OpenAI Starts Watermarking ChatGPT Text in Europe, and Only OpenAI Can Read the Mark
OpenAI did not launch a detection tool, and it did not give anyone a way to check a document. On 5 October it said it would begin embedding an invisible signature in text produced by ChatGPT and Codex in the European Union, published a twenty-page technical report explaining how, and kept the key to itself. For teams that produce marketing content with these tools, the useful questions are not about the technology. They are about which of your outputs carry the mark, who can read it, and what survives when a human edits the draft. Here is what the announcement actually changes.
Key takeaways
- The watermark is on by default in ChatGPT and Codex in the EU, and off by default in the API, where an organisation has to switch it on. Most industrial content production runs through the API.
- The detector is restricted. Regulators get access and researchers can apply. A brand cannot test its own content.
- The signal degrades fast under editing. What stays detectable is output nobody reworked.
What OpenAI announced, and what it kept back
On 5 October OpenAI published a short post called "Our approach to EU text provenance rules" and a technical report on a method it calls textGrain. The company will add an invisible watermark to eligible text from ChatGPT and Codex for users in the European Union, rolling out over the coming weeks across every plan. API customers anywhere in the world can switch watermarking on for selected models from the same day, through a Text provenance setting in organisation or project settings. It is off unless someone turns it on.
The reason is Article 50 of the AI Act, which has applied since 2 August and requires providers of generative systems to mark their output in a machine-readable form. OpenAI had built a text watermark two years earlier and never shipped it, reportedly out of concern that users would move to competitors who did not mark anything. Anthropic has been marking Claude text worldwide since August. Google has been doing it with SynthID for longer.
What OpenAI did not release is the detector. Regulators are granted access, researchers can apply for it, and everyone else is outside.
How a text watermark works, in plain terms
At every step, a language model has several words that would each work. textGrain uses a secret key to tilt that choice, very slightly, in a direction only the key can predict. One word tells you nothing. A few hundred of them produce a statistical pattern a detector holding the key can recognise.
The effect is invisible to a reader, it does not identify the user, and it survives copying and pasting. It does not survive much else. OpenAI is direct about the limits in its own announcement: rewriting or translating the text can remove the mark entirely, and short passages often carry too little signal to be read at all. Independent write-ups put numbers on the decay. Swapping roughly one word in ten for a synonym drops detection from around ninety percent to the mid-sixties. At one word in four, it collapses.
There is also a floor. The EU code of practice exempts very short text, defined as under 200 tokens, which is roughly 150 words. Social captions, subject lines and product bullets fall below it.
And the reverse test does not work. OpenAI states that an absent watermark does not prove a human wrote the text. It might be too short, too heavily edited, or produced by another company's model.
Which of your content is marked, and which is not
This is where the announcement stops being abstract.
A strategist drafting a LinkedIn post in the ChatGPT window on a Tuesday afternoon, in Paris or Madrid, produces marked text. A content pipeline built on the API, which is how most agencies and most in-house teams produce at volume, produces unmarked text unless somebody has gone into the settings and enabled it.
So the mark does not correlate with scale, or with how little human work went into a piece. It correlates with which interface somebody happened to use. The improvised draft is signed. The industrial output is not.
Very few content leads could currently say which surface their team generates on. That question is now worth asking, and it takes about ten minutes.
Nobody can run the test, including you
The restricted detector is the part most coverage has skipped. A brand cannot check whether its own blog post carries a mark. Neither can a client, a journalist, a procurement team or a university. The organisations that can are regulators and approved researchers.
Which produces an awkward situation. The question "was this written by ChatGPT" has become answerable, mechanically and reliably, by a small number of parties, and unanswerable by everyone else, including the party whose name is on the content.
It also means the practical effect in the next twelve months will be close to zero for most companies. Nobody is going to run the test on your newsletter. The exposure is narrow and specific: a regulatory inquiry, a dispute with a client over what was delivered, a research paper that samples a sector.
The incentive this creates is not the one anyone intended
The rule was written to make AI-generated content identifiable. What it will identify, in practice, is content that nobody edited.
Rework the draft properly, change the structure, replace the weak sentences, and the signature thins out until it cannot be read. Ship the output as generated and it stays legible for years. The regulation ends up sorting by effort rather than by tool, which is not what Article 50 set out to measure.
For a brand, that distinction is arguably the more useful one. It is just not the one anyone announced, and no compliance process is built around it.
What the law asks of you, as opposed to OpenAI
Article 50 binds the organisation that publishes as well as the one that generates, and most summaries make that duty sound broader than it is. The obligation on deployers covers text published to inform the public on matters of public interest, and it falls away where a human has reviewed the content and an identifiable person or organisation holds editorial responsibility for it.
Most brand marketing sits outside that scope. A product page or a campaign is not published to inform the public on a matter of public interest. Brand journalism, trend reports, opinion pieces on policy and anything that reads as reporting sit closer to the line, and a named author with real review is what keeps you on the right side of it.
What has changed for everyone, scope aside, is that provenance is now a property of the file rather than a line in a brief. Where that information lives matters, and in most production chains it lives nowhere. The model used, the version, who edited it and how much are known for about a week, by one person, and then lost. Keeping that record attached to the asset is the part you control, and it is the only version of provenance you will be able to produce on request.
The case for doing very little
The watermark applies to ChatGPT and Codex, in the EU, by default, and nowhere else by default. A team using Claude, Gemini, Mistral or an open model is governed by a different set of decisions. A team using the API is unmarked. The coverage is thin, and treating this as a general AI-detection regime would be a mistake.
The detector is restricted, so the test will rarely be run. And OpenAI itself describes current text watermarking as having significant limitations.
There is a specific risk worth naming. Dozens of unreliable AI detectors are already sold to schools and employers, and this announcement will be read as evidence that detection now works. It shows the opposite. The company best placed to build a working detector built one and then limited who may use it, precisely because the method is fragile and false accusations are easy. If anyone inside your organisation starts citing a detector score as proof, that is the moment to point at this announcement rather than away from it.
Three things to settle this month
First, for content and brand leads. Write down your own disclosure position before a client asks for it. Not because the law demands it in most marketing cases, but because the question is now answerable by someone else, and improvising an answer under pressure is worse than having one on file.
Second, for whoever owns the tooling. Find out which surface your team actually generates on, and whether anyone has touched the API provenance setting. The answer determines whether your output carries a mark, and almost nobody currently knows it.
Third, for creative operations. Record provenance at the point of creation rather than reconstructing it later. Which model, which version, who edited, how much. This is the same problem as tracking when a licence expires: the information exists at the moment of the work and disappears within weeks unless something holds it.
That is the part of this that lands on creative operations rather than on legal. The file and the facts about the file now travel together, and in most production chains they do not. MTM keeps them in one place, with assets organised automatically and findable in plain language rather than through tags someone has to remember to apply.
See how MTM handles assets and the data attached to them → https://www.mtm.video/platform/
FAQ
Can anyone now detect whether text came from ChatGPT? No. OpenAI has not released a public detector. Regulators are given access and researchers can apply for it, but a brand, an agency or a client cannot test a document. The watermark is readable only by a party holding the key, which for now means OpenAI and a short list of approved organisations.
Do we have to label AI-written marketing copy in the EU? In most cases, no. The obligation on the organisation that publishes covers text put out to inform the public on matters of public interest, and it does not apply where a human has reviewed the content and someone holds editorial responsibility for it. A product page or a campaign is not covered. Brand journalism, policy commentary and anything that reads as reporting sit closer to the line, and a named author with genuine review is the practical answer there.
Will the watermark survive if we edit the draft? Partly, and less than most people assume. OpenAI says rewriting or translating can remove the mark completely. Independent reporting puts detection at around two thirds once roughly one word in ten has been changed, and far lower once a quarter of the text has been reworked. Text under about 150 words is exempt from marking in the first place.
We generate through the API rather than ChatGPT. Are we marked? Not unless someone enabled it. Watermarking in the API is off by default and has to be switched on in organisation or project settings, under a Text provenance option, for selected models. This is the single most useful thing to check, because it is where most volume production happens and because the setting is rarely visited.
What about Claude, Gemini and the others? Anthropic has been watermarking Claude text worldwide since August, with detection access initially limited to regulators, researchers, media and similar organisations. Google has used SynthID for longer. The labs have answered the same law in different ways, so the correct assumption is that provenance behaviour varies by vendor and by surface, and has to be checked per tool rather than assumed.
Sources
- OpenAI, Our approach to EU text provenance rules, 5 October 2026 · https://openai.com/index/our-approach-to-eu-text-provenance-rules/
- TechCrunch, OpenAI will start watermarking ChatGPT's text in the EU, 5 October 2026 · https://techcrunch.com/2026/10/05/openai-will-start-watermarking-chatgpts-text-in-the-eu/
- ActuIA, OpenAI will watermark ChatGPT in the EU but leaves the API opt-in · https://www.actuia.com/en/news/openai-will-watermark-chatgpt-in-the-eu-but-leaves-the-api-opt-in/
- Parameter, ChatGPT text in EU now carries hidden statistical watermark under AI Act compliance · https://parameter.io/chatgpt-text-in-eu-now-carries-hidden-statistical-watermark-under-ai-act-compliance/
- Interesting Engineering, OpenAI adds invisible watermarks to ChatGPT text under EU rules · https://interestingengineering.com/ai-robotics/openai-chatgpt-invisible-watermarks-eu
- Cellcog, OpenAI text watermark: ChatGPT EU rollout and textGrain · https://cellcog.ai/blog/openai-text-watermark-eu/