Starting in the coming weeks, eligible ChatGPT and Codex users in the EU will receive text outputs carrying an invisible watermark called textGrain, embedded in the statistical pattern of word choices the model makes. No banner. No disclaimer. Nothing you can see.
The rollout is connected to the EU AI Act’s transparency requirements, and OpenAI is not alone. Anthropic has announced comparable watermarking for Claude, using an approach comparable to Google DeepMind’s SynthID text method.
How textGrain Actually Works
The model nudges its word choices across a passage so a detector can read the pattern later.
The system works by subtly shifting which words or word pieces the model selects, so that across a long enough passage, a statistical fingerprint emerges. As OpenAI’s help documentation states, “The watermark is part of the wording itself and is not visible to readers.”
That detector is not something you can run yourself, at least not yet. Access is limited at launch to approved researchers and expert organizations on a case-by-case basis, because OpenAI says missed detections and false positives could cause real harm if a public checker existed.
What textGrain Changes for You
The rollout affects different groups in meaningfully different ways.
- Eligible ChatGPT and Codex users in the EU: generated text may carry a provenance signal with no visible watermark in the output.
- API developers worldwide: watermarking is opt-in for selected models, which may help you disclose AI-generated content in your own products.
- Researchers and expert organizations: you can apply for detector access, but this is not a public tool anyone can query.
- Educators, employers, and publishers: treat a positive detection result as one data point, not a verdict on misconduct or authorship.
The Part OpenAI Doesn’t Bury
The company publishes its own caveats plainly, and they are worth reading carefully.
According to a unite.ai summary of OpenAI’s evaluations, detection reaches roughly 80% for 200-token passages and about 95% for 400-token passages at a 1% false-positive rate under specific test conditions. Those figures vary by subject matter and passage length, and should not be read as universal benchmarks. OpenAI states plainly that “textGrain does not guarantee reliable detection.”
The vulnerability is real. Replacing just 10% of words with synonyms drops detection for 400-token passages from around 92% to 66%, according to the same reported evaluation. Swap out 25% and the signal falls to roughly 17% under those test conditions.
The watermark also cannot verify whether the text is accurate, identify who generated it, or establish ownership. It cannot measure how much a human edited the final version either. A failed detection is not proof a human wrote something. A positive result indicates that an OpenAI system may have generated or processed some of the text, and nothing more definitive than that.
The Wider Picture
Anthropic is moving in the same direction, but the systems do not talk to each other.
Anthropic’s Claude watermarking uses a comparable statistical approach, with detector access also initially restricted to eligible organizations. Each provider’s watermark requires its own detector, so a universal AI-text checker is not established by anything currently available.
Treat a watermark result the way you would treat a single witness account: relevant, worth considering, and nowhere near sufficient on its own. textGrain moves the provenance conversation forward. It is evidence, not proof.




























