SDSignal Desk

OpenAI will start watermarking ChatGPT’s text in the EU

Oct 5, 2026, 1:36 PM · TechCrunch

Image: TechCrunch

OpenAI is watermarking ChatGPT and Codex text in Europe because the law now requires it, and the most important detail is how easily OpenAI admits the mark can be weakened.

Why it matters

Starting over the coming weeks, eligible ChatGPT and Codex users on all plans in the European Union will get an invisible watermark on generated text. The EU AI Act’s transparency rules, in effect since August 2, require AI companies to mark generated content in a machine-detectable way. Developers anywhere can turn the watermark on for select API models starting now; it’s off by default, and OpenAI is not making it a global default.

This is the moment text provenance stops being a research topic and becomes a compliance requirement. It will shape how schools, publishers, platforms and courts think about whether a piece of writing came from a machine.

From the desk

We’re broadly for this. Provenance tools help people make informed judgments about what they’re reading, and a mark that lives in the word choices themselves, surviving copy and paste, is more robust than metadata that disappears the moment text leaves the app. OpenAI says the watermark doesn’t identify the user and saw no meaningful change in model performance with it on. If both hold, the cost to ordinary users is low.

What earns our respect is the honesty about limits. OpenAI’s own tests show that swapping 10% of words for synonyms drops detection from about 92% to 66%. Short passages, math answers and translated text are harder to catch. And the company says outright that a missing watermark does not prove a human wrote something. That is the line we most want institutions to hear.

Here’s the harm we see coming if this scales carelessly. A detector with a meaningful miss rate and an evasion path will be most effective against people who aren’t trying to hide, like a student who used ChatGPT honestly for a draft, and least effective against those who are. If schools or employers treat a positive hit as proof of misconduct, or a negative as proof of innocence, they’ll get both kinds of error. OpenAI limiting detector access to approved researchers and expert organizations at first is the right call for that reason.

There’s also the question of what a watermark actually measures. OpenAI notes it can show an OpenAI system generated or processed part of a passage, but not how much human judgment went into it. Anthropic’s plan to watermark Claude text worldwide drew backlash from users who said they supplied the instructions, context and decisions while the model was just the tool. That argument is going to get louder as more professional writing passes through these systems.

And the competitive pressure is real. The Wall Street Journal reported in 2024 that OpenAI held back an earlier watermark partly over fears users would switch to rivals that didn’t mark text. Regulation solved that collective-action problem in Europe. Outside it, the off-by-default setting tells us the commercial worry hasn’t gone away.

Context

The method, called textGrain and described in a technical report co-written with researchers from the University of Pennsylvania and Yale, uses a secret key to subtly bias next-word choices; across hundreds of these nudges, a detector with the key can spot the pattern from the text alone. Anthropic, Google, Meta, Microsoft and OpenAI are among companies committed to the EU’s code of practice on AI-generated content.

Who feels it

EU users
Their ChatGPT and Codex output will carry an invisible mark that OpenAI says does not identify them.
Educators and employers
Should treat detection as a signal, not proof, given OpenAI’s own reported miss rates and evasion results.
Developers
Can opt into watermarking on select API models worldwide today, which may matter for platforms building trust features.
Rival AI providers
Face the same EU obligation, narrowing the room to compete on not watermarking in Europe.

What to watch

  1. Whether detector access expands beyond approved researchers and organizations
  2. Whether OpenAI makes watermarking default outside the EU, as Anthropic says it is doing with Claude
  3. How EU regulators judge watermark robustness given the reported synonym-swap results

Read the original

Continue at the source.

TechCrunch

Companies: OpenAI

Also covering this