OpenAI Launches 'textGrain' Watermarking for ChatGPT: How it Works and Why it's Fragile
OpenAI introduces 'textGrain' invisible watermarking for ChatGPT in the EU to comply with the AI Act. While effective for some content, simple editing can bypass detection.
07 Oct 2026, 20:21 UTC

OpenAI has begun rolling out a new invisible watermarking technology called textGrain for ChatGPT and Codex. While the feature is primarily aimed at complying with the European Union's strict AI transparency laws, its introduction has sparked significant interest globally, including a surge in searches for chatgpt in India.
EU AI Act Compliance and Global Availability
The rollout is a direct response to Article 50(2) of the EU AI Act, which requires generative AI providers to ensure that AI-generated content is machine-readable and detectable. These transparency obligations became effective on August 2, 2026. Consequently, OpenAI is implementing textGrain for eligible users across all ChatGPT and Codex plans within the EU over the coming weeks, as reported by The Hindu.
For users outside the European Union, watermarking is not a global default. However, starting October 5, 2026, API customers worldwide can opt in to text watermarking for select models to meet their own transparency requirements, according to The Verge.
How textGrain Works: Beyond Hidden Characters
Unlike traditional watermarks that might insert hidden characters or specific tokens, textGrain uses a statistical approach. It subtly influences the model's choice of words (tokens) during the generation process using a secret key and the preceding context. A detector can then analyze the resulting text and, using the same secret key, identify the statistical signal to determine if the content was AI-generated.
Detection Performance and Limitations
The effectiveness of textGrain varies significantly depending on the subject matter and the length of the text. According to OpenAI's technical data, detection rates for psychology-related content are high, reaching approximately 95% for 400-token passages. However, detection is "substantially lower for mathematics," where word choice is less flexible.
The system is also highly susceptible to human editing. OpenAI's evaluations show that the watermark is fragile; replacing just 10% of words with synonyms drops the detection rate from 92% to 66%. If 25% of the words are replaced, the detection rate plummets to approximately 17%.
Key Constraints of AI Watermarking
OpenAI has explicitly stated that textGrain is a "provenance signal" rather than a definitive test of authorship. It is important for users and researchers to understand the following limitations:
- No Proof of Authorship: The absence of a watermark does not prove a human wrote the text.
- No Quality Verification: Watermarks cannot verify the accuracy of the text or establish ownership.
- Limited Scope: It cannot determine the extent of human creativity or editing involved in a final piece of writing.
- Restricted Access: To prevent false positives, the detector is currently limited to approved researchers and expert organizations.
Sources & further reading
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.