The watermark reaches EU users in the coming weeks, but OpenAI’s own tests found that changing one word in four cut the detection rate to 17%.
OpenAI said on Oct. 5 that it will add an invisible watermark to text that ChatGPT and Codex, its coding assistant, write for users in the European Union. The watermark is a pattern in the words the AI model chooses. A reader cannot see the pattern, but OpenAI’s software can check a passage for it.
OpenAI said it will add the watermark “over the coming weeks” for eligible ChatGPT and Codex users on all plans in the EU. It did not say which users are eligible.
Outside the EU, the watermark stays off unless a customer turns it on. Starting Oct. 5, companies anywhere in the world that connect their own software to OpenAI’s models can turn the watermark on for some of those models. OpenAI did not say which models. OpenAI also said it is working with cloud companies so their customers can use the watermark on the OpenAI models those cloud companies sell.
EU law requires that software be able to identify AI-written text
OpenAI said it is acting in response to the EU’s AI Act. The law requires companies that provide AI systems to make the text those systems write identifiable “in a machine-readable way,” meaning software can detect it.
The European Commission says the AI Act’s rules on marking AI-generated content have applied since Aug. 2. The Commission has also published a code of practice companies can sign to show compliance. Signing is optional, but complying with the law is not. OpenAI announced its support for the code in June.
OpenAI’s tests found that editing weakens the watermark
OpenAI calls the technology that adds the watermark textGrain. A second OpenAI tool, called a detector, checks a finished passage for the watermark.
OpenAI said a detector can make two kinds of mistakes. It can report a watermark in text that has none, or it can miss a watermark that is there.
OpenAI tested the detector on watermarked answers to psychology questions and mathematics questions. The detector scores each passage on how strongly the pattern shows up and reports a watermark when the score passes a set bar. OpenAI set the bar so that about 1 in every 100 passages with no watermark would pass it.
The detector found the watermark in about 80% of the psychology answers that were 200 tokens long and about 95% of those that were 400 tokens long. A token is a word or part of a word.
The detector found the watermark less often in the mathematics answers. OpenAI said mathematics leaves fewer ways to word an answer, which gives the model fewer word choices to build the pattern from.
Editing a passage also made the watermark harder to find. In another test, on 400-token passages, the detector found the watermark about 92% of the time. After replacing 10% of the words with synonyms, the detector found the watermark 66% of the time. After 25% of the words were replaced, the detector found it 17% of the time.
OpenAI said the watermark did not meaningfully change how its latest model, Astra, scored on eight tests the company uses to measure the model’s performance.
A detection result does not show who wrote a passage
OpenAI said a passage with no detected watermark was not necessarily written by a person. The text may be too short, or it may have been edited or translated. It may also have come from an OpenAI model that does not add the watermark, or from another company’s AI tool.
Finding a watermark does not identify the user, OpenAI said. The watermark is not tied to a person, an organization, an account, or the instructions someone gave the model.
OpenAI said a watermark also does not show how much of a passage a person contributed, who is responsible for the text, or whether anyone was required to disclose that AI was used.
Only approved researchers and expert organizations can use the detector
OpenAI began taking applications Oct. 5 for access to the detector. It said it will approve researchers and expert organizations one at a time. OpenAI said it is not making the detector public because it may miss watermarks or report watermarks that aren’t there.
OpenAI’s tools for checking whether an image or audio file came from its systems remain public.
OpenAI said it plans to publish textGrain’s code so that others can build on it. The company said it will widen access to the detector “when we believe results can be interpreted responsibly.”

