Evidence at a glance
The Obligation Is Clear; the Technology Is Not Prescribed
On October 5, 2026, OpenAI announced its approach to EU text provenance rules. Customers can opt in to watermarking for select API models, while eligible text from ChatGPT and Codex in the EU is planned to receive watermarks over the coming weeks. Access to the detector will initially be limited to approved researchers and expert organizations. This is a phased deployment, not a single switch applied to every product and region.
The timing has a legal context. Article 50(2) of the EU AI Act applies from August 2, 2026, requiring providers of generative AI systems to mark generated text in a machine-readable way and make it detectable. The law does not prescribe watermarking as the only method, and it includes scope limits and exceptions. Some systems placed on the market before that date have a limited grace period until December 2. Watermarking is therefore OpenAI’s chosen compliance path, not the only route specified by the EU; the announcement’s post-deadline timing does not mean the rules have yet to take effect.
textGrain Encodes Its Signal in Word-Choice Statistics
textGrain does not insert hidden characters or unusual punctuation. Instead, it influences word choices during generation so that the output carries an invisible statistical pattern. The technical report describes grouping vocabulary according to a key and context, then using an entropy budget to constrain changes to sampling randomness. The detector checks whether a passage shows a statistical dependency associated with that key. The watermark is not a label attached to a sentence; it is a probabilistic trace left by the generation process.
That design depends on the text retaining enough of its original signal for detection to work. Sampling changes are constrained so that the model does not freely distort its wording just to create a watermark. But shorter text, limited room for alternative wording, and later edits can all weaken the statistical trace. OpenAI says it will add detail to the technical report and plans to open-source the technology. Those are future plans, not evidence that detection is already a public, universal service.
Detection Rates Depend on the Text, Not a Single Fixed Score
In tests targeting a 1% false-positive rate, detection for psychology-related text rose from about 80% for 200-token passages to about 95% for 400-token passages. Detection was substantially lower for mathematics, where there is less flexibility in word choice. Performance is therefore not simply a property of the model or detector: passage length and subject matter matter too. Holding the target false-positive rate constant does not make results equally reliable across different texts.
Editing weakens the signal further. In tests on 400-token passages, detection was about 92% before editing. Replacing 10% of the words with synonyms reduced it to about 66%, while replacing 25% reduced it to about 17%. OpenAI’s help center also says it tested all 24 official EU languages. At a 1% target false-positive rate, reported detection was highest for Spanish at 69.0% and lowest for Romanian at 42.2%. These are results under specific evaluation conditions, not a promise of everyday performance for text in any language, length, or translated and revised form.
Phased Access Is a Way to Manage Uncertainty
API customers worldwide can choose to enable watermarking for select models, and it is off by default. Eligible ChatGPT and Codex text in the EU is planned to receive watermarks in stages, while access to the detector requires an application and approval. Each arrangement serves a different purpose: API customers can incorporate watermarking into their own disclosure processes, product deployment responds to the EU regulatory context, and restricted detector access gives researchers room to evaluate false positives, false negatives, and responsible use. OpenAI says detector results will not reveal a user’s identity, prompts, or conversation content, but that does not remove uncertainty from the detection result itself.
For technical leaders, the key mistake would be to treat “detectable” as “decidable.” A positive result can indicate a signal associated with a generation process, but it does not establish who wrote the text, who is responsible for it, or whether it is accurate. Conversely, failure to detect a watermark does not prove human authorship: editing can weaken the signal, and detectors can miss it. OpenAI’s image and audio verification tools will remain publicly accessible, while the different access rules for text detection reflect a more cautious view of its reliability.
Use Watermarks in a Provenance Chain, Not as a Verdict
For teams integrating generative models, the practical question is not whether to trust a detector outright, but whether watermarking adds a useful signal to an existing provenance and disclosure process. Because API watermarking is off by default, teams need to decide whether to enable it, how to explain it to users, and what happens when text is edited, translated, or combined with other material. Their evaluations should cover their own content types and editing workflows, rather than relying only on results from long, unmodified English passages. The reported tests show that these conditions can substantially change detection rates.
A more defensible approach is to combine machine-readable watermarks with provenance records, platform review, and human checks, while being explicit about what each can establish. A watermark can help assess whether text carries a statistical signal associated with a particular model, but it cannot by itself establish authorship, trace responsibility, or verify facts. The available evidence does not support workflows that punish an author, reject content, or declare a violation solely on the basis of one detector result. Treat the detector as a limited provenance tool, not a stamp of authenticity.