The watermark nobody can see
OpenAI announced this week that it will begin applying an invisible watermark to text generated by ChatGPT and Codex for European Union users. The feature, internally known as textGrain, does not consist of a visible symbol or hidden notice — instead, the model subtly alters the statistical pattern of its word choices so that a specialized detector can identify, after the fact, whether the passage was produced by an OpenAI system.
The decision is a direct response to the transparency rules of the EU AI Act, which entered into force on August 2, 2026, and require AI providers to make generated content identifiable through machine-readable marks. The compliance deadline under Article 50 is December 2, 2026.
How textGrain works (and where it fails)
textGrain's operation is, in practice, a sophisticated variation of watermarking techniques that have circulated in academia since 2023. Large language models select word tokens sequentially from a probability distribution. textGrain slightly modifies that distribution, periodically favoring synonym words that preserve the original meaning but deviate the text from an unmarked statistical pattern. A detector, powered by a secret key, looks for that vocabulary shift and emits a signal indicating AI authorship.
In theory, the watermark travels with the text when it is copied and pasted — something that differentiates this approach from visual marks or metadata that are lost in transit. In practice, however, the results are inconsistent. OpenAI itself acknowledged in its announcement that short passages (about 200 words) are detected with only an 80% success rate, compared to 95% for 400-word passages. For functional texts, such as code or mathematical explanations, detection drops even further, as synonym substitutions introduce errors the model would normally avoid.
Tests conducted by The Register revealed an even more fragile point: the watermark can be defeated with a simple word substitution. In 400-token passages, replacing 10% of terms with synonyms reduced detection from 92% to 66%. With 25% substitution, the watermark was detectable in only 17% of cases. In other words, minimal human editing renders the technique practically harmless.
Why only Europe?
OpenAI's geographic approach is not incidental. The company cited the need to "learn from real-world use and feedback" before expanding to other regions. But there are other motivations. Unlike rival Anthropic, which has been adopting watermarks in its outputs globally, OpenAI decided to keep watermarking as an opt-in option for API customers outside the EU and as default only in Europe. For global API clients, the feature remains off by default as of October 5, 2026.
The decision reflects a dilemma that affects the entire sector: text watermarks have historically been more problematic than image or video watermarks, where techniques like Google's SynthID have shown more robust results. Microsoft and Meta, for instance, already apply similar provenance signals to AI-generated images, but text detection remains an open problem.
What the watermark DOES NOT do
OpenAI was explicit in its caveats. The watermark can indicate that an OpenAI system "generated or processed part of a passage," but it does not measure how much human judgment, creative editing, or subjective judgment was applied to the result. Moreover, the company stated that the watermark does not establish ownership or responsibility for the content, does not identify who generated the text, and does not verify factual accuracy.
The textGrain detector is also not a universal service — OpenAI is initially limiting access to approved researchers and organizations under the European Code of Practice on transparency of AI-generated content. This means that, at present, there is no public verification tool accessible to journalists, platforms, or ordinary readers.
What comes next
The company announced plans to make textGrain open-source soon, which could accelerate adoption by third parties — but also create more sophisticated evasion tools. Google's SynthID, by comparison, is already available globally and gained a dedicated web interface launched the same week.
Meanwhile, OpenAI continues working with cloud partners to offer watermarking on models accessed through their services, which may be significant for the enterprise sector: a large share of business traffic never touches ChatGPT's own interface.
The problem the industry still hasn't solved
Statistical text watermarking is, ultimately, a solution to a problem that still lacks a definitive answer. If the goal is to combat AI-generated disinformation, the technique fails when applied to short, edited, or translated texts — precisely the cases where detection matters most. And if the goal is simply to comply with European legislation, then restricting the feature to the EU may prove a long-term strategic decision: learning in a regulated market without risking user experience in other regions.
The question remains whether text watermarks, given their demonstrated fragility, will become a permanent standard in the ecosystem or merely a temporary step until the industry finds a truly reliable mechanism — and in the meantime, how many EU users will continue generating texts that resist any verification with a simple synonym swap.
Sources: TechCrunch, The Register, The Next Web
✓ Independent sources cross-checked and verified before publishing