Policy#Content quality

OpenAI adds textGrain watermark in EU

Invisible watermarks roll out across EU ChatGPT and Codex output for AI Act transparency rules; the detector stays closed to the public.

The OpenAI wordmark in black on a mint field with dark teal arrows — The Verge art

The Verge and TechCrunch reported on October 5 that OpenAI has introduced textGrain, an invisible, machine-readable statistical watermark that will roll out across all paid tiers of ChatGPT and Codex output in the European Union over the coming weeks. The driver is the EU AI Act’s transparency requirements — Anthropic moved first under the same law in August. API customers worldwide can opt in to watermarked outputs for select models, and cloud partners get access in the coming weeks. For users, the experience is uniform in its emptiness: invisible inside the EU, absent outside it — and the gap between “watermarked” and “verifiable” is controlled unilaterally by the vendor, the design critics trust least. OpenAI says textGrain “matched or exceeded” competing approaches such as DeepMind’s SynthID, and that watermarked and unwatermarked text perform identically on benchmarks.

The catch: the detector is not public

OpenAI concedes that textGrain “does not guarantee reliable detection.” The detector is available only to case-by-case approved researchers and expert organizations, reports solely whether an OpenAI watermark is present, and never identifies users or exposes conversations; it stays closed at launch because of false-positive and missed-watermark risks. The company is equally explicit about what the watermark cannot do: verify accuracy, establish ownership, measure human contribution, or prove human authorship.

Statistical watermarking’s ceiling

From the disclosed design, textGrain embeds statistical signal during generation — the pattern of token choices carries machine-readable information invisible to readers and unchanged by casual edits. Its structural weakness follows: paraphrase, translation, or mixing in human text dilutes the signal, which is what “does not guarantee reliable detection” concedes in one line. The claim of zero benchmark cost, if it holds, addresses the quality tax that plagued SynthID-class schemes — but it is vendor-reported until independently reproduced.

Only where regulation has teeth

EU-only is the most informative decision in the announcement: OpenAI explicitly declines to make watermarking “a global default” at launch, preferring to learn from the regulated market first. That mirrors Anthropic’s path — transparency obligations follow the AI Act, not idealism. The worldwide API opt-in is the door left open for enterprise customers in industries that need provenance — publishing, finance, legal — who can adopt it without waiting for their own regulators.

Compliance first, provenance second

For observers, the structure is the story: the watermark’s first user is the regulator, ahead of any reader — “was this produced by an OpenAI model” now has a machine-readable answer, while detection authority is consolidated with the vendor. It lands in the same quarter as Google freezing bounty submissions and Wikimedia naming rogue agents: the provenance layer for AI content and AI behavior is being built under duress, and each vendor is answering “how strict, open to whom” differently. For EU users the practical change is a first: living inside an environment where AI-generated text carries provenance by default, and the experience data will decide whether watermarking goes global. Removability remains the old problem — early testing suggests the watermark is not hard to strip; good enough for compliance, not for adversarial settings.

The open question is whether the EU-first rollout becomes the global floor or stays a compliance island. The AI Act gave OpenAI no choice about whether to mark outputs; it gave the rest of the world a live demonstration of what marking costs — apparently nothing in benchmark terms — and what it buys: a machine-readable answer to a question regulators, platforms and publishers have been asking for three years. If the measured downside stays this small, the “not a global default” position will be hard to hold against advertisers who want provenance and platforms who want to detect synthetic text at scale.