Live
Abstract illustration of flowing lines of small grains, a band of them subtly aligned into a hidden pattern, with a clean break where the pattern stops
AI & ML

OpenAI Will Watermark ChatGPT Text in the EU. Why Britain Isn’t Getting It

Ask ChatGPT in Paris for a 300-word essay and OpenAI’s own detector should spot its new hidden watermark about 95% of the time. Swap one word in four for a synonym and, in OpenAI’s editing test, detection falls to 17%. Both numbers come from OpenAI itself, which said on Oct. 5 that it will start hiding an invisible statistical signal in ChatGPT and Codex text across the European Union.

OpenAI's header image for its announcement on EU text provenance rules
OpenAI announced its textGrain watermark for EU ChatGPT and Codex text on Oct. 5, 2026. Image: OpenAI

The same essay written in Manchester gets no watermark at all. Britain left the EU, so the EU AI Act, the law forcing OpenAI’s hand, does not apply to text generated for UK users. And the UK government has, so far, chosen not to write an equivalent rule of its own.

Here is how the system works, where it breaks, and what it does and does not change for people in Britain.

What OpenAI announced on Oct. 5

“Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union,” OpenAI wrote in a post titled Our approach to EU text provenance rules. TechCrunch reported the rollout covers eligible users on all plans.

Outside the EU, the feature is voluntary. “Starting today, API customers around the world will be able to opt in to watermarked text outputs for select models,” OpenAI said. It is off by default. That means a British company building on OpenAI’s API can switch it on; an ordinary ChatGPT user in Leeds cannot.

The detector is not public. OpenAI says approved researchers and expert organisations can apply for access, granted “on a case-by-case basis”. The company also says it plans to release the technology as open source, and that across benchmarks for Astra, its latest frontier model, it does not see “meaningful performance differences” with watermarking switched on. The system is called textGrain and is described in a 20-page technical report co-written with researchers from the University of Pennsylvania and Yale, according to ActuIA.

How ChatGPT text watermarking works

A language model writes by repeatedly choosing the next word, or fragment of a word, from a list of likely candidates. Normally a dose of randomness decides which one wins.

textGrain replaces that randomness with pseudo-random values computed from a secret key, ActuIA reports. Each choice is still plausible, so the text reads normally. But across hundreds of words, the choices lean in a pattern that anyone holding the key can test for. OpenAI describes it as “an invisible statistical signal” in the model’s word choices. No hidden characters, no odd spacing, nothing you could delete with a find-and-replace.

The idea is not new. Google DeepMind uses a similar approach, SynthID Text, in Gemini and open-sourced it in October 2024, after a test on around 20 million chatbot responses found users had no preference between watermarked and unwatermarked replies, MIT Technology Review reported.

OpenAI has been here before. In August 2024, after the Wall Street Journal revealed that it had built a text watermark and not released it, the company said in a blog update that its method was “trivial to circumvention by bad actors” using translation or rewording by another model, and that it could “stigmatize use of AI as a useful writing tool for non-native English speakers,” TechCrunch reported. What changed is the law.

The limits: short answers, maths and a thesaurus

OpenAI is unusually blunt about what textGrain cannot do. “At a target false positive rate of 1%, our detector identified watermarks in about 80% of 200-token passages, compared with about 95% of 400-token passages,” its post says. A token is roughly three-quarters of an English word, so 400 tokens is about 300 words.

Bar chart of OpenAI's textGrain detection rates: 95% for 400-token passages, 80% for 200-token passages; 92% with no edits, 66% after 10% of words are swapped for synonyms, 17% after 25%.
OpenAI’s watermark is easy to find in long, untouched text and fades quickly with light editing. Source: OpenAI. Graphic: prompt/power

Light editing hurts. Replacing 10% of words with synonyms cut detection from about 92% to 66%, and replacing 25% cut it to 17%, BleepingComputer reported from OpenAI’s figures. “Detection rates were substantially lower for content such as mathematics, where there is less flexibility in word choice,” OpenAI says. Other languages fare worse than English too: ActuIA, citing the technical report, puts detection at 69.0% for Spanish and 42.2% for Romanian.

“The absence of a detected watermark does not prove human authorship.” OpenAI, Oct. 5, 2026

Then there is that 1% false positive target. It sounds small. Applied to a thousand genuinely human essays, it would be expected to wrongly flag around ten, which is why OpenAI is keeping the detector away from the general public for now. It also says a detected watermark reveals nothing about the user, account or conversation, and “can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it.”

Why Britain isn’t getting the ChatGPT watermark

The trigger is Article 50 of the EU AI Act, which requires generative AI providers to mark synthetic text, images, audio and video in a machine-readable way. Its transparency rules took effect on Aug. 2, 2026. Under the EU’s AI Omnibus amendments, which entered into force on July 27, systems already on the market before Aug. 2 have until Dec. 2, 2026 to comply with the marking duty, law firm White & Case notes. ChatGPT is one of those systems.

OpenAI could have applied the watermark everywhere. It chose not to. “We are not making text watermarking a global default at launch. This regional approach gives us room to learn from real-world use and feedback,” the company wrote.

Britain has no rule that would force the question. “There is currently no UK legislation specifically requiring AI-generated content to be labelled,” the House of Commons Library said in a January 2026 briefing. In a written statement on March 18, Liz Kendall, the Secretary of State for Science, Innovation and Technology, said: “It can be helpful to consumers to understand whether content has been made using AI. It may also help protect against disinformation and harmful deepfakes.” Her department’s answer was a taskforce, not a law.

Kanishka Narayan, the AI and online safety minister, repeated the commitment in a written answer on May 22: a labelling taskforce with an interim report due in autumn. As of Oct. 6, we could find no sign it has been published. Kendall has also said she is thinking “in terms of specific areas where we may need to act rather than a big all-encompassing bill,” according to a House of Lords Library briefing on the King’s Speech.

What it means for UK students, teachers and workers

Students and teachers: nothing changes yet. ChatGPT text produced in Britain is not being watermarked, and even EU text can only be checked by approved researchers. No school or university can run OpenAI’s detector. Commercial “AI detectors” have no way to check for textGrain without OpenAI’s secret key.

Workers and businesses: if your organisation builds on OpenAI’s API, watermarking is now a setting you can choose to switch on. Firms that sell into the EU may want to, because their own customers there will face Article 50 questions.

Everyone: treat a missing watermark as meaningless, exactly as OpenAI says. The judgement calls that matter still rest on reading closely and checking sources, the same habits we recommend for spotting AI-generated images.

Two years ago, OpenAI called this kind of watermark trivial to beat. On Oct. 5 it shipped one anyway, to 27 countries, and published the figure that proves its old point: swap a quarter of the words, and about 83% of marked passages walk past the detector.

// AI Editor
Cassandra Lee

Cassandra Lee covers AI and machine learning for prompt/power: the labs, the model releases, the research and the safety fights that come with them. She reads model cards the way other people read horoscopes: skeptically, and mostly for what's left unsaid.

Latest from prompt/power

  1. Thomson Reuters Won the First AI Training Appeal. Footnote 7 Is the CatchOct 7
  2. The Family Safe Word: How to Beat AI Voice-Clone Emergency ScamsOct 7
  3. Reflection AI’s Beam, Explained: The 501B Open-Weight Model Aimed at ChinaOct 7
  4. Your SSN or SIN Leaked in a Breach? Do These 8 ThingsOct 7
  5. Apple’s Oct. 13 Event Rumour, Plus iPhone Duo Pre-Order Dates for CanadaOct 7

Leave a Reply

Your email address will not be published. Required fields are marked *