OpenAI has outlined its approach to text provenance in response to the European Union AI Act, introducing a phased rollout of text watermarking technology that acknowledges the current limitations of detection systems.

What Happened

Starting immediately, API customers globally can opt in to text watermarking for select models, though the feature will remain off by default in the API. Over the coming weeks, OpenAI plans to add an invisible watermark to eligible ChatGPT and Codex text outputs specifically for users in the European Union. The company is also opening applications for access to its text watermark detector, initially limiting access to approved researchers and expert organizations to help evaluate the technology. Existing verification tools for images and audio, such as the openai.com/verify web tool and the Content Provenance API, will remain publicly accessible.

The underlying technology, named textGrain, adds an invisible statistical signal to model word choices. According to OpenAI’s technical report, the detector looks for this signal to assess whether a passage contains an OpenAI watermark. The company states that textGrain matched or exceeded the performance of other approaches tested, including SynthID for text, in their evaluations. However, OpenAI emphasizes that strong performance under ideal conditions does not guarantee reliable detection in everyday use.

Why It Matters

The rollout highlights the technical challenges inherent in text watermarking compared to image or audio provenance. OpenAI’s evaluations illustrate that detection rates vary significantly based on text length and content type. For example, at a target false positive rate of 1%, the detector identified watermarks in about 80% of 200-token passages compared with about 95% of 400-token passages. Detection was substantially lower for content like mathematics, where word choice flexibility is limited.

Editing also poses a significant hurdle. In evaluations of 400-token passages, replacing 10% of words with synonyms reduced detection rates from about 92% to 66%, while replacing 25% of words reduced detection to 17%. These limitations inform OpenAI’s decision to restrict initial detector access to researchers rather than making it publicly available. The company notes that a watermark does not measure human contribution, establish ownership, identify the user, or verify accuracy. Furthermore, the absence of a detected watermark does not prove human authorship, as text may be too short, edited, or generated by unsupported models.

OpenAI plans to make the textGrain technology available in open source to allow others to build upon it. The company reports no meaningful performance differences in its latest frontier model, Astra, when comparing outputs with and without watermarking across benchmarks. This regional approach for EU users allows OpenAI to gather real-world feedback before potentially expanding the strategy globally.

The Bottom Line

OpenAI is implementing a limited, phased text watermarking strategy to comply with EU regulations while managing the technical risks of false positives and missed detections. By keeping API watermarking opt-in and restricting detector access to experts, the company aims to refine the technology before broader adoption.