
OpenAI shipped textGrain on October 5, 2026 — an invisible statistical watermark baked into every word its models select. For developers on the API, it’s available right now as an opt-in toggle at no extra cost. For EU ChatGPT and Codex users, it becomes mandatory in the coming weeks under the EU AI Act. One catch worth knowing up front: replace 25% of the words in an output with synonyms, and the detection rate collapses from 92% to 17%. OpenAI just deployed the world’s most widely used AI text watermark — and published exactly how to defeat it.
How textGrain Works
The watermark doesn’t add anything visible. No hidden characters, no metadata you can strip out. It lives in how the model chooses words. OpenAI describes it this way: “using a secret key to sort next-word predictions to finish the sentence. Add hundreds of these nudges together, and the detector can spot AI-generated content.”
The technical version: textGrain solves an optimal transport problem that biases token sampling using Kullback-Leibler regularization. An entropy budget limits how much randomness the model gives up in exchange for the signal. The result is text that reads and behaves normally but carries a statistical fingerprint a trained detector can identify. OpenAI’s tests show no meaningful quality degradation — humans in blind evaluations couldn’t tell watermarked from unwatermarked output.
Detection performance at a 1% false positive rate: 80% on 200-token passages (roughly 150 words), 95% on 400-token passages (roughly 300 words). Performance drops significantly on code, math, structured formats, and short passages where word choice is tightly constrained.
Who Is Affected Right Now
As of October 5, the rollout breaks down as follows:
- API developers globally: Opt-in toggle, off by default, no cost changes. Enable it per request via a configuration flag on compatible models.
- EU ChatGPT and Codex users: Mandatory watermarking rolling out across all plans in the coming weeks.
- Detector access: Not available to developers yet. Restricted to approved researchers and expert organizations, granted case-by-case per the EU’s Code of Practice on AI transparency.
The regulatory driver is EU AI Act Article 50, which took effect August 2, 2026. It requires AI providers to mark AI-generated content in a machine-readable way. OpenAI is complying — notably with the most permissive rollout of the three major providers.
The Part That Should Bother You
The detection numbers under stress are the real story. Replacing 10% of words with synonyms drops detection from 92% to 66%. Replace 25% — easily done by running output through a paraphrasing tool — and detection falls to 17%. Separate research on similar watermarking schemes found that a single automated paraphrase pass removes over 98% of the watermark signal entirely.
This isn’t a flaw specific to OpenAI. It’s a fundamental constraint: the watermark lives in the exact token sequence. Change the tokens enough and the signal degrades. The EU regulation demands watermarking; OpenAI delivers it; and the watermark breaks with the kind of light editing any content farm runs on autopilot.
OpenAI is upfront about the limits: “Watermarks can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it.” Missing watermarks don’t prove human authorship. The tool is a provenance signal, not proof.
OpenAI Is Last — And Most Permissive
Google has had SynthID watermarking in Gemini since 2024 — mandatory, no opt-out, and you can run the detector yourself. Anthropic made Claude’s text watermark mandatory for all users, including API calls, in August 2026. OpenAI’s textGrain is the last major LLM provider to ship this, and it chose the softest rollout: optional for API developers globally, mandatory only for EU consumer products.
That’s a developer-friendly call. Most teams building on the OpenAI API outside the EU won’t see this unless they go looking for it.
What Developers Should Do
If you’re building EU-facing products, enable it. Imperfect watermarking still satisfies a compliance requirement, and the opt-in requires minimal effort. Don’t architect anything around watermark detection as a security control — it isn’t one. Treat it as an audit trail: a way to document that OpenAI systems touched this content, for regulatory or governance purposes.
When detector access eventually opens to developers — OpenAI hasn’t committed to a timeline, but it will — you’ll want logs. Record the model version and watermark setting per output now. That data will matter when verification becomes possible.
textGrain is real infrastructure with real limits. The EU mandate created a floor, not a ceiling. The ceiling is what the technology can actually deliver right now: 95% detection on unedited 300-word outputs. That’s useful for platform-level content moderation. It’s less useful for anything that passes through human hands. All three major providers are shipping watermarks under the same constraints — OpenAI just gave developers the most room to decide for themselves.













