AI-generated text in Europe is about to carry a new signal that readers will not be able to see.
OpenAI says it will begin adding an invisible watermark to eligible text produced by ChatGPT and Codex in the European Union over the coming weeks.
The system is called textGrain.
It does not add hidden characters, unusual punctuation or visible labels. Instead, it changes the statistical pattern of the model’s word choices so that a detector can look for evidence that an OpenAI system generated or processed the passage.
OpenAI is introducing the system in response to the EU AI Act’s text-provenance requirements.
But the important part for marketers, publishers and agencies is what the watermark does not do.
It is not a public AI detector.
It does not identify the person who generated the text.
It does not prove that a passage is accurate.
And OpenAI’s own tests show that ordinary editing can significantly weaken the signal.
What OpenAI is actually rolling out
There are three different implementation states.
First, OpenAI says eligible ChatGPT and Codex text will receive the watermark in the EU over the coming weeks.
The company says this will cover eligible users across all plans in the EU.
That means the announcement is a rollout commitment, not evidence that every ChatGPT response generated in Europe today is already watermarked.
Second, API customers worldwide can opt in to text watermarking for select models.
The API setting is not an automatic global default.
OpenAI says it is off by default.
Third, the detector itself is not being made publicly available at launch.
Access will initially be limited to approved researchers and expert organisations.
That distinction matters because “OpenAI is watermarking text” can easily be misread as “anyone will now be able to paste text into a public checker.”
OpenAI is not offering that.
| Question | Current position |
|---|---|
| ChatGPT text in the EU | Watermark rolling out over coming weeks |
| Codex text in the EU | Watermark rolling out over coming weeks |
| EU plans covered | Eligible users across all plans |
| API customers | Global opt-in for select models |
| API default | Off |
| Public watermark detector | No |
| Initial detector access | Approved researchers and expert organisations |
| Visible label added to text | No |
textGrain changes word-choice patterns
The watermark is statistical.
OpenAI says textGrain adjusts how the model chooses between possible words or word pieces during generation.
Across a sufficiently long passage, those choices create a detectable pattern.
That makes text watermarking fundamentally different from putting metadata into a document or inserting an invisible marker into copied text.
Copying and pasting the text does not reveal a hidden code.
A detector instead evaluates whether the language contains the statistical pattern associated with the watermark.
That also explains the system’s main weakness.
Text can be rewritten.
A person can edit it.
A translation system can change it.
Another AI system can paraphrase it.
Each transformation can weaken the original pattern.
OpenAI’s own tests show how quickly detection can fall
OpenAI is unusually explicit about this limitation.
In one evaluation of 400-token passages, the company says its detector identified around 92% of watermarked text under the original test conditions.
When 10% of words were replaced with synonyms, detection fell to about 66%.
When 25% were replaced, detection dropped to 17%.
| Test condition | Reported detection |
|---|---|
| Original 400-token passage | ~92% |
| 10% of words replaced with synonyms | ~66% |
| 25% of words replaced with synonyms | ~17% |
These numbers come from OpenAI’s own evaluation rather than an independent benchmark.
They also do not mean every passage starts with a 92% detection probability.
OpenAI says detection varies with text length and the type of language being generated.
Shorter passages and highly constrained writing can be more difficult to identify because the model has fewer alternative word choices in which to encode the signal.
The practical lesson is not that the watermark “doesn’t work.”
It is that provenance detection is probabilistic rather than absolute.
A watermark does not prove who wrote something
This is the guardrail most organisations should put into their AI policies.
OpenAI says a detected watermark can indicate that one of its systems generated or processed part of a passage.
It cannot tell you:
- who used the system;
- which account generated the text;
- what prompt was entered;
- how much a person edited the result;
- how much human judgment went into the final version;
- who owns the content;
- whether its use was lawful;
- whether the content is factually correct.
The inverse is also important.
No detected watermark does not prove human authorship.
The signal could have been weakened by editing or translation.
The text could be too short.
It could have come from an unsupported model.
It could predate the watermark rollout.
Or it could have been generated by another AI system.
That makes textGrain a provenance signal rather than an authorship verdict.
Article 50 compliance is broader than watermark detection
OpenAI is presenting textGrain as part of its response to the EU AI Act.
That does not mean adding a watermark automatically resolves every Article 50 question for the organisations using AI-generated material.
Provider-side provenance and downstream disclosure are different compliance questions.
NEMO’s EU AI Act Article 50 marketing checklist covers the broader distinction between provider obligations, disclosure requirements and the situations marketers actually need to review.
For brands and publishers, the useful rule is not:
“The model watermarked it, so compliance is finished."
It is:
“The model may now carry a machine-readable provenance signal. We still need to determine what our own use of the content requires."
The watermark also does not replace editorial review.
A watermarked passage can still be inaccurate.
An unwatermarked passage can still have been AI-generated.
Those are separate problems.
What EU content teams should change now
The immediate workflow changes are modest but important.
1. Record where AI-generated text enters the workflow
Identify teams using ChatGPT, Codex or OpenAI API outputs for publishing, advertising, customer communication or internal production.
The provenance state may differ depending on product and API configuration.
2. Do not promise clients a public detector
OpenAI’s detector is not being released as a general public tool at launch.
A client should not be told that customers, search engines or competitors can automatically “check the watermark” today.
3. Separate ChatGPT from API behaviour
EU ChatGPT and Codex watermarking is being introduced by OpenAI.
API watermarking is opt-in and global.
Do not assume an API workflow has the signal simply because an equivalent ChatGPT workflow does.
4. Log substantial editing and translation
Editing can weaken detection materially.
If provenance matters to a regulated publishing workflow, keep an internal record of whether text was translated, heavily rewritten or passed through another model.
5. Keep provenance separate from factual review
A watermark answers a limited origin question.
It does not verify claims.
NEMO’s AI fact-checking pre-publish audit addresses the separate problem of checking AI-assisted material before publication.
6. Review disclosure separately
Do not use the presence or absence of a text watermark as the sole test for whether a disclosure is required.
The legal and editorial context of the published material still matters.
This is not an SEO penalty signal
Nothing in OpenAI’s announcement says Google Search, Bing or another search engine will use textGrain as a ranking signal.
Nothing says watermarked text is automatically treated as low quality.
Nothing says a detected watermark proves spam.
For SEO teams, the immediate issue is therefore not rankings.
It is provenance, governance and client disclosure.
That could change if search platforms later document their own use of machine-readable text provenance signals.
Until then, NEMO would not tell publishers to rewrite content simply to remove or weaken a watermark.
That would turn a compliance signal into an SEO superstition without evidence.
What NEMO will watch next
The rollout raises several questions that can now be measured.
When does watermarking actually become visible across different EU accounts and products?
How does detection perform across European languages?
How quickly does normal editorial rewriting weaken the signal outside OpenAI’s controlled tests?
When will detector access expand?
And how will OpenAI’s planned open-source release of textGrain change independent testing?
Those are more useful questions than asking whether AI text is now “detectable.”
The current evidence supports a narrower conclusion:
OpenAI is adding a machine-readable provenance signal to eligible EU ChatGPT and Codex text. The signal can survive some changes, but it is not a universal AI detector and it does not establish authorship, ownership or truth.