pushing companies toward clearer disclosure of synthetic content. The regional launch also allows the company to test the technology in a legally demanding market where provenance tools are likely to matter most.
By keeping the global default off at launch, OpenAI is signalling that text watermarking remains an experimental compliance tool rather than a settled product standard. The company is effectively saying the technology is ready for limited deployment, but not yet ready to be imposed universally on every user and every workflow.
| Rollout area | Who gets it | Status | Key limitation |
|---|---|---|---|
| European Union | Eligible ChatGPT and Codex users across all plans | Rolling out over coming weeks | Not a global default |
| API customers worldwide | Developers using select models | Opt-in available now | Customer must enable it |
| Researchers and expert organisations | Approved applicants | Applications open now | Case-by-case access only |
| Cloud partner integrations | Users accessing OpenAI models via partners | Coming soon | Availability varies by partner |
What textGrain can and cannot do
OpenAI’s textGrain system is designed to insert an invisible pattern into generated text that authorised tools can later detect. In theory, that creates a trail showing whether a passage likely came from an OpenAI model. In practice, the company says the system is still imperfect and should be treated as a provenance aid rather than a definitive judge.
That distinction is critical. Watermarking may help companies and researchers trace the origin of some AI output, but it does not tell anyone whether the text is truthful, original, plagiarised or ethically used. Nor does it establish whether a human edited the text before publishing it.
What the watermark does not prove
OpenAI is explicit that the new tool does not function as a universal authentication stamp. According to the company, it cannot confirm whether text is accurate, whether the user owns the content, or how much human editing took place. It also cannot prove that a person wrote the text from scratch.
- It does not verify factual accuracy.
- It does not determine ownership or copyright status.
- It does not measure the level of human contribution.
- It does not guarantee detection in every case.
- It does not make the text publicly traceable by default.
That caution reflects a broader problem in the AI industry: provenance tools can help, but they are not a complete defence against misuse, misinformation or hidden automation. A watermark may be useful in regulated workflows, newsroom checks or enterprise audit trails, but it is not a silver bullet.
How reliable is AI text watermarking?
OpenAI says its approach “matched or exceeded” competing text watermarking methods in its own benchmark testing, including Google DeepMind’s SynthID for text, which has also been adopted as the basis for Anthropic’s watermarking initiative. The company shared performance comparisons suggesting that watermarked and unwatermarked text performed similarly on quality measures.
Even so, the company is warning users not to overstate what the tool can do. It says textGrain still can miss some watermarked content and may sometimes flag text incorrectly. Those trade-offs are one reason the detector is not being opened to the public at launch.
OpenAI says only approved researchers and expert organisations will get detector access at first, and the tool will simply indicate whether an OpenAI watermark is present without exposing prompts, conversations or user identity.
This restricted access suggests OpenAI wants independent evaluation without creating a public system that could be misused, reverse-engineered or gamed. It also reflects concern that unreliable detection could lead to false accusations if a tool were widely deployed without guardrails.
Why the EU AI Act is shaping product design
The European Union AI Act is becoming one of the most important policy forces shaping product decisions at major AI companies. OpenAI’s move follows similar compliance-driven steps from Anthropic and other developers seeking to align their tools with emerging European transparency requirements.
For companies that generate text at scale, the challenge is increasingly not just building models that sound good, but proving how those models are used. Regulators want more accountability around synthetic media, and watermarking is one of the few technical methods available to address that demand at the output level.
Why other companies are doing this too
OpenAI is not alone. Anthropic introduced its own watermarking-related move in August, and OpenAI points to Google DeepMind’s text watermarking work as a benchmark reference. The converging direction suggests the industry is coalescing around a shared view: if AI-generated text is going to flood everyday workflows, provenance tools will be needed to keep pace.
Still, there is no consensus that watermarking will be enough. Critics have long argued that any detectable pattern can be weakened or removed through editing, translation, rewriting or even simple paraphrasing. That makes watermarking more useful as a piece of a broader transparency stack than as a standalone solution.
How researchers and companies may use the detector
OpenAI says approved researchers and expert organisations can apply for access beginning now. The goal is to support evaluation and improvement of text provenance tools, not to build a public-facing checker that anyone can run on any paragraph.
For API customers, the ability to opt in gives developers flexibility. A company building compliance-heavy products may want watermarked output for audit purposes, while a creative tool or consumer app may prefer not to add any additional metadata to its generated text. OpenAI is trying to accommodate both use cases.
Potential use cases
In practice, the feature may be most valuable where organisations already have a reason to track content origin. That includes customer support systems, enterprise knowledge tools, publishing workflows, academic integrity systems and internal corporate assistants.
- Helping organisations document when text came from an AI system.
- Supporting internal compliance checks and audit trails.
- Assisting researchers studying synthetic text detection.
- Giving enterprise customers more transparency options.
- Testing how provenance tools behave in real-world environments.
Even in those settings, however, users will need to combine watermarking with other controls such as disclosure policies, editorial review and model logs. A hidden marker alone cannot replace institutional oversight.
What OpenAI’s benchmark claims mean
OpenAI says its own evaluation showed textGrain performing at least as well as other known text watermarking methods, including approaches associated with Google DeepMind. That claim is important because the technical race around provenance tools is still young, and no system has yet become the industry standard.
Benchmark results can be useful, but they do not always reflect messy real-world usage. AI outputs are edited, copied, reformatted and translated constantly. A watermark that performs well in a controlled test may behave differently once users start pasting text into other apps, mixing content with human writing or feeding it through downstream tools.
That gap between lab testing and deployment reality is likely one reason OpenAI is rolling the feature out slowly. The company wants data, feedback and misuse reports before deciding whether the technology deserves broader adoption.
What happens next
In the near term, the main development to watch is whether the EU rollout goes smoothly and whether developers actually use the opt-in version through the API. If adoption is strong and the technology proves useful without causing major friction, OpenAI may have more confidence to expand it.
But the company is not promising a global default, and that wording matters. It suggests the current step is more about compliance, testing and optional transparency than a permanent policy commitment to watermark every output everywhere.
| Milestone | What happened | Why it matters |
|---|---|---|
| August | Anthropic announced a watermarking-related move | Showed the industry trend toward provenance tools |
| Earlier benchmark work | Google DeepMind’s SynthID text approach became a reference point | Provided one of the main technical baselines |
| Now | OpenAI starts EU-only rollout for ChatGPT and Codex | Brings watermarking into mainstream consumer and developer products |
| Coming weeks | Cloud partner support and EU access expand | Tests whether watermarking can scale across products |
The bigger picture for AI transparency
OpenAI’s announcement is less about one technical feature than about a shifting industry baseline. As generative AI moves from novelty to infrastructure, companies are being pushed to account for where text comes from, how it is labelled and whether it can be traced after publication.
Text watermarking will not settle debates about authorship, trust or accountability on its own. But it is becoming one of the clearest signs that AI companies expect regulation to shape product design more directly in the years ahead.
For OpenAI, the EU-first launch offers a pragmatic compromise: comply where the pressure is strongest, let developers choose elsewhere, and keep detector access narrow enough to study the system without broadcasting a universal verification tool. Whether that approach becomes a template for the rest of the industry may depend on how often the watermarks survive the messy reality of everyday use.
Key details at a glance
Here are the main points from OpenAI’s announcement:
- Text watermarking is arriving in ChatGPT and Codex.
- The initial consumer rollout is limited to the European Union.
- API customers worldwide can opt in for select models.
- Approved researchers and expert organisations can apply for detector access.
- OpenAI is not making watermarking a global default at launch.
- The company says the system helps with provenance but is not fully reliable.
Frequently asked questions
What is OpenAI’s text watermarking feature?
OpenAI’s text watermarking feature is an invisible, machine-readable signal embedded in AI-generated text so approved tools can later identify that the content likely came from an OpenAI model. It is meant to help with provenance, not to prove accuracy, ownership or human authorship.
Is text watermarking being rolled out globally?
No, text watermarking is not a global default at launch. OpenAI is starting with eligible ChatGPT and Codex users in the European Union, while API customers around the world can opt in for select models if they want watermarked outputs.
Can anyone use OpenAI’s watermark detector?
No, the detector is not being made public at launch. OpenAI says only approved researchers and expert organisations can apply for access, and the tool will be granted on a case-by-case basis to help evaluate and improve text provenance.
Does a watermark prove that text is accurate or AI-generated with certainty?
No, it does not. OpenAI says text watermarking does not verify truth, ownership or authorship, and it also cannot guarantee perfect detection. The company warns that missed watermarks and false positives are possible, so the tool should not be treated as definitive proof.
Why is OpenAI launching text watermarking in the EU first?
OpenAI is launching text watermarking in the EU first because the European Union AI Act and related transparency expectations are pushing AI companies toward better content provenance tools. The regional rollout also lets the company learn from real-world use before deciding on broader expansion.









