OpenAI will add invisible textGrain watermarks to eligible ChatGPT and Codex text for users in the European Union across all plans. The rollout will take place over the coming weeks; there is no single announced activation date for every eligible account.
API customers worldwide can already opt in to watermarking for supported models through project or organization text-provenance settings. OpenAI is not making text watermarking a global default at launch.
Watermarking changes how text is generated. It does not attach a visible label to an answer. Detecting an OpenAI watermark provides a limited provenance signal, not proof of who authored a document, who owns it, whether it is accurate, or how much a person contributed.
The EU Rollout Covers All Plans, but Only Eligible Text
In its October 5, 2026 announcement, OpenAI says it will introduce text watermarking for eligible ChatGPT and Codex users across all plans in the EU over the coming weeks.
“Across all plans” means the announcement is not limited to a particular subscription tier. The regional rollout applies across the plan lineup, subject to eligibility.
The word “eligible” is narrower than “all output.” The announcement does not guarantee that every response, text fragment, or piece of generated code will carry a reliably detectable watermark. These limits are especially relevant to Codex, where output may be highly constrained.
The rollout is phased. OpenAI has not specified the exact day each eligible EU account will receive the change. October 5 is the announcement date, not a universal activation deadline.
For users outside the EU, the announcement does not establish the same default. OpenAI says its regional approach gives it room to learn from real-world use and feedback before any broader decision.
The EU product rollout and the optional API control available internationally are separate paths. Treating them as one worldwide switch would misstate who is affected and how the feature becomes active.
API Developers Can Opt In Through Text-Provenance Settings
According to OpenAI’s provenance documentation, API customers worldwide can opt in to watermarked text output for supported models through project or organization text-provenance settings.
Developers should look for that setting. The announcement alone does not establish a specific dashboard click sequence, a request parameter, or a complete supported-model list.
The option became available on the announcement day, October 5. Its worldwide availability is separate from the coming-weeks rollout for EU ChatGPT and Codex users.
For an application developer, the immediate checks are practical:
- Confirm that the model used by the application supports text watermarking.
- Locate the applicable project or organization text-provenance setting.
- Decide whether to opt in and document that choice for the application’s operators.
An organization using several models should not assume that enabling a provenance setting makes every output watermarked. Nor does the existence of a setting make every response equally suitable for detection.
Cloud-provider availability has its own timeline. OpenAI says it is working with cloud partners to make eligible provenance signals available through their services in the coming weeks. Customers accessing OpenAI models through a partner should check that provider’s availability instead of assuming the direct API rollout applies identically.
Watermarking can serve as an additional provenance measure. It should not replace application records showing which model generated an output, what transformations followed, and where a person reviewed or edited it. Those records answer workflow questions that a statistical watermark cannot.
textGrain Changes Token Choices, Not Hidden Characters
OpenAI calls its technology textGrain. The company describes it as embedding an invisible statistical signal by adjusting the model’s word or token choices. It does not insert hidden characters into the output.
A token is a unit of text processed by a model, which may be a word, part of a word, or punctuation. The watermark operates through choices made during text generation, without a separate string of invisible symbols appended to the answer.
“Invisible” can be misleading here. Readers cannot reveal the watermark by changing a font or inspecting a document for an extra character. The signal exists in the statistical pattern of generated text and requires a detector to assess it.
Detection is therefore different from checking an intact digital signature. A document can be edited while retaining some of its original language, or rewritten in ways that substantially alter the pattern the detector looks for. A model may have produced watermarked text even if a later version no longer provides enough evidence for reliable detection. The generation mechanism and detection result need to be evaluated separately.
OpenAI says it plans to release textGrain as open-source technology. This is a future commitment, not confirmation that a public implementation is already available. An eventual technology release would also be distinct from unrestricted access to OpenAI’s detector.
Detector Access Begins With Approved Organizations
Approved researchers and expert organizations can apply for detector access, OpenAI says, with access initially granted case by case. The detector will not be publicly released at launch.
As The Verge’s reporting explains, the tool reports whether it detects an OpenAI watermark without identifying the user or revealing their prompts or conversations. OpenAI cites the risks of missed watermarks and false positives in explaining the initial access restrictions.
textGrain is an OpenAI-specific detection system. It tests for the watermark it is designed to recognize and cannot establish whether some other AI system contributed to the text. It is not a universal test for AI-generated writing.
Ordinary users will also have limited access at first. The rollout does not give every teacher, publisher, employer, or reader a public tool for checking a passage.
Approved detector access may help researchers evaluate the signal. The announcement itself, however, is not independent validation of reliability in every setting. Text length, editing history, and output type can all affect detection conditions.
Future evaluations need to look beyond untouched model output and assess how reliably textGrain distinguishes watermarked text from other text in actual documents, including revisions and mixed human-AI workflows.
Detection Cannot Settle Authorship, Ownership, or Accuracy
OpenAI’s stated limitations should shape how any textGrain result is interpreted. False positives and false negatives remain possible. A detected watermark is evidence to consider, not a conclusive verdict about a document or its author.
Detection is less reliable for short or highly constrained text, code, and text that has been substantially rewritten, paraphrased, or translated. Short passages provide less material for a statistical assessment. Constrained output gives the model less freedom to make the choices that carry the signal.
The code caveat deserves attention because Codex is part of the EU rollout. Availability in a coding product does not establish dependable detection for every code snippet.
Several conclusions remain outside the detector’s scope:
- Authorship: It does not identify the person responsible for a document or establish human authorship.
- Ownership and responsibility: It does not determine copyright ownership or legal responsibility.
- Human contribution: It does not measure how much a person wrote, edited, or contributed.
- Accuracy: It does not verify whether statements in the text are true.
Consider an editor revising an AI-generated draft. A detectable signal would not quantify the editor’s contribution. If substantial rewriting made detection fail, that would not prove the resulting document had no AI involvement. The detector assesses a statistical pattern; it cannot reconstruct the entire writing process.
Watermarked text can contain errors, while text without a detected watermark can be accurate. Provenance and correctness are separate questions.
An absent watermark is particularly easy to overinterpret. It could reflect non-watermarked AI output, a text type that is difficult to detect, substantial editing, or a missed signal. It does not prove human authorship.
Eligible EU output will gain another provenance signal, and API developers worldwide have a new opt-in control. That signal is best used alongside other evidence. Relying on it alone to assign authorship, judge misconduct, or establish ownership would ask the detector to answer questions OpenAI says it cannot answer.
Frequently Asked Questions
4 questions
1When will OpenAI watermark ChatGPT and Codex text in the EU?
OpenAI says eligible ChatGPT and Codex text across all EU plans will receive textGrain watermarks over the weeks following its October 5, 2026 announcement. It has not specified an activation date for each eligible account. Watermarking is not becoming a global default at launch.
2Where can API developers enable textGrain watermarking?
API developers can opt in through project or organization text-provenance settings for supported models. OpenAI made this option available worldwide on October 5, 2026. Developers should confirm model eligibility and check their cloud partner’s availability, if applicable, without assuming identical support.
3Does textGrain insert invisible characters into generated text?
No. OpenAI says textGrain adjusts word or token choices to embed an invisible statistical signal. Detection assesses that pattern. Reliability can decrease for short passages, constrained output, code, and text that has been substantially rewritten, paraphrased, or translated.
4Does a detected watermark prove who wrote the text?
No. A detected textGrain watermark does not identify the user, establish ownership or legal responsibility, measure human contribution, or verify factual accuracy. False positives and false negatives are possible. An absent watermark does not prove human authorship either, so detection should be considered alongside other evidence.
Sources
- October 5, 2026 announcementopenai.com
- provenance documentationhelp.openai.com
- The Verge’s reportingtheverge.com





