Regulation
OpenAI Begins Phased Text Watermarking Under EU AI Act Rules

OpenAI on October 5, 2026, set out its approach to text watermarking under the EU AI Act, opening opt-in watermarking to API customers worldwide and announcing that invisible watermarks will be added to eligible ChatGPT and Codex text output in the European Union over the coming weeks.
The EU AI Act requires generative AI providers to make generated text identifiable in a machine-readable way. OpenAI described text watermarking and detection as early technologies with significant limitations, and said its phased approach reflects both the legal requirements and those limits.
Opt-In API Access and Regional EU Rollout
From October 5, 2026, API customers globally can opt in to text watermarking for select models, and the setting remains off by default. OpenAI said the opt-in design lets customers decide how watermarking fits their transparency obligations and the experiences they provide to users, and that it is working with cloud partners to make watermarking available for OpenAI model outputs accessed through their services in the coming weeks.
For its own products, OpenAI will introduce text watermarking for eligible ChatGPT and Codex users across all plans in the European Union only, also in the coming weeks. The company said it is not making text watermarking a global default at launch and that the regional approach will let it learn from real-world use and feedback.
OpenAI also opened applications for access to its text watermark detector on October 5, 2026. Access will initially be limited to approved researchers and expert organizations, granted case by case in accordance with the EU’s Code of Practice on transparency of AI-generated content, to support evaluation and improvement of text provenance. The announcement applies only to text: OpenAI said its verification tools for audio and images, including the openai.com/verify web tool and the Content Provenance API, remain publicly accessible.
How textGrain Works
OpenAI’s watermarking technology, textGrain, embeds an invisible statistical signal in the words a model selects, and the company’s detector tests a passage for that signal to judge whether it carries an OpenAI watermark. A technical report titled “textGrain: Entropy-Calibrated Watermarking for Language Model Text,” dated October 5, 2026, lists authors affiliated with the University of Pennsylvania, Yale University, and OpenAI.
According to the report, the method ties token generation to keyed randomness by solving an optimal transport problem whose costs derive from Gumbel random variables, with Kullback–Leibler regularization penalizing departures from independence. An entropy budget caps the average sampling entropy given up in exchange for the watermark signal, and the report states that the KL penalty equals exactly the average entropy the watermark removes, giving the strength parameter a direct information-theoretic meaning. Applying the transport step to keyed blocks of vocabulary tokens cuts the size of the optimization while keeping relative token probabilities within each block unchanged. The detector needs only the generated text and the secret key, and not the entropy budget used during generation.
OpenAI said it plans to release the technology as open source so others can build on it, and that the report will be updated with additional details in the coming weeks.
Detection Performance and Stated Limitations
OpenAI reports that in its evaluations textGrain matched or exceeded the performance of other approaches it tested, including SynthID for text, while cautioning that strong performance under ideal conditions does not guarantee reliable detection in everyday use.
At a target false positive rate of 1%, the detector identified watermarks in about 80% of 200-token passages and about 95% of 400-token passages for content such as psychology, OpenAI reported, with substantially lower rates for content such as mathematics, where word choice is less flexible. In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%, and replacing 25% of words reduced it to 17%. The evaluations used watermarked English responses to questions from the ELI5 dataset.
On output quality, OpenAI said that across the benchmarks it uses to assess Astra, which it describes as its latest frontier model, it does not see meaningful performance differences with and without watermarking. Its published table reports, for unwatermarked and watermarked text respectively, 49.57 and 49.76 points on the Artificial Analysis Intelligence Index and 94.44% and 93.94% on GPQA Diamond. OpenAI said the detection limitations contributed to its decision to restrict initial detector access to approved researchers and expert organizations.
What a Watermark Does Not Establish
OpenAI states that a text watermark provides a limited signal about the role its systems played in a passage. A watermark does not measure human contribution, does not establish ownership or responsibility, does not identify the user, and does not verify accuracy, the company states. It also states that the absence of a detected watermark does not prove human authorship, because text may be too short, edited, or translated for reliable detection, may come from an unsupported model, may predate watermarking, or may have been generated by another company’s tools.
The detector will report whether it detects an OpenAI watermark without identifying the user or revealing their prompts or conversations. Given the risk of missed watermarks and false positives, OpenAI is not making the tool publicly available at launch.
EU Transparency Obligations
The transparency obligations under Article 50 of the AI Act, covering marking and detection of AI-generated content and labelling of deepfakes and certain AI-generated publications, apply from August 2, 2026. The Code of Practice on Transparency of AI-generated Content was drawn up by independent experts in a multi-stakeholder process facilitated by the AI Office, with the final code published June 10, 2026.
Adherence to the code is voluntary, but the Article 50 transparency requirements are legal obligations. The Commission and the AI Board have confirmed the code is an adequate voluntary tool to demonstrate compliance, and about 190 companies and organizations had signed the code by the end of July 2026, according to the Commission.
OpenAI said it will continue improving detection, studying how watermarks withstand editing and translation, and exploring ways to distinguish AI assistance from AI authorship, and that it will expand detector access when it believes results can be interpreted responsibly.












