OpenAI joins Anthropic in text watermarking but limits ChatGPT rollout to EU

The company will add invisible signals to eligible ChatGPT and Codex responses, while restricting detector access to approved researchers and expert organizations

Green digital shield illustration accompanying ETIH coverage of OpenAI’s text watermarking rollout and the limits of AI content detection.

OpenAI will introduce text watermarking for eligible ChatGPT and Codex output in the EU, with detector access initially restricted.

OpenAI will introduce invisible text watermarks to eligible ChatGPT and Codex responses across all plans in the European Union, as it responds to EU AI Act requirements for identifying AI-generated content.

The rollout will take place over the coming weeks. API customers worldwide can also opt in to watermarking for selected models, although the feature will remain switched off by default in the API.

OpenAI joins Claude developer Anthropic in adopting text watermarking, but the companies have taken different approaches to geography. Anthropic applies watermarking globally to supported Claude models, explaining that it does not yet have a reliable way to restrict the feature by region. Its rollout does not mean every older Claude model already supports watermarking.

For ChatGPT and Codex, OpenAI has not announced a default rollout in the UK or elsewhere outside the EU. That position could change, but the company has given no timetable for expanding it.

“We are not making text watermarking a global default at launch,” OpenAI says. “This regional approach gives us room to learn from real-world use and feedback.”

The tool used to detect those watermarks will not be publicly available at launch. Access will initially be limited to approved researchers and expert organizations, rather than offered as an unrestricted service for checking written work.

A signal in word choices

OpenAI’s technology, called textGrain, embeds a statistical signal in the model’s word choices. A detector then looks for that pattern to assess whether a passage contains an OpenAI watermark.

The company says its evaluations show textGrain matching or exceeding other approaches it tested, including SynthID for text. However, its results also show how much detection depends on the length, subject and subsequent editing of a passage.

At a target false positive rate of 1%, the detector identified watermarks in about 80% of 200-token passages on topics such as psychology. That rose to about 95% for 400-token passages. Tokens are the units of text processed by a model.

Detection was substantially lower for mathematics, where there is less flexibility in word choice.

Editing also weakened the signal. In a separate evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% of words brought it down to 17%.

These are company evaluation results, and OpenAI cautions that performance under ideal conditions does not guarantee reliable detection in everyday use. Across the benchmarks it uses to assess its Astra model, the company says it found no meaningful performance differences between watermarked and unwatermarked output.

Watermarks do not establish authorship

A detected watermark can indicate that an OpenAI system generated or processed part of a passage. It cannot establish how much of the work came from a person.

“A watermark does not measure human contribution,” OpenAI states. “It can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it.”

The signal also does not identify the user, account, prompt or conversation behind the text. Nor does it establish ownership, responsibility or whether the content is accurate.

An undetected watermark is equally limited as evidence. OpenAI-generated text may be too short, edited or translated for detection to work reliably. It may also have come from an unsupported model or been produced before watermarking was introduced. Text from another company’s tools would not necessarily carry an OpenAI watermark.

OpenAI cites the risks of both false positives and missed watermarks as reasons for restricting access to its detector. Its existing image and audio verification tools will remain publicly accessible.

Applications for text detector access are now open to researchers and expert organizations, with approval assessed case by case. OpenAI also plans to make its watermarking technology open source and is working with cloud partners to support watermarked model output through their services in the coming weeks.

Previous
Previous

Google backs 890 MW nuclear expansion as Gemini Enterprise moves into Constellation plants

Next
Next

AI for Math Fund expands to $35.1m as new grants back open tools, theorem proving and AI-generated proofs