OpenAI on October 5 detailed its answer to the EU AI Act's requirement that providers mark AI-generated text in a machine-readable way: a text watermark called textGrain. The system embeds an invisible statistical signal into the model's word choices; a detector looks for that signal to judge whether a passage carries OpenAI's watermark. Over the coming weeks, eligible ChatGPT and Codex text outputs in the EU will get the watermark across all plan tiers — and OpenAI is explicit that it will not be a global default at launch.
The numbers OpenAI published are unusually candid about the technique's limits. At a target false-positive rate of 1%, the detector catches roughly 80% of 200-token passages and about 95% of 400-token passages in psychology-style prose. Mathematical content, where word choice is far more constrained, detects markedly worse. Editing erodes the signal fast: swapping synonyms into 10% of words drops detection from about 92% to 66%, and at 25% replacement it falls to 17% — meaning a determined rewriter can effectively wash the watermark out.
On quality, the company reports no meaningful difference with watermarking switched on for its frontier Astra (max) model: GPQA Diamond moved from 94.44% to 93.94%, BrowseComp from 87.92% to 87.35%, and Terminal-Bench 4.0 actually rose from 53.90% to 56.06%. OpenAI also says textGrain performed on par with or better than other schemes it tested, including Google's SynthID for text — a comparison based on the company's own evaluations and not independently verified. A technical report is out, with more details promised, and OpenAI says it plans to open-source the technique.
Availability is staged. From today, API customers anywhere can opt in to watermarking on selected models; it is off by default in the API, leaving compliance decisions to developers. OpenAI is working with cloud partners to extend watermarking to model outputs served through their platforms in the coming weeks. The detector itself will not be public: approved researchers and expert organizations can apply for access on a case-by-case basis under a code of conduct, and the tool only reports whether an OpenAI watermark is present — it does not identify users or expose prompts.
The announcement devotes an entire section to what watermarking cannot do. It cannot measure how much a human contributed, establish ownership or legal responsibility, identify the user, or verify whether content is accurate. And the inverse trap matters just as much: failure to detect a watermark proves nothing about human authorship, since text may be too short, edited, translated, or generated by a different provider's model entirely.
Text is the last and hardest layer of OpenAI's provenance stack. Image outputs already carry C2PA Content Credentials, image and audio embed visible-tooling-agnostic SynthID-style signals where supported, and the company's verify portal and Content Provenance API for image and audio remain publicly accessible — unlike the text detector. The regional EU-first rollout, OpenAI argues, buys room to learn from real usage before deciding whether watermarking should ever become a global default.
Comments (0)
Log in to join the discussion
Log InNo comments yet