Invisible watermark: ChatGPT starts marking its text in the EU

AI news9 min read · 7 October 2026

The GetPack team

You ask ChatGPT for a paragraph, you paste it into your document, and nothing changes on screen. Yet within a few weeks, that text will carry a mark in the European Union that you will never see. Here is how it works, what it proves, and the four things it does not.

In short: OpenAI published a post titled « Our approach to EU text provenance rules » on October 5, 2026, along with a technical report on textGrain, its statistical watermark for text. In the EU, the mark arrives over the coming weeks on eligible ChatGPT and Codex output, on every plan; elsewhere, only API customers can switch it on, and it is off by default. According to OpenAI’s own evaluations as reported by the tech press, the detector finds the watermark in about 80% of 200-token passages and 95% of 400-token passages, but detection collapses as soon as the text is rewritten or translated. Anthropic, meanwhile, has been marking Claude’s text worldwide since August 2026.

What OpenAI announced on October 5, 2026

TechCrunch and BleepingComputer both date the announcement to October 5, 2026: text produced by ChatGPT and Codex in the European Union will carry an invisible watermark, documented in a technical report on the method, named textGrain.

The rollout is not instant. According to IT-Connect, it lands « over the coming weeks » for eligible users in the EU, on every plan, free tier included. Outside the EU, nothing changes for the consumer apps.

The real asymmetry is on the developer side. API customers anywhere in the world have been able to enable the watermark on select models since October 5, but it is off by default. ActuIA highlights the grey area this creates: a company embedding the API in its own product cannot rely on OpenAI’s marking if it leaves the default untouched. According to Slashdot, OpenAI says textGrain « matched or exceeded » the other approaches it tested, including Google DeepMind’s SynthID for text, and plans to open-source it, with no date given.

How a text watermark works, and why you will never see it

Forget the stamp at the bottom of the page, and forget the rumour about invisible characters or odd em dashes too. A text watermark adds nothing to the page.

The principle is statistical. When a model writes, it does not pick a single certain word: it samples the next word from several plausible candidates. The watermark slips in exactly there. As TechCrunch puts it, it « is not an actual symbol, but works by subtly shaping the model’s word choices ». A secret key always settles between equivalent candidates the same way: invisible across one sentence, the process ends up drawing a pattern across a few hundred words that a detector holding the key can recover.

Because it lives in the words themselves, it survives copy-paste, a font change and a PDF export, without adding tokens or degrading quality — BleepingComputer reports a negligible effect on benchmark scores. But it has a structural weakness: when the model has no real choice of word, there is nowhere to hide anything. That is the case for very factual answers, formulas and code.

What the detection numbers say

OpenAI publishes its own measurements, at a target false-positive rate of 1%: the detector should wrongly accuse a human-written text at most once in a hundred tries.

On humanities-style content, IT-Connect reports around 80% detection at 200 tokens (roughly 150 words) and 95% at 400 tokens. On mathematics, rates are markedly lower: according to XenoSpectrum, there is too little freedom of phrasing to carry a solid signal. Language matters too: across the 24 official EU languages, the same report gives 69.0% for Spanish and 42.2% for Romanian. Detection is therefore distinctly less reliable outside English.

Then comes robustness to rewriting, and that is where it all falls apart. On 400-token passages, BleepingComputer reports detection dropping from about 92% to 66% when 10% of words are swapped for synonyms, and to 17% when a quarter are.

These numbers are not a how-to, and there is no trick to take from them: passing off AI text as your own is still fraud, watermark or no watermark. What they actually say is the opposite — a watermark cannot serve as evidence against you.

Article 50 of the AI Act: why Europe goes first

If the EU goes first, it is because there is a law. Article 50 of Regulation (EU) 2024/1689 requires providers of generative AI systems to mark their outputs in a machine-readable format and detectable as artificially generated or manipulated. It has applied since August 2, 2026.

According to IT-Connect, systems already on the market at that date have until December 2, 2026 to comply, and penalties can reach 15 million euros or 3% of annual turnover. The timing makes sense: the October 5 announcement lands less than two months before that deadline.

Claude already marks its text everywhere: the other half of the picture

Anthropic made the opposite call, and earlier. Its page How Claude’s text watermark works, published on August 14, 2026, describes a watermark based on a version of SynthID-Text, the approach Google DeepMind published in Nature in 2024.

Two major differences. The marking is worldwide, not European: lacking a reliable way to scope it by region, Anthropic applies it everywhere, across every product and the API, with no way to turn it off. And it has been live since August 2026, two months before OpenAI’s announcement: Anthropic had signed the EU Code of Practice in July 2026.

The company is just as explicit about the limits: less effective on short passages, ineffective on code and highly factual answers, unable to distinguish text « written by Claude » from text « heavily edited with Claude », and substantial rewriting can erase it. Word for word, textGrain’s limits.

What the watermark proves — and the four things it does not

What it proves, at best: that a reasonably long, lightly edited passage probably came out of a model that applies this watermark. That is all, and it is already useful against content farms and industrial-scale disinformation.

What it does not prove — and IT-Connect lays out the list:

  1. It does not measure the human share. A marked text may have been thought through, structured and corrected by you.
  2. It does not establish ownership. It does not say who asked for it, or who it belongs to.
  3. It does not verify accuracy. A factual error is still an error, watermarked or not.
  4. It does not identify the user. Not your account, not your prompt, not your name.

The most important point runs the other way. OpenAI writes, in the line quoted by Mixed News, that « the absence of a detected watermark does not prove human authorship ». That follows: the passage may be too short, edited, translated, or produced by a model that is not covered.

A closed detector: who gets to check, and on what terms

You will not be able to paste your text into a public tool to find out whether it is marked, and neither will your professor. Access to OpenAI’s detector will, according to Mixed News, « initially be limited to approved researchers and expert organizations », granted case by case; ActuIA names teams at Cornell, ETH Zurich and the Slovak institute KInIT among the first.

Same logic at Anthropic: the detection API is in private beta, reserved for organizations eligible under EU law — regulators, law enforcement, media, fact-checkers, researchers, educational institutions and European civil society organizations. That last point is worth your attention. Nothing so far suggests a university has obtained access, but the door is not closed.

What it changes for your assignments, your translations and your code

For a graded assignment. In the short term, almost nothing visible: your school has no « check the watermark » button, and the tools it uses today are classic statistical detectors of debatable reliability. In the medium term, a sturdier verification channel could exist for institutions. The compass stays the same: your school’s rules on AI use, to be read before relying on a tool for graded work, and an honest statement of what you used.

For a translation. If you generate in English and translate into another language, the watermark generally does not survive. That is a technical fact, not a recommendation: it simply makes detection unusable as proof, in either direction.

For your code. Codex output is covered in the EU, but a snippet is often too short and too constrained to carry a usable signal — Anthropic says so outright for Claude. If your school asks you to declare AI use in a project, it is your declaration that counts, not a watermark.

Our take

This watermark is good news for traceability at scale, and bad news for anyone hoping for a clean verdict on a single assignment. Both labs are publishing the very numbers that show the limits of their own technology, and that is to their credit: 17% detection after a quarter of the words are rewritten means no serious board can base a sanction on it.

The division of roles is telling. OpenAI marks where the law requires it; Anthropic marks everywhere because it has no reliable way to do otherwise. In both cases the detector stays closed, so a student can neither verify nor contest. That is the blind spot in the whole setup.

For you, the conclusion does not move an inch: stay the author of what you hand in. Use AI to understand, practise and proofread, and cite it when you have used it. Work whose every idea you can defend out loud never needs to pass a detector.

FAQ

Can my professor tell I used ChatGPT thanks to this watermark?

Not today. OpenAI’s detector is limited to approved researchers and expert organizations, case by case. At Anthropic, the detection API is in private beta, open to eligible bodies including educational institutions, but nothing indicates a given university has access.

Is the watermark already live in Europe?

For ChatGPT and Codex, the rollout was announced on October 5, 2026 « over the coming weeks » for the EU. For Claude, the marking is worldwide and has been live since August 2026.

Does this replace Turnitin, Compilatio or GPTZero?

No, these are two different things. Those tools guess at origin from style; a watermark looks for a signal planted at generation time. It is more reliable when found, but its absence proves nothing, and institutions do not have access to it.

Does the watermark contain my name or my account?

No. According to both OpenAI and Anthropic, it identifies neither the user, nor the account, nor the prompt, and does not indicate which share of the text came from you.

I use the OpenAI API for a project — am I affected?

The watermark is available worldwide for select models through the API, but off by default: enabling it in your organization or project settings is on you. If you publish generated text in Europe, look closely at your own transparency obligations.

Further reading

Sources

  1. Our approach to EU text provenance rules — OpenAI · accessed 7 October 2026
  2. OpenAI will start watermarking ChatGPT’s text in the EU — TechCrunch · accessed 7 October 2026
  3. OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU — BleepingComputer · accessed 7 October 2026
  4. OpenAI va ajouter un filigrane invisible aux textes de ChatGPT et Codex dans l’UE — IT-Connect · accessed 7 October 2026
  5. OpenAI will watermark ChatGPT in the EU but leaves the API opt-in — ActuIA · accessed 7 October 2026
  6. OpenAI will watermark ChatGPT text in the EU, and says 25 % synonym swaps cut detection to 17 % — Mixed News · accessed 7 October 2026
  7. OpenAI to Add Invisible Watermarks to ChatGPT Text in the EU — XenoSpectrum · accessed 7 October 2026
  8. OpenAI Is Adding Text Watermarking In ChatGPT and Codex — Slashdot · accessed 7 October 2026
  9. Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems — EU Artificial Intelligence Act · accessed 7 October 2026
  10. How Claude’s text watermark works — Anthropic · accessed 7 October 2026

Read the next article

Explainer4 October 2026

Gemini 4 Argon: why you can’t use it (yet)

AI news1 October 2026

OpenAI dots: always-on agents, but not in Europe

Tutorial30 September 2026

How to disable or remove a Claude skill, connector or plugin

Code30 September 2026

Claude Code plugins: install, manage and build your own

Tools30 September 2026

Skills vs MCP connectors vs plugins: the difference explained

Tools28 September 2026

The new Microsoft Copilot: Home, Code and Autopilot explained

Explainer27 September 2026

AI agents: OpenAI bots probed public and university sites

Code27 September 2026

Learning to code in the age of AI: what you still need to know how to do yourself

Code27 September 2026

The one-page spec to write before you prompt an AI to code

Thesis27 September 2026

How to cite ChatGPT or Claude in a thesis: APA, MLA, ISO 690

Code27 September 2026

Claude Code for beginners: install, first launch, CLAUDE.md

AI news27 September 2026

Claude Opus 5.5: what really changes (and how to use it to study)

Analysis27 September 2026

The AI race: why some people are scared and others aren't

Code27 September 2026

Building your first MCP server, step by step

Code27 September 2026

Deploying your first site for free: Vercel, Netlify, Cloudflare Pages, or GitHub Pages

Explainer27 September 2026

AI detectors: are Turnitin, GPTZero and Compilatio reliable?

Code27 September 2026

Writing your own Claude skill: structure, SKILL.md, and a description that triggers

Career27 September 2026

France's national student-entrepreneur status (SNEE) and the PEPITE network, explained

Analysis27 September 2026

France in the AI race: Mistral, energy and talent

AI news27 September 2026

French Tech and AI: the French startups to know in 2026

Code27 September 2026

Git without fear: commit, branch, remote explained, then the commands that save you

Explainer27 September 2026

Chinese AI: DeepSeek, Qwen, Kimi… why Europe is wary

Health27 September 2026

AI in medical school: study for PASS, LAS and the EDN safely

Tools27 September 2026

Free AI for students: every offer and discount (2026)

Career27 September 2026

AI on an internship or apprenticeship: what’s allowed, what isn’t

Code27 September 2026

From IDE to ADE: coding with AI agents in 2026

Code27 September 2026

Reading an error without panicking: the anatomy of a stack trace (Python and JavaScript)

Tools27 September 2026

Best AI for students in 2026: the honest comparison

Tools27 September 2026

New AI models in 2026: which one should you study with?

Tools27 September 2026

French AI tools you’ve never heard of: Noota, Moshi, Vibe…

Analysis27 September 2026

Why AI is so expensive (and American AI even more so)

Code27 September 2026

How to prompt an AI coding tool well: the method that changes everything

Code27 September 2026

Securing a vibe-coded app: 7 mistakes to fix before you publish

Code27 September 2026

Slopsquatting: when AI recommends packages that don't exist

Weekly brief27 September 2026

AI news roundup: the week of September 21–27, 2026

Code27 September 2026

Vibe coding: what it actually means (and how not to mess it up)

AI news27 September 2026

Why Yann LeCun wants AMI: AI beyond LLMs

Tutorial26 September 2026

Connect an MCP connector to Claude without writing a line of code

Degrees26 September 2026

Choosing your program with real MonMaster and InserSup data

Method26 September 2026

APA 7, ISO 690, Vancouver: how to cite your sources properly

Explainer26 September 2026

ChatGPT's 'hidden codes' on TikTok: fact vs. fiction

Health26 September 2026

Medicine: revise for the EDN with France's public drug database

Career26 September 2026

Internship pay and apprentice wages in 2026: the rules

Explainer26 September 2026

AI and academic integrity: what universities actually say

Tutorial26 September 2026

Installing a skill in Claude in 2 minutes

Thesis26 September 2026

Thesis: building your research question and outline with AI

Method26 September 2026

Building your exam study schedule with AI, the right way

Method26 September 2026

Revising with AI, honestly: active recall, Feynman, quizzes

Career26 September 2026

Choosing your apprenticeship with real employment data

Join GetPack

Already have an account? Sign in