Our approach to EU text provenance rules
Promoting transparency within the limits of today’s technology.
Content provenance helps people understand where content came from, how it was created or edited, and whether it contains signals associated with our models. We’ve already made tools publicly available to identify images and audio generated by our models. Today, we’re sharing our approach to text watermarking in response to the EU AI Act, and how it fits into our broader work.
The EU AI Act requires generative AI providers to make generated text identifiable in a machine-readable way. Text watermarking and detection remain early technologies with significant limitations, and views about their benefits and responsible uses are still developing. Our phased approach reflects both the EU AI Act requirements as well as the technology’s limitations, with an emphasis on transparency about what a text watermark can and cannot tell people:
Starting today, API customers globally will be able to opt in to text watermarking for select models. Text watermarking will remain off by default in the API.
Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union.
We’re opening applications to access our text watermark detector. Access will initially be limited to approved researchers and expert organizations that can help us evaluate and improve the technology.
The above only applies to text provenance—our verification tools for audio and images, including our openai.com/verify web tool and our Content Provenance API(opens in a new window), will continue to be publicly accessible to organizations looking to understand whether an image or audio file was generated by one of our systems.
Our text watermarking technology, textGrain, adds an invisible statistical signal to the model’s word choices. Our detector looks for that signal to assess whether a passage contains an OpenAI watermark. More details about how textGrain works can be found in our technical report(opens in a new window), which will be updated with additional details in the coming weeks. We also plan to make the technology available in open source so that others can build on it.
In our evaluations, textGrain matched or exceeded the performance of other approaches we tested, including SynthID for text. Even so, strong performance under ideal conditions does not guarantee reliable detection in everyday use.
Detectors can make two kinds of errors: they can report a watermark where none is present—a false positive—or miss a watermark that is present—a false negative. Our evaluations below illustrate some of the challenges:
Shorter or more constrained text is harder to detect. At a target false positive rate of 1%, our detector identified watermarks in about 80% of 200-token passages, compared with about 95% of 400-token passages, for content such as psychology. Detection rates were substantially lower for content such as mathematics, where there is less flexibility in word choice.
Editing can weaken the watermark. In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% of words reduced it to 17%.
These limitations contribute to our decision to provide initial detector access only to approved researchers and expert organizations, who can help us evaluate reliability and responsible uses.
This chart shows results for watermarked responses to mathematics and psychology questions from the ELI5 dataset(opens in a new window) at a target false positive rate of 1%. Detection improves with text length, but is substantially lower overall for content where there is less flexibility in word choice, such as mathematics.
Editing can substantially weaken the watermark signal. This chart shows how replacing 10% or 25% of the words in a passage affects detection. Results are based on watermarked English responses to questions from ELI5(opens in a new window).
Across the benchmarks we use to assess Astra, our latest frontier model, we do not see meaningful performance differences with and without watermarking.
Benchmark | Unwatermarked text (Astra, max) | Watermarked text (Astra, max) |
|---|---|---|
Artificial Analysis Intelligence Index | 49.57 points | 49.76 points |
AutomationBench | 34.09% | 34.86% |
DeepSWE v1.1 | 72.80% | 71.68% |
Terminal-Bench 4.0 | 53.90% | 56.06% |
Terminal-Bench Science 0.1 | 56.90% | 60.00% |
BrowseComp | 87.92% | 87.35% |
HealthBench Professional | 64.27% | 64.60% |
GPQA Diamond | 94.44% | 93.94% |
Text watermarks provide a limited signal about the role our systems played in a passage. It’s important to understand what can and cannot be concluded from a detection result.
A watermark does not measure human contribution. It can indicate that an OpenAI system generated or processed part of a passage, but not how much human judgment, editing, or creativity went into it.
A watermark does not establish ownership or responsibility. It does not determine who owns the text, whether its use was lawful, whether disclosure was required, or who is responsible for it.
A watermark does not identify the user. It does not associate a person, organization, account, prompt, or conversation with the text.
A watermark does not verify accuracy. It does not tell you whether a passage is true, misleading, harmful, or presented in the right context.
The absence of a detected watermark does not prove human authorship. Text generated with OpenAI tools may be too short, edited, or translated for detection to work reliably. It may also come from an unsupported model, predate watermarking, or have been generated by another company’s tools.
Rolling out text watermarking in the EU. Over the coming weeks, we will introduce text watermarking to eligible ChatGPT and Codex users across all plans in the EU only. We are not making text watermarking a global default at launch. This regional approach gives us room to learn from real-world use and feedback.
Enabling opt-in watermarking for API customers. Starting today, API customers around the world will be able to opt in to watermarked text outputs for select models. This lets customers decide how watermarking fits their transparency obligations and the experiences they provide to users. We are also working with cloud partners to make watermarking available for OpenAI model outputs accessed through their services in the coming weeks.
Providing detector access to researchers and expert organizations. Approved researchers and expert organizations can apply starting today. In accordance with the Code of Practice(opens in a new window), access will be initially granted on a case-by-case basis to support evaluation and improvement of text provenance. The tool will report whether it detects an OpenAI watermark, without identifying the user or revealing their prompts or conversations. Given the risk of missed watermarks and false positives, we are not making it publicly available at launch.
We expect to revisit each part of this approach as the technology, standards, and evidence evolve.
No single provenance technique is enough on its own, so we take a layered approach that combines open standards, durable watermarking, and verification tools.
We add Content Credentials to supported image outputs, are C2PA conformant(opens in a new window), embed invisible SynthID(opens in a new window) watermarks in supported images and audio, and make image and audio verification available through openai.com/verify and our Content Provenance API(opens in a new window). These techniques complement one another: Content Credentials can record a file’s origin and history, while invisible watermarks can preserve a signal when metadata is removed.
As we described in our election safeguards work, provenance can help people and platforms assess potentially misleading AI-generated content, including deepfakes. We pair these signals with policies, abuse detection, reporting, investigations, and enforcement, and work with researchers, standards bodies, platforms, and civil society to make provenance useful across the wider ecosystem.
Extending provenance to text requires accounting for how easily it can be rewritten, translated, or edited. As we discussed in June, our approach must reflect the practical limits of current technology. We’ll continue improving detection, studying how watermarks withstand editing and translation, and exploring ways to distinguish AI assistance from AI authorship more meaningfully. We’ll adapt our approach as evidence, standards, and regulatory requirements evolve, and expand detector access when we believe results can be interpreted responsibly.
For more information, please visit our help center article(opens in a new window).


