← Back
LLMsNEW

ChatGPT Now Watermarks Its Text in the EU. Who It Affects, How It Works, and What It Cannot Prove

On October 5, 2026, OpenAI said it will add an invisible watermark to eligible ChatGPT and Codex text for users in the EU, to meet the EU AI Act. API developers anywhere can opt in. Only approved researchers get the detector. Swapping one word in ten cuts detection from about 92% to 66%. Here is what changes and what it does not mean.

5 min read
Updated Oct 6, 2026
QUICK ANSWER

On October 5, 2026, OpenAI said it is extending content provenance from images and audio to text.

Key Takeaways
  • This guide provides comprehensive, actionable information
  • Consider your specific workflow needs when evaluating options
  • Explore our curated LLMs tools for specific recommendations

What OpenAI announced

On October 5, 2026, OpenAI said it is extending content provenance from images and audio to text. Over the coming weeks, eligible ChatGPT and Codex output for users in the European Union will carry an invisible, machine-readable watermark, on every plan. Outside the EU, ChatGPT is not watermarked by default. Developers using the API anywhere in the world can switch the watermark on for select models from launch day; it is off unless they do, as TechCrunch reported.

The reason is regulatory. The EU AI Act's transparency rules took effect on August 2, 2026, and require AI-generated content to be marked in a way other systems can identify. OpenAI is one of the signatories of the EU's code of practice on this, alongside Anthropic, Google, Meta and Microsoft.

EU only
where ChatGPT and Codex watermark by default
92% → 66%
detection rate after replacing 10% of words with synonyms
17%
detection rate after replacing 25% of words

How the watermark works

Nothing visible is added. A language model writes one token at a time by sampling from a set of likely next words. OpenAI's method, called textGrain, nudges that sampling using pseudorandom values derived from a secret key, so the words it picks carry a faint statistical pattern. Because the pattern lives in the word choices themselves, it travels with the text when you copy and paste it.

The technical report, written with researchers from the University of Pennsylvania and Yale, describes two properties worth knowing. The watermark is designed to be unbiased: averaged over keys, the model's word choices follow the same distribution as without it, and the amount of randomness it removes is set by an explicit budget. And the detector needs only the text and the secret key. Without the key, there is nothing to check against.

On quality, OpenAI reports that watermarked output scored about the same as, or slightly better than, unwatermarked output on benchmarks including GPQA Diamond, DeepSWE, Terminal-Bench, BrowseComp and HealthBench, per 9to5Mac's summary. OpenAI also told The Verge its approach matched or exceeded rivals such as Google DeepMind's text watermark. Those are OpenAI's numbers; no independent evaluation exists yet, which is what the researcher-only detector is for.

What it cannot do

OpenAI is unusually direct about the limits, and they are the most important part of the announcement:

  • Light editing weakens it fast. Replacing 10% of the words with synonyms drops detection from about 92% to 66%. Replacing 25% drops it to 17%.
  • Short text and math are hard. A few sentences, or an answer that is mostly equations, give the detector too little to work with.
  • Translation breaks it. Text translated into another language does not keep the pattern.
  • It makes mistakes both ways. OpenAI says the detector has false positives and false negatives.
  • Absence proves nothing. In OpenAI's words, "a missing watermark does not prove human authorship." It also does not measure how much a person contributed, establish who owns the text, identify the user, or say whether the content is accurate.

Who can check for it

Not you, and not your teacher or employer, for now. Detection access starts with approved researchers and expert organizations, so the method's reliability can be tested before anyone relies on it. There is no public OpenAI checker for text. Any website claiming to detect the ChatGPT watermark is not OpenAI's detector, and has no access to the key it needs.

How this compares with Claude

Anthropic went first and went further. In August it said it would watermark text at the model level, so the mark is present in every Claude product, including the API and Claude Code, and not only for EU users. Claude Fable 5.1 and Claude Mythos 5.1 were its first watermarked models, with a detection API for eligible groups. OpenAI's version is narrower: on by default only in the EU, and opt-in on the API everywhere else.

What it means for you

You use ChatGPT or Codex in the EU
Expect your output to be watermarked within weeks, whatever your plan. You will not see any difference in the text.
You use ChatGPT outside the EU
Nothing changes by default. If you paste ChatGPT text into a product built on the API, that product's settings decide, not yours.
You build on the OpenAI API
It is off unless you enable it, on select models. If you serve EU users, read the transparency obligations with your counsel before deciding that off is fine.
You are a teacher or reviewer
This is not an AI detector you can use, and OpenAI says a missing mark proves nothing. Judge the work, not a score from a site claiming to read the watermark.
You are tempted by a "watermark remover"
Be wary. Removal tools appeared as soon as Claude started watermarking, and Forbes found the field full of scams. Ordinary editing already weakens the mark, and no third party can verify what it has removed without the key.

The products are listed at Codex, GPT-6 Sol and every LLM in the directory. For the wider question of what to trust from a model, see LLM security and privacy for businesses. The day's news is in the October 5 briefing, and Anthropic's move is in the August 11 briefing.

FREQUENTLY ASKED QUESTIONS
Is OpenAI watermarking ChatGPT and Codex text, who does it apply to, how does the watermark work, and can it be detected or removed?
On October 5, 2026, OpenAI said it is extending content provenance from images and audio to text.
EXPLORE TOOLS

Ready to try AI tools? Explore our curated directory:

SHARE THIS GUIDE

On October 5, 2026, OpenAI said it is extending content provenance from images and audio to text.

Share on X LinkedIn Reddit Email
Copied to clipboard