product updateOpenAI

OpenAI to watermark ChatGPT and Codex text in the EU with textGrain; API watermarking is opt-in worldwide

TL;DR

OpenAI will switch on invisible text watermarks called textGrain for ChatGPT and Codex users in the EU over the coming weeks. API watermarking will be opt-in worldwide, unlike Anthropic's mandatory approach for Claude. OpenAI's own data shows detection drops sharply when text is edited.

3 min read
0

OpenAI will begin watermarking ChatGPT and Codex text for users in the European Union over the coming weeks, using a new technique called textGrain. API watermarking will be opt-in for customers worldwide, according to The Decoder, which cites OpenAI's announcement.

The move is tied to the EU AI Act, which reportedly requires AI providers to label generated text in a machine-readable format. textGrain embeds an invisible statistical signal in the model's word choices. The approach is similar to the SynthID-based watermark Anthropic uses for Claude, which is built on Google's open-source technology.

Rollout and scope

  • ChatGPT and Codex: Watermarking is enabled for EU users in the coming weeks.
  • API: Opt-in worldwide. Anthropic's Claude watermarking, by contrast, is mandatory and global regardless of access method.
  • Cloud partners: API watermarking will also be available through partners such as Microsoft Azure in the coming weeks.
  • Open source: OpenAI plans to release the technology as open source. No date was given.
  • Pricing: Not disclosed. No fee for watermarking has been mentioned.

Detection rates, per OpenAI

OpenAI claims textGrain matched or beat other approaches, including Google's SynthID for text, in internal tests. These results have not been independently verified.

With the detector set to a 1 percent false-positive rate:

  • 400-token passages (about 300 words) on psychology: about 95 percent detected (a chart caption in the source says about 94 percent).
  • 200-token passages: about 80 percent detected.
  • Math content: "substantially lower" detection, because the model has less freedom in word choice. A chart caption puts 400-token math detection at about 60 percent.

Editing hurts detection sharply. Replacing 10 percent of words with synonyms cuts detection for 400-token passages from about 92 percent to 66 percent. Replacing 25 percent drops it to about 17 percent. OpenAI provides no data on whether longer passages would improve detection.

Quality claims

OpenAI says watermarking does not degrade output quality. It cites tests on its frontier model Astra, which showed no significant performance differences with watermarking on or off across eight benchmarks, including GPQA Diamond, BrowseComp, and DeepSWE. Those benchmarks do not measure writing quality, a concern critics have also raised about Claude's watermark.

Limited detector access

Only selected researchers and specialist organizations will initially get access to the textGrain detector, through an application form. OpenAI will grant access case by case under the EU's Code of Practice. Anthropic takes a similar approach with its detection API.

The detector reports only whether it found an OpenAI watermark. It does not identify users or reveal prompts or conversations. OpenAI says it is restricting access because the detector can flag unmarked text or miss watermarks. It will expand access "when we believe results can be interpreted responsibly" but gave no timeline.

OpenAI also states that a detected watermark does not establish ownership, responsibility, user identity, or accuracy, and does not show how much human editing went into the text. A missing watermark does not prove human authorship: the passage may be too short, edited, translated, or from an unsupported model. Existing image and audio verification tools remain public, including openai.com/verify and the Content Provenance API.

What this means

The two leading closed-model providers now watermark text, but with different policies. Anthropic applies it globally and by default. OpenAI limits the default to the EU and lets API customers decide. That split favors developers who do not want watermarks in their products, and it leaves less text marked than a universal policy would.

The larger limitation is robustness. By OpenAI's own numbers, a 25 percent synonym swap pushes detection to about 17 percent. textGrain therefore works as compliance labeling and a signal for good-faith detection, not as a reliable way to catch deliberate evasion. The restricted detector reflects the same uncertainty: OpenAI is not confident enough in the false-positive and false-negative behavior to release it publicly.

Two things to watch are the open-source release, which would allow independent robustness testing, and whether detection results hold up outside OpenAI's internal evaluations.

Related Articles

analysis

Ramp AI Index: US business AI spending falls while usage rises about 50% from July peak

US companies are spending less on AI even as usage hit a record high at the end of September, according to the latest Ramp AI Index. Ramp economist Ara Kharazian attributes the drop almost entirely to price competition between OpenAI and Anthropic. In the last week of September, Anthropic took 51% of token spending and OpenAI 44.5%.

product update

GPT-6 Astra Ultrafast Claims Up to 8x Faster Token Generation on NVIDIA Blackwell GPUs

GPT-6 Astra Ultrafast, running on NVIDIA Blackwell GPUs, is available now in the OpenAI API and to eligible ChatGPT Work and Codex users. NVIDIA says it generates tokens up to 8x faster than Astra Standard mode. Pricing and context window details were not disclosed in the source.

product update

ChatGPT adds virtual try-on and Favorites in global shopping update built on Images 2.5

OpenAI launched two shopping features in ChatGPT globally on Thursday: a virtual try-on tool for clothing and accessories, and a Favorites function for saving products. OpenAI says both use its newly launched ChatGPT Images 2.5 model. Pricing and plan availability were not disclosed in the source reporting.

product update

Claude Opus 5.5 and Sonnet 5.5 now on Amazon Bedrock in AWS GovCloud (US), with Claude Code support

Claude Opus 5.5 and Claude Sonnet 5.5 are available on Amazon Bedrock in AWS GovCloud (US) Regions. AWS published a setup guide for running Anthropic's Claude Code against them for regulated workloads, including ITAR. Pricing, context window and benchmark figures were not disclosed.

Comments

Loading...