SSD Nodes Learn Hosting plans →
Guides Matt ConnorBy Matt Connor

ChatGPT Text Watermarking in the EU, Explained

OpenAI is adding an invisible textGrain watermark to ChatGPT and Codex text in the EU. See who is covered and why a detection proves less than you might think.

What ChatGPT text watermarking in the EU means

ChatGPT text watermarking in the EU means that text written by ChatGPT and Codex for users in the European Union (EU) now carries an invisible statistical mark called textGrain. OpenAI started the rollout on 5 October 2026 and says it will reach all plans over the following weeks. Outside the EU, ChatGPT text is not watermarked by default. API (application programming interface) customers anywhere can switch the mark on for selected models. It stays off unless they do.

The mark lives in the choice of words. You cannot see it on screen, and copying the text does not remove it. Only a detector that holds OpenAI's secret key can test for it. At launch, OpenAI gives that detector to approved researchers and expert organisations, not to the public.

The rest of this guide explains how a mark can hide in word choice. Then it answers the questions readers actually ask: what a detection proves, and whether the rule applies to their account.

Why OpenAI is doing this: Article 50 of the EU AI Act

The EU AI Act is the EU's law on artificial intelligence (AI). Article 50 holds its transparency rules. Paragraph 2 requires providers of AI systems that generate synthetic text, audio, images or video to mark that output in a machine-readable format, so that it can be detected as AI-generated. These rules apply from 2 August 2026.

The law does not name a technique. A voluntary EU code of practice on marking AI-generated content describes how providers can meet the duty, and OpenAI says it grants detector access under that code. For text, OpenAI's answer is a watermark in the wording. Text gets no public checking tool at launch.

Who gets watermarked ChatGPT and Codex text?

OpenAI splits the rollout by product and by region. As of October 2026 it looks like this:

  • ChatGPT in the EU, on every plan. OpenAI describes the EU rollout as covering all plans. That wording covers free and paid personal plans, and it does not carve out Business, Enterprise or Edu workspaces.
  • Codex in the EU. Eligible Codex text output gets the same treatment as ChatGPT. If you reach Codex through your plan, using Codex with a ChatGPT subscription explains how that access works.
  • The OpenAI API, worldwide, off by default. From 5 October 2026 an API organisation can turn the watermark on for selected models in its settings. Nothing changes until someone opts in.
  • ChatGPT outside the EU. No watermark by default. OpenAI says it is not making text watermarking a global default at launch.

"Over the coming weeks" means two EU users can get different behaviour during the rollout. You cannot tell which group you are in by looking at a reply, because the mark is invisible by design.

How does a statistical watermark in word choice work?

A language model writes one token at a time. A token is a small piece of text, often a whole word or part of one. At each step the model has a list of possible next tokens, each with a probability, and it picks one with some randomness. That randomness is why the same prompt gives a different answer each time.

OpenAI describes textGrain as a change to how that random pick is made. Schemes of this kind work like this: a secret key, combined with the text written so far, slightly favours some candidates over others at each step. A single choice still looks natural, because every candidate was a reasonable word. Across hundreds of choices, though, the pattern of which candidates won becomes statistically unusual. Only someone who holds the key knows which pattern to look for.

The detector runs the same process in reverse. It takes a passage, uses the key to work out which candidates each step would have favoured, and counts how often the text agrees. Human writing agrees about as often as chance predicts. Watermarked text agrees more often. The output is a statistical score, so a result is a level of confidence, not a stamp.

textGrain adds no hidden characters or invisible spaces. Older tricks that hid zero-width characters in text could be found and stripped by a script. Here there is nothing extra to find, because the mark is the words.

This design has direct consequences, and OpenAI's own results reflect them:

  • Longer text holds more choices to count, so detection gets more reliable as a passage grows. A one-line reply carries very little signal.
  • Text with little freedom in word choice carries a weaker mark. OpenAI reports lower detection on mathematics, because the next symbol in a calculation is often forced.
  • Every word a person changes removes one data point. Light edits leave most of the signal, while heavy rewriting removes much of it.
  • Translation replaces every original word, so the choices the key favoured are gone.

How reliable is the ChatGPT watermark detector?

OpenAI published a technical report with its detection rates, linked from its EU text provenance announcement. Each rate in that report comes with conditions. The main ones are the passage length in tokens, the false positive rate the detector was set for (how often it wrongly flags human text), the kind of text tested, and how much of it was edited.

Press coverage quotes different figures from the same report. One summary quotes rates for unedited passages at two lengths. Another quotes a single length before and after a share of words were swapped for synonyms. Each figure describes one test condition. None of them is "the" detection rate. If you need to cite a number, take it from OpenAI's report and keep its conditions attached.

The direction of the results is consistent, and OpenAI states it itself:

  • Detection rises with passage length.
  • Detection is lower for mathematics, and it varies by language.
  • Light edits and copying and pasting leave the mark detectable.
  • Swapping a large share of words for synonyms drops detection sharply, and substantial paraphrasing or translation can make the mark undetectable.

OpenAI presents that last point as a limitation of its own system. It also says that strong results under ideal conditions do not guarantee reliable detection in everyday use. That is the main reason it gives for keeping the detector restricted.

Who can run the detector?

At launch, ordinary users cannot. OpenAI limits the text detector to approved researchers and expert organisations. They apply through OpenAI's content provenance form, and OpenAI grants access case by case.

This means a teacher or an employer cannot upload a document to OpenAI and get an answer. A website that offers to check text for the ChatGPT watermark is not running OpenAI's detector unless OpenAI approved it, because the check needs OpenAI's secret key. Keep that in mind before you trust any public "ChatGPT watermark checker".

What does a watermark detection prove?

A positive result is statistical evidence that an OpenAI model, with the watermark switched on, generated a substantial part of the passage. That is all it shows.

OpenAI is direct about the limits. It says a watermark "does not measure human contribution, does not establish ownership or responsibility, does not identify the user, and does not verify accuracy." In practice, a positive result cannot tell you any of these:

  • which person or which account used ChatGPT
  • how much of the work a person wrote or edited
  • whether the content is true
  • who is responsible for it

Take two students. One asked ChatGPT to rewrite one paragraph of their own essay. The other pasted in a full generated essay. Both essays can produce a detection, and the score does not separate the two cases.

Does a missing watermark prove a human wrote the text?

No. OpenAI says this plainly as well. Text can be unmarked for many reasons that have nothing to do with human authorship:

  • it is too short to carry a signal, or it was edited, paraphrased or translated
  • it was generated before the rollout reached that user, or by a user outside the EU
  • it came from the API with the setting left off, which is the default
  • it came from another company's model, which uses a different method or none

To the detector, all of these look the same as human writing. A missing mark only means the detector found no signal. It says nothing about who wrote the text.

Does the watermark apply to Codex code output?

OpenAI's wording is "eligible" ChatGPT and Codex text output. The prose that Codex writes, such as explanations and commit messages, is ordinary text and fits the same scheme as ChatGPT replies. Check OpenAI's help pages for the exact list of eligible outputs.

Code itself is harder to mark, for the same reason mathematics is. Syntax and existing names fix many tokens in a file, so the model has fewer free choices for the key to bias. Expect any mark in code to be weaker than in prose of the same length. The conclusions from the previous sections still hold. A detection on code says nothing about how much a developer contributed, and an unmarked file says nothing about who wrote it.

This matters for maintainers who want to enforce open source policies on AI-assisted code. A watermark check cannot do that job, because maintainers have no access to the detector and a clean result proves nothing. Disclosure rules that ask contributors to state their AI use remain the practical tool.

What about ChatGPT Business, Enterprise and Edu?

OpenAI describes the EU rollout as covering all plans. An EU workspace on Business, Enterprise or Edu should therefore expect its users' text to carry the mark. The watermark does not identify the user, so it does not tell an outside reader which employee or which workspace produced a document.

If your organisation has staff both inside and outside the EU, ask OpenAI how it decides which users count as EU users. Do not guess from IP address or billing country. If you are comparing vendors for a team, comparing Claude and ChatGPT for enterprise teams puts this difference next to the others between the two products.

How does OpenAI's approach differ from Anthropic's?

Both companies mark text statistically through word choice, and neither adds anything visible. The clear difference is scope.

OpenAI limited ChatGPT watermarking to the EU at launch and made the API mark an opt-in everywhere. It says it chose a regional rollout so it could learn from real-world use and feedback first. Anthropic applies its watermark to Claude globally. Its argument is that a watermark cannot be durably limited by region, because text written in one country is read and republished everywhere. The full Claude side is in how Claude's text watermarking works.

The practical result for readers is this. Claude text may carry a mark wherever it was written, while ChatGPT text carries one only where OpenAI turned it on. Each company's detector looks for the pattern of its own secret key, so a check for one company's mark says nothing about the other's.

What should you do as a user or developer?

If you use ChatGPT in the EU for work you hand in under your name, follow your school's or employer's rules on AI disclosure. The watermark does not replace those rules, and it is not a reliable way for anyone to enforce them.

If you build on the OpenAI API, make the opt-in a deliberate decision. If your product generates text for people in the EU, Article 50 may place marking duties on you as a provider. The opt-in is one way to meet them. A lawyer can confirm what actually applies to you.

FAQ

Does ChatGPT watermark text outside the EU?

Not by default. As of October 2026, OpenAI adds the textGrain watermark to ChatGPT and Codex text only for users in the EU. It says it is not making text watermarking a global default at launch. API customers anywhere in the world can opt in for selected models, and that setting is off by default.

Are ChatGPT Business, Enterprise and Edu accounts watermarked in the EU?

OpenAI describes the EU rollout as covering all plans. EU users on Business, Enterprise and Edu workspaces should expect their text to be watermarked once the rollout reaches them, over several weeks from 5 October 2026. The mark does not identify the user or the workspace.

Can I check whether a text has the ChatGPT watermark?

Not through OpenAI at launch. The text detector needs OpenAI's secret key. OpenAI grants access only to approved researchers and expert organisations, case by case, through its content provenance form. A public website that claims to detect the ChatGPT watermark is not using OpenAI's detector unless OpenAI approved it.

If a text has no ChatGPT watermark, does that prove a human wrote it?

No. Text can be unmarked because it is short, edited, paraphrased or translated. It can also be unmarked because it was generated outside the EU or before the rollout, because it came from the API with the setting off, or because another company's model wrote it. OpenAI says a missing mark does not prove human authorship.

Is code written by Codex watermarked?

OpenAI covers eligible Codex text output in the EU. Codex prose such as explanations and commit messages fits the scheme directly. Code has fewer free word choices, so any mark in it is weaker. A detection on code still says nothing about how much a developer contributed.