Invisible watermark: ChatGPT starts marking its text in the EU
AI news9 min read · 7 October 2026
You ask ChatGPT for a paragraph, you paste it into your document, and nothing changes on screen. Yet within a few weeks, that text will carry a mark in the European Union that you will never see. Here is how it works, what it proves, and the four things it does not.
In short: OpenAI published a post titled « Our approach to EU text provenance rules » on October 5, 2026, along with a technical report on textGrain, its statistical watermark for text. In the EU, the mark arrives over the coming weeks on eligible ChatGPT and Codex output, on every plan; elsewhere, only API customers can switch it on, and it is off by default. According to OpenAI’s own evaluations as reported by the tech press, the detector finds the watermark in about 80% of 200-token passages and 95% of 400-token passages, but detection collapses as soon as the text is rewritten or translated. Anthropic, meanwhile, has been marking Claude’s text worldwide since August 2026.
What OpenAI announced on October 5, 2026
TechCrunch and BleepingComputer both date the announcement to October 5, 2026: text produced by ChatGPT and Codex in the European Union will carry an invisible watermark, documented in a technical report on the method, named textGrain.
The rollout is not instant. According to IT-Connect, it lands « over the coming weeks » for eligible users in the EU, on every plan, free tier included. Outside the EU, nothing changes for the consumer apps.
The real asymmetry is on the developer side. API customers anywhere in the world have been able to enable the watermark on select models since October 5, but it is off by default. ActuIA highlights the grey area this creates: a company embedding the API in its own product cannot rely on OpenAI’s marking if it leaves the default untouched. According to Slashdot, OpenAI says textGrain « matched or exceeded » the other approaches it tested, including Google DeepMind’s SynthID for text, and plans to open-source it, with no date given.
How a text watermark works, and why you will never see it
Forget the stamp at the bottom of the page, and forget the rumour about invisible characters or odd em dashes too. A text watermark adds nothing to the page.
The principle is statistical. When a model writes, it does not pick a single certain word: it samples the next word from several plausible candidates. The watermark slips in exactly there. As TechCrunch puts it, it « is not an actual symbol, but works by subtly shaping the model’s word choices ». A secret key always settles between equivalent candidates the same way: invisible across one sentence, the process ends up drawing a pattern across a few hundred words that a detector holding the key can recover.
Because it lives in the words themselves, it survives copy-paste, a font change and a PDF export, without adding tokens or degrading quality — BleepingComputer reports a negligible effect on benchmark scores. But it has a structural weakness: when the model has no real choice of word, there is nowhere to hide anything. That is the case for very factual answers, formulas and code.
What the detection numbers say
OpenAI publishes its own measurements, at a target false-positive rate of 1%: the detector should wrongly accuse a human-written text at most once in a hundred tries.
On humanities-style content, IT-Connect reports around 80% detection at 200 tokens (roughly 150 words) and 95% at 400 tokens. On mathematics, rates are markedly lower: according to XenoSpectrum, there is too little freedom of phrasing to carry a solid signal. Language matters too: across the 24 official EU languages, the same report gives 69.0% for Spanish and 42.2% for Romanian. Detection is therefore distinctly less reliable outside English.
Then comes robustness to rewriting, and that is where it all falls apart. On 400-token passages, BleepingComputer reports detection dropping from about 92% to 66% when 10% of words are swapped for synonyms, and to 17% when a quarter are.
These numbers are not a how-to, and there is no trick to take from them: passing off AI text as your own is still fraud, watermark or no watermark. What they actually say is the opposite — a watermark cannot serve as evidence against you.
Article 50 of the AI Act: why Europe goes first
If the EU goes first, it is because there is a law. Article 50 of Regulation (EU) 2024/1689 requires providers of generative AI systems to mark their outputs in a machine-readable format and detectable as artificially generated or manipulated. It has applied since August 2, 2026.
According to IT-Connect, systems already on the market at that date have until December 2, 2026 to comply, and penalties can reach 15 million euros or 3% of annual turnover. The timing makes sense: the October 5 announcement lands less than two months before that deadline.
Claude already marks its text everywhere: the other half of the picture
Anthropic made the opposite call, and earlier. Its page How Claude’s text watermark works, published on August 14, 2026, describes a watermark based on a version of SynthID-Text, the approach Google DeepMind published in Nature in 2024.
Two major differences. The marking is worldwide, not European: lacking a reliable way to scope it by region, Anthropic applies it everywhere, across every product and the API, with no way to turn it off. And it has been live since August 2026, two months before OpenAI’s announcement: Anthropic had signed the EU Code of Practice in July 2026.
The company is just as explicit about the limits: less effective on short passages, ineffective on code and highly factual answers, unable to distinguish text « written by Claude » from text « heavily edited with Claude », and substantial rewriting can erase it. Word for word, textGrain’s limits.
What the watermark proves — and the four things it does not
What it proves, at best: that a reasonably long, lightly edited passage probably came out of a model that applies this watermark. That is all, and it is already useful against content farms and industrial-scale disinformation.
What it does not prove — and IT-Connect lays out the list:
- It does not measure the human share. A marked text may have been thought through, structured and corrected by you.
- It does not establish ownership. It does not say who asked for it, or who it belongs to.
- It does not verify accuracy. A factual error is still an error, watermarked or not.
- It does not identify the user. Not your account, not your prompt, not your name.
The most important point runs the other way. OpenAI writes, in the line quoted by Mixed News, that « the absence of a detected watermark does not prove human authorship ». That follows: the passage may be too short, edited, translated, or produced by a model that is not covered.
A closed detector: who gets to check, and on what terms
You will not be able to paste your text into a public tool to find out whether it is marked, and neither will your professor. Access to OpenAI’s detector will, according to Mixed News, « initially be limited to approved researchers and expert organizations », granted case by case; ActuIA names teams at Cornell, ETH Zurich and the Slovak institute KInIT among the first.
Same logic at Anthropic: the detection API is in private beta, reserved for organizations eligible under EU law — regulators, law enforcement, media, fact-checkers, researchers, educational institutions and European civil society organizations. That last point is worth your attention. Nothing so far suggests a university has obtained access, but the door is not closed.
What it changes for your assignments, your translations and your code
For a graded assignment. In the short term, almost nothing visible: your school has no « check the watermark » button, and the tools it uses today are classic statistical detectors of debatable reliability. In the medium term, a sturdier verification channel could exist for institutions. The compass stays the same: your school’s rules on AI use, to be read before relying on a tool for graded work, and an honest statement of what you used.
For a translation. If you generate in English and translate into another language, the watermark generally does not survive. That is a technical fact, not a recommendation: it simply makes detection unusable as proof, in either direction.
For your code. Codex output is covered in the EU, but a snippet is often too short and too constrained to carry a usable signal — Anthropic says so outright for Claude. If your school asks you to declare AI use in a project, it is your declaration that counts, not a watermark.
Our take
This watermark is good news for traceability at scale, and bad news for anyone hoping for a clean verdict on a single assignment. Both labs are publishing the very numbers that show the limits of their own technology, and that is to their credit: 17% detection after a quarter of the words are rewritten means no serious board can base a sanction on it.
The division of roles is telling. OpenAI marks where the law requires it; Anthropic marks everywhere because it has no reliable way to do otherwise. In both cases the detector stays closed, so a student can neither verify nor contest. That is the blind spot in the whole setup.
For you, the conclusion does not move an inch: stay the author of what you hand in. Use AI to understand, practise and proofread, and cite it when you have used it. Work whose every idea you can defend out loud never needs to pass a detector.
FAQ
Can my professor tell I used ChatGPT thanks to this watermark?
Not today. OpenAI’s detector is limited to approved researchers and expert organizations, case by case. At Anthropic, the detection API is in private beta, open to eligible bodies including educational institutions, but nothing indicates a given university has access.
Is the watermark already live in Europe?
For ChatGPT and Codex, the rollout was announced on October 5, 2026 « over the coming weeks » for the EU. For Claude, the marking is worldwide and has been live since August 2026.
Does this replace Turnitin, Compilatio or GPTZero?
No, these are two different things. Those tools guess at origin from style; a watermark looks for a signal planted at generation time. It is more reliable when found, but its absence proves nothing, and institutions do not have access to it.
Does the watermark contain my name or my account?
No. According to both OpenAI and Anthropic, it identifies neither the user, nor the account, nor the prompt, and does not indicate which share of the text came from you.
I use the OpenAI API for a project — am I affected?
The watermark is available worldwide for select models through the API, but off by default: enabling it in your organization or project settings is on you. If you publish generated text in Europe, look closely at your own transparency obligations.
Further reading
- /en/blog/detecteurs-ia-fiables
- /en/blog/ia-integrite-academique-universites
- /en/blog/citer-ia-chatgpt-memoire
- /en/skills/citer-sans-plagier
Sources
- Our approach to EU text provenance rules — OpenAI · accessed 7 October 2026
- OpenAI will start watermarking ChatGPT’s text in the EU — TechCrunch · accessed 7 October 2026
- OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU — BleepingComputer · accessed 7 October 2026
- OpenAI va ajouter un filigrane invisible aux textes de ChatGPT et Codex dans l’UE — IT-Connect · accessed 7 October 2026
- OpenAI will watermark ChatGPT in the EU but leaves the API opt-in — ActuIA · accessed 7 October 2026
- OpenAI will watermark ChatGPT text in the EU, and says 25 % synonym swaps cut detection to 17 % — Mixed News · accessed 7 October 2026
- OpenAI to Add Invisible Watermarks to ChatGPT Text in the EU — XenoSpectrum · accessed 7 October 2026
- OpenAI Is Adding Text Watermarking In ChatGPT and Codex — Slashdot · accessed 7 October 2026
- Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems — EU Artificial Intelligence Act · accessed 7 October 2026
- How Claude’s text watermark works — Anthropic · accessed 7 October 2026






