OpenAI Plans Invisible ChatGPT Watermarks for AI-Generated Text in the EU
OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex for users in the European Union.
The watermark will not be visible when people read or copy the text. Instead, OpenAI says its text watermarking technology, called textGrain, slightly changes the model’s word selection to create statistical patterns that can be detected later.
“In the coming weeks, we plan to add invisible watermarks to ChatGPT and Codex text output targeted to the European Union,” OpenAI explained.
OpenAI has not made invisible AI text watermarking a worldwide default. However, API developers around the world can now opt in to watermarking for supported models. The feature will remain disabled by default.
The company is also accepting applications for access to watermark detectors. Initially, these tools will be limited to approved researchers and professional organizations.
How OpenAI’s invisible text watermark works
OpenAI’s system does not add a visible logo, label, or character to ChatGPT output. Instead, it subtly influences the model’s word choices, creating a statistical signature that detection tools may identify later.
The watermark is designed to help determine whether text was generated by OpenAI tools. However, it does not identify the person who created the text or reveal their account, prompts, or conversations. It also cannot show how much of the final work was written or edited by humans.
Editing can make AI watermarks harder to detect
Text watermarks are not perfect. OpenAI’s own testing shows that even relatively minor edits can significantly reduce the ability to detect AI-generated text.
“In an evaluation of a 400-token passage, replacing 10% of the words with synonyms reduced the detection rate from approximately 92% to 66%. Replacing 25% of the words reduced the detection rate to 17%,” OpenAI noted.
With a target false-positive rate of 1%, OpenAI detected watermarks in approximately 80% of 200-token psychology responses. Detection increased to about 95% when the responses reached 400 tokens.

Detection was even less reliable for subjects such as mathematics, where the model has less freedom to choose among different words.
“Failure to detect a watermark is not proof of human authorship,” OpenAI warned. “Text generated by OpenAI tools may be too short or edited or translated for detection to work reliably.”
OpenAI says textGrain has little impact on output quality
OpenAI states that enabling textGrain does not significantly affect the quality of GPT-6 Astra. The company says benchmark results remain largely similar when the watermarking technology is enabled.
The planned EU rollout could give researchers and organizations another way to analyze AI-generated content, but OpenAI’s testing shows that detection remains dependent on factors such as text length, subject matter, translation, and editing.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



