Skip to content

Build4 publishers3 min readPublished

OpenAI makes textGrain watermarking opt-in for API customers everywhere

OpenAI will watermark ChatGPT and Codex text for EU users, but API customers worldwide get textGrain only if they switch it on from October 5. Teams building on the API now decide for themselves whether to mark output, while Anthropic applies Claude's watermark everywhere.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying OpenAI makes textGrain watermarking opt-in for API customers everywhere
Generated illustration

What happened

  • ChatGPT and Codex users outside the European Union will not get watermarked text under OpenAI's plan.
  • Replacing 10% of words with synonyms cut detection on 400-token passages from about 92% to 66%, and replacing a quarter cut it to 17%.
  • Only selected researchers and specialist organisations can use the detector for now, approved case by case under the EU Code of Practice.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision An API team serving EU users has to settle with counsel whether Article 50 makes it responsible for marking output, then set textGrain to match, because the default leaves the mark off.
  • constraint A school, hiring or moderation tool that treats a textGrain hit or miss as proof of authorship will be wrong in both directions: on short, maths-heavy or edited text, and on about 1 human passage in 100.
  • cost Switching textGrain on for a writing product leaves the team to pay for its own prose-quality testing, since OpenAI's eight benchmarks measured task scores.
  • exposure Products built on Claude ship marked text in every market, including human-written text Claude only edited, while Anthropic has not published how often its detector finds the mark.

Article 50 of the EU AI Act requires providers of generative AI to mark their output in a machine-readable way, and it has applied since August 2, 2026 [11]. Crypto Briefing says it covers anyone serving EU users [12]. City A.M. notes an exception for AI that only assists with editing without substantially changing the original meaning [13]. Whether a company calling OpenAI's API counts as a provider is a legal question. Tech AI Wire's advice to teams serving EU users is to ask their legal department [14].

On the API side, the switch is set per project, according to Unite.AI as cited by Tech AI Wire [2]. Customers on Microsoft Azure get the same option through OpenAI's cloud partners in the coming weeks [15]. The reports do not include the parameter name or say whether a single request can override it.

textGrain biases which words the model picks, and the detector tests a passage for that statistical pattern [5]. Length and subject decide the result [6][7]. At a 1% false-positive target, OpenAI reported about 95% detection on 400-token psychology passages and about 80% at 200 tokens [6]. At 200 tokens, roughly one marked passage in five goes undetected [26]. Maths output scored "substantially lower" because the model has less freedom to choose words [7].

For the 95% figure to transfer to a product, its output has to resemble OpenAI's test: around 400 tokens of prose with room in word choice, left unedited. Editing is where it breaks [8]. Swapping 10% of words for synonyms cut detection on 400-token passages from about 92% to 66%, and swapping a quarter cut it to 17% [8]. Replacing a quarter of the words removes 75 points of detection [28]. Robustness has stalled OpenAI before: Crypto Briefing reports that a 2024 prototype was "about 99.9% effective" and was held back over concerns about how robust it was [23].

A 1% false-positive rate means about one human-written passage in 100 is wrongly flagged [16]. Across 10,000 human passages, expect about 100 false flags [27]. OpenAI also says a missing watermark does not prove a human wrote the text [17]. Few teams can run the check yet: the detector is limited to selected researchers and specialist organisations, who apply through a form and are approved case by case under the EU Code of Practice [9]. OpenAI said it will widen access "when we believe results can be interpreted responsibly," and has not said when [10].

On quality, OpenAI tested its frontier model Astra on eight benchmarks, including GPQA Diamond, BrowseComp and DeepSWE, and found no significant difference with the watermark on or off [18]. A good DeepSWE score says little about whether a cover letter still sounds like its author [18]. The Decoder notes that the results do not establish whether watermarking affects writing quality, a point critics have also raised about Claude's watermark [19].

Teams on Claude skip the decision. Anthropic's watermark is mandatory and applies globally however the model is reached [4]. City A.M. says the marks survive copy and paste, and that human-written text edited by Claude may carry them [21]. Anthropic says its system holds up well against edits but has not published detection rates [20]. I think OpenAI's disclosure is the better engineering practice: a technical report, a stated false-positive target, failure rates by length, subject and edit fraction, and a plan to open-source the method [22][6][8]. OpenAI also says textGrain matched or beat Google's SynthID for text in internal tests, and SynthID is the technology The Decoder says Claude's watermark uses [25][24].

What to watch

  • OpenAI opening the textGrain detector beyond approved researchers, the step Tech AI Wire says could bring watermark checks into publishing and education tools.
  • EU guidance on whether a company building on a model API is itself a provider with Article 50 marking duties.
  • Anthropic publishing detection rates for Claude's watermark at a stated false-positive target, so the two schemes can be compared on the same terms.
Loading claim ledger
Loading source directory links
Loading share composer