By This Hour Technology Desk

OpenAI is rolling out an invisible, machine-readable watermark for text generated through ChatGPT and Codex, beginning with eligible users in the European Union, according to a report. The system, called textGrain, is intended to make it possible to test whether a piece of text carries a signal associated with OpenAI-generated output without visibly changing the writing itself.

The move places provenance, rather than judgment, at the center of the product change. A watermark may offer a way to ask whether qualifying text appears to have come from a particular AI system. It does not, OpenAI says, establish whether the material is true, who owns it, how much of it a person contributed, or whether a human wrote it. Those limits will shape whether textGrain becomes a useful transparency measure or an overinterpreted technical label.

The reported launch is regional rather than universal. OpenAI is said to be introducing the feature across ChatGPT and Codex plans for eligible EU users over the coming weeks, while declining to make watermarking a global default at launch. Separately, API customers worldwide can reportedly elect to receive watermarked outputs from selected models. The split approach gives the company different paths for consumer products and businesses that use its models in their own services.

A signal for origin, not a verdict on content

TextGrain is described as invisible and machine-readable. In practical terms, the watermark is not meant to be a visible notice pasted into a response. Its purpose is to allow a detector to look for a signal in text and report whether it finds an OpenAI watermark. That distinction matters because the presence of a signal addresses only a narrow question about origin.

OpenAI’s stated caveats are unusually central to the rollout. A positive detection would not validate the accuracy of a statement in the text. It would not settle ownership. Nor would it quantify the share of work done by a person rather than a model. It also would not prove human authorship. Each of those questions can matter to readers, publishers, employers, customers and creators, but none is answered simply by knowing that a watermark may be present.

The inverse is also important. The company says textGrain does not guarantee reliable detection. A detector’s failure to find the signal therefore cannot be treated as proof that no OpenAI system was involved. OpenAI has cited the risk of missed watermarks as one reason not to make its detector publicly available at launch. That warning puts a firm boundary around the technology: it is not presented as a comprehensive means of classifying all AI-assisted writing, or even as an infallible test for its own marked output.

False positives are the other stated concern. A mistaken positive result could attach an AI-origin label to text that should not receive one. By withholding broad public access to the detector initially, OpenAI appears to be limiting how readily such a result can be used outside controlled evaluation. The decision may reduce immediate availability for people who want to check text for themselves, but it also reflects the potential consequences of presenting a probabilistic or fallible technical finding as a definitive conclusion.

EU launch creates a limited first test

The initial consumer-facing rollout is confined to the European Union. OpenAI says it is using a regional launch to learn from real-world use and feedback, rather than imposing watermarking as the default everywhere from the outset. The company has not, in the available account, set out a timetable for expanding the default beyond the EU or committed to doing so.

That choice means the same OpenAI products may not handle generated text in the same way across markets at the beginning of the rollout. Eligible users of ChatGPT and Codex in the EU are expected to receive watermarked text over the coming weeks, while users elsewhere are not included in the reported default launch. “Eligible” is significant: the account does not define every condition that determines eligibility, so the practical reach of the feature inside the EU is not fully clear.

The regional plan also separates deployment from proof of effectiveness. OpenAI has pointed to benchmark results that reportedly showed similar performance for watermarked and unwatermarked text. That is a meaningful claim because a provenance tool that materially degraded output would impose an obvious cost on users. Still, comparable benchmark performance does not resolve how textGrain will behave across the full range of writing tasks, editing practices, product settings or subsequent handling of the text.

OpenAI has also said its approach performed at least as well as other text-watermarking methods in benchmarks it cited, including Google DeepMind’s SynthID. The comparison indicates that OpenAI is positioning textGrain within a wider effort to build technical signals for AI-generated material. Yet the available reporting does not provide the underlying benchmark detail needed to assess the scope of that comparison, the conditions tested, or the extent to which the results translate into ordinary use. The company’s own warning about unreliable detection should remain part of any reading of the performance claim.

API customers can choose, while detection stays restricted

For organizations using OpenAI models through its API, the reported policy is opt-in rather than automatic. Customers worldwide can choose watermarked text outputs for select models, allowing them to decide whether and where the feature fits into their own transparency practices and user experiences. The limitation to selected models leaves open which models are covered and whether the scope will change.

OpenAI is also said to be working with cloud partners so that watermarking can be available for outputs obtained through those partners’ services in the coming weeks. That work matters because model output can reach customers through more than one route. But the report does not identify the partners, specify which services will support the option, or state when each implementation may arrive. The direction is clear; the operational coverage is not.

Access to the detector itself is expected to be narrow at first. Approved researchers and expert organizations can reportedly apply for access, with decisions initially made case by case. The detector is designed to report whether it finds an OpenAI watermark while not identifying the user behind the text or disclosing prompts and conversations. That design separates a provenance result from account-level attribution and from the contents of the interaction that produced the output.

Restricting the tool creates a practical division between the capability to insert a watermark and the ability to check for one. Users may receive marked text, and API customers may opt in to it, while the mechanism for testing text remains limited to organizations OpenAI approves. The approach could support evaluation of the system before wider access, as OpenAI has indicated. It also means outside users cannot yet assume they will be able to independently run their own checks on material they encounter.

The central question is how results will be interpreted

The usefulness of textGrain will depend not merely on whether the marker can be embedded, but on how carefully its results are read. OpenAI’s stated limitations rule out a simple equation between a detection result and a final answer about authorship, truth or rights. A watermark can be a clue about the path through which text was generated. It cannot, on the information available, describe the full history of drafting, revision or human involvement that may have produced the final version.

That caution applies equally to positive and negative outcomes. A detected watermark does not establish that every word was generated without human contribution, and a missed watermark does not establish that an AI system played no role. OpenAI’s explicit mention of false positives and missed detections makes those two errors part of the product’s known limitations, rather than edge cases that can be ignored when a result is used.

The staged rollout may therefore function as a test not only of the watermark’s technical behavior but also of the practical meaning assigned to it. OpenAI says it wants feedback from real-world use in the EU. The available information does not say what feedback would lead it to alter the system, broaden it, make it a global default or open the detector to the public. It likewise does not describe how often a detector may miss a watermark or issue a false positive.

For now, the reported policy establishes three different levels of access: a default rollout for eligible ChatGPT and Codex users in the EU, an opt-in choice for certain API customers worldwide, and case-by-case detector access for approved researchers and expert organizations. That arrangement makes textGrain available in meaningful but bounded ways, while retaining control over the most consequential interpretive tool.

This report has not been independently corroborated. It is based on a single source account and on claims attributed to OpenAI; no independent testing, public detector access or underlying benchmark material was provided here to verify the watermark’s performance, coverage or reliability.

For further context on this subject, see NASA Campaign Examines Fire-Generated Thunderclouds Over Western North America.

Reporting notes

What is confirmed: The reported plan covers EU consumer products, opt-in API outputs worldwide and application-based detector access for approved organizations.

Why this matters: The tool may help indicate whether qualifying text carries an OpenAI signal, but the company says it cannot establish truth, ownership or the degree of human contribution.

What remains unclear: The available account does not establish the feature’s exact eligibility rules, model coverage, detection error rates, wider rollout plans or benchmark methodology. This report is based on one source and has not been independently corroborated.

Sources