On October 5, 2026, OpenAI announced worldwide API opt-in text watermarking for selected models, with the setting off by default. Eligible ChatGPT and Codex text in the EU will gain watermarks over the following weeks, across plans—not as a worldwide default. API builders and EU-facing product teams now have a new provenance decision to make. OpenAI’s announcement.
Text detector access initially goes to approved researchers and expert organizations. The application form focuses on research into provenance, detection reliability and interpretation. A business can therefore choose to mark its output without being able to verify incoming text.
Decide what you need the watermark to do
The practical distinction is between marking your own output, checking someone else’s text, and explaining AI use to readers. Treat these as separate product decisions:
Your goal | Recommended next step | Do not assume |
|---|---|---|
Mark an API product’s output | Start with a scoped project and record the enabled models and change date. | The setting grants detector access. |
Prepare an EU ChatGPT or Codex team | Update support explanations and confirm coverage before promising it to users. | Every answer or code snippet will be detectable. |
Review submitted text | Retain source and revision evidence; keep unavailable checks distinct from negative results. | A missing signal establishes human authorship. |
Study watermark reliability | Apply with a defined research question and evaluation plan. | Submitting the form guarantees approval or a deadline. |
How API teams can opt in
The documented controls are Organization settings → Data controls → Text provenance for defaults, or Project Settings → Text provenance for overrides. Enable Allow text watermarking, choose eligible models and save. The available-model list is in those settings; no account was inspected for this guide.
Recommendation: choose a pilot whose users benefit from provenance information. Record which output paths use the selected models, including fallbacks. Keep the original generated version and subsequent edits where your retention policy permits; that record answers different questions from a detector result.
OpenAI describes the speed impact as negligible and reports no meaningful quality change in its evaluations. Those are vendor findings, not workload-specific guarantees. Cloud-partner coverage varies. The reviewed help documentation does not establish a watermark-specific generation surcharge.
Marking does not unlock public text verification
The public Content Provenance API guide documents image and audio checks, with text requiring separate approval. It is not a universal AI detector. No public text request schema, approval timetable or text-detector price was established in the reviewed documentation.
For a product that reviews submissions, represent an unavailable detector as “not checked,” not “no watermark.” This is a recommended workflow distinction, not an OpenAI API response field. Do not make a launch depend on access your organization has not received.
Teams handling several media types can use the related RohitAI guide to OpenAI audio watermarking and verification for background without assuming its access arrangements extend to text.
A statistical signal, not an authorship certificate
The textGrain technical report describes a keyed pattern created by adjusting token sampling—the model’s selection of words and word pieces. An entropy budget controls how much sampling randomness is traded for a detectable signal. Detection checks the text against the key and matching configuration; it is not a search for a visible stamp.
OpenAI’s Help Center says the method adds neither hidden characters nor watermark-only tokens. Short, code-like or tightly constrained factual outputs are harder to detect; rewriting and translation can weaken the signal. A result cannot establish authorship, ownership, user identity, legality, accuracy or the amount of human contribution.
For publishers, the operational implication is to preserve editorial responsibility separately from provenance checks. Use a detected signal to inform review, not as an automatic finding that a contributor misrepresented their work.
Why a 1% false-positive rate is not 99% confidence
In OpenAI’s reported evaluations, psychology-like passages reached roughly 80% detection at 200 tokens and 95% at 400 tokens, with a target false-positive rate of 1%. Mathematics performed worse. A separate 400-token English editing experiment fell from about 92% detection to 66% after 10% synonym replacement, and to 17% after 25%. These experiments have different baselines; they are not one general accuracy score.
Illustrative calculation—not a deployment measurement: suppose 10,000 passages are checked, only 1% carry the target watermark, and every check is valid. Assume the reported 80% sensitivity and 1% false-positive rate transfer to this hypothetical population:
100 marked passages × 80% sensitivity = 80 expected true positives.
9,900 unmarked passages × 1% false-positive rate = 99 expected false positives.
80 ÷ (80 + 99) ≈ 44.7% of positive results would be true positives.
The assumed prevalence and transfer of evaluation performance are unverified. “Unmarked” here includes both human text and output from other AI systems. The calculation explains why the frequency of the target watermark matters; it does not estimate OpenAI’s real-world precision.
If your organization gains access, evaluate representative languages, lengths and ordinary editing workflows separately before attaching consequences to a result. Neither this calculation nor the vendor’s examples replace that evaluation.
Keep EU disclosure decisions separate
The European Commission says Article 50 transparency obligations apply from August 2, 2026. Participation in the accompanying Code of Practice is voluntary; the underlying legal obligations are not.
Article 50(2) addresses provider-side machine-readable marking and detectability, qualified by technical feasibility and exceptions, including standard editing or no substantial alteration of supplied content. Article 50(4) separately addresses disclosure for AI-generated or manipulated text published to inform the public on matters of public interest. It includes an exception where human review or editorial control occurs and a person or legal entity holds editorial responsibility.
An invisible watermark therefore does not settle a publisher’s disclosure decision. Identify the applicable role and use case, document editorial responsibility, and assess any notice requirement separately. This guide describes the published rules; it does not determine a particular organization’s compliance.
For builders, the immediate choice is whether marking belongs in a supported generation workflow. For publishers and platforms, keep verification access and evidence handling as separate workstreams. Neither decision should be represented to users as proof of who wrote a passage.
Methodology: AI-assisted reporting and analysis of published sources, with official OpenAI and European Commission material rechecked on October 5, 2026. No model, detector, account-setting or integration tests were conducted. Reported evaluation figures are OpenAI’s; the probability example is hypothetical.
