At a 1% false-positive rate, OpenAI’s detector finds its own watermark in about 80% of 200-token ChatGPT outputs and about 95% of 400-token ones, according to the company’s technical report. Replace one word in ten with a synonym and detection on a 400-token passage drops from a reported baseline near 92% to 66%. Replace one in four and it collapses to 17%. Those numbers, not the announcement around them, are the real story: as Ars Technica reported, OpenAI will start marking ChatGPT and Codex text by default in the European Union, while leaving the feature off everywhere else unless a developer opts in through the API.
The marking is called textGrain. OpenAI describes the mechanism in a paper titled “textGrain: Entropy-Calibrated Watermarking for Language Model Text”, co-authored with researchers at Yale and the University of Pennsylvania. A large language model normally picks its next word by sampling from a probability distribution over the vocabulary. textGrain instead solves, at each token, a Kullback-Leibler-regularized optimal transport problem seeded with Gumbel noise and a secret key, which nudges the choice toward whichever plausible word correlates with that key. An “entropy budget” caps how much variety the model is allowed to sacrifice per token, which is why OpenAI can claim the scheme is “unbiased”: averaged over many generations and many keys, the marginal distribution of tokens matches the unwatermarked one, so aggregate output quality doesn’t move even though any single response has been steered. OpenAI’s own benchmark comparisons report textGrain matching or beating Google DeepMind’s SynthID-Text on the metrics it tested, a self-reported result with no independent replication yet.
Detection works by giving the detector the same secret key as the generator, then running a statistical test over the token sequence to check whether the observed word choices are more consistent with the keyed bias than with chance. More tokens means more statistical power, which is why 400-token passages detect far more reliably than 200-token ones. It also means the test degrades on anything short: a two-sentence reply, a headline, a single paraphrased paragraph lifted out of a longer piece, all sit in the regime where the signal is weak to begin with, before anyone has edited a word.
Why the EU and not everywhere
The deadline driving this is Article 50 of the EU AI Act, whose transparency obligations took effect on 2 August 2026, with a transition period for already-deployed systems running to 2 December 2026, according to the European Commission’s own guidance. Article 50(2) requires providers of generative systems to mark synthetic audio, image, video and text output so it is machine-detectable; Article 50(4) separately requires deployers who publish AI-generated text to inform the public on matters of public interest to label it as such, and a provider’s embedded mark under 50(2) does not by itself discharge that deployer obligation. Fines for breaching Article 50 run up to €15 million or 3% of a company’s global annual turnover, whichever is higher, under Article 99 of the Act, as a compliance guide to the article lays out. That penalty, not a technical breakthrough, is the proximate cause of this launch.
The law is deliberately silent on method. It does not mandate SynthID, C2PA or textGrain, only that marking be “effective, interoperable, robust and reliable as far as this is technically feasible.” The Commission’s Code of Practice, finalized in July 2026, is what narrows the field in practice, and roughly 190 companies had signed on by the end of that month, including Google, Meta, Microsoft, Mistral, Anthropic and OpenAI. The code is also what lets providers restrict detector access to vetted researchers rather than the public, the loophole OpenAI is using: its help pages name three initial recipients, John Thickstun at Cornell, Martin Vechev at ETH Zurich and INSAIT, and researchers at the Kempelen Institute of Intelligent Technologies, with a request process for others.
A method OpenAI already built once and shelved
OpenAI isn’t watermarking text for the first time. As TechCrunch reported in August 2024, the company had already built a ChatGPT text watermark the Wall Street Journal said was 99.9% effective on sufficiently long passages, and sat on it. Internal surveys found 69% of ChatGPT users thought the tool would produce false accusations of AI-assisted cheating, and 30% said they would use ChatGPT less, or switch to a rival that didn’t watermark, if OpenAI shipped it. OpenAI’s own spokesperson called the approach “trivial to circumvention by bad actors” through translation or rewording with another model, and flagged a risk of disproportionately flagging non-native English speakers. None of those technical concerns has been resolved by textGrain; the synonym-replacement numbers above are the same failure mode under a new name. What changed is that a regulator now imposes a cost for not shipping something.
| From | To | How |
|---|---|---|
| Next-token probabilities (from the language model) | KL-regularized token pick (Gumbel-noise optimal transport) | candidate words |
| Secret key + context | KL-regularized token pick (Gumbel-noise optimal transport) | biases choice |
| Entropy budget (caps quality loss) | KL-regularized token pick (Gumbel-noise optimal transport) | limits bias |
| KL-regularized token pick (Gumbel-noise optimal transport) | Watermarked ChatGPT/Codex text | |
| Watermarked ChatGPT/Codex text | Detector (same secret key) (access limited to vetted researchers) | |
| Secret key + context | Detector (same secret key) (access limited to vetted researchers) | shared key |
| Detector (same secret key) (access limited to vetted researchers) | Statistical test over tokens | |
| Statistical test over tokens | Watermark found / not found |
Based on OpenAI, textGrain technical report
What the competitors are doing differently
Anthropic reached the same regulatory deadline from a different design choice. Its watermark, announced in August 2026, is an adaptation of Google DeepMind’s SynthID-Text and applies to Claude everywhere, not just the EU. Anthropic’s own explanation is blunt about why: “We’re applying watermarking globally at launch because we don’t yet have a durable way to scope it by region.” OpenAI, by contrast, has built region-scoping into ChatGPT and Codex and left the API off by default worldwide, which means an EU user’s watermark status depends on which product surface they use, not on jurisdiction in any simple sense. Anthropic’s detection API is also in private preview, limited to regulators, law enforcement, media and fact-checking organizations and researchers, the same narrow-access pattern OpenAI is using. Google DeepMind’s own SynthID-Text work, published in Nature in October 2024, remains the only one of the three with large-scale field data: the paper reports measuring quality across nearly 20 million live Gemini responses with no detected degradation. Independent audits of SynthID-Text, run by researchers at ETH Zurich’s Secure, Reliable, and Intelligent Systems Lab, found the scheme easier to scrub than other state-of-the-art watermarks even for an unsophisticated attacker, a finding with obvious relevance to any textGrain claim of comparable or better robustness.
For non-text media, both companies fall back on C2PA, the Coalition for Content Provenance and Authenticity’s open standard for signed metadata, plus Google’s SynthID for the pixel- or audio-level signal itself. That split exists because nobody has a watermarking method for text as hard to strip as metadata signing is for files, and metadata signing isn’t very hard to strip either: ordinary re-encoding removes C2PA provenance data, and diffusion-based regeneration removes imperceptible image watermarks, according to researchers cited in coverage of the EU’s Code of Practice.
We are not making text watermarking a global default at launch.
That line from OpenAI’s own announcement is the whole policy in one sentence. The company says it intends to open-source textGrain eventually, which raises the question of whether publishing the method removes whatever protection currently comes from attackers not knowing the exact transport-and-key scheme being used. A watermark whose robustness depends partly on its code being closed is a different thing from one proven robust once the code is open; OpenAI has not published results for the open-source version because it doesn’t exist yet.
The number worth tracking between now and the 2 December 2026 transition deadline is not OpenAI’s self-reported detection rate. It’s whether any EU regulator, newsroom or independent lab runs its own adversarial test, the way ETH Zurich’s group already did to SynthID-Text, and whether textGrain’s numbers hold up once someone other than OpenAI is doing the measuring.
