SDSignal Desk

OpenAI will watermark ChatGPT outputs by default—but only in the EU

Oct 6, 2026, 1:50 PM · Ars Technica

Image: Ars Technica

OpenAI's own numbers show its text watermark weakens fast under light editing, which makes the EU-only default less a safety system than a compliance checkbox with a short shelf life.

Why it matters

OpenAI will turn on its textGrain watermark by default for ChatGPT and Codex text in the European Union in the coming weeks, and offer it as an off-by-default option elsewhere, including the API. The trigger is the EU AI Act, in force since August, which requires AI-generated content to be marked in a way other tools can detect.

What Ars adds is the fine print from OpenAI's own testing. The watermark was detected about 92 percent of the time. Change 10 percent of the text and the detection rate drops by almost 30 percent; change 20 percent and it drops by almost 75 percent. Shorter and translated text are harder to catch. Those figures matter more than the launch itself.

From the desk

We've already said we think text provenance is worth building, and we still do. Here we want to focus on the durability problem, because it changes how this should be used. A signal that fades sharply after a fifth of the words are touched will survive casual copy-and-paste. It will not survive anyone who edits on purpose, runs a paraphrase pass or translates. The people most motivated to hide AI use are the ones best positioned to strip the mark.

That skews who gets caught. Detection will mostly flag people who used ChatGPT and left the output largely alone: hurried students, overworked staff, honest users who never thought to hide it. Sophisticated bad actors walk past it. A tool that catches the careless and misses the deliberate is fine for measuring broad patterns of synthetic text. It is a poor basis for discipline, grading or accusations.

The regional split sharpens the point. Anthropic switched on text watermarking for its models globally in August. OpenAI is making it the default only where regulators require it, at least for its apps. That is a defensible business call, but it tells us where OpenAI thinks the value sits: in meeting the rule, not in a global norm. If the strongest argument for watermarking is a healthier information ecosystem, Europe-only defaults leave most of that ecosystem unmarked.

Our read: OpenAI deserves credit for publishing a technical paper and numbers that show the weaknesses rather than hiding them, and for keeping detector access limited to researchers and approved organizations for now. Regulators, schools and employers should take those numbers as seriously as the company apparently does, and design policy that treats a hit as a clue, never a conviction.

Context

Like other language-model watermarks, textGrain nudges word choices in patterns a human reader won't notice and a keyed detector can find. Ars notes that existing approaches such as SynthID and C2PA are also relatively easy for someone with basic know-how to get around.

Who feels it

EU ChatGPT and Codex users
Default watermarking arrives within weeks; lightly edited or translated text may not carry a detectable signal.
Educators and employers
OpenAI's own robustness data argues against using detection results as proof of misconduct.
API developers
The feature stays opt-in, so teams with EU obligations must decide deliberately whether to enable it.
Regulators
The AI Act's machine-detectable marking rule is being met with tools whose limits are now documented in public.

What to watch

  1. Independent tests of textGrain from researchers granted detector access
  2. Whether OpenAI follows Anthropic and makes watermarking a global default
  3. How EU regulators judge compliance given published circumvention rates
  4. Any move to combine watermarks with other provenance signals for text

Read the original

Continue at the source.

Ars Technica

Companies: OpenAI