
ChatGPT and Codex will soon add invisible watermarks to eligible text generated in the European Union. But the technology is far from an infallible AI detector.
OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union, giving authorized researchers and organizations a new way to spot content produced or processed by its AI systems.
The company announced the move as part of its response to the EU AI Act, which requires providers of generative AI systems to make AI-generated text identifiable in a machine-readable way.
For ordinary ChatGPT users, however, the term "watermark" may give the wrong impression. Nothing will suddenly appear at the bottom of your ChatGPT responses, and copied text won't carry an obvious "made with AI" label.
Instead, the marker is buried in the language itself.
OpenAI calls its technology textGrain.
Rather than adding hidden characters or invisible spaces, textGrain subtly influences how an AI model chooses among possible words or pieces of words while generating an answer.
Across a sufficiently long passage, those choices form a statistical pattern. A detector with the necessary information can then check the text for that pattern.
This also means the watermark can persist when someone simply copies and pastes ChatGPT output into an email, document, website or social media post.
OpenAI says it found no meaningful difference in model performance when comparing watermarked and non-watermarked output in its benchmarks.
No.This is an important distinction, particularly given the privacy implications people might associate with the word "watermark."
According to OpenAI, the watermark contains no information identifying the person who generated the text. It isn't linked to your name, OpenAI account, prompt or individual ChatGPT conversation.
Finding the watermark essentially provides one piece of information: an OpenAI system may have been involved in generating or processing the passage.
It doesn't reveal who used it.
That limitation becomes particularly important as AI increasingly becomes part of everyday writing.
Imagine you write an article yourself and ask ChatGPT to improve a few awkward paragraphs. Or you use ChatGPT to produce a rough draft before extensively rewriting it. Someone else might simply generate an entire document and publish the output untouched.
A detected watermark can’t reliably distinguish between those scenarios.
OpenAI explicitly says its watermark doesn't measure the amount of human contribution, establish ownership of the text, determine whether AI use was lawful or required disclosure, or tell readers whether the information is accurate.
In other words, "OpenAI detected" is not necessarily the same thing as "written by AI."
There’s another catch: text is easy to change. OpenAI's own testing illustrates the problem.
In one experiment involving 400-token English passages, its detector identified the watermark roughly 92% of the time before editing. Replacing just 10% of the words with synonyms reduced detection to around 66%.
Replacing 25% of the words pushed detection down to just 17%.
Length matters too. At a target false-positive rate of 1%, OpenAI says its detector identified watermarks in about 80% of certain 200-token passages, compared with roughly 95% for 400-token passages.
Results were substantially worse for material such as mathematics, where a model has less freedom over which words to choose. Translation can also interfere with detection.

Source: openai.com

Source: openai.com
That creates an important rule when interpreting AI-detection claims: no watermark doesn't mean no AI.
Text might have been edited, translated or shortened. It could have been generated before watermarking was introduced, produced by an unsupported OpenAI model or created using an entirely different AI service.
Not yet.
Unlike OpenAI's verification tools for supported AI-generated images and audio, its text watermark detector won't initially be available to the public.
OpenAI is instead opening access on a case-by-case basis to approved researchers and organizations studying issues such as text provenance and detection reliability. The company cites both false positives and missed watermarks as reasons for a cautious approach.
That's particularly relevant where a wrong answer could have consequences — for example, accusing a student of cheating or an employee of secretly using AI.
A detection result should therefore be treated as a signal rather than proof of misconduct or authorship.
The rollout depends on how OpenAI's technology is used.
Over the coming weeks, OpenAI says it will introduce text watermarking for eligible ChatGPT and Codex users across all plans in the European Union. It isn't making watermarking a global default for ChatGPT at launch.
Developers are getting more choice.
As of Oct. 5, API customers worldwide can opt in to watermarked output for selected models. Watermarking remains switched off by default for API use. OpenAI says it’s also working with cloud partners to make the capability available for model output accessed through their services.
For most ChatGPT users in the EU, there is little they need to do differently.
The watermark isn't a tracking code attached to your identity, and it doesn't expose your prompts or conversations. Nor does it visibly alter documents you copy from ChatGPT.
Its significance is broader.
Schools, publishers, employers and online platforms have struggled with a deceptively simple question since generative AI became mainstream: Can we reliably tell when something was written by AI?
OpenAI's answer is effectively: sometimes — but don't draw too many conclusions from it.
Watermarking could become another useful signal for identifying AI-generated material, particularly when combined with other evidence. But OpenAI's own results demonstrate why an automated detector shouldn't become judge and jury.
AI-generated text can be edited by humans. Human-written text can be processed by AI. Watermarks can disappear. Detectors can be wrong.
As AI becomes woven into everyday writing, the more useful question may increasingly be not simply "Did AI write this?", but "How was AI used to create it?"
Will ChatGPT text have a visible watermark?
No. You won't see a label, symbol or notice attached to text you copy from ChatGPT. OpenAI's textGrain technology creates an invisible statistical pattern by influencing word choices the AI makes while generating text.
Can someone tell that I used ChatGPT?
Possibly, but with important limitations. An authorized detector may be able to identify OpenAI's watermark in eligible text. However, detecting a watermark doesn't reveal who generated the text or which ChatGPT account was used.
Does the watermark contain my personal information?
No. OpenAI says the watermark doesn't encode your identity, account information, prompts or conversation history. It’s designed to indicate that an OpenAI system may have generated or processed the text, not who used it.
Will someone know exactly how much of a document was written by AI?
No. A watermark can't reliably determine how much of a document came from AI and how much was written or edited by a person. For example, someone could write a document themselves and use ChatGPT only to rewrite or polish parts of it.
Can editing ChatGPT text remove the watermark?
It can weaken it significantly. OpenAI's testing shows that replacing words, rewriting passages, translating text or otherwise substantially editing AI-generated content can make the watermark much harder to detect. Short passages can also be more difficult to identify reliably.
Does no watermark mean a person wrote the text?
No. The absence of a detectable watermark isn't proof of human authorship. The text may have been edited or translated, generated by a model that doesn't use the technology, created before watermarking was introduced, or produced by another AI service.
Can I check text for an OpenAI watermark myself?
Not for now. OpenAI isn't launching its text watermark detector as a general-purpose public tool. Access is initially offered on a limited basis to approved researchers and organizations studying provenance and detection.
Will all ChatGPT users get watermarked text?
OpenAI says eligible ChatGPT and Codex text will be watermarked across all plans in the European Union as the technology rolls out. The company isn't making text watermarking a global ChatGPT default at launch.
Does a watermark prove someone cheated or broke the rules?
No. A watermark indicates that an OpenAI system may have played a role in producing or processing the text. It doesn't establish how AI was used, how much human work went into the document, or whether using AI violated any school, workplace or other rules.
Does the watermark mean the information is trustworthy?
No. Provenance and accuracy are two different things. A watermark can provide information about the possible origin of text, but it doesn't verify whether the claims in that text are accurate. AI-generated information should still be checked against reliable sources when accuracy matters.
OpenAI's invisible watermark gives ChatGPT-generated text something it has largely lacked: a machine-readable clue about where it came from.
But it isn't a digital fingerprint.
It won't tell someone who you are, reveal your ChatGPT conversation, prove that an entire document was generated by AI, or establish that the information in it is trustworthy. And because ordinary editing can dramatically weaken the signal, the absence of a watermark proves very little.
For consumers, educators and employers alike, that's the most important takeaway: AI provenance tools can provide evidence, but they shouldn't be mistaken for proof.
On topic:
Rogue AI agents probed US and Canadian government sites for flaws
AI agents want to shop for you; banks warn of scams and privacy risks
AI hallucinated a nuclear threat. The US military nearly responded
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts