TL;DR On October 5, 2026 OpenAI said it will add an invisible watermark, called textGrain, to ChatGPT and Codex text in the EU over the coming weeks, and let API customers anywhere opt in today. Its own tests show editing breaks detection (92% falls to 66% when 10% of words change) and a missing watermark does not prove a human wrote the text. Your policy should say so before someone uses it as proof.
OpenAI published its approach to EU text marking on Monday, October 5, 2026, and TechCrunch, PCMag and others ran it the same day. The headline is "ChatGPT text will be watermarked in the EU." The more useful part is in OpenAI's own post: a plain list of what the watermark cannot tell you. If you run a company, a school, a hiring process or a newsroom, that list is the part to turn into policy.
What OpenAI announced
| Item | What OpenAI says |
|---|---|
| Date | October 5, 2026 |
| Who gets it | Eligible ChatGPT and Codex users on all plans, in the EU only, rolling out "over the coming weeks" |
| API | Developers anywhere can opt in for select models starting October 5; off by default; cloud partners "in the coming weeks" |
| Method | textGrain, an invisible statistical signal in the model's word choices |
| Detector | Applications open, but access is limited at first to approved researchers and expert organizations |
| Other media | Image and audio verification tools remain publicly available |
| Global default | Not at launch |
The trigger is the EU AI Act. In the site's verified tracker, the transparency obligations apply from August 2, 2026, and systems already on the market before that date have until December 2, 2026 under the AI Omnibus. The Commission published the final Code of Practice on marking and labelling AI-generated content on June 10, 2026. TechCrunch notes Anthropic, Google, Meta, Microsoft and OpenAI are among the companies that committed to follow it, and that Anthropic said in August it would watermark Claude text worldwide.
The numbers OpenAI published
These are OpenAI's own evaluations at a target false positive rate of 1%, for English text from the ELI5 dataset.
| Test | Detection rate |
|---|---|
| 200-token passage (psychology content) | About 80% |
| 400-token passage (psychology content) | About 95% |
| Mathematics content | "Substantially lower" |
| 400 tokens, 10% of words replaced with synonyms | About 92% down to 66% |
| 400 tokens, 25% of words replaced with synonyms | Down to 17% |
Read the first two rows as the best case. A short email is closer to 200 tokens than 400, math and code leave less room for word choice, and anyone who edits the text lightly pushes detection toward a coin flip. OpenAI says that is why it limits detector access for now.
What a watermark cannot tell you
OpenAI lists five limits in its post. They are blunt, and worth quoting in your own materials.
- It does not measure human contribution. It can indicate an OpenAI system generated or processed part of a passage, not how much judgment or creativity a person added.
- It does not establish ownership or responsibility. It does not determine who owns the text, whether use was lawful, or whether disclosure was required.
- It does not identify the user. No person, account, prompt or conversation is tied to the text.
- It does not verify accuracy. A watermarked passage can be false.
- The absence of a watermark does not prove human authorship. The text may be short, edited, translated, from an unsupported model, from before watermarking, or from another company's tool.
The last point is the one that will go wrong in practice. Someone will paste a candidate's cover letter or a student's essay into a detector, get "no watermark," and treat it as proof of honest work. Or get a hit and treat it as proof of cheating. Neither follows.
What changes for a small team
If you use ChatGPT in the EU: your staff's output will carry the signal. It is not visible and does not identify them. It does mean text you paste into a document or a client email may later be flaggable by someone with detector access.
If you build on the API: you decide. OpenAI says opting in "lets customers decide how watermarking fits their transparency obligations." If you ship AI text to EU users, check with your counsel whether your own duties under Article 50 are met by the provider's marking, because OpenAI says its watermark does not decide whether disclosure was required. Our Article 50 guide and the December 2026 checklist cover the provider and deployer split.
If you review other people's text: stop using "no watermark" as evidence of anything.
If you use several vendors: the marking will differ by provider and region, so a single detector will not cover your text. That is a vendor question, below.
Three places this goes wrong
These are our reading of OpenAI's own limits, not additional findings from the announcement.
A cover letter or work sample. A reviewer runs a detector, sees nothing, and concludes a person wrote it. OpenAI says the absence of a watermark proves nothing: the text may be short, edited, translated or from another company's model. A candidate who lightly edits an AI draft would look "clean" while one who wrote honestly could be wrongly doubted if a tool returns noise.
A school or training course. The published numbers say a 400-token passage is detected about 95% of the time at a 1% false positive target. At that rate, a class of 100 honest students still means roughly one false flag, and heavier editing drops detection sharply. A detection result should open a conversation, never end one.
A client deliverable. An agency delivers text written with an AI tool and the client later runs a detector. If your contract and your policy already say AI assistance is disclosed, a hit is unremarkable. If they say nothing, you have a trust problem that no watermark created and no watermark fixes.
Copy this: staff rule on AI text provenance
AI TEXT PROVENANCE RULE (draft, review with counsel before adoption)
1. Some AI providers add an invisible watermark to generated text. We do not
remove, disguise or try to defeat it.
2. We never treat the absence of a watermark as proof that a person wrote a text,
and we never treat a watermark detection as proof of misconduct. A detection
result is one weak signal and starts a conversation, not a decision.
3. Where we must tell people that content is AI-generated (client work, public
statements, EU-facing material), we say so in plain words, whether or not the
text carries a watermark.
4. We record which tool produced AI-assisted text we publish or send to
clients: tool name, date, and who reviewed it.
5. Decisions about hiring, grading or discipline are never based on a watermark
or detector result alone.
Owner: [role] Review date: [date]
Rule 2 and rule 5 are the ones that protect you. They keep a weak signal from becoming an accusation.
Four questions for your AI vendors
- Do you watermark text output, in which regions, and is it on by default?
- Can we turn it on or off for our account, and who decides?
- What detection rates and false positive rates have you published, and for which text lengths?
- If we publish AI text in the EU, what do you state about whose disclosure duty applies?
Add these to your vendor due diligence checklist. If you sell to California as well, our SB 942 transparency guide covers the state rule that points the same way.
What we could not verify
- We read OpenAI's October 5 post and TechCrunch's report. We did not read the textGrain technical report or the Commission's guidelines in full.
- The date the watermark reaches any given ChatGPT account is "over the coming weeks." We have no per-account date.
- The Anthropic worldwide watermark detail comes from TechCrunch's summary; we did not read Anthropic's own announcement.
- We found no verified post from OpenAI or a regulator that we could embed, so this page has no embed.

