ChatGPT Watermark: What OpenAI's textGrain Does and Doesn't Do

Alex Halpin
10/7/2026

On 5 October 2026 OpenAI said that they would be putting an invisible watermark into the text of ChatGPT and Codex in the European Union. The detector that reads this watermark will not be public. For now, only a short list of approved researchers and organizations will be able to check whether a given paragraph contains the mark.
That combination is what most coverage of this topic skips. Instead, this post will cover what OpenAI published regarding its watermark system, textGrain, what the numbers say and what those numbers mean for people who write with ChatGPT. Every figure comes from OpenAI's announcement, which I read on 7 October 2026.
What OpenAI announced
OpenAI describes textGrain as an approach that adds an invisible statistical signal to the model's word choices. A detector then looks for that signal to assess whether a passage contains an OpenAI watermark. The signal is within which words are chosen, not within extra characters.
The rollout will have two parts: API customers from anywhere in the world can opt-in to watermarking of text from select models; by default, the API will not enable watermarking of text. Over the coming weeks, OpenAI says it will add the watermark to eligible ChatGPT and Codex text output in the European Union. The ChatGPT part of the rollout is regional, limited to the EU.
What the numbers say
OpenAI reports that its detector has a false positive rate of 1%. For psychology, the detector found the watermark in about 80% of 200-token passages and about 95% of 400-token passages. However, for mathematics, the rates were substantially lower. A watermark needs room to work, and a short answer or a formula-heavy one gives it less.
The edit results are the part students and writers will read first. OpenAI says replacing 10% of words with synonyms reduced detection from about 92% to 66%, and replacing 25% reduced it to 17%.
| Test reported by OpenAI | Detection rate |
|---|---|
| Psychology text, 200 tokens | about 80% |
| Psychology text, 400 tokens | about 95% |
| Mathematics text | substantially lower (no figure given) |
| Unedited baseline in the synonym test | about 92% |
| 10% of words replaced with synonyms | about 66% |
| 25% of words replaced with synonyms | about 17% |
Read those as OpenAI's own results on its own test sets. They are useful for understanding how the mark behaves. They are not a measurement of what happens to your essay, and the announcement does not claim they are.
What a watermark does not tell you
OpenAI is direct about the limits, and the page has a section titled what a text watermark doesn't tell you. It says a watermark cannot measure how much a human contributed, establish ownership, identify users, verify accuracy, or prove human authorship by its absence.
That is the most important point to consider. If the watermark is not found in the text, it does not show that the individual wrote the text. The text could have been written by another model, by a model with the watermark switched off or even by ChatGPT outside of the EU. The signal can only confirm text from a watermarked OpenAI source and only with some probability.
Who can check for it
OpenAI says access to the detector will initially be limited to approved researchers and expert organizations, through an application. It is not publicly available at launch. In practice that means a teacher, an employer or a free website cannot run your text through textGrain today. A site that claims to give you a textGrain score right now would not be using OpenAI's detector.
This is also why the detectors schools use are a different thing. A tool such as Turnitin estimates how likely text is to be machine-written from the writing itself. A watermark detector looks for a planted signal. I explained that split in how AI detectors work, and the accuracy figures for the writing-based tools are in are AI detectors accurate.
What this means if you use ChatGPT
If you are in the EU and write with ChatGPT, longer unedited output will carry the signal more reliably than short snippets, going by OpenAI's 200 and 400 token figures. Heavy editing weakens it. OpenAI's synonym test is one kind of edit, and it does not say how rewriting whole sentences or restructuring paragraphs would score.
I haven't tested textGrain against any tool, including ours, because there is no public detector to test with. What I can offer is an inference from OpenAI's own numbers. In its test, replacing 25% of words with synonyms cut detection from about 92% to 17%, and RewriteAI works by rewriting the wording of a text, which is exactly the kind of change that weakens a statistical watermark. That is why we expect our ChatGPT watermark remover to hold up well against textGrain. It is a reasoned expectation, not a measurement. Once there is a detector I can use, I will publish measured results with the date and the numbers.
The false positive side is worth a sentence too. OpenAI set its results at a 1% false positive rate, which is a design target for the test and says nothing about how any one person's writing will be treated. If a score is ever used against you, why an AI detector says your essay is AI when it isn't covers what to do.
The short version
On 5 October 2026, OpenAI announced that they would begin watermarking eligible ChatGPT and Codex text within the EU, as well as provide an option to watermark text from their API for select models. The signal is statistical, hidden in word choices and detection is stronger on longer text and weaker after editing. Only approved researchers and organizations can run the detector at launch. A missing watermark proves nothing about who wrote a passage.
If you want the longer treatment:
- How Claude's watermark works — the same question for a different model
- Will Google punish AI content? — what watermarks mean for search
- How AI detectors work — watermarks next to perplexity and classifiers
- Are AI detectors accurate? — every published figure in one table
For the file-metadata approach instead of a text watermark, see C2PA Content Credentials and what Claude attaches to files.
Keep reading
- C2PA Content Credentials: What Claude Attaches to Your Files
Claude attaches signed C2PA provenance metadata to supported files and a separate watermark to text. Here is what each does, and what a mark can and cannot prove.
- Does Turnitin Detect AI From ChatGPT, Claude and Gemini?
Turnitin's AI detection documentation names GPT-3.5, GPT-4, GPT-4o and GPT-4o-mini, and no Claude or Gemini model. What that does and does not tell you about your score.
- How AI Detectors Work: Perplexity, Classifiers and Watermarks
GPTZero stopped using perplexity and burstiness in autumn 2023, which is awkward, because that is still how almost every explainer says AI detectors work. Here are the three generations, and the one that actually scores your writing.
Humanize AI Text and Improve Your Writing Right Now
Rewrite for clarity, flow, and readability while keeping your original meaning and writing style.


