IA · 6 October 2026 · 4 min read

OpenAI Rolls Out Invisible Text Watermarking to ChatGPT and Codex in the EU

In brief: OpenAI has announced an invisible watermarking system for text generated by ChatGPT and Codex, rolling out exclusively to European Union users to comply with the EU AI Act's transparency mandates. The proprietary technique, dubbed textGrain, subtly influences token probabilities rather than embedding visible symbols or hidden metadata. However, tests show the watermark remains vulnerable to simple synonym replacements and light paraphrasing.

by Team Mocchi's

OpenAI Rolls Out Invisible Text Watermarking to ChatGPT and Codex in the EU

Meeting the Mandates of the EU AI Act

Regulatory compliance under the European framework for artificial intelligence has reached its most technically demanding frontier: the provenance of synthetic text. OpenAI announced it will begin applying invisible cryptographic watermarks to text generated across ChatGPT and its coding tool Codex within the European Union. The initiative follows the transparency provisions of the EU AI Act, which took effect on August 2, 2026, requiring AI developers to ensure artificial outputs can be systematically identified by machine detectors.

As reported by TechCrunch, this rollout is strictly regional. While eligible EU users across all tiers—including Free, Plus, and Enterprise—will have the feature activated automatically over the coming weeks, it will not become a default setting globally. For API customers worldwide, OpenAI is offering watermarking on an opt-in basis for select models, leaving it disabled by default. The move mirrors Anthropic's August deployment of SynthID-based text watermarking, similarly designed to satisfy Brussels regulators.

Under the Hood: textGrain and Pseudorandom Nudges

Watermarking textual output without altering semantics or degrading user experience has long posed an algorithmic challenge. Unlike images or audio, text cannot hide imperceptible noise without altering characters. In a technical report co-authored with researchers from the University of Pennsylvania and Yale, OpenAI detailed its solution, named textGrain.

The system avoids hidden zero-width characters or file-level metadata that would instantly vanish upon copying and pasting. Instead, textGrain operates at the token selection stage. Driven by a secret cryptographic key, the model applies subtle mathematical nudges to rank and select next-word predictions. While individual sentences read naturally to human readers, the accumulated distribution across paragraphs creates a distinct statistical signature. Armed with the corresponding key, a specialized detector can confirm whether a text was generated by OpenAI models using purely the raw words.

OpenAI highlighted that the mechanism does not embed identifiable user data and showed negligible impact on benchmark accuracy during internal quality evaluations.

Fragility and Detection Limits

Despite the sophisticated mathematical underpinnings, the real-world robustness of text watermarking remains precarious. As highlighted by The Verge, OpenAI openly acknowledged that textGrain «does not guarantee reliable detection.» Testing showed that swapping just 10% of the words with synonyms caused detection rates to tumble from approximately 92% to 66%.

Furthermore, the system struggles significantly with short answers, math formulas, programming snippets, and passages translated across languages. OpenAI explicitly clarified that text watermarks cannot authenticate factual accuracy, settle intellectual property disputes, or quantify the extent of human editorial contribution.

Compounding these technical boundaries, the detector tool will not be publicly accessible. Access is currently reserved for vetted academic researchers and institutional evaluators, leaving enterprise end-users without direct tooling to inspect outputs.

Mocchi's Take

For European enterprises and developers leveraging generative models, the deployment of textGrain underscores how the AI Act is actively shaping model behavior along geopolitical lines. Teams consuming OpenAI's APIs for proprietary code generation or automated communications must audit these token adjustments to ensure consistency between European and overseas environments. Because statistical watermarks degrade quickly under minimal human editing, organizations cannot rely on automated detection as a silver bullet for IP hygiene or compliance; internal governance frameworks and explicit provenance disclosures remain an absolute necessity.

Further reading

All articles on the Mocchi's blog