OpenAI Just Started Watermarking ChatGPT Text in the EU — Your AI Disclosure Policy Can't Be Invisible Ink

OpenAI Just Started Watermarking ChatGPT Text in the EU — Your AI Disclosure Policy Can't Be Invisible Ink

2026-10-06

On October 5, OpenAI said it will start adding an invisible watermark to text that ChatGPT and Codex produce for users in the European Union. It is doing this to meet the EU AI Act, the European law that requires AI providers to make generated text identifiable by machines (OpenAI).

The takeaway for operators: a vendor watermark is the vendor’s compliance, not yours. It cannot tell anyone why your team used AI, who checked the output, or whether you followed your own rules. You still need a disclosure policy that a human can read.

What OpenAI actually shipped

The watermark is called textGrain. It does not insert hidden characters. Instead, it nudges the model’s word choices so that, across a long enough passage, a detector holding a secret key can spot a statistical pattern (OpenAI technical report).

The rollout has three parts (OpenAI):

  • EU ChatGPT and Codex users on all plans get watermarked text over the coming weeks. It is not a global default.
  • API customers anywhere (companies building on OpenAI’s developer interface) can opt in for select models starting now. It stays off unless you turn it on.
  • The detector is limited at first to approved researchers and expert organizations. Regular users and businesses do not get one.

OpenAI is not alone. The Verge notes that Anthropic announced its own watermarking in August, built on Google DeepMind’s SynthID approach, for the same EU reason (The Verge).

The numbers that matter

OpenAI was refreshingly upfront about the limits. At a 1% false-positive target, the detector found the watermark in about 80% of 200-token passages and about 95% of 400-token passages (a token is roughly three-quarters of a word). Detection is much weaker on text where word choice is predictable, like math (OpenAI).

Editing hurts it fast. Search Engine Journal walked through OpenAI’s test: swapping 10% of words for synonyms dropped detection from about 92% to 66%, and swapping 25% dropped it to 17% (Search Engine Journal). TechRepublic adds that EU guidance does not expect watermarks on code snippets or responses under 200 tokens (TechRepublic).

So a light human edit, a short answer, or a code block can all slip past. That is not a scandal. It is just what this technology can do today.

What a watermark cannot tell you

OpenAI itself says a text watermark does not verify accuracy, decide who owns the text, measure how much a human contributed, or prove human authorship (The Verge). TechRepublic puts it plainly: an invisible marker cannot document why AI was used, how a draft changed afterward, or whether its use followed an employer, client, or school rule (TechRepublic).

Those are exactly the questions your customers, auditors, and lawyers will ask.

The deadlines are real

The EU AI Act’s transparency rules (Article 50) began applying on August 2, 2026. AI systems already on the market before that date have until December 2 to meet the marking and detection obligation (Search Engine Journal). If you sell into Europe, or your product puts AI text in front of European users, this is a Q4 item, not a someday item.

A five-step disclosure plan for operators

  1. Map where AI text leaves the building. List every place generated text reaches a customer: support replies, sales emails, product copy, reports, chatbots. Flag anything that reaches EU users.
  2. Decide on the API opt-in on purpose. If you build on OpenAI’s API, watermarking is off by default. Turning it on may help your transparency story. Leaving it off should be a written decision with a reason, not an accident.
  3. Write a policy humans can follow. One page is enough: which tools are approved, when AI use must be disclosed, who reviews output before it ships, and what never goes through AI. A watermark is a footnote to this policy, not a substitute for it.
  4. Keep your own provenance log. Record which model drafted what, who edited it, and who approved it. That record answers the questions a watermark cannot, and it works across every vendor you use.
  5. Do not treat detection as proof. Nobody on your team should accuse an employee, freelancer, or vendor of anything based on a watermark score. With 17% detection after heavy edits and short text exempt, a “clean” result proves nothing either way.

Soft next step

OpenAI did the responsible thing by publishing its numbers, and those numbers make the point for you: watermarks are a useful signal, not a governance program. Own your disclosure policy, keep your own records, and let the watermark be a bonus.

Yellow Coop helps owners and operators map AI use across the company, choose vendors, and turn EU AI Act requirements into a practical checklist — with fractional CTO judgment on who should own AI compliance. See our track record, or start at contact.

Internal links: Secure, What We Do, How We Engage, CIO vs CTO vs CISO, Track Record, Insights.

Sources