- OpenAI will watermark ChatGPT and Codex text in the EU, but API watermarking is opt-in worldwide. Anthropic's Claude watermark is mandatory, per The Decoder.
- In OpenAI's tests, replacing 25% of words with synonyms in 400-token passages cut detection to 17%; only selected researchers get the detector at first.
- Treat a missing watermark as no evidence of human authorship. Ask vendors whether watermarking is on in your API contracts.
A watermark on text sounds like a stamp. It is closer to a weather forecast. It gives a probability, and the probability shifts when someone edits the words. OpenAI's new text watermark shows why, and why a label that machines can read is not the same as proof.
What OpenAI announced
OpenAI is adding an invisible watermark called textGrain to ChatGPT text, according to The Decoder. The report says the EU's AI Act is understood to demand that providers tag machine-written text in a form computers can read. The watermark is OpenAI's answer.
OpenAI plans to enable it for EU users of ChatGPT and Codex within weeks.
The rules differ by access route. For API customers, watermarking is opt-in everywhere. It will also be offered through cloud partners such as Microsoft Azure. The Decoder reports that Anthropic's watermark for Claude is mandatory worldwide, however the models are accessed.
So the same model can produce marked or unmarked text depending on where the customer sits and how they connect. That matters to any company that builds products on an API.
How a text watermark works
A language model picks each next word from a set of likely options. textGrain, as The Decoder describes it, embeds a statistical signal in those word choices. No single word gives it away. A detector looks for the pattern across a whole passage.
That explains the limits OpenAI reports. Maths content leaves less room for word choice, so detection was "substantially lower". Short passages carry less signal. Edits break the pattern, because every swapped word removes part of it.
Longer passages might strengthen the signal, according to the report. OpenAI offers no data to test that idea.
The weak point is editing
OpenAI's own edit test is blunt. In it, 400-token passages started at about 92% detection. Replacing 10% of words with synonyms cut that to about 66%. Replacing a quarter of the words cut it to 17%.
So a light edit cuts detection noticeably, and a heavier one nearly erases it. The reported figures cover synonym swaps only. OpenAI also lists translation and editing among the reasons a watermark may go undetected, but the figures do not measure translation.
The Decoder argues the weakness could work in OpenAI's favour. If the watermarks became harder to remove, users who want to avoid detection might move to open-weight models.
Who can check the label
The detector is not public. Only selected researchers and specialist organizations get access at first. Applicants fill in a form, and OpenAI reviews each request individually, following the EU's Code of Practice. OpenAI says it will widen access "when we believe results can be interpreted responsibly". It has given no date.
The tool answers one question: did it detect an OpenAI watermark? It does not identify users or reveal prompts. OpenAI also says a detected watermark does not show ownership, responsibility, accuracy or how much a human contributed. A missing watermark does not prove a human wrote the text.
Image and audio verification tools remain publicly available. Text is the format where the check is hardest to get.
What this shows
The lesson here is that machine-readable labels shift trust but do not settle it. The label exists to help software sort content at scale. Yet the sorting is only as reliable as the weakest link: short text, edited text, maths-heavy text, a different vendor's model, or an API customer who left watermarking off.
The risk falls on whoever treats the signal as a verdict. Think of an HR team screening applications, a publisher checking submissions, or a compliance officer reviewing client letters. A false sense of certainty can be worse than none. OpenAI itself gives errors as the reason for restricting the detector. It can wrongly flag plain text and can overlook text that is marked.
One caveat on quality. In tests on its frontier model Astra, OpenAI found no meaningful score gap between watermarked and unwatermarked output across eight benchmarks. The Decoder points out that this does not settle whether writing quality changes.
Questions to put to your team
First, check whether any policy or workflow assumes that unwatermarked text is human. Remove that assumption, since OpenAI itself says absence proves nothing.
Second, ask which AI vendors feed your products and whether each API contract has watermarking on or off. API defaults differ by vendor: OpenAI's is opt-in, Anthropic's is mandatory. OpenAI's watermarking of its consumer products starts in the EU.
Third, if you operate in the EU, ask legal what labelling duties apply to text you publish, and who owns the answer. The source describes the EU requirement only as reported.
Fourth, treat detection as one input among several, with provenance records and human review alongside it. A watermark that survives 10% editing in part but not 25% is a clue, not evidence.
A label can say where text came from. It cannot say what a person did with it afterwards.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Decoder.





