Franklin AI News Brief

OpenAI will watermark eligible EU ChatGPT and Codex text, with detector access restricted

Key Takeaways

  • OpenAI is introducing text watermarks in the EU and an opt-in API option, while warning that detection can miss edited or short passages.
  • OpenAI will add invisible watermarks to eligible ChatGPT and Codex text output in the European Union over the coming weeks.
  • API customers worldwide can opt in for select models, while watermarking remains off by default in the API.
  • The company announced the approach on October 5 in response to the EU AI Act's machine-readable identification requirements.
  • The most consequential limitation is access to the detector.

OpenAI will add invisible watermarks to eligible ChatGPT and Codex text output in the European Union over the coming weeks. API customers worldwide can opt in for select models, while watermarking remains off by default in the API. The company announced the approach on October 5 in response to the EU AI Act's machine-readable identification requirements.

The most consequential limitation is access to the detector. OpenAI is taking applications from approved researchers and expert organizations rather than opening detection to the public at launch. Its own evaluations show that short passages and editing can weaken the signal. Anyone reading a watermark result therefore needs to distinguish a technical signal from a judgment about a writer.

A statistical signal in word choices

In its announcement about EU text provenance, OpenAI describes textGrain as a system that adds an invisible statistical signal to the model's word choices. A detector then looks for that signal in a passage. The approach differs from adding a visible label that a reader could notice in the text.

The company reports that detection improves with passage length. At a target false-positive rate of 1%, its detector identified watermarks in about 80% of 200-token passages and about 95% of 400-token passages in content such as psychology. It says detection was lower for mathematics, where there is less flexibility in word choice.

Those figures describe particular evaluations, rather than a promise about a document you might submit. A passage's length and subject can affect the result before anyone has edited it. Comparing a short equation-heavy answer with a longer explanatory passage would therefore require attention to the test conditions.

Editing changes what the detector can find

OpenAI also tested synonym replacement in 400-token passages. Replacing 10% of the words reduced detection from about 92% to 66%; replacing 25% reduced it to 17%. These figures are separate from the passage-length evaluation and should not be combined into a single accuracy claim.

For a publisher or an employer evaluating text, the practical consequence is that a negative result cannot settle an authorship dispute. A person may have edited or translated AI-assisted text, or the output may come from an unsupported model. OpenAI says the absence of a detected watermark does not prove human authorship.

The reverse inference has limits too. A detected watermark does not measure how much human judgment or creativity went into a passage. It also does not establish ownership or responsibility, identify the user, or verify whether the text is accurate. A provenance signal cannot replace checking the substance of a claim.

Different rollout rules for apps and the API

The EU rollout applies to eligible ChatGPT and Codex users across plans. OpenAI says it is not making text watermarking a global default at launch. Developers using the API instead receive a choice to opt in for select models, including customers outside the EU.

Detector access starts on a case-by-case basis so approved researchers and expert organizations can evaluate reliability and responsible uses. The company plans to make textGrain available as open source and says its technical report will receive more details in the coming weeks. These are stated plans, not evidence that unrestricted detection or an open-source release is available now.

For teams deciding how to describe AI-assisted work, the sensible distinction is between documenting their own process and relying on a detector to reconstruct it afterward. Editing records and explicit disclosures can explain human involvement; the watermark alone cannot. OpenAI's announcement leaves that boundary intact even as it adds another way to identify signals associated with its models.

Our read

Franklin AI Take

OpenAI is restricting detector access at launch. That restraint matters: a watermark result should not become a shortcut for accusing a student, writer or employee of deception. We would treat it as one provenance signal and keep the evidence about editing and authorship separate. The useful test is whether the rollout helps people interpret uncertainty, rather than giving an imperfect detector more authority than its measurements support.