OpenAI outlines text watermarking textGrain under EU AI Act

On October 5, 2026, OpenAI published its approach to meeting the EU AI Act requirement that generative text be identifiable in a machine-readable way. The company said it will deploy an invisible watermarking system called textGrain and make a detector available to approved researchers and expert organisations for evaluation.

How textGrain works and measured performance

OpenAI describes textGrain as an invisible statistical signal embedded in a model’s word choices; a detector then looks for that signal to judge whether a passage contains an OpenAI watermark. A technical report will provide more details and OpenAI said it plans to release the technology in open source.

In OpenAI’s evaluations, textGrain matched or exceeded other approaches tested, including SynthID for text. However, the company emphasised that detectors are imperfect and can yield false positives and false negatives.

OpenAI reported detection rates at a target false positive rate of 1%: for 200-token psychology passages the detector found watermarks in about 80% of cases, while for 400-token passages detection rose to about 95%. Detection rates were substantially lower for mathematics, where word choice is more constrained. Editing also reduced detectability: in a set of 400-token passages, replacing 10% of words with synonyms lowered detection from about 92% to 66%, and replacing 25% reduced it to 17%.

Impact on model output and deployment plan

OpenAI said watermarking did not produce meaningful performance differences across the benchmarks it used for Astra, its latest frontier model. Reported scores for unwatermarked and watermarked Astra (max) included:

  • Artificial Analysis Intelligence Index: 49.57 points → 49.76 points
  • AutomationBench: 34.09% → 34.86%
  • DeepSWE v1.1: 72.80% → 71.68%
  • Terminal-Bench 4.0: 53.90% → 56.06%
  • Terminal-Bench Science 0.1: 56.90% → 60.00%
  • BrowseComp: 87.92% → 87.35%
  • HealthBench Professional: 64.27% → 64.60%
  • GPQA Diamond: 94.44% → 93.94%

Operationally, OpenAI said API customers worldwide may opt in to text watermarking for select models beginning the day of the announcement; watermarking will remain off by default in the API. Over the coming weeks the company plans to add an invisible watermark to eligible ChatGPT and Codex text output in the European Union only. Detector access is being opened for approved researchers and expert organisations on a case-by-case basis; the detector will report whether it finds an OpenAI watermark without identifying users, prompts, or conversations.

OpenAI noted that a text watermark conveys a limited signal: it does not measure human contribution, establish ownership or responsibility, identify a user, or verify factual accuracy. The company said the absence of a detected watermark does not prove human authorship. OpenAI also described a layered content-provenance strategy that includes Content Credentials, C2PA conformance, embedded SynthID watermarks for images and audio, and verification tools such as its Content Provenance API and verification service. Approved researchers may apply for detector access starting immediately; more information is available in OpenAI’s help centre materials.


Original source: OpenAI News

Leave a Comment