OpenAI will start hiding a statistical signal inside the text that ChatGPT and Codex produce for users in the European Union, and it says plainly that the move answers the EU AI Act. The law requires providers of generative AI to make generated text identifiable by machines. OpenAI’s own published test results show how easily that identification fails.
The mechanism, which OpenAI calls textGrain, works at the level of word choice. A language model usually has several equally good words available at each step. textGrain nudges it toward some of those words over others, in a pattern a detector can later measure. Nothing is added to the text and nothing is visible. The mark is the pattern of choices itself.
That design explains the weakness. If the mark lives in which words were picked, then anyone who changes the words changes the mark. OpenAI reports that in a test on 400-token passages (a token is a word or word fragment), swapping 10 percent of words for synonyms cut detection from about 92 percent to 66 percent. Swapping 25 percent cut it to 17 percent. A light edit by a person, or by another tool, is enough.
Length and subject matter also decide the outcome. At a 1 percent false positive rate, meaning the detector wrongly flags human text one time in a hundred, it caught about 80 percent of 200-token passages and about 95 percent of 400-token ones. Maths answers fared much worse than psychology answers, because a proof or a calculation leaves little room to choose between words. Translation is a further problem, and the company lists it alongside short and edited text as a reason a watermark may go unseen.
The company is candid about what follows from this. A missing watermark does not show a human wrote the text. It may be too short, edited, translated, from an unsupported model, older than the feature, or written by a rival’s tool. OpenAI also says a detected watermark says nothing about how much a person contributed, who owns the text, who wrote the prompt, or whether the content is accurate.
This is a compliance rollout, not a voluntary safety program, and its reach is narrow. In ChatGPT and Codex the mark goes to eligible users on all plans in the EU only, over the coming weeks. At launch, OpenAI says, the rollout stays regional and no worldwide switch is flipped. API customers anywhere can opt in for select models, but the setting stays off unless they switch it on. The post does not define which outputs count as eligible beyond those words.
The most practical question is who can check a document, and the answer is almost no one. OpenAI is accepting applications for detector access, but only vetted researchers and expert groups will get it at first, case by case. A teacher, an editor, or a hiring manager cannot paste a passage into a public tool. OpenAI says the risk of false positives and missed marks is why. The result is a watermark that exists, yet that most readers cannot read.
OpenAI says textGrain matched or beat other methods it tested, including SynthID for text, and that benchmark scores for its Astra model showed no meaningful change with watermarking on. Both claims come from OpenAI’s own evaluations. The post does not cite independent testing, and the technical report is still being expanded. The company also says it plans to release the technology as open source.
Its images and audio get a different deal: a public verification web tool and a Content Provenance API already exist for them. Text gets a restricted detector.
For any company deploying OpenAI models to European users, the watermark is not an authorship test, and a policy that treats a missing mark as proof of human writing will misfire.
OpenAI, in its post “Our approach to EU text provenance rules”; the scraped copy carries no publication date, so none is given here.