OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
by Mayank Parmar · BleepingComputerOpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union.
The watermark will not be visible when you read or copy the text. Instead, OpenAI says its new textGrain technology slightly changes the model's word choices to create a statistical pattern that can later be detected.
"Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union," OpenAI explained.
OpenAI is not making this a global default yet.
Starting today, API developers worldwide can opt in to watermarking for supported models, but it remains disabled by default.
The company is also opening applications for its watermark detector, although access will initially be limited to approved researchers and expert organizations.
OpenAI admits its AI watermark can disappear when you edit the text
Text watermarking is far from perfect, and OpenAI's own tests show that fairly normal editing can significantly reduce its ability to detect AI-generated text.
"In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% of words reduced it to 17%," OpenAI noted.
At a 1% false-positive target, OpenAI detected the watermark in about 80% of 200-token psychology responses, compared with roughly 95% when the text reached 400 tokens.
Detection was even worse for subjects such as mathematics, where the model has less freedom to choose different words.
"The absence of a detected watermark does not prove human authorship," OpenAI warned. "Text generated with OpenAI tools may be too short, edited, or translated for detection to work reliably."
OpenAI also says a detected watermark does not reveal who generated the text, their account, prompt, or conversation, and it cannot tell how much of the final work was written or edited by a human.
Interestingly, OpenAI says watermarking does not meaningfully affect the quality of GPT-6 Astra, with benchmark results remaining broadly similar when textGrain is enabled.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.