The European Union's transparency regime for artificial intelligence has been in force since August 2, 2026, when Article 50 of the bloc's AI Act began to apply to providers of systems that generate synthetic audio, image, video or text. Under those rules, set out in Regulation (EU) 2024/1689, such providers must ensure that outputs are marked in a machine readable format and are detectable as artificially generated or manipulated. Deployers carry a separate duty: they must disclose AI generated text published to inform the public on matters of public interest, although content that undergoes human review or editorial control is exempt.
The European Commission stated on July 24, 2026, that a limited grace period is envisaged only for AI systems placed on the market before August 2, 2026, and only as regards the marking and detection obligation for AI generated content under Article 50(2), with providers of those systems required to comply from December 2, 2026. The Commission had adopted guidelines on these obligations on July 20, 2026, and the Code of Practice on Transparency of AI generated content had gathered about 190 signatories by the end of July 2026, including Anthropic, Google, Meta, Microsoft and OpenAI. That roster suggests the largest model developers decided to shape the compliance regime rather than fight it.
Against that backdrop, OpenAI made its first concrete move on October 5, 2026. In a company blog post the firm said it would begin adding an invisible watermark to text generated by ChatGPT and Codex inside the European Union, with the change rolling out over the coming weeks to eligible users on all plans. The same day, OpenAI opened an opt-in watermarking setting for API customers anywhere in the world, covering select models. The setting is off by default, and OpenAI said it is not making text watermarking a global default at launch.
The method behind the rollout is called textGrain. It is not a visible symbol or a hidden character: it works by subtly shaping the model's word choices so that a statistical pattern is embedded in the words themselves. Readers cannot see the pattern, but a detector holding a secret key can pick it up. Because the signal lives in the words, it travels with copied and pasted text, and OpenAI says it does not identify the user. A technical report describing the approach was co-written with researchers from the University of Pennsylvania and Yale.
TechCrunch reported on October 5, 2026, that the watermark would reach eligible ChatGPT and Codex users on all plans but only in the EU, while developers using the OpenAI API worldwide can switch it on for select models starting that day. OpenAI is also working with cloud partners to offer watermarking for model outputs accessed through their services, an arrangement that matters because a large share of enterprise traffic never touches OpenAI's own interface.
Unite.AI reported on October 5, 2026, that applications for the text watermark detector opened the same day, initially limited to approved researchers and expert organizations under the EU Code of Practice on transparency of AI generated content. Detector access is a bottleneck by design. Without a detector, a watermark is only a promise, and OpenAI has chosen to hand the measuring tool to a vetted group rather than publish it openly at launch.
The published numbers show why the company is cautious. At a target false positive rate of 1 percent, the detector identified watermarks in about 80 percent of 200 token passages and about 95 percent of 400 token passages for content such as psychology, with substantially lower rates for mathematics, where word choice is less flexible. Editing erodes the signal further. In a 400 token evaluation, replacing 10 percent of words with synonyms reduced detection from about 92 percent to 66 percent, and replacing 25 percent brought it down to 17 percent, using answers from the ELI5 dataset.
AI Affairs reported on October 5, 2026, that the announcement concerns text only, and that OpenAI's existing verification tools for images and audio, including the openai.com/verify web tool and the Content Provenance API, remain publicly accessible. On model quality, OpenAI reported no meaningful differences across benchmarks for its newest frontier model, Astra: an Artificial Analysis Intelligence Index of 49.57 unwatermarked against 49.76 watermarked, and 94.44 percent versus 93.94 percent on GPQA Diamond.
OpenAI also set out what the watermark cannot do. It cannot measure human contribution, establish ownership, identify the user, or verify accuracy, and the company cautioned that a missing watermark does not prove human authorship. OpenAI said it plans to release the technology as open source.
The headline number is not the 95 percent detection rate on long passages; it is the 17 percent that remains after a quarter of the words are swapped for synonyms. Any student, editor or marketing team with a thesaurus can move a passage from probably machine written to no signal found in a few minutes, and that is before translation, which OpenAI itself lists among the hard cases. A marking obligation that can be defeated by ordinary copy editing satisfies the letter of Article 50 while leaving the practical detection gap wide open. What this really means is that text watermarking as shipped in October 2026 is a compliance instrument first and a forensic tool second.
That is not a reason to dismiss it. Watermarking shifts the default: a detector hit is meaningful evidence, and OpenAI's decision to publish a technical report and to promise open source code invites outside scrutiny of the false positive rate rather than asking the public to trust a black box. The 1 percent false positive target is stated plainly, and the company's admission that short passages, math answers and translated text are harder to detect is more useful than a vague claim of robustness.
The bigger picture here is that the EU has effectively exported a technical standard. OpenAI applied the watermark in the EU only, but it opened opt-in access to API customers worldwide on the same day, which gives developers in every jurisdiction a switch that exists because of a European regulation. Anthropic said two months earlier that it would watermark Claude text worldwide, so the two largest rivals are converging on the same architecture: an invisible statistical signal, a gated detector, and language that carefully avoids promising provenance.
Enforcement will decide whether any of this hardens. National competent market surveillance authorities carry most of the burden, while the AI Office has a limited role, being competent mainly for AI systems built on general purpose AI models where the same entity provides the system and the model, or where the system is integrated into a very large online search engine or platform designated under the Digital Services Act. Fines can reach 15 million euros or 3 percent of total worldwide turnover for the preceding financial year, with proportionality possible for SMEs and small mid cap companies. A 15 million euro ceiling is a rounding error for OpenAI; a 3 percent turnover figure is not, and that is the lever regulators will reach for if marking turns out to be decorative.
For anyone who publishes text, the practical change is small and the evidentiary change is large. A watermark that travels with copied text gives platforms, publishers and researchers a signal that survives the clipboard, and it gives them something to test. But because a missing watermark proves nothing, the absence of a signal can never be used to accuse a human writer, which preserves the presumption that unmarked text is simply unmarked text.
For businesses, the decision to leave the API setting off by default is the detail to watch. Developers who want the signal must ask for it, and OpenAI has said plainly that it is not making text watermarking a global default at launch. Enterprise customers with strict requirements about output predictability will weigh a small statistical perturbation in word choice against a compliance checkbox, and the benchmark figures for Astra suggest the quality cost is, at least on those tests, negligible.
For the wider transparency project, the interesting question is what happens to the detector. Image and audio verification tools at OpenAI remain open to the public, while the text detector starts behind an application form limited to approved researchers and expert organizations. If that gate stays closed, the watermark will be verifiable in principle and unverifiable in practice for the journalists, moderators and auditors who most need it.
The EU rollout proceeds over the coming weeks, plan by plan, and the December 2, 2026 deadline for systems already on the market sets the outer boundary of the grace period. OpenAI has said it will release textGrain as open source, which would let outside researchers test detection rates on their own corpora instead of relying on vendor numbers.
The next real test is behavioral rather than technical: whether the opt-in rate among API customers is high enough for the signal to appear in the wild, and whether the EU's market surveillance authorities treat a watermark that fades to 17 percent under light editing as compliance or as a promise that still has to be kept.