# OpenAI starts text watermark rollout with limits on what detection proves
> OpenAI is introducing textGrain for eligible ChatGPT and Codex output in the EU and offering opt-in watermarking to select API customers worldwide. Its detector remains limited to approved researchers and expert organizations.
By BIG CHANGE Editorial
Published: 2026-10-05T20:26:25.813Z
Updated: 2026-10-05T20:26:25.813Z
Canonical: https://bigchange.ai/blog/openai-textgrain-text-watermark-rollout-limits

AI-generated conceptual editorial illustration by BIG CHANGE.
OpenAI announced textGrain on October 5, an invisible watermark that changes the statistical pattern of words its models choose. The company says it is starting a phased rollout in response to EU text provenance rules. A matching detector can look for the pattern in a passage, but a result supplies only a limited clue about whether an OpenAI system generated or processed text.
## The big change
- **What changed:** OpenAI is moving from text provenance as a research problem to a limited release. Eligible ChatGPT and Codex output in the EU will gain a watermark over the coming weeks; select API customers can opt in globally now.
- **Why it matters:** Organizations assessing AI text may eventually have a signal embedded in wording itself. OpenAI's published results show why a detector result needs context: short or tightly constrained passages and edited text can defeat detection, while false positives remain possible.
- **What to watch:** The immediate test is how reliably the signal survives ordinary use across lengths, subjects and languages. OpenAI is restricting detector access to approved researchers and expert organizations while it evaluates those limits.
## Two releases, different access
OpenAI says it will add textGrain to **eligible** ChatGPT and Codex text output across all plans in the European Union over the coming weeks. That is a planned regional rollout, not a claim that every EU response is watermarked today. For the API, customers worldwide can opt in for select models starting October 5; watermarking is off by default. OpenAI says customers can enable it in project or organization settings and choose supported models. The list of eligible models appears in those settings and may change.
TextGrain works through the model's choices among possible words or word pieces, known as tokens. OpenAI says a secret key guides slight changes to those choices during generation. A detector with the matching key and settings then checks whether a passage contains the resulting statistical pattern. The watermark adds no hidden characters, spaces or visible punctuation. Copying text therefore does not require carrying separate metadata, although keeping the words intact does not guarantee a detectable signal.
That distinction also limits who can check a passage. OpenAI is accepting applications for the text detector, initially from approved researchers and expert organizations. It is not opening the detector to the public at launch. Its public verification tools for supported images and audio are separate; they do not provide an open textGrain check.
## A signal can be missed or found in error
OpenAI reports detection rates at a **target false positive rate of 1%** in one evaluation. For psychology passages, its detector found a watermark in about 80% of 200-token samples and about 95% of 400-token samples. It says detection was substantially lower for mathematics, where there is less freedom in wording. These are company evaluation results under specified conditions, not a measured success rate for text encountered in the wild.
Edits weakened the signal in another company test of 400-token passages: replacing 10% of words with synonyms reduced detection from about 92% to 66%; replacing 25% reduced it to 17%. Translation, substantial paraphrasing, short answers and code are also harder cases in OpenAI's documentation. The company says detection varies by language. A negative result therefore cannot establish that a human wrote the text. The passage might be too short, altered, produced before rollout, or generated by a model or product outside watermark coverage.
A positive result has limits too. A detector can falsely report a watermark. When it does find a signal, OpenAI says that is evidence its system likely generated or processed at least part of the passage. It does not measure how much a person contributed, identify an account or prompt, or settle who authored, owns or is responsible for the text. It cannot verify whether the passage is accurate. A result alone cannot identify the person who used a tool.
OpenAI plans further evaluation and says it intends to release textGrain as open-source technology. For now, the practical change is narrower: some newly generated OpenAI text will carry a machine-readable signal, while the means to inspect it and the conclusions it supports remain constrained. Our account is based on OpenAI's announcement and help documentation; BIG CHANGE did not generate watermarked text or run the detector.
## Sources
- [Our approach to EU text provenance rules](https://openai.com/index/eu-text-provenance/) — Primary announcement for release paths, detector restrictions, evaluation examples and limits; performance figures are OpenAI's own.
- [Provenance signals in OpenAI-generated content](https://help.openai.com/en/articles/8912793-provenance-signals-in-openai-generated-content) — Current product documentation for mechanism, settings and interpretation. The displayed relative update time is not a stable source date.
The BIG CHANGE newsletter
The big picture. At your pace.
Recent stories on AI and robotics, the shifts worth watching and practical ideas to use. Choose a daily briefing, weekly digest or monthly perspective.
Sent at 09:00 Belgrade time: daily, Mondays or the first of the month. Your first edition arrives at the next scheduled send after you confirm.
Your privacy, your choice.
Necessary storage supports site security and remembers your choices. Optional Google Analytics stays off until you allow it. You can read every story with necessary storage only. Privacy details