OpenAI Outlines Text Watermarking Plan and Its Detection Limits
OpenAI has detailed textGrain watermarking for AI-generated text in response to EU rules, while acknowledging detection failures after editing and other limitations.
On October 5, 2026, OpenAI described its text watermarking approach, called textGrain, in response to EU AI rules. The technique adds an invisible statistical signal to word choices that a dedicated detector can look for.
Unlike a visible mark on an image, a text watermark is not apparent to readers. OpenAI says eligible API customers worldwide can opt in for select models, with watermarking off by default in the API.
WHY TEXT PROVENANCE MATTERS: AI-generated writing can be copied, edited and published as ordinary text. Its appearance does not reliably reveal whether a person or model wrote it. Watermarking attempts to preserve a signal that may help identify a generating system, but such a signal says nothing about whether the content is true.
HOW TEXT WATERMARKING DIFFERS FROM IMAGE MARKS: Images can carry subtle pixel-level changes. Text is different because word choice and sequence are the content itself. OpenAI describes textGrain as adding a statistical pattern during generation that a specialized detector can examine. Readers cannot identify that pattern simply by looking at the words.
WHAT A DETECTION RESULT MEANS: A detected signal may provide evidence that text came from a compatible generation system. It does not identify the final publisher, establish how much editing occurred or verify the factual claims. Provenance, authorship, copyright and accuracy are separate questions.
UNDERSTANDING THE ROLLOUT: OpenAI says eligible API customers around the world can opt in for selected models, while the API default remains off. For eligible ChatGPT and Codex outputs in the EU, it announced a rollout over subsequent weeks. This is not a claim that all text generated by every OpenAI product worldwide will carry a watermark.
WHO CAN USE THE DETECTOR: Initial access is planned for approved researchers and specialist organizations. The announcement does not mean a public detector is available to anyone who wants to paste in a paragraph. The scope of watermark generation and access to verification tools need to be considered separately.
WHY EDITING WEAKENS DETECTION: Statistical signals depend on the original sequence of word choices. Replacing words with synonyms can preserve meaning while disrupting that pattern. OpenAI reports that, for a 400-token passage, substituting 10% of words reduced detection from about 92% to 66%, while 25% substitution reduced it to 17%.
HOW TO READ THOSE NUMBERS: The percentages describe a particular experiment, passage length and editing procedure. They are not universal detection rates. Short passages and highly constrained writing may carry weaker signals. Evaluations need to specify text length, editing methods and detector thresholds.
TRANSLATION AND SUMMARIZATION: Translating or heavily summarizing text can change word sequences substantially, potentially destroying the original signal. Text produced by other models without compatible watermarking may also fall outside the detector's scope. A negative result must not be interpreted as proof of human authorship.
THE COST OF FALSE ACCUSATIONS: In education, hiring and journalism, a mistaken claim about AI authorship can harm individuals. Even a detector with useful aggregate accuracy should not become the sole basis for accusing someone of misconduct. Draft histories, editing records and explanations from the author provide important additional context.
WHAT PUBLISHERS SHOULD DO: A news organization may use AI during drafting while remaining responsible for everything it publishes. Verifying primary sources, checking factual claims and maintaining editorial oversight are still essential. Watermarks may support transparency, but they cannot replace reporting and verification.
OTHER PROVENANCE METHODS: Beyond watermarking, organizations can retain editing histories or disclose how content was created. Each approach has limitations. Readers need both provenance information and reliable evidence for the claims in a document.
WHAT TO WATCH: As EU-related transparency requirements develop, the important questions include resistance to editing, short-text performance, detector availability and false-positive handling. textGrain is best viewed as one possible provenance signal rather than a definitive AI-authorship test.
For eligible ChatGPT and Codex text output in the EU, OpenAI plans to introduce watermarks over the following weeks. This is not a global default for every output. Initial access to the detector will be limited to approved researchers and expert organizations.
Detection is far from foolproof. In one OpenAI evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%; replacing 25% reduced it to 17%. Shorter passages and more constrained writing are also harder to identify.
A detected watermark does not establish factual accuracy, ownership or the amount of human editing involved. Likewise, a missing watermark does not prove human authorship: text may have been edited, translated or generated by a different system.
Provenance signals may become useful as AI-generated content grows, but they should be combined with source checks and transparent editorial processes rather than treated as definitive proof.