Why OpenAI is watermarking ChatGPT text in the EU

OpenAI will add an invisible watermark to text generated by ChatGPT and Codex for eligible users in the European Union. The move is tied to EU AI Act transparency rules, but OpenAI says detection has limits and a missing watermark does not prove a person wrote the text.

Why OpenAI is watermarking ChatGPT text in the EU

OpenAI is preparing to mark text generated by ChatGPT and Codex in the European Union with an invisible watermark. The change is designed to help other systems identify AI-generated content, while leaving the text readable in the same way to ordinary users.

The rollout is tied to the EU AI Act’s transparency rules, which took effect on August 2. OpenAI said the feature will come to eligible ChatGPT and Codex users on all plans in the EU over the coming weeks.

What OpenAI is changing

The watermark will apply to text from ChatGPT and Codex for eligible users in the European Union. OpenAI is not making text watermarking a global default at launch.

Developers using OpenAI’s API anywhere in the world can turn on the watermark for select models starting today, but it is off by default. That creates two different paths: a regional default for eligible ChatGPT and Codex users in the EU, and an optional developer setting for selected API use elsewhere.

The change is not a visible label, badge, or symbol. Readers will not see a mark on the page. Instead, the watermark is built into the wording of the output itself.

How the invisible watermark works

OpenAI described the system as a way of subtly shaping the model’s word choices. Those small choices leave a pattern that people cannot see, but a detector can identify.

Because the signal is carried by the words, it can remain with the content when the text is copied and pasted. That is different from metadata or a visible disclosure, which can be separated from the text more easily.

OpenAI also said the watermark does not identify the user. The company said it saw no meaningful change in model performance when the watermark was switched on.

Alongside the announcement, OpenAI published a technical report for its method, called textGrain. The report was co-written with researchers from the University of Pennsylvania and Yale. It explains an example in which a secret key is used to sort next-word predictions as a sentence is completed.

The core idea is cumulative. One small nudge in word choice may not prove much. Add hundreds of such signals together, and a detector can assess whether text appears to have been generated by an OpenAI system using the relevant key.

Detection has clear limits

OpenAI’s own testing points to important weaknesses. In one test, replacing 10% of words with synonyms dropped detection from about 92% to 66%.

The company also said some kinds of text are harder to detect. Short passages, math answers, and translated text can make the watermark less reliable.

Those limits matter because watermarking can be misunderstood as a simple yes-or-no authorship tool. OpenAI specifically cautioned that a missing watermark “does not prove human authorship.” The text might be too short, too heavily edited, or generated by another company’s AI system.

OpenAI also said, “[Watermarks] can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it.”

For that reason, the detector will not be broadly available at first. OpenAI said these limits are part of why initial detector access will go only to approved researchers and expert organizations, who can evaluate reliability and responsible uses.

Why the EU rollout matters

The immediate driver is regulatory. The EU AI Act’s transparency rules require AI companies to mark AI-generated content in a way other systems can identify.

OpenAI is one of several companies that have committed to following the EU’s code of practice on AI-generated content. Anthropic, Google, Meta, Microsoft, and OpenAI are among the companies named in that group.

The approach differs from Anthropic’s recent move. Anthropic said two months earlier that it would watermark text generated by Claude worldwide. That decision drew backlash from some Claude users, who argued that they had supplied “the instructions, context, decisions” while Claude was just “the tool.”

OpenAI has previously built a text watermark but did not release it at the time. The Wall Street Journal reported in 2024 that one concern was that users might switch to competitors that did not watermark text.

What users should take from it

The practical effect is narrow but significant. In the EU, eligible ChatGPT and Codex users should expect future generated text to carry an invisible signal. Developers outside the EU can choose to enable the feature for select models through the API.

But the watermark should not be treated as a full account of authorship. It can indicate that an OpenAI system generated or processed part of a passage. It cannot, by itself, explain how much a person shaped the result.

That distinction will be central as AI-generated content rules mature. Watermarking may help with transparency, but OpenAI’s own description makes clear that detection is probabilistic, context-dependent, and vulnerable to editing.