
OpenAI has announced its approach to text provenance in response to the EU AI Act, which requires generative AI providers to make generated text identifiable in a machine-readable way. The company says its phased approach reflects both the requirements of the regulation and the limitations of current text watermarking and detection technology.
OpenAI’s text watermarking technology, called textGrain, adds an invisible statistical signal to model-generated text. However, the company says text watermarking and detection remain early technologies with significant limitations, while approaches to their benefits and responsible uses continue to develop.
How textGrain works
According to OpenAI’s technical report, textGrain couples token generation to keyed pseudorandomness using optimal transport. It applies the coupling to vocabulary blocks rather than independently optimizing every token, while preserving the original relative probabilities of tokens within each block.
The watermark is designed to be unbiased, meaning the original next-token prediction distribution is recovered when averaged over the keyed randomness. In addition, the system uses an entropy budget to control the amount of sampling randomness removed by the watermark. The report defines this entropy reduction as the mutual information between the generated token and the keyed randomness, providing an information-theoretic measure of watermark strength.
For detection, the system uses the secret key and observed text to reconstruct the keyed information and look for the statistical signal. The detector does not require the model that generated the text, the generation budget or the coupling used during generation.
OpenAI says textGrain matched or exceeded the performance of other approaches it tested, including SynthID for text. Even so, the company notes that strong performance under ideal conditions does not guarantee reliable detection in everyday use.
Detection limitations
OpenAI’s evaluations show that detection performance varies based on text length, subject matter and the amount of editing applied to the text.
- At a target false-positive rate of 1%, the detector identified watermarks in about 80% of 200-token passages and about 95% of 400-token passages for content such as psychology.
- Detection rates were substantially lower for mathematics, where there is less flexibility in word choice.
- In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%.
- Replacing 25% of words reduced detection to 17%.

A false positive occurs when the detector reports a watermark where none is present, while a false negative occurs when it fails to detect a watermark that is present. Therefore, detection results can be affected by the length, subject matter and subsequent editing of the text.

The technical report describes an idealized detection model in which scores from distinct context windows follow a Gamma distribution under the unwatermarked hypothesis. It also notes that repeated contexts, finite-precision implementations and the use of a fixed deployed key require empirical calibration. As a result, the theoretical false-positive rate does not guarantee the same error rate for every key or application.
Impact on output quality
OpenAI says it does not see meaningful performance differences with and without watermarking across the benchmarks it uses to assess Astra, its latest frontier model. Meanwhile, the technical report says the entropy budget controls the average reduction in sampling randomness, while the coupling preserves the original next-token distribution when averaged over the keyed randomness.

What a text watermark can and cannot establish
OpenAI says a text watermark provides a limited signal about the role its systems played in a passage. In particular, a detection result does not establish:
- Human contribution: It can indicate that an OpenAI system generated or processed part of a passage, but it cannot determine how much human judgment, editing or creativity went into it.
- Ownership or responsibility: It does not determine who owns the text, whether its use was lawful, whether disclosure was required or who is responsible for it.
- User identity: It does not associate a person, organization, account, prompt or conversation with the text.
- Accuracy: It does not determine whether a passage is true, misleading, harmful or presented in the right context.
Furthermore, the absence of a detected watermark does not prove human authorship. Text generated with OpenAI tools may be too short, edited or translated for detection to work reliably. It may also come from an unsupported model, predate watermarking or have been generated by another company’s tools.
OpenAI’s broader content provenance
OpenAI says no single provenance technique is sufficient on its own and is using a combination of open standards, durable watermarking and verification tools. For supported image outputs, the company adds Content Credentials and is C2PA conformant, while supported images and audio use invisible SynthID watermarks. Image and audio verification will continue to be publicly accessible through OpenAI’s verification tools and Content Provenance API.
Content Credentials can record a file’s origin and history, while invisible watermarks can preserve a signal when metadata is removed. Together, these techniques form part of OpenAI’s broader approach to content provenance.
Text presents additional challenges because it can be rewritten, translated or edited. OpenAI says it will continue improving detection, studying how watermarks withstand editing and translation, and exploring ways to distinguish AI assistance from AI authorship more meaningfully. The company expects to revisit its approach as the technology, standards, evidence and regulatory requirements evolve and expand detector access when results can be interpreted responsibly.
Text watermarking availability
OpenAI’s rollout will take place in phases across its consumer and developer products:
- ChatGPT and Codex: Text watermarking will be introduced for eligible users across all plans in the European Union over the coming weeks. It will not become a global default at launch.
- API: Customers worldwide can opt in to watermarked text outputs for select models starting today. Watermarking will remain off by default.
- Cloud partners: OpenAI is working with cloud partners to make watermarking available for OpenAI model outputs accessed through their services in the coming weeks.
- Text watermark detector: Applications are open to approved researchers and expert organizations. Access will initially be granted on a case-by-case basis in accordance with the Code of Practice.
- Open source: OpenAI plans to make textGrain available as open source.
The detector will report whether it detects an OpenAI watermark without identifying the user or revealing prompts or conversations. OpenAI says it is not making the detector publicly available at launch because of the risk of missed watermarks and false positives. The company says it will revisit detector access as the technology, standards and evidence evolve.
