OpenAI says API customers worldwide can now opt in to text watermarking for select models. The change makes marked output a production option for developers, but it does not come with a public detector that anyone can use to inspect a piece of text.
The October 5 announcement, reported by The Verge, separates three developments: an available API opt-in, a coming rollout for eligible ChatGPT and Codex users in the European Union, and restricted access to a watermark detector.
Those distinctions matter. Generating watermarked text, receiving watermarked text in a consumer product, and being able to check for a watermark are separate capabilities with different availability rules. Developers making transparency or compliance decisions should not treat them as one global launch.
The API Option Is Available; the EU Rollout Is Phased
The immediate change is for API customers. OpenAI says customers around the world can opt in to watermarked text outputs for select models, giving developers a choice about whether to use the feature in their applications.
The wording limits the scope. This is an optional capability, not a requirement that every API response carry a watermark. It also covers select models, so developers should confirm support for the particular model they use rather than assume availability across the API.
ChatGPT and Codex are on a different schedule. OpenAI says it will introduce watermarking for eligible users across all plans in the EU over the coming weeks. That is a phased regional rollout, not a statement that every eligible user received it on announcement day.
OpenAI explicitly says it is not making watermarking a global default at launch. An API customer outside the EU can therefore choose watermarked output even though the announced ChatGPT and Codex rollout is initially EU-only.
The company also says it is working with cloud partners to make watermarking available for OpenAI model outputs accessed through their services in the coming weeks. That remains a planned extension. Customers using a partner service should check that provider’s availability rather than assume OpenAI’s direct API launch automatically applies to them.
For product teams, the practical distinction is straightforward: direct API opt-in is available now for supported models; the EU product rollout and cloud-partner availability are still being introduced.
Watermarked Output Does Not Include Public Detector Access
OpenAI calls its system textGrain. It places an invisible, machine-readable watermark in generated text, rather than adding a visible label that a reader can inspect.
The detection service has a narrower audience than the generation feature. Approved researchers and expert organizations can apply for access, with OpenAI initially granting it case by case. An application opening is not the same as unrestricted access, and opting in to watermarked API output does not imply that a developer receives the detector.
OpenAI says the tool reports whether it detects an OpenAI watermark without identifying the user or revealing their prompts or conversations. The company attributes its decision not to offer public access at launch to the risks of missed watermarks and false positives.
This creates an operational gap for developers. A team may be able to generate marked output without having a detector available to validate every response or investigate every disputed passage.
For that reason, applications should keep their own generation records where appropriate. A watermark should not become the sole record of whether a system called an OpenAI model, particularly when access to the detection tool is restricted.
Nor should teams promise customers a verification feature before they know whether they qualify for detector access and what that access permits. The generation launch and the detector-access program need separate implementation decisions.
Detection Is Evidence of a Signal, Not Proof of Authorship
OpenAI’s warning that textGrain “does not guarantee reliable detection” places an important boundary around the product. A detection result needs interpretation, not just a yes-or-no display.
A positive result concerns the watermark the tool was designed to detect. It does not establish who wrote, requested, edited, published, or owns the text. OpenAI also says watermarking does not verify accuracy or measure how much a human contributed.
Those distinctions rule out several tempting uses:
- User identification: The detector does not reveal the person behind a response or expose their conversation.
- Authorship judgments: Detecting a watermark does not prove that a particular person authored the document.
- Ownership decisions: A provenance signal does not determine who owns the text.
- Fact-checking: Watermarked output can still contain incorrect information.
- Contribution estimates: Detection does not quantify the balance between human work and AI assistance.
Consider an illustrative workflow in which someone generates a draft, substantially rewrites it, and passes it to an editor. Even if a watermark remains detectable, the result would not describe who contributed which passages or settle responsibility for the final publication.
A negative result has limits too. Because OpenAI acknowledges missed watermarks, failure to detect one cannot establish that text was written entirely by a human. It also cannot rule out generation by a system that did not apply an OpenAI watermark.
The tool’s stated purpose is to detect a particular provenance signal. Turning that into a general verdict on honesty, identity, or ownership would go beyond what OpenAI says it can establish.
Short Passages and Edits Need Separate Validation
Developers should be especially cautious when their application publishes only short excerpts or substantially changes model output after generation.
A shorter passage gives a detector less text to examine. Editing may alter the text carrying the original signal. It would therefore be unsafe to assume that a result obtained on a complete, unmodified response applies equally to a headline, a brief summary, or a rewritten paragraph.
The relevant engineering question is whether detection works on the text the application actually delivers, not merely on the original model response. Teams should seek evidence for their own passage lengths, languages, content types, and editing workflows before making detection promises.
OpenAI’s reliability warning also requires attention to both kinds of error. A missed watermark can leave marked output undetected; a false positive can flag text incorrectly. Neither outcome should automatically trigger an accusation or a consequential decision about a person.
The Verge’s coverage notes that OpenAI also published benchmarks showing similar performance for watermarked and unwatermarked output. That vendor-reported comparison addresses model performance, not whether detection will remain dependable after an application shortens or edits the response.
Sources
- October 5 announcement, reported by The Vergetheverge.com





