OpenAI has begun embedding an invisible, machine-readable watermark in the text generated by ChatGPT and Codex, a phased rollout that begins in the European Union and marks the company's first serious deployment of a technology it publicly shelved more than a year ago. The watermark carries no visible change to the words users see, but it encodes a hidden signal into the underlying token patterns that the company says can later be detected by automated tools.
The system, internally called textGrain, is being applied to text output rather than images or audio — a technically harder problem, since language offers fewer redundant bits to hide a signal in than pixels or waveforms do.
Why now: the EU AI Act
The timing is not accidental. The EU's AI Act imposes transparency obligations on providers of general-purpose AI models, requiring that machine-generated content be marked in a machine-readable format so that it can be identified as artificially produced. OpenAI's watermark is, in effect, a compliance measure — and the company is not alone.
Anthropic announced its own text watermarking in August, built on SynthID, the watermarking toolkit developed by Google DeepMind. OpenAI says its textGrain approach "matched or exceeded" other methods, including SynthID for text, in internal evaluations — a claim that positions the deployment as both a regulatory box-tick and a technical competitive statement.
The rollout is geographically limited at first. Users in the European Union will see watermarked output before anyone else; the company has not given a timeline for extending the feature to the United States or other markets. Alongside the consumer rollout, OpenAI has opened an opt-in for its API, letting developers who build on its models request watermarked output for their own applications — a nod to businesses that may face similar disclosure rules down the line.
How textGrain is meant to work
Unlike a visible label or a metadata tag, a text watermark is woven into the generation process itself. As the model chooses each successive word, a statistical bias nudges it toward one of several equally plausible options — a pattern invisible to a human reader but recoverable by anyone holding the detection key. Done well, the bias is too small to degrade quality; done poorly, it makes prose feel stilted or repetitive.
OpenAI appears aware of that risk. The company published benchmark scores alongside the announcement showing broadly similar performance between watermarked and unwatermarked text — an attempt to pre-empt the criticism that watermarking dulls a model's output. Even so, OpenAI concedes that textGrain "does not guarantee" that all watermarked content will be detected, nor that detection will work in every context. Short passages, heavy editing, translation, and paraphrasing can all erode the signal.
A reversal, not a debut
For close observers, the most notable thing about the announcement is that it happened at all. OpenAI had explored text watermarking in 2024 but held back, citing concerns about user backlash and the ease with which determined users could strip the mark. That hesitation has now been overridden by regulatory pressure.
The reaction this time has been mixed. Some developers welcomed a concrete, standards-adjacent step toward provenance. Others objected on principle — arguing that watermarking treats every user as a suspect and that any detectable signal is, by definition, a signal that can eventually be forged, misattributed, or removed.
Watermarking is only as useful as it is robust — and text, unlike images, is trivially easy to rewrite.
The robustness problem
Critics point to a structural weakness: text watermarks are fragile in ways image watermarks are not. A user who asks ChatGPT for a paragraph and then lightly edits it, runs it through a paraphrasing tool, or translates it into another language may well strip the mark without ever knowing it was there. Several commentators have described the EU rollout as easy to circumvent — a characterization OpenAI does not directly dispute, framing textGrain instead as one layer in a broader provenance strategy rather than a forensic guarantee.
That framing matters. If watermark detection is treated as proof of AI authorship, false negatives become a real hazard: unwatermarked AI text could be passed off as human, and watermarked text that has been edited could evade detection entirely. The more responsible reading — the one OpenAI appears to encourage — is that a watermark is evidence, not verdict.
What happens next
Three questions will shape how this story develops. First, whether the EU's enforcement bodies accept textGrain as satisfying the AI Act's transparency requirements, or whether they demand a more standardized, interoperable scheme that spans OpenAI, Anthropic, Google, and others. Second, whether the watermark survives contact with real users — and whether the API opt-in becomes a de facto expectation for enterprise customers. Third, whether OpenAI extends the feature beyond Europe, where political appetite for AI labeling is rising but remains far less codified than in Brussels.
For now, the practical effect for most of the world's ChatGPT users is nothing at all: the text looks the same, reads the same, and behaves the same. But the quiet addition of an invisible mark to hundreds of millions of generated words is a signal in its own right — that the era of unlabeled machine text, at least in Europe, is drawing to a close.




