OpenAI is introducing invisible watermarks into ChatGPT text. The accurate version is narrower than "everything ChatGPT writes can now be detected." Starting October 5, 2026, OpenAI says API customers around the world can opt in to its new textGrain watermark for selected models. Over the coming weeks, eligible ChatGPT and Codex text output will also be watermarked across all plans in the European Union.
There is no public OpenAI text detector at launch, and the EU rollout is not a global ChatGPT default. Detection gets weaker on short, mathematical, heavily edited and translated text. OpenAI says a detected watermark cannot identify the user or reveal their prompt or conversation, and it cannot prove who authored the work. That makes this a material product change with equally material limits.
Quick answer: does ChatGPT watermark text now?
Yes, in a phased and limited way.
| Question | Current answer |
|---|---|
| ChatGPT users in the EU | Eligible text output is rolling out with textGrain across all plans |
| ChatGPT users outside the EU | Not a global default at launch |
| OpenAI API | Optional globally for supported models and off by default |
| Codex | OpenAI includes eligible Codex text output in the EU rollout, but that does not establish that all generated code is watermarked |
| Public text detector | No |
| Teachers or employers | No general public OpenAI text detector is available at launch |
| Hidden characters or spaces | No. textGrain changes statistical word and token choices |
| Can a watermark prove AI authorship? | No |
| Can no watermark prove human authorship? | No |
OpenAI's wording matters here. It says eligible ChatGPT and Codex users across all plans in the EU, not every user, every model and every kind of output everywhere.
What OpenAI actually changed
OpenAI has added text to a provenance system that already covers supported images and audio.
The new text system is called textGrain. OpenAI describes it as an invisible statistical signal embedded while a model chooses words and word pieces. A compatible detector can later look for that pattern.
The rollout has two separate tracks.
Consumer ChatGPT and Codex: OpenAI says eligible text output in the EU will gain the watermark over the coming weeks. It is not making text watermarking a global ChatGPT default at launch.
API customers: Customers globally can opt in now for selected models. Watermarking remains off by default in the API.
This distinction is the first thing most headlines will lose.
What is textGrain?
Large language models do not choose the next word from one fixed script. They assign probabilities to possible next tokens, then generate from those possibilities.
textGrain changes those choices in a controlled way so that a statistical pattern accumulates across a passage. OpenAI says the adjusted probability distributions are balanced to preserve the model's normal behavior overall, while a detector using the matching key and settings can test whether the expected pattern appears more often than chance.
The watermark is therefore part of the generated wording itself.
It is not:
- an invisible Unicode character;
- a hidden space;
- unusual punctuation;
- metadata attached to a text file;
- an extra watermark-only token;
- a user ID hidden in the answer.
That means the familiar "ChatGPT hidden character remover" idea is aimed at the wrong mechanism. textGrain is not a stray character you can reveal by turning on formatting marks.
Can you see the watermark?
No.
The text should look like ordinary prose to a reader. OpenAI says copying and pasting unchanged wording does not introduce hidden material because there is no hidden character layer to expose.
The signal only becomes meaningful to a detector that knows what statistical pattern to test.
That also means ordinary visual inspection cannot tell you whether textGrain is present.
Who can detect ChatGPT text?
This is where the rollout becomes much less dramatic.
OpenAI is not making its text watermark detector public at launch.
Approved researchers and expert organizations can apply for access. OpenAI's current Help Center guidance describes qualifying uses such as academic and research work studying provenance, detection reliability and how people interpret results. Access is reviewed case by case.
OpenAI's public verification tool currently covers supported images and audio, not ordinary text.
So the practical answers are:
Can a normal user paste text into an OpenAI detector today? No public text tool has been launched for that.
Can a teacher use a public OpenAI textGrain detector on student work? Not as a normal public service at launch.
Can an employer use one on staff documents? Not through a generally available public text detector. OpenAI's current Help Center says text detector access is limited to approved research and academic organizations working on provenance, detection reliability and how results are understood. Routine employer screening is not a documented access path.
Third-party AI text detectors still exist. They generally use classifiers that guess from writing patterns. That is a different technology from detecting OpenAI's embedded textGrain signal.
How reliable is textGrain detection?
OpenAI's own numbers are a useful warning against turning a watermark into a verdict.
In one passage-length evaluation, at a target 1% false-positive rate, OpenAI reported:
| Passage-length evaluation | Reported result |
|---|---|
| 200-token passages on content such as psychology | about 80% detected |
| 400-token passages on content such as psychology | about 95% detected |
In a separate 400-token synonym-editing evaluation, OpenAI reported:
| Synonym-editing evaluation | Reported result |
|---|---|
| Before synonym replacement | about 92% detected |
| After replacing 10% of words with synonyms | about 66% detected |
| After replacing 25% of words | about 17% detected |
These are separate experimental evaluations under specified conditions. They should not be collapsed into a single "95% accurate" score.
OpenAI says detection is substantially weaker on mathematical text because the model has less freedom in word choice. Short passages are also harder. So are outputs that must closely reproduce supplied wording.
Translation and substantial paraphrasing can weaken the signal further. The same basic problem applies to constrained outputs: the fewer plausible ways there are to say something, the less room the watermark has to shape token choice.
Does detection work equally well across EU languages?
No.
OpenAI says it evaluated textGrain across all 24 official EU languages using 500 synthetic English prompts spanning different topics, then translating them into the other 23 languages.
At a 1% false-positive rate, Spanish had the highest reported detection rate at 69.0%, while Romanian had the lowest at 42.2%. OpenAI says textGrain has an adjustable strength parameter and used it to strengthen the watermark for languages that initially tested below 60%.
Those multilingual results come from a different evaluation setup, so they should not be compared directly with the English 200-token and 400-token figures above.
The practical point is more important: an EU-wide rollout does not mean detection is equally strong in every EU language.
OpenAI also says watermarking did not measurably reduce model quality in its Astra benchmark suite. Performance differences with and without textGrain fell within normal run-to-run noise, and prior ChatGPT tests showed no change in thumbs-down rates or other product measures.
What about short answers and code?
OpenAI explicitly says short passages often do not contain enough material for reliable detection. Its Help Center also says code is harder to watermark because there are fewer plausible next-token choices than in normal prose.
The EU Code of Practice does not require watermarks for outputs shorter than 200 tokens, roughly 150 English words, or for code snippets.
That matters for Codex.
OpenAI's announcement says it will watermark eligible ChatGPT and Codex text output in the EU. It does not separately establish that every piece of code generated by Codex will carry a reliable textGrain watermark.
The careful answer today is therefore:
Codex is included in OpenAI's text-provenance rollout, but "Codex code is watermarked" is too broad.
Until OpenAI publishes more specific Codex and code coverage, treat that point as unresolved rather than filling the gap with an assumption.
Can editing or paraphrasing remove the watermark?
It can make detection much weaker.
OpenAI's 400-token synonym experiment fell from about 92% detection before editing to 66% after 10% of the words were replaced and 17% after 25% were replaced.
That does not mean there is a reliable "remove 25% and you are safe" rule. The result comes from one experimental setup. Different text lengths, languages, topics, models and edits can behave differently.
The practical lesson is simpler: text watermarking is a statistical signal, not an indestructible stamp.
Shortening, paraphrasing, translating, mixing AI output with human writing or rewriting a passage can all reduce detectability.
What does a positive watermark result actually prove?
Less than many institutions will be tempted to claim.
OpenAI says a detected watermark can indicate that an OpenAI system generated or processed some of the text.
It does not establish:
- who authored the ideas;
- how much a person contributed;
- whether the model wrote all or only part of the passage;
- whether the user owned the output;
- whether using AI was permitted;
- whether the text is accurate;
- which account created it;
- which prompt was used;
- which conversation it came from.
A person could write a report, ask ChatGPT to tighten the wording, then receive watermarked text back. A detector finding the signal would not tell you where human authorship ended and model editing began.
That distinction matters for schools, workplaces and publishers.
Detectable signal is not proof of authorship.
What does a missing watermark prove?
Also less than people will want it to.
No detected watermark does not prove a human wrote the text.
OpenAI lists several reasons a watermark may be absent or missed:
- the text predates the rollout;
- the model or output path is unsupported;
- the passage is too short;
- the content is highly constrained;
- the text was edited or paraphrased;
- it was translated;
- it came from another AI provider.
So the reverse rule matters just as much:
No signal is not proof of human authorship.
Anyone using watermark detection as a misconduct or employment decision should understand both sides before treating the result as evidence.
Does textGrain identify you, your prompt or conversation?
No, according to OpenAI's current documentation.
OpenAI's Help Center says provenance signals do not include details about the user, organization or prompt. OpenAI's textGrain announcement also says detection does not reveal the user's conversations.
That is different from saying OpenAI has no internal account records. It means the watermark itself is not described as carrying personal identity, prompt or conversation data.
The watermark is a provenance signal about model involvement, not a public tracking code for the individual who generated the text.
Which ChatGPT plans are affected?
OpenAI says the EU rollout will cover eligible ChatGPT and Codex users across all plans.
That wording does not mean every output on every plan becomes watermarked simultaneously. OpenAI still uses the qualifier "eligible," and coverage can vary by product, model, output and rollout timing.
For now, the safest reading is:
- plan tier is not the main dividing line in the EU rollout;
- geography and output eligibility matter;
- exact model coverage is still moving.
Which API models support textGrain?
OpenAI has deliberately made this dynamic.
API customers can see the currently supported model list inside project or organization settings. OpenAI says it will extend coverage to legacy models over the coming weeks.
That is better handled as live product state than a frozen list in an article.
If your organization needs a specific model watermarked, check the current text-provenance setting before assuming support.
Cloud-service users should not assume identical coverage. OpenAI says it is working with its cloud and distribution providers to embed provenance signals in eligible outputs, with availability varying by output and partner.
How do API customers turn watermarking on or off?
API text watermarking is off by default.
OpenAI says customers can enable it for a project or more broadly for an organization, then choose supported models.
Current settings paths are:
- Organization settings → Data controls → Text provenance
- Project Settings → Text provenance
Turn on Allow text watermarking, select the supported models you want covered, then save.
Enabling the watermark does not give the organization access to the text detector. Detector access is a separate restricted program.
This global API opt-in is important because it means watermarked OpenAI text can appear outside the EU even though consumer ChatGPT is not getting a global default at launch.
ChatGPT vs Claude vs Gemini text watermarking
OpenAI is joining a provenance shift that was already underway, but the providers are not using identical rollout rules.
| Provider | Current text position | Geography | Detection access |
|---|---|---|---|
| OpenAI / ChatGPT | textGrain rolling out to eligible ChatGPT and Codex text; API opt-in | EU consumer rollout; API opt-in globally | Restricted for text at launch |
| Anthropic / Claude | Embedded text watermarks on supported Claude models | Worldwide on supported models | Private preview for eligible organizations |
| Google / Gemini | SynthID watermarks text generated through the Gemini app and web experience | Not described as an EU-limited rollout | Current public guidance highlights image, video and audio verification; current text-detector access is unclear |
Anthropic now publishes a model-by-model support table, which makes its current coverage easier to inspect. Choosely has separately updated its Claude watermark explainer to reflect that newer state.
Google DeepMind says SynthID changes token probability scores to embed an invisible signal in Gemini-generated text. Google's May 2025 SynthID Detector launch said early testers could upload text, while journalists, media professionals and researchers could join a waitlist. Google's current DeepMind page now tells users to verify image, video and audio and still describes the detector as an early-tester collaboration. Choosely therefore would not assume that self-serve text verification is currently available.
The common theme is not "AI detectors are finally solved." It is that major providers are embedding provenance signals while still acknowledging important limits.
Why is OpenAI doing this now?
The immediate trigger is the European Union's AI Act.
European Commission guidance says Article 50 applies from August 2, 2026 and requires providers of relevant generative AI systems to add machine-readable marks that enable detection of AI-generated or manipulated content. The Commission gives systems placed on the market before that date a limited transition for the marking obligation until December 2, 2026.
OpenAI signed the related Code of Practice on Transparency of AI-Generated Content and says textGrain is part of how it is implementing those commitments.
The EU requirement explains why consumer rollout begins there. OpenAI's decision to offer global API opt-in goes further than a simple EU-only product switch.
The company also says it plans to release textGrain as open-source technology so others can build on it and help improve text watermarking.
What should users actually do?
Students: Follow your institution's AI-use rules and keep drafts or revision history where authorship matters. Do not assume a watermark result can prove misconduct.
Writers and professionals: Keep original drafts when provenance is important. If ChatGPT edits human-written work, a positive signal may show model processing rather than original authorship.
Educators: Treat provenance as one signal, not a disciplinary verdict. There is no generally available public OpenAI textGrain detector at launch.
Employers: Define the difference between generation, editing, translation and formatting before introducing any AI-detection policy. A binary "AI used" flag is too crude for most professional work.
Developers and API customers: Decide whether watermarking serves your disclosure or compliance needs, then test supported models and representative outputs. Do not promise customers that every short, constrained or heavily edited passage will remain detectable.
Anyone evaluating AI text: Ask what detector is being used. A classifier guessing that prose "looks like AI" is not the same as detecting an embedded provider watermark.
Choosely's verdict
ChatGPT text watermarking is now real. Universal ChatGPT detectability is not.
OpenAI's launch is narrower and more cautious than the headline version: EU consumer rollout over the coming weeks, global API opt-in, restricted text-detector access and explicit warnings about false positives, false negatives, editing, short passages and constrained text.
That caution is warranted.
The biggest risk is not that an invisible signal exists. It is that schools, employers or platforms treat that signal as proof of authorship when OpenAI itself says it is not.
The second risk is the reverse assumption. A missing signal does not certify human work.
textGrain gives institutions another piece of provenance evidence. It does not settle the harder question of who actually wrote, edited, decided or took responsibility for the final work.
Frequently asked questions
Does ChatGPT put an invisible watermark in text?
Yes. OpenAI is rolling textGrain into eligible ChatGPT text output in the EU. It is not a global ChatGPT default at launch, while API customers can opt in globally for supported models.
Is ChatGPT text watermarked outside the EU?
Not by default for ordinary ChatGPT at launch. API customers globally can enable text watermarking for supported models, so OpenAI-watermarked text can still be generated outside the EU.
Can teachers or employers use OpenAI's text detector?
There is no public textGrain detector at launch. OpenAI currently limits text detector access to approved research and academic organizations studying provenance and detection. Routine school disciplinary checks or employer screening are not documented access paths.
Does ChatGPT use invisible spaces or Unicode to watermark text?
No. OpenAI says textGrain changes the statistical pattern of word and token choices. It does not insert hidden characters, invisible spaces, unusual punctuation or watermark-only tokens.
Does a textGrain match prove ChatGPT wrote the whole passage?
No. A match is evidence that an OpenAI model likely generated or processed the content. It does not establish how much a human contributed or prove authorship. The reverse is also important: no detected watermark does not prove the text was written by a human.
Does Codex watermark code?
OpenAI includes eligible Codex text output in its EU rollout, while also saying code is harder to watermark and noting that the EU Code does not require watermarking of code snippets. OpenAI has not established that all Codex-generated code is watermarked.
Keep your AI stack current
Models, plans, policies and provenance rules change quickly. Save the tools you rely on, track what changes and know when something in your stack needs another look.
The Change Brief
Get the week’s AI changes in one clear read
Pricing moves, tool launches, free-tier changes and practical stack updates, filtered for people who actually use these tools.
Stay ahead of AI without following it all day. We’ll send you what matters each week.
Continue reading
Related reads
Product Update
Claude's Invisible Watermark Is Real. The Panic Is Ahead of the Facts
Claude text watermarking is now active across multiple current models worldwide, but a watermark is provenance evidence rather than proof of authorship or personal identity.
AI Strategy
OpenAI's Agents Posted 53 ChatGPT User Images Online. How to Opt Out of Training
OpenAI says research agents posted 53 user-provided images to third-party hosts. Here’s how ChatGPT’s training opt-out works and what the incidents reveal about agent containment.
AI Strategy
The Always-On AI Assistant Is Here. What Should You Actually Let It Do?
Persistent AI assistants can remember, act and continue working after the prompt ends. The real product decision is how much authority they should receive.
