×

OpenAI initiates text watermarking in phases according to the rules of the EU artificial intelligence law – Unite.AI

OpenAI initiates text watermarking in phases according to the rules of the EU artificial intelligence law – Unite.AI

OpenAI on October 5, 2026, defined its approach to text watermarking under EU AI law, opening opt-in watermarking to API customers worldwide and announcing that invisible watermarks will be added to eligible text outputs of ChatGPT and Codex in the European Union in the coming weeks.

EU law on artificial intelligence requires providers of generative AI to make the generated text identifiable in a machine-readable way. OpenAI described watermarking and text detection as the first technologies with significant limitations and said its phased approach reflects both legal requirements and those limitations.

Optional API access and regional implementation in the EU

Starting October 5, 2026, API customers globally can enable text watermarking for select templates, and the setting remains off by default. OpenAI said the opt-in design allows customers to decide how watermarking fits into their transparency obligations and the experiences they provide to users, and that it is working with cloud partners to make watermarking available for OpenAI model outputs accessed through their services in the coming weeks.

For its own products, OpenAI will introduce text watermarking for eligible ChatGPT and Codex users only across all European Union plans, including in the coming weeks. The company said it will not make text watermarking a global default at launch, and that the regional approach will allow it to learn from real-world use and feedback.

OpenAI also opened requests for access to its text watermark detector on 5 October 2026. Access will initially be limited to approved researchers and expert organisations, granted on a case-by-case basis in accordance with the EU Code of Conduct on Transparency of AI-Generated Content, to support the assessment and improvement of text provenance. The announcement applies only to text: OpenAI said its verification tools for audio and images, including the openai.com/verify web tool and content provenance API, remain publicly accessible.

How textGrain works

OpenAI’s watermarking technology, textGrain, embeds an invisible statistical signal into words selected by a model, and the company’s detector tests a pass for that signal to judge whether it carries an OpenAI watermark. A technical report titled “textGrain: Entropy-Calibrated Watermarking for Language Model Text,” dated October 5, 2026, lists authors affiliated with the University of Pennsylvania, Yale University, and OpenAI.

According to the report, the method ties token generation to keyed randomness by solving an optimal transportation problem whose costs arise from Gumbel random variables, with Kullback-Leibler regularization penalizing deviations from independence. An entropy budget limits the average sampling entropy given up in exchange for the watermark signal, and the report states that the KL penalty is exactly equal to the average entropy removed from the watermark, giving the strength parameter a direct information-theoretic meaning. Applying the transport phase to keyed blocks of vocabulary tokens reduces the size of the optimization while keeping the relative probabilities of the tokens within each block unchanged. The detector only needs the generated text and the secret key, and not the entropy budget used during generation.

OpenAI said it plans to release the technology as open source so others can build on it, and that the report will be updated with more details in the coming weeks.

Detection performance and stated limitations

OpenAI reports that in its evaluations textGrain matched or exceeded the performance of other tested approaches, including SynthID for text, while cautioning that high performance under ideal conditions does not guarantee reliable detection in everyday use.

With a target false positive rate of 1%, the detector identified watermarks in about 80% of 200-token passages and about 95% of 400-token passages for content such as psychology, OpenAI reported, with substantially lower rates for content such as mathematics, where word choice is less flexible. In an evaluation of 400-token passages, replacing 10% of the words with synonyms reduced detection from approximately 92% to 66%, and replacing 25% of the words reduced it to 17%. The assessments used watermarked English responses to questions from the ELI5 dataset.

As for output quality, OpenAI said that across the benchmarks used to evaluate Astra, which it describes as its latest frontier model, it sees no significant differences in performance with and without watermarking. The published table reports, respectively for the text without watermark and with watermark, 49.57 and 49.76 points on the Artificial Analysis Intelligence Index and 94.44% and 93.94% on the GPQA Diamond. OpenAI said detection limitations contributed to its decision to limit initial access to the detector to approved researchers and expert organizations.

What a watermark does not establish

OpenAI says a text watermark provides a limited signal about the role its systems play in a step. A watermark does not measure human input, establishes ownership or liability, does not identify the user, and does not verify accuracy, the company says. It is also stated that the absence of a detected watermark does not prove human authorship, because the text may be too short, edited or translated for reliable detection, may be from an unsupported template, may pre-date the watermark, or may have been generated by another company’s tools.

The detector will report if it detects an OpenAI watermark without identifying the user or revealing their suggestions or conversations. Given the risk of missed watermarks and false positives, OpenAI will not make the tool publicly available at launch.

EU transparency obligations

The transparency obligations under Article 50 of the AI ​​Law, which cover the marking and detection of AI-generated content and the labeling of deepfakes and certain AI-generated publications, apply from 2 August 2026. The Code of Conduct on Transparency of AI-Generated Content was developed by independent experts in a multi-stakeholder process facilitated by the AI ​​Office, with the final code published on 10 June 2026.

Adherence to the code is voluntary, but the transparency requirements set out in Article 50 are legal obligations. The Commission and the AI ​​Board confirmed that the code is an appropriate voluntary tool to demonstrate compliance and, according to the Commission, around 190 companies and organizations had signed the code by the end of July 2026.

OpenAI said it will continue to improve detection, studying how watermarks resist modification and translation and exploring ways to distinguish AI assistance from AI authorship, and that it will expand access to the detector when it believes the results can be interpreted responsibly.

Post Comment