AI News · Hot news ·

OpenAI starts adding invisible text watermarks to ChatGPT and Codex in the EU

OpenAI starts adding invisible text watermarks to ChatGPT and Codex in the EU

OpenAI is introducing invisible watermarks for eligible ChatGPT and Codex text outputs in the EU over the coming weeks. The company says the change responds to EU AI Act requirements and covers eligible users across all plans. Text watermarking remains opt-in for API customers worldwide, while detector access is restricted to approved researchers. OpenAI cautions that the technology cannot establish authorship, accuracy or responsibility.

Key points

  • OpenAI is rolling out invisible text watermarks to eligible ChatGPT and Codex users across all plans in the EU.
  • API watermarking remains off by default, with worldwide opt-in access for selected models.
  • Editing, shorter passages and maths content can reduce watermark detection reliability.
  • Watermarks do not establish authorship, ownership, responsibility or accuracy.
  • Detector access is initially restricted to approved researchers and expert organizations.

What happened: OpenAI is introducing invisible watermarks for eligible text generated by ChatGPT and Codex in the EU over the coming weeks, The Next Web reported. The rollout covers eligible users across all plans. OpenAI said the change responds to the EU AI Act, which requires AI-generated text to be identifiable by machines. It is not making watermarking a global default at launch, saying the regional approach will allow it to learn from real-world use and feedback.

The details: The system, called textGrain, adds a hidden statistical signal to the model’s word choices rather than a visible label. A detector then checks for that signal. OpenAI said benchmark scores for its Astra model showed no meaningful difference with watermarking enabled. The company published a technical report with researchers from the University of Pennsylvania and Yale and said it plans to release the technology as open source. For API customers worldwide, watermarking remains off by default, with an opt-in option for selected models. OpenAI also said it is working with cloud partners to offer watermarking through their services.

The details: OpenAI’s testing illustrates why detection should not be treated as a definitive verdict. At a target false positive rate of 1%, the detector found the watermark in about 80% of 200-token passages on topics such as psychology, rising to about 95% for 400-token passages. Editing weakened the signal: replacing 10% of words with synonyms reduced detection from about 92% to 66%, while replacing a quarter reduced it to 17%. Detection was also substantially lower for maths, where word choice is less flexible, the company said.

Who it affects: For business teams reviewing AI-generated content, the distinction is between machine-readable identification and proof of authorship. OpenAI said the watermark does not identify the user, measure human contribution, establish ownership or responsibility, or verify accuracy. A detected watermark therefore does not establish whether a passage is true or appropriately presented. Conversely, a missing watermark does not prove human authorship. OpenAI said text may be too short, edited or translated, or may have come from another company’s tools.

What to watch: Independent verification will initially be limited. OpenAI is restricting detector access to approved researchers and expert organizations, granting access case by case to help evaluate reliability and responsible uses. The detector reports whether it finds an OpenAI watermark without identifying the user or revealing prompts. OpenAI said it will widen access once results can be interpreted responsibly, but a timetable was not reported. For organizations adopting the feature through the API, enabling watermarking and obtaining access to detection are therefore separate considerations.

Our take

Teams should distinguish machine-readable identification from reliable proof of authorship. Restricted detector access also limits how organizations can independently verify watermarked content.

Sources