On October 5, 2026, OpenAI said it will add an invisible statistical watermark, called textGrain, to eligible ChatGPT and Codex text in the European Union over the coming weeks, according to MediaNama's report. API customers worldwide can opt in for select models, but the feature stays off by default. The announcement is useful less for what it solves than for what it reveals: a candid look at how far machine-readable text marking can actually go.
The case for the mandate
The strongest argument for the rule is straightforward. Article 50(2) of the AI Act requires providers of systems that generate synthetic audio, image, video or text to ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Synthetic text can be produced at near-zero marginal cost, and without some provenance signal, platforms, newsrooms and schools have little to work with. A legal duty also levels the field: it stops a responsible provider from being undercut by one that ships no marking at all. The Commission says these transparency obligations apply from 2 August 2026, and OpenAI's move is a visible sign that the largest providers intend to comply rather than litigate.
What textGrain does
Per MediaNama's account, textGrain shifts the statistical pattern of the words a model selects, without visible marks or hidden characters. A detector then tests whether a passage carries that pattern. OpenAI says the detector will only report whether it finds an OpenAI watermark. It will not identify the user or expose prompts or conversations. That design choice matters for privacy and for speech: a detector that cannot link text to a person is far less likely to become a surveillance tool.
The limits OpenAI itself disclosed
OpenAI published its own weaknesses, which deserves credit. At a 1% target false-positive rate, the detector found the watermark in about 80% of 200-token psychology passages and about 95% of 400-token passages. Detection was lower for mathematics, where word choice is more constrained. Editing hurts more: replacing 10% of words with synonyms cut detection from about 92% to 66%, and replacing 25% reduced it to roughly 17%, per the same report.
Those numbers define what a text watermark is. It is a reasonable signal for unedited, longer output. It is a weak one for short messages, code-like or formulaic text, and anything a person lightly rewrites. It is also trivially bypassed by a determined actor, and it says nothing about text from models whose providers do not watermark, including open-weight models run locally. A missing watermark therefore cannot mean 'human-written,' and OpenAI is explicit that the detector will not confirm human authorship.
Why this matters for policy design
The risk is not the watermark; it is how institutions might use it. If a university, employer or platform treats a failed detection as evidence of human authorship, or a positive hit as proof of misconduct, the error costs fall on students, writers and non-native English speakers whose text is heavily edited or constrained. The detection rates above show why that would be unsafe. A 1% false-positive rate sounds small until it is applied to millions of documents.
The Commission's approach appears to recognise this. Its Code of Practice on marking and labelling, published on June 10, 2026, is voluntary and, as summarised by Jones Day, accepts that no single marking technique can fully meet the Act's requirements. It points providers toward at least two layers of machine-readable marking where necessary, such as metadata, watermarks or other technical measures. The legal text itself already hedges: solutions must be effective, interoperable, robust and reliable only as far as technically feasible. That is the right standard. Demanding perfect robustness would be both impossible and an invitation to over-engineered, privacy-invasive tracking.
Where proportionality should hold
Three principles follow, consistent with a pro-innovation, evidence-based approach.
- Judge effort, not outcomes. Regulators should assess whether a provider deployed credible, layered marking and published its error rates, not whether every edited passage still tests positive. OpenAI's disclosure of false-positive targets and degradation under editing should be the norm for the sector, and would be a useful benchmark for signatories.
- Keep detection narrow. Restricting the detector initially to approved researchers and expert organisations limits misuse, but it also limits independent verification. A staged expansion with audit access and clear rules against using results as sole evidence of wrongdoing would balance both concerns.
- Do not extend the burden to small developers and open-source projects. A watermark only works if the party controlling the model applies it. Pushing equivalent duties onto small developers or open-weight releases would raise costs while achieving little, since anyone can run an unwatermarked model.
The Commission's own guidance also draws a sensible line on the deployer side: the labelling duty covers AI-generated or AI-manipulated text published on matters of public interest, not every email, draft or private note. That narrowness protects ordinary expression, and it should be preserved as enforcement guidance develops.
What to watch
Two questions will determine whether this works. First, whether market surveillance authorities accept single-layer statistical watermarking for text, or push providers toward additional measures that may carry more privacy cost. Second, whether other providers publish comparable detection and false-positive data, so that regulators and users can compare claims rather than take them on trust. If transparency about limits becomes the industry standard, the AI Act's marking duty can deliver modest, honest provenance signals. If marks are oversold as authenticity guarantees, they will mislead more than they inform.
OpenAI's announcement is best read as a calibration point. A watermark that works well on longer, unedited output and degrades under paraphrase is a useful but partial tool. Policy should treat it that way.