Security & Governance

OpenAI's textGrain embeds invisible watermarks in AI text: here's what changes for you

OpenAI's textGrain watermarks AI-generated text statistically. API opt-in opens 5 October 2026; EU ChatGPT and Codex users get it automatically.

security governance category

OpenAI has announced textGrain, a system that embeds an invisible statistical watermark into the words its models choose when generating text. From 5 October 2026, API customers worldwide can opt in. ChatGPT and Codex users in the EU will receive it automatically over the coming weeks, with no action required. The text reads exactly as it always did. The mark is in the pattern of word choices, not in any visible symbol or metadata tag.

What textGrain actually does

A language model picks the next word by scoring a probability distribution across thousands of options. Many of those choices are functionally interchangeable: “fast”, “quick”, and “rapid” often mean the same thing in context. textGrain links those choices to randomness derived from a secret key, so the resulting text carries a statistical signal that a detector holding the same key can recognise.

OpenAI models the selection as an optimal transport problem, using Gumbel random variables and a Kullback-Leibler regularisation term that penalises large deviations from normal model behaviour. An entropy budget caps how much variety the model can sacrifice to insert the signal. That constraint is why output quality stays close to normal: OpenAI reports 49.57 versus 49.76 benchmark points for watermarked against unwatermarked text, a difference that is not meaningful in practice.

Detection requires only the text itself and the secret key. The system does not need to know any generation parameters.

How well does it work?

Accuracy depends heavily on text length and how much the passage has been edited since generation.

ConditionDetection rate (at 1% false-positive rate)
200-token passage, unedited~80%
400-token passage, unedited~95%
400-token passage, 10% of words swapped for synonyms~66%
400-token passage, 25% of words swapped~17%

Code is harder to watermark than prose because there are fewer plausible alternatives at each step. Natural-language elements inside code, such as comments, remain more amenable to the technique than the logic itself.

Multilingual performance varies. Across the 23 other official EU languages tested, detection rates at the same 1% false-positive threshold range from 42.2% in Romanian to 69.0% in Spanish. OpenAI says it has applied a strengthened signal to languages that fell below 60%.

The 200-token threshold is not arbitrary: it mirrors the exemption in the European Code of Practice on AI transparency, which excludes “very short text” from watermarking requirements.

Why now, and why the EU specifically?

Article 50(2) of the EU AI Act requires providers of AI systems that generate text to mark their outputs in a machine-readable format so they can be identified as artificially generated. The obligation took effect from 2 August 2026, with a grace period running to 2 December 2026 for systems already on the market. Non-compliance carries penalties of up to €15 million or 3% of global annual turnover.

OpenAI is not the first to act. Anthropic began applying SynthID-Text watermarking to Claude outputs in August 2026, and unlike OpenAI’s approach, Anthropic’s watermarking applies globally by default, including via the API. OpenAI’s API opt-in structure means developers outside the EU are not required to enable it, though they can.

It is worth noting that OpenAI acknowledged in 2024 that it had built an effective watermarking system but held back deployment, citing concerns about false accusations against non-native English speakers and competitive risk. Regulation appears to have resolved that internal debate.

What changes for you

If you use ChatGPT or Codex in the EU: Eligible text output will carry a textGrain mark automatically over the coming weeks. Nothing changes in how the text reads or behaves.

If you are an API developer: Watermarking is off by default globally. You can enable it via Organisation settings, then Data controls, then Text provenance. It can be overridden at the project level under Project Settings, then Text provenance. There is no added cost.

If you build products that serve EU users: The API opt-in is the most straightforward route to meeting your own Article 50 obligations when you are passing OpenAI output to end users. Microsoft Azure support for textGrain is also coming in the weeks following launch.

If you are a researcher: A restricted detection tool is available to approved researchers and expert organisations operating under the EU Code of Practice. OpenAI is not releasing a public detector, and that restraint is deliberate. The concern is that a freely available tool would be misused as a verdict system, when the underlying statistics do not support that use.

If you are a teacher, editor, or hiring manager: A detected watermark tells you that an OpenAI system generated or processed part of that passage, and that is the full extent of the claim. It does not identify the user, account, or prompt. It does not establish whether the use was appropriate or disclosed. The absence of a detected watermark does not confirm human authorship. Text can fail detection because it was too short, edited, translated, generated by a different company’s model, or produced before watermarking was active.

What the watermark cannot tell you

OpenAI is explicit about this in their technical announcement, and it is worth repeating clearly: a positive detection is not proof of wrongdoing, and a negative detection is not clearance. The system establishes provenance signals, not intent or responsibility. Using it as a pass/fail detector for academic integrity or hiring decisions is not a supported use case, and the accuracy figures above show why that matters practically.

The technical report also notes that the theoretical false-positive rate requires empirical calibration in real deployments because of repeated contexts, finite-precision implementations, and the use of a fixed deployed key. The 1% figure is a controlled-condition result, not a universal guarantee.

The bigger picture

textGrain sits inside a broader framework that includes Content Credentials, C2PA conformance for images and audio, and OpenAI’s verify tool. Text watermarking is the piece that has taken longest to arrive, in part because text is the most editable medium and the one with the most acute false-positive risk.

OpenAI has said it intends to publish the textGrain technology as open source, without committing to a date. If that happens, other providers could implement compatible watermarks, which would make cross-provider detection more feasible. For now, the detector works only against OpenAI-generated text.

The practical takeaway is straightforward: if you operate in the EU, watermarked output is coming whether you enable it yourself or not. If you are building on the API outside the EU and care about provenance, the opt-in is free and available from 5 October 2026.