OpenAI Begins Text Watermarking Ahead of EU Rollout
OpenAI opened optional text watermarking to API customers globally on 5 October and said eligible ChatGPT and Codex output in the European Union would receive invisible marks over the following weeks. Its textGrain technology embeds a statistical signal in generated text, while initial detector access is restricted to approved researchers and expert organisations. The company presented the phased release as its response to European text-provenance requirements. It is not a global default for every OpenAI product, and the API option remains off by default. For customers and publishers, the practical change is a potential new signal of machine involvement, rather than a reliable certificate of authorship, accuracy or ownership.
The accompanying technical report explains a trade-off between preserving variation in generated language and making a detectable signal. A secret key influences how the system samples text, with a budget limiting the amount of randomness removed. The method groups vocabulary into blocks to reduce computation while retaining relative probabilities inside those groups. Detection uses the text and key without needing the generation budget. The commercial relevance of that design is that provenance must coexist with useful output: a marking system that makes answers repetitive or degrades specialised writing could impose a product cost even when it improves detectability under laboratory conditions.
OpenAI’s published examples underline the reliability limits. At a target false-positive rate of 1%, detection reached roughly 80% for 200-token passages and 95% for 400-token passages in a relatively flexible subject area; constrained mathematical text performed worse. The company also reported that editing substantially reduced detection. Those numbers are conditional evaluation results rather than universal probabilities for arbitrary documents. A publisher reviewing a long explanatory passage and a teacher reviewing a short mathematical answer should not assume they face the same evidence quality. The content, length, model support and changes made after generation all affect how much weight any positive or negative result can reasonably carry.
As OpenAI puts it, “A watermark does not verify accuracy.” The distinction has practical consequences beyond wording. A marked passage might have been substantially revised by a person, while an unmarked passage might still have originated from an unsupported system or undergone changes that weakened the signal. Detection therefore cannot settle responsibility for a publication or determine whether a particular use of AI complied with an organisation’s rules. That is an interpretation of the technology’s limited purpose, not legal advice. The safest operational role is as one source of evidence within a review process whose decision criteria remain explicit and whose users understand the possibility of error.
Restricted detector access leaves a gap between creating a provenance signal and allowing the general public to inspect it. OpenAI says the initial expert access is intended to improve evaluation and responsible use, and plans to make the technology available in open source. Broader availability could make checking easier, but it would also increase the number of consequential decisions made by people unfamiliar with statistical evidence. There is a product-design challenge here independent of the watermark algorithm: a system must communicate uncertainty without inviting a binary reading of a probabilistic result. Its usefulness will depend on how the detector is presented and incorporated into existing editorial or institutional procedures.
Analysis
Provenance can support continued market access and reduce uncertainty for customers, but it is unlikely to become a universal enforcement mechanism. At a 1% false-positive rate, testing 10,000 genuinely unmarked passages under matching conditions would produce about 100 false flags in expectation; that is arithmetic, not a field-performance forecast. Organisations therefore need review and appeal processes wherever a flag has consequences. OpenAI’s limited detector rollout recognises that implementation carries costs beyond embedding the mark. The strategic benefit will come from credible, appropriately bounded evidence of origin, rather than promising an authoritative test of human authorship.