OpenAI watermarks ChatGPT and Codex text in the EU, and editing cuts detection from 92% to 66%
Under the EU AI Act, OpenAI will add an invisible watermark to ChatGPT and Codex output in the EU, but its own tests show light editing cuts detection from 92% to 66%.

OpenAI has started rolling out invisible watermarks on ChatGPT and Codex text generated for users in the European Union, a response to the EU AI Act's transparency rules requiring generative AI output to be machine-identifiable, the company said in a blog post Monday.
What's rolling out, and where
The EU AI Act's transparency provisions took effect August 2, and OpenAI's answer is a technique it calls textGrain: a statistical pattern baked invisibly into the model's word choices, readable only by OpenAI's own detector. Over the coming weeks the mark will reach eligible ChatGPT and Codex users on every plan inside the EU. Outside the consumer apps, nothing changes automatically — API customers anywhere in the world can switch watermarking on for select models starting now, but it ships off, and OpenAI was explicit that this is a regional rollout, not, in its own words, "a global default at launch."
Detector access stays closed for now. OpenAI is taking applications from "approved researchers and expert organizations" to help it study how the signal holds up, alongside a technical paper written with academics at the University of Pennsylvania and Yale. On the quality side, the company reports near-identical scores with watermarking on versus off across its benchmark suite — differences of roughly half a point or less on tests like GPQA Diamond and the Artificial Analysis Intelligence Index, small enough that the mark shouldn't change what the output reads like.
The signal doesn't survive a light edit
OpenAI's own figures show how little it takes to break the pattern. Length alone moves detection a lot: at a 1% false-positive rate, a 200-token passage was flagged correctly only around four times in five, while a 400-token passage was caught closer to nineteen times in twenty — and passages with less room for word-choice variation, like math answers, scored worse than conversational prose at either length. Editing moves it further, and faster. Swap one word in ten for a synonym across a 400-token passage, and the detection rate falls from roughly 92% to 66%. Push that to one word in four, and it collapses to 17%.
The company is upfront about what that leaves unresolved.
"A watermark does not measure human contribution... does not establish ownership or responsibility... does not identify the user... does not verify accuracy." — OpenAI
The reverse case matters just as much for anyone trying to draw conclusions from it: a clean passage with no detected mark proves nothing on its own, since short, heavily edited, translated, or non-OpenAI text will all come back the same way.
What it means for software marketers
Most AI-assisted marketing work — landing page drafts, release notes, ad copy, in-app microcopy — runs through an API or a third-party writing tool built on one, not the ChatGPT consumer interface directly. Under this rollout, that pipeline stays exactly as it is, since API watermarking requires someone to turn it on deliberately. The group actually affected is narrower: EU-based staff or contractors drafting straight inside ChatGPT or Codex, then carrying that text into a CMS, a support macro, or an internal brief.
The bigger shift for marketing teams is that AI-disclosure behavior is turning into something vendors compete on, not just a box regulators tick. TechCrunch reports that Anthropic rolled a Claude watermark out globally two months before this, which some users pushed back on, saying they had contributed the thinking and the model had only executed it. TechCrunch's reporting also points to an earlier Wall Street Journal account of OpenAI shelving its own watermark previously, wary that marking output would push people toward tools that didn't. Put those two data points together and a pattern emerges: regulation is pulling AI vendors toward disclosure in one market while user preference pulls them away from it everywhere else, which means the writing tool your team standardizes on may end up handling this differently depending on where your audience sits and which vendor you picked.
- Map which tools in your content stack touch OpenAI's consumer apps directly versus its API, since only the former gets watermarked automatically for now.
- Don't build a compliance process, or a competitive read on a rival's content, around detecting AI-written text — OpenAI's own numbers show a light edit cuts detection by roughly a third, and a heavier one nearly erases it.
- When evaluating AI-writing vendors, ask how each one handles disclosure by default — it's shaping up as a real point of difference, not a footnote in the terms.
If your team publishes AI-assisted content to EU audiences, find out which part of your stack actually touches OpenAI's consumer apps versus its API — only the former picks up the watermark automatically today. Treat watermark detection as unreliable for any internal policy or vendor comparison; OpenAI's own data shows it degrades fast under ordinary editing.
PricingChargebee's billing overhaul shows how CodeRabbit, Gorgias and Zapier actually price their AI features
Sienna Mcpherson · 4 min read
Pricing