ChatGPT text watermark arrives in the EU — swap 10% of words and detection falls to 66%
OpenAI said on October 5, 2026 that it will add an invisible watermark, called textGrain, to text written by ChatGPT and Codex for users in the European Union, rolling out over the coming weeks across all plans. The legal driver is Article 50 of the EU AI Act, in force since August 2, which requires AI-generated content to be marked in a machine-readable, detectable way. textGrain nudges word choices against a secret key, leaving a statistical pattern a detector can find. In OpenAI tests, 400-token passages were detected about 95% of the time, but replacing 10% of words with synonyms cut that to 66%, and 25% cut it to 17%. In the API the feature is off by default worldwide
The three lines
- Announcement — October 5: textGrain watermark for ChatGPT and Codex text, EU users first, all plans within weeks
- Method — a secret key tilts word choice; ~95% detection at 400 tokens, 66% after 10% of words are changed
- Limits — weak against paraphrase and translation; detector limited to approved researchers; no watermark ≠ human
Key questions
- Will ChatGPT watermark text outside the EU
- **Not by default, as of October 2026.** | Group | Status | |---|---| | EU ChatGPT and Codex users | Default, rolling out over weeks | | ChatGPT users elsewhere | No announced plan | | API customers worldwide | Opt-in, off by default, select models |
- How accurate is textGrain detection
- **Strong on long, untouched text; weak once edited.** (OpenAI report, 1% false-positive rate) | Condition | Detection | |---|---| | 400 tokens | ~95% | | 200 tokens | ~80% | | 10% of words swapped | 92% → 66% | | 25% swapped | 17% | | Math answers, 400 tokens | ~60% | | Other EU languages | 42.2% (Romanian) to 69.0% (Spanish) |
- Does no watermark mean a human wrote it
- **No — OpenAI says so explicitly.** | Case | Why the mark is missing | |---|---| | Short text | Too few signals | | Heavy editing | Pattern broken | | Translation | Pattern lost | | Another vendor model | Never marked |
AI-written text is about to carry an invisible stamp — at least in Europe. On October 5, 2026, OpenAI said it will watermark text generated by ChatGPT and Codex for users in the European Union, rolling out across all plans over the coming weeks. Image watermarks are routine; a major chatbot marking the words themselves is new. The test results OpenAI published alongside show how easily the stamp can be rubbed off.
1. Why now, and why only the EU
The reason is law. Article 50(2) of the EU AI Act requires providers of generative AI to mark outputs "in a machine-readable format" so they are "detectable as artificially generated." That obligation applied from August 2, 2026, with systems already on the market given until December 2 to comply.
| Item | Detail |
|---|---|
| Announced | October 5, 2026 (technical report) |
| Products | ChatGPT and Codex text |
| Region | EU users, all plans |
| Timing | Phased over the coming weeks |
| API | Worldwide opt-in, off by default, select models |
| Legal basis | EU AI Act Article 50(2), applied August 2; legacy deadline December 2 |
| Detector | Approved researchers first (Cornell, ETH Zurich and others) |
Users in South Korea, the U.S. and elsewhere see no change for now; businesses on the API can switch it on in their data controls.
2. How it hides, and how often it is caught
textGrain does not insert hidden characters. As the model picks each next word, a value computed from the preceding words and a secret key tilts it slightly toward certain choices. The text reads normally; a detector holding the key looks for hundreds of these tilts adding up. So longer text is easier to catch, and every edited word weakens the signal.
| Condition (1% false positives) | Detection rate |
|---|---|
| 400-token passage | ~95% |
| 200-token passage | ~80% |
| 10% of words replaced with synonyms | 92% → 66% |
| 25% replaced | 17% |
| Math answers, 400 tokens | ~60% |
| Non-English EU languages | 42.2% (Romanian) to 69.0% (Spanish) |
The last row stands out: at the same length, detection drops sharply outside English. OpenAI has not published results for Korean, Japanese or other Asian languages.
3. What changes and what does not
What changes: regulators and researchers get, for the first time, a way to check after the fact whether a major chatbot was involved in a piece of text — useful for tracing election disinformation or mass-produced spam.
What does not: OpenAI states that the absence of a watermark "does not prove human authorship." Short answers, heavily edited text, translations and output from other vendors all slip through, and a positive result says only that AI was involved, not how much. That makes it a poor tool for schools or employers judging cheating. Access to the detector is also narrow: the EU code of practice calls for regulators, police, media, fact-checkers and civil society to get it, but not ordinary businesses. For the full set of disclosure duties, see "What Article 50 of the EU AI Act is."
4. What remains unconfirmed
- The EU rollout end date has been given only as "the coming weeks."
- Detection rates for Korean and other non-EU languages, and any plan to make watermarking default elsewhere, are unpublished.
- How Google, Anthropic and other providers will meet the same EU text-marking duty has not been announced.
- All accuracy figures are OpenAI's own and await outside testing.