2026-10-11 17:14 UTC

OpenAI has published how it will watermark ChatGPT text to comply with EU provenance rules; whether other labs and platforms adopt comparable watermarking — or EU institutions or users reject or route around the approach — resolves whether it becomes the reference compliance posture for AI text provenance.

state: corroboratedheat: lowuncertainty: mediumconvergesscott: hightext-watermarking ai-provenance eu-regulation ai-governanceOpenAI
Surfaced 2026-10-06T18:59:45Z — Per the echoes: 'Our approach to EU text provenance rules' — OpenAI explains how it will watermark ChatGPT text to comply with EU provenance — The case's pivot fact moved: The Verge reports OpenAI is actually adding text watermarking to ChatGPT and Codex — converting the compliance-cosplay reading (published posture, text mark held unshipped since 2024) into posture becoming executable control, and extending the mark into the developer surfaces Scott's agent pipelines touch. Meanwhile the announcement wave is fully decayed (~4.3 pts/h off an ~85 peak; the only new engagement is a dupe-flagged 1-point echo) and the community is actively rejecting the quality-cost claim (ratios 0.33–0.36, both threads score 0), so heat stays low despite valve eligibility — the spread is three platforms echoing one announcement with a non-expanding periphery, not expanding coverage.

What is this?

OpenAI published its compliance posture for EU AI Act Article 50 (transparency rules effective Aug 2, 2026) on October 5, 2026, detailing a text watermarking system called textGrain. The approach: an invisible watermark rolls out automatically to EU ChatGPT and Codex users 'over the coming weeks' (inside the Dec 2, 2026 compliance window), while global API customers can opt in now (off by default). Detection is gated to approved researchers/expert organizations only; open-sourcing is planned. OpenAI's own evaluation concedes fragility — 25% synonym replacement drops detection from 92% to 17% — and an independent interactive attack lab reproduces this collapse. Anthropic already marks Claude text globally (since Aug 2); Google marks Gemini via SynthID; xAI abstained from the EU Transparency Code. The web search returned only generic OpenAI landing pages, not the specific announcement; the grounding above comes from the case's first-party and independent evidence.

Why it matters to Scott

OpenAI's published EU watermarking posture — fragile detection (25% synonym rewrite drops it to 17%), detector gated to approved researchers, no authority chain, EU-only automatic rollout — is a first-party dated receipt for Scott's guardrail-illusion and compliance-cosplay diagnosis: the EU's Article 50 reference control creates the appearance of provenance without a decision-time authority boundary. This independently arrives at the exact failure mode the Governance Stack and Proof-Carrying Receipts frameworks predict, and arms LeverageAI's signed-decision-receipts pitch with a live, major-lab example.
ip:concept.guardrail-illusionip:concept.compliance-cosplayip:concept.proof-carrying-receiptsip:framework.the-governance-stackip:framework.decision-authority-infrastructureip:framework.agent-provenance-stackip:framework.ai-readiness-staircaseip:concept.provenanceip:concept.decision-attestation-packageip:source.compliance-cosplayip:source.decision-attestation-packagesip:source.ai-readiness-staircaseip:concept.authority-gapip:concept.zero-trust-for-decisionsip:concept.runtime-governanceip:concept.regulatory-complianceip:source.governance-as-codeip:source.ai-that-survives-audit-ebookip:source.witness-not-oracle-ebookip:source.agent-provenance-stackradar:concept.ai-governanceradar:concept.ai-regulationradar:concept.provenanceradar:concept.agent-provenanceradar:concept.ai-transparencyradar:eu-chatgpt-vlose-designationradar:california-ai-transparency-law-enforcementradar:synthid-detector-portalradar:agentgate-signed-agent-receiptsradar:proofrun-local-agent-verification-receipts
queries asked of Scott's wikis
  • proof-carrying-receipts guardrail-illusion compliance-cosplay
  • AI Readiness Staircase governance stack provenance
  • open-weights sovereignty model-regulation safety-asymmetry
  • signed-decision-receipts LeverageAI audit-trail
  • local-inference-economics watermark-bypass enforceability
  • EU AI Act Article 50 transparency obligations implementation

Measured heat

now 0 pts/hpeak 112 pts/hcomments 0/hpeers p16momentum: steady4 platformsage 145h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

10-05 17:52 (minted)⭐ origin echo-reconstructedPer the echoes: 'Our approach to EU text provenance rules' — OpenAI explains how it will watermark ChatGPT text to comply with EU provenance
OpenAI on blog (echo) · attributed from reddit.post.1wyci57, hn.story.49966293 · published time unknown
—
10-05 15:00first on openai · published · lag ?Our approach to EU text provenance rules
OpenAI
—
10-05 15:38first on hacker news · published · lag ?Our approach to EU text provenance rules
tosh
—
10-05 16:06first on r/OpenAI · published · lag ?OpenAI explains how it will watermark ChatGPT text to comply with EU provenance rules
rhiever
—
10-06 00:58first on r/LocalLLaMA · published · lag ?Doesn’t OpenAI’s watermarking affect the quality of the models?
ResearchCrafty1804
—
10-07 23:01first on r/ClaudeAI · published · lag ?OpenAI is not watermarking text output outside the EU. Will Anthropic follow suit?
vb100
—
10-10 08:28first on r/artificial · published · lag ?OpenAI's text watermark can't prove you didn't write something. I built a lab where you can watch it die.
masiha97
—
10-05 15:38amplified on hacker newshn.story.49966293
tosh
peak 70 · 60 comments · 22% of case engagement
10-05 16:06amplified on r/OpenAI 👑reddit.post.1wyci57
rhiever
peak 437 · 137 comments · 55% of case engagement
10-06 00:58amplified on r/LocalLLaMAreddit.post.1wypgkq
ResearchCrafty1804
peak 0 · 23 comments · 2% of case engagement
10-06 01:02amplified on r/OpenAIreddit.post.1wypk87
ResearchCrafty1804
peak 0 · 12 comments · 1% of case engagement
10-06 11:06amplified on hacker newshn.story.49976795
pseudolus
peak 2 · 1 comments · 1% of case engagement
10-06 16:13amplified on hacker newshn.story.49980602
thm
peak 2 · 1 comments · 1% of case engagement
5 more amplifiers in ainews.case_chain
10-05 17:20our radar first saw it · lag ?discovery anchor: reddit.post.1wyci57—
10-06 18:42reached heat=high · lag ? · via ledger——
pace: p91 vs 1247 stories at the 96h mark (now 145h old) — ahead of openai-lockheed-f35-engineering (1.0x), behind ai-graphene-simulator-claim (1.0x)

Evidence (13) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditOpenAI explains how it will watermark ChatGPT text to comply with EU provenance rules
OpenAI
rhiever436137
🟧 hnOur approach to EU text provenance rulestosh7060
🟧 echo.blog ⭐Per the echoes: 'Our approach to EU text provenance rules' — OpenAI explains how it will watermark ChatGPT text to comply with EU provenanceOpenAI——
🟠 redditDoesn’t OpenAI’s watermarking affect the quality of the models?
LocalLLaMA
ResearchCrafty1804023
🟠 redditDoesn’t OpenAI’s watermarking affect the quality of their models?
OpenAI
ResearchCrafty1804010
🟧 hnOpenAI rolls out weak sauce watermarking for AI textpseudolus21
🟧 hnOpenAI is adding text watermarking in ChatGPT and Codexthm21
🟧 openaiOur approach to EU text provenance rules
Retrieved article excerpt

Open article · Retrieved 2026-10-07T06:21:43.692124+00:00

October 5, 2026

[Safety](https://openai.com/news/safety-alignment/)

# Our approach to EU text provenance rules

Promoting transparency within the limits of today’s technology.

Loading…

Share

[Content provenance](https://openai.com/index/advancing-content-provenance/) helps people understand where content came from, how it was created or edited, and whether it contains signals associated with our models. We’ve already made tools publicly available to identify images and audio generated by our models. Today, we’re sharing our approach to text watermarking in response to the EU AI Act, and how it fits into our broader work.

The EU AI Act requires generative AI providers to make generated text identifiable in a machine-readable way. Text watermarking and detection remain early technologies with significant limitations, and views about their benefits and responsible uses are still developing. Our phased approach reflects both the EU AI Act requirements as well as the technology’s limitations, with an emphasis on transparency about what a text watermark can and cannot tell people:

- Starting today, API customers globally will be able to opt in to text watermarking for select models. Text watermarking will remain off by default in the API.
- Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union.
- We’re opening applications to access our text watermark detector. Access will initially be limited to approved researchers and expert organizations that can help us evaluate and improve the technology.

  - The above only applies to text provenance—our verification tools for audio and images, including our [openai.com/verify⁠](https://openai.com/verify) web tool and our [Content Provenance API⁠(opens in a new window)](https://developers.openai.com/api/docs/guides/content-provenance), will continue to be publicly accessible to organizations looking to understand whether an image or audio file was generated by one of our systems.

## How our watermarking works and performs

Our text watermarking technology, textGrain, adds an invisible statistical signal to the model’s word choices. Our detector looks for that signal to assess whether a passage contains an OpenAI watermark. More details about how textGrain works can be found in our [technical report⁠(opens in a new window)](https://cdn.openai.com/pdf/e9508624-d767-41b6-a26d-e34ca798ada6/textgrain-entropy-calibrated-watermarking-for-language-model-text.pdf), which will be updated with additional details in the coming weeks. We also plan to make the technology available in open source so that others can build on it.

In our evaluations, textGrain matched or exceeded the performance of other approaches we tested, including SynthID for text. Even so, strong performance under ideal conditions does not guarantee reliable detection in everyday use.

Detectors can make two kinds of errors: they can report a watermark where none is present—a false positive—or miss a watermark that is present—a false negative. Our evaluations below illustrate some of the challenges:

- **Shorter or more constrained text is harder to detect.** At a target false positive rate of 1%, our detector identified watermarks in about 80% of 200-token passages, compared with about 95% of 400-token passages, for content such as psychology. Detection rates were substantially lower for content such as mathematics, where there is less flexibility in word choice.
- **Editing can weaken the watermark.** In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% of words reduced it to 17%.

These limitations contribute to our decision to provide initial detector access only to approved researchers and expert organizations, who can help us evaluate reliability and responsible uses.

This chart shows results for watermarked responses to mathematics and psychology questions from the [ELI5 dataset⁠(opens in a new window)](https://huggingface.co/datasets/rexarski/eli5_category) at a target false positive rate of 1%. Detection improves with text length, but is substantially lower overall for content where there is less flexibility in word choice, such as mathematics.

Editing can substantially weaken the watermark signal. This chart shows how replacing 10% or 25% of the words in a passage affects detection. Results are based on watermarked English responses to questions from [ELI5⁠(opens in a new window)](https://aclanthology.org/P19-1346/).

### Impact of watermarking on output quality

Across the benchmarks we use to assess Astra, our latest frontier model, we do not see meaningful performance differences with and without watermarking.

| **Benchmark** | **Unwatermarked text (Astra, max)** | **Watermarked text (Astra, max)** |
| --- | --- | --- |
| Artificial Analysis Intelligence Index | 49.57 points | 49.76 points |
| AutomationBench | 34.09% | 34.86% |
| DeepSWE v1.1 | 72.80% | 71.68% |
| Terminal-Bench 4.0 | 53.90% | 56.06% |
| Terminal-Bench Science 0.1 | 56.90% | 60.00% |
| BrowseComp | 87.92% | 87.35% |
| HealthBench Professional | 64.27% | 64.60% |
| GPQA Diamond | 94.44% | 93.94% |

## What a text watermark doesn’t tell you

Text watermarks provide a limited signal about the role our systems played in a passage. It’s important to understand what can and cannot be concluded from a detection result.

- **A watermark does not measure human contribution.** It can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it.
- **A watermark does not establish ownership or responsibility.** It does not determine who owns the text, whether its use was lawful, whether disclosure was required, or who is responsible for it.
- **A watermark does not identify the user.** It does not associate a person, organization, account, prompt, or conversation with the text.
- **A watermark does not verify accuracy.** It does not tell you whether a passage is true, misleading, harmful, or presented in the right context.
- **The absence of a detected watermark does not prove human authorship.** Text generated with OpenAI tools may be too short, edited, or translated for detection to work reliably. It may also come from an unsupported model, predate watermarking, or have been generated by another company’s tools.

## Our next steps

- **Rolling out text watermarking in the EU.** Over the coming weeks, we will introduce text watermarking to eligible ChatGPT and Codex users across all plans in the EU only. We are not making text watermarking a global default at launch. This regional approach gives us room to learn from real-world use and feedback.
- **Enabling opt-in watermarking for API customers.** Starting today, API customers around the world will be able to opt in to watermarked text outputs for select models. This lets customers decide how watermarking fits their transparency obligations and the experiences they provide to users. We are also working with cloud partners to make watermarking available for OpenAI model outputs accessed through their services in the coming weeks.
- **Providing detector access to researchers and expert organizations.** Approved researchers and expert organizations can [apply](https://openai.com/form/content-provenance-api/) starting today. In accordance with the [Code of Practice⁠(opens in a new window)](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content), access will be initially granted on a case-by-case basis to support evaluation and improvement of text provenance. The tool will report whether it detects an OpenAI watermark, without identifying the user or revealing their prompts or conversations. Given the risk of missed watermarks and false positives, we are not making it publicly available at launch.

We expect to revisit each part of this approach as the technology, standards, and evidence evolve.

## Our broader approach to content provenance

No single provenance technique is enough on its own, so we take a layered approach that combines open standards, durable watermarking, and verification tools.

We add Content Credentials to supported image outputs, are [C2PA conformant⁠(opens in a new window)](https://c2pa.org/conformance/), embed invisible [SynthID⁠(opens in a new window)](https://deepmind.google/models/synthid/) watermarks in supported images and audio, and make image and audio verification available through [openai.com/verify⁠](https://openai.com/verify) and our [Content Provenance API⁠(opens in a new window)](https://developers.openai.com/api/docs/guides/content-provenance). These techniques complement one another: Content Credentials can record a file’s origin and history, while invisible watermarks can preserve a signal when metadata is removed.

As we described in our [election safeguards work](https://openai.com/index/election-safeguards-2026/), provenance can help people and platforms assess potentially misleading AI-generated content, including deepfakes. We pair these signals with policies, abuse detection, reporting, investigations, and enforcement, and work with researchers, standards bodies, platforms, and civil society to make provenance useful across the wider ecosystem.

Extending provenance to text requires accounting for how easily it can be rewritten, translated, or edited. As we discussed in [June](https://openai.com/index/supporting-eu-trustworthy-ai-ecosystem/), our approach must reflect the practical limits of current technology. We’ll continue improving detection, studying how watermarks withstand editing and translation, and exploring ways to distinguish AI assistance from AI authorship more meaningfully. We’ll adapt our approach as evidence, standards, and regulatory requirements evolve, and expand detector access when we believe results can be interpreted responsibly.  
  
For more information, please visit our [help center article⁠(opens in a new window)](https://help.openai.com/articles/8912793-provenance-signals-content-credentials-synthid-in-openai-generated-content).

## Keep reading

[View all](https://openai.com/news/)

Safety cases for frontier AI training > Card image

[Towards safety cases for frontier AI training

SafetySep 28, 2026](https://openai.com/index/towards-safety-cases-for-frontier-ai-training/)

How we will do better for Australia — Cover

[How we will do better for Australia

CompanySep 28, 2026](https://openai.com/index/how-we-will-do-better-for-australia/)

Sam Altman’s remarks at the United Nations Security Council cover image

[Sam Altman’s remarks at the United Nations Security Council

Global AffairsSep 23, 2026](https://openai.com/index/sam-altman-un-security-council-remarks/)
OpenAI——
🟠 redditOpenAI is not watermarking text output outside the EU. Will Anthropic follow suit?
ClaudeAI
vb1004558
🟠 redditOpenAI is not watermarking text output outside the EU. Will Anthropic follow suit?
OpenAI
vb1001718
🟧 hnOpenAI will start watermarking ChatGPT's text in the EUulrischa61
🟠 redditOpenAI's text watermark can't prove you didn't write something. I built a lab where you can watch it die.
artificial
masiha971112
🟧 hnOpenAI's New ChatGPT Watermark Breaks If You Edit One Word in Fourojosilva51

Interpretation history

Decision trace