OpenAI ships opt-in textGrain text watermarking in API, with EU ChatGPT and Codex rollout to follow
OpenAI has launched textGrain, an invisible statistical text watermark, as opt-in for API customers worldwide on select models. ChatGPT and Codex output in the EU will be watermarked in the coming weeks, in response to the EU AI Act. OpenAI says detection drops from about 92% to 17% when 25% of words in a 400-token passage are replaced.
OpenAI has launched textGrain, a text watermarking system, as an opt-in feature for API customers worldwide on select models, effective October 5, 2026. The company says it will add the invisible watermark to eligible ChatGPT and Codex text output in the European Union "in the coming weeks." OpenAI framed the move as compliance with the EU AI Act, which requires providers of generative AI systems to mark AI-generated text so it is identifiable.
What is changing
- API: Customers globally can opt in to watermarking for select models. It stays off by default. OpenAI has not said which models are included.
- ChatGPT and Codex: Watermarking applies initially only to eligible users in the EU, starting in the coming weeks.
- Detector: Applications are open, but access is limited to approved researchers and expert organizations while OpenAI evaluates and improves the technology.
- Open source: OpenAI says it plans to release the technology as open source. No date was given. A technical report will be updated with more details in the coming weeks.
According to OpenAI, textGrain adds "an invisible statistical signal to the model's word choices," and its detector looks for that signal to assess whether a passage carries an OpenAI watermark. Anthropic announced a similar word-choice approach for Claude a few months ago. Claude's watermark uses a secret key specific to Anthropic, so its detector cannot identify text from OpenAI or other providers. OpenAI has not said whether textGrain works the same way.
Robustness figures
OpenAI's own evaluation shows the watermark degrades quickly under editing. On 400-token passages:
- Replacing 10% of words with synonyms reduced detection from about 92% to 66%.
- Replacing 25% of words reduced detection to 17%.
OpenAI also says the detector can produce both false positives and false negatives, particularly on short texts and in domains with little word-choice flexibility, such as mathematics.
Impact on model quality
OpenAI says it found no meaningful difference in overall performance. It compared watermarked and unwatermarked output from a configuration labeled "Astra, max":
| Benchmark | Unwatermarked | Watermarked |
|---|---|---|
| Artificial Analysis Intelligence Index | 49.57 | 49.76 |
| AutomationBench | 34.09% | 34.86% |
| DeepSWE v1.1 | 72.80% | 71.68% |
| Terminal-Bench 4.0 | 53.90% | 56.06% |
| Terminal-Bench Science 0.1 | 56.90% | 60.00% |
| BrowseComp | 87.92% | 87.35% |
| HealthBench Professional | 64.27% | 64.60% |
| GPQA Diamond | 94.44% | 93.94% |
These are company-reported results. Four benchmarks moved up and four moved down, with the largest swing a 3.1-point gain on Terminal-Bench Science 0.1. OpenAI did not publish confidence intervals or run counts in the material available.
Stated limitations
OpenAI says a watermark does not measure human contribution, establish ownership or responsibility, identify the user, or verify accuracy. It adds that the absence of a detected watermark does not prove human authorship. The company says it will keep studying how well watermarks survive editing and translation, and whether they can better distinguish AI assistance from AI authorship.
What this means
The rollout is deliberately narrow. The API is opt-in and the consumer products are limited to the EU, so for most developers outside Europe nothing changes by default. This is a minimal-footprint compliance move rather than a global provenance system.
The robustness numbers limit what textGrain can do. A 75-point drop in detection from a 25% synonym swap means anyone who wants to evade it can do so with light editing. It is useful for catching unedited output at scale, not for adversarial settings. With the detector restricted to vetted researchers, educators and publishers cannot use it to check student or contributor text.
For API builders, the practical questions are which models support watermarking, whether it affects latency or cost, and how it behaves with structured output and code. OpenAI has not answered these. The planned open-source release matters most here. If it ships with a reproducible detector, outside researchers can test the claims independently.
Related Articles
OpenAI to watermark ChatGPT and Codex text in the EU under AI Act; API opt-in available worldwide
OpenAI will add an invisible watermark to text generated by ChatGPT and Codex in the European Union to comply with the EU AI Act's transparency rules. Developers anywhere can enable it on select API models starting today, but it is off by default. OpenAI's own tests show detection falling from about 92% to 66% after 10% of words are replaced with synonyms.
OpenAI to watermark ChatGPT and Codex text in the EU with textGrain; API watermarking is opt-in worldwide
OpenAI will switch on invisible text watermarks called textGrain for ChatGPT and Codex users in the EU over the coming weeks. API watermarking will be opt-in worldwide, unlike Anthropic's mandatory approach for Claude. OpenAI's own data shows detection drops sharply when text is edited.
GPT-6 Astra Ultrafast Claims Up to 8x Faster Token Generation on NVIDIA Blackwell GPUs
GPT-6 Astra Ultrafast, running on NVIDIA Blackwell GPUs, is available now in the OpenAI API and to eligible ChatGPT Work and Codex users. NVIDIA says it generates tokens up to 8x faster than Astra Standard mode. Pricing and context window details were not disclosed in the source.
ChatGPT adds virtual try-on and Favorites in global shopping update built on Images 2.5
OpenAI launched two shopping features in ChatGPT globally on Thursday: a virtual try-on tool for clothing and accessories, and a Favorites function for saving products. OpenAI says both use its newly launched ChatGPT Images 2.5 model. Pricing and plan availability were not disclosed in the source reporting.
Comments
Loading...