OpenAI will add invisible watermarks to ChatGPT text in the EU. No special characters are required. It may become invalid after rewriting.

📅 2026-10-06

Abstract:

OpenAI is gradually adding invisible watermarks to texts generated by ChatGPT and Codex in the European Union to meet the EU Artificial Intelligence Act's requirements for the legibility of AI-generated content. OpenAI said that this text watermarking technology called textGrain does not add hidden characters, invisible spaces or special punctuation to the article. Instead, it adjusts the word selection method when the model generates text, forming a statistical feature in the entire text that cannot be directly detected by the human eye but can be recognized by the machine.

1780081657_chatgpt_logo.webp

According to information released by OpenAI, the relevant transparency requirements of the European Union's Artificial Intelligence Act will come into effect on August 2, 2026. Generative AI service providers are required to have AI-generated content with machine-recognizable marks. OpenAI therefore plans to gradually roll out text watermarks to eligible ChatGPT and Codex users in the EU in the next few weeks, and this deployment will cover all ChatGPT packages, not just paying users.

This kind of watermark is different from "hidden text" in the traditional sense. When users copy the content generated by ChatGPT, a hidden character will not be copied at the same time, and no special symbols will be found in the text. What textGrain actually changes is the random selection probability of the model when faced with multiple possible words. The changes in a single word may be completely undetectable, but when a large number of words are combined, a statistical pattern may be formed that the detection system can recognize.

OpenAI stated that the advantage of this design is that it does not significantly change the normal text output. The company's tests found that the difference in model performance between adding watermarks and without adding watermarks was within the normal test fluctuation range, and the impact on text generation speed was also very small. During OpenAI's previous internal testing of ChatGPT, it did not find that the watermark function led to an increase in negative user reviews.

However, OpenAI also admitted that text watermarking is not a 100% reliable method of identifying AI content. There are two possible errors in watermark detection. One is that text without a watermark is misjudged as having a watermark, and the other is that the text actually has a watermark, but the detection system does not recognize it.

Text length is also an important factor affecting detection results. Shorter text has less room for the model to adjust word selection, making it more difficult to form a stable statistical signal. The rules published by OpenAI also show that in accordance with the EU AI transparency specifications, output of less than 200 tokens, about 150 English words, and code snippets are not required to add text watermarks.

There are also differences in detection results between different languages. OpenAI tested all 24 official languages ​​of the European Union. While maintaining a false positive rate of 1%, the detection rate of Spanish reached a maximum of 69%, while the detection rate of Romanian was only 42.2%. For languages ​​with weak detection effects, OpenAI can increase the watermark strength to enhance detection capabilities.

This means that textGrain cannot be understood as a technology that can 100% prove that it was generated by ChatGPT when you see the watermark. OpenAI makes it clear that even if the original text has not been modified, there is no guarantee that the detection system will be able to detect the watermark, especially when the text is short or the range of selectable words is small.

At the same time, there are obvious differences between text watermarks and AI text detectors currently on the market. Third-party AI detection tools such as Pangram mainly use classifiers to determine whether a piece of text is likely to be generated by AI by analyzing word choice, sentence structure and other language features. This method analyzes the text after it has been generated, while textGrain directly leaves a machine-readable statistical signal during the text generation process.

OpenAI believes that this approach is more in line with the EU AI Act’s requirements for “embedded” identifiable signals.

OpenAI did not directly adopt Google DeepMind's SynthID or other existing text watermarking solutions, but developed textGrain on its own. The company said that its self-developed technology allows it to more flexibly adjust the balance between the detectability of watermarks and the diversity of model outputs. In internal testing, textGrain recognized watermarked text at a rate that was equal to or higher than other solutions the company had tested, including SynthID for text.

OpenAI also plans to open source textGrain technology, hoping that other research institutions and companies can use this technology to further research and improve AI text source recognition. However, OpenAI will not immediately open the text watermark detector to the public, but will first provide application channels to approved researchers and professional institutions.

These authorized researchers and institutions can use OpenAI's detection tools to determine whether a piece of text contains a watermark generated by OpenAI, but the detection results will not reveal the user identity, prompt words or chat records corresponding to the generated content. OpenAI believes that since current technology still has risks of false positives and false negatives, directly opening detection tools to everyone may lead to over-interpretation of watermark detection results.

It is worth noting that OpenAI does not plan to enable text watermarks by default globally this time. The company stated that ChatGPT and Codex’s text watermarks will be gradually rolled out only for the EU region at this stage. This regional deployment will allow OpenAI to observe performance in real usage environments and adjust the technology based on actual feedback.

For API developers, the situation is different. OpenAI has begun allowing global API customers to actively turn on the text watermark function for some models, but it is still turned off by default. This means that companies can decide whether to watermark text generated through APIs based on their own transparency requirements.

OpenAI is also coordinating with cloud service partners, hoping that in the next few weeks, eligible content generated by calling OpenAI models through these cloud platforms will also receive corresponding source signals.

However, text watermarks will not replace other AI content identification methods. OpenAI emphasizes that source information such as machine-readable watermarks and C2PA cannot replace public statements such as visible AI labels and prompt banners required by law or platform. They solve content source problems at different levels.

For ordinary users, the most noteworthy thing about this change is: if you are in the EU and use ChatGPT to generate long text, then from the time the watermark system officially covers your account, the generated content may already contain source signals that are invisible to the naked eye. Direct copying of the original text will usually not destroy this signal, but if the text is significantly rewritten, reworded, or translated, the watermark's detectability may be significantly reduced.

OpenAI also explicitly acknowledges this limitation. textGrain's signal exists in the model's word selection, rather than as an invisible character independently attached to the text file. Therefore, sufficient rewriting of the text may destroy the original statistical pattern. This is why OpenAI emphasizes that text watermarks are currently more suitable as a source judgment signal and cannot be regarded as an absolutely reliable "AI identification certificate."

Generally speaking, OpenAI launched textGrain in the EU this time mainly to adapt to the new regulatory requirements brought by the AI ​​Act. It also represents that the source identification of AI-generated text is evolving from traditional "declarative tags" to machine-recognizable signals. It will not change the text that users see, nor will mysterious characters appear when copying text, but it will allow systems with detection permissions to try to determine whether a piece of content comes from an OpenAI model.

However, since text watermarks still have problems such as language differences, text length restrictions, and signal weakening after rewriting, it is currently more suitable as an auxiliary evidence in the AI ​​content traceability system, rather than being used alone to determine whether an article was "written by AI."

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet