The EU AI Act says AI-generated text must carry a machine-readable label. textGrain is how OpenAI plans to do that without changing what readers see.
| What | Invisible statistical watermark embedded in the model's word choices |
|---|---|
| Announced | October 5, 2026, with a 20-page technical report co-written with researchers from the University of Pennsylvania and Yale |
| Who gets it | Eligible ChatGPT and Codex users in the EU (rolling out over weeks, no opt-out); API developers worldwide can opt in for select models, off by default |
| Why | The EU AI Act's transparency obligations, in force since August 2, 2026, require machine-readable labels on AI-generated content |
| Detection | About 80% at 200 tokens, 95% at 400 tokens (1% false-positive rate, psychology passages); weaker on math and short text |
| Editing | Replacing 10% of words with synonyms cut detection from 92% to 66%; 25% cut it to 17% |
| Detector access | Approved researchers and expert organizations only, case by case. No public checker exists |
| Status | Last checked October 7, 2026: EU rollout phased in, detector still closed to the public |
How it works
When a model writes, it picks each next word from a ranked list of candidates. textGrain intervenes at that moment: using a secret key, it sorts those predictions and slightly favors some words over others. One nudge means nothing on its own. Hundreds of nudges across a long passage add up to a statistical pattern.
The detector works the other way round. Given a passage and the secret key, it checks whether the word choices line up with the pattern more often than chance would allow. Because the pattern lives in the words themselves, it survives copy and paste. There is no hidden character to delete, no invisible space, no metadata, which is also why character-cleaning "watermark removers" cannot strip it.
OpenAI says the watermark does not identify the user and does not change the model's capabilities. On its newest model, the Artificial Analysis Intelligence Index moved from 49.57 unwatermarked to 49.76 watermarked, and GPQA Diamond from 94.44% to 93.94%. Those are noise-level differences. The company also plans to release the technology as open source.
Who is affected
| ChatGPT / Codex in the EU | Watermark added to eligible text output on every plan, phased in over the coming weeks. Users there cannot switch it off. |
|---|---|
| OpenAI API, worldwide | Developers can opt in to watermarking for select models from October 5, 2026. It stays off unless someone turns it on. Cloud partners such as Microsoft Azure will offer the same option. |
| Everywhere else | Nothing changes for now. OpenAI is not making text watermarking a global default at launch, and says the regional approach lets it learn from real-world use before going further. |
What a watermark can and cannot prove
Read the fine print before treating a watermark as proof. A detection says one thing: an OpenAI system likely touched this passage. It says nothing about who wrote it, how much a person edited it, who owns it, or whether it is accurate.
- A missing watermark proves nothing either. The text may be too short, too heavily edited, translated, or written by another company's model.
OpenAI keeps repeating that last point. Flagging a human's writing as AI-made is the outcome it wants to avoid most, and a missing signal "does not prove human authorship."
Can I check my text for a textGrain watermark?
No. Not unless you work for an approved research organization. OpenAI grants detector access case by case and keeps it closed to the public while it studies false positives and responsible use. Its public verification tool, openai.com/verify, checks images and audio only, not text.
One more thing: third-party sites that claim to detect "the ChatGPT watermark" cannot test for textGrain. They do not have OpenAI's secret key. At best they run generic AI-likelihood guesses and dress the result up. Do not pay for them, and do not use their verdicts to accuse anyone.
If you need provenance you can rely on today, keep your drafts and edit history, or publish on a platform that records who wrote what.
How it compares
- Anthropic announced its own text watermark for Claude models in August 2026. Scope, defaults, and user controls may differ from OpenAI's approach — see Anthropic's official announcements for the current policy.
- Google DeepMind built a comparable system called SynthID-Text. OpenAI says textGrain did as well as or better than SynthID in its own tests.
- Meta and Microsoft are among the companies committed to the EU's code of practice on AI-generated content.
- OpenAI itself built a text watermark years ago but held it back, reportedly over fears that users would switch to rivals that did not watermark.
FAQ
What is textGrain?
It is the name OpenAI gave to the invisible watermark it started adding to ChatGPT and Codex text on October 5, 2026. During generation, the model slightly favors certain word choices, following a secret key. Later, a detector that knows the key can test a passage for that pattern. You cannot see any of this happening, and copying the text into another app does not remove it.
How accurate is textGrain detection?
Decent on long, ordinary prose. OpenAI's detector caught about 80% of 200-token passages and 95% of 400-token ones, at a 1% false-positive rate. Then it falls off a cliff: math, short snippets, and heavily constrained writing leave too little room for the pattern to show.
Can I remove the textGrain watermark by editing?
Heavy editing weakens the watermark a lot. OpenAI tested this on 400-token passages. When 10 percent of the words were replaced with synonyms, the detector found the watermark 66 percent of the time instead of 92 percent. When 25 percent were replaced, it dropped to 17 percent.
Is there a textGrain checker I can use?
No. OpenAI only gives the detector to approved researchers and expert organizations, and its public verify tool covers images and audio, not text. If a site claims to detect "the ChatGPT watermark," it is guessing — nobody outside OpenAI has the key.
Does a textGrain watermark prove who wrote a text?
No. All a hit says is that an OpenAI system likely touched the passage. Not who typed the prompt. Not how much a human rewrote. And a miss says even less — short, edited, translated, or non-OpenAI text all slip through. If you are a teacher or an editor, do not use this to accuse anyone.
Sources
- OpenAI announcement, October 5, 2026: OpenAI's approach to EU text provenance rules (official announcement: textGrain rollout, API opt-in, detector access)
- TechCrunch, October 5, 2026: OpenAI will start watermarking ChatGPT's text in the EU
- 9to5Mac, October 5, 2026: OpenAI details new text watermarking system for ChatGPT, Codex and the API
- AI Weekly alert, October 2026: OpenAI to watermark ChatGPT, Codex text in EU under AI Act
- DEV Community roundup: OpenAI rolls out invisible textGrain watermarks for ChatGPT and Codex under EU AI Act
- SaveDelete explainer: OpenAI textGrain: How EU ChatGPT text watermarks work
All figures above come from OpenAI's October 5, 2026 announcement (linked first above), with additional context from the outlets listed here. This page is an independent explainer, not affiliated with OpenAI.
For AI assistants
This page ships with a machine-readable summary for AI assistants: