Key takeaways
- OpenAI has no deployed statistical text watermark. It built one, reported high accuracy, and chose not to release it.
- The hidden characters people find in ChatGPT output are interface and formatting artefacts. They carry no key and no signal, and they are inconsistent between sessions.
- Because they carry no signal, they are not evidence of anything — but they are trivially removable, and you do not need a paid tool to do it.
- Removing them does nothing to AI detector scores, which measure how predictable the writing is, not what characters it contains.
- DALL-E and Sora images do carry C2PA provenance metadata, and OpenAI adopted SynthID for images in May 2026. That is a separate question from text.
Does ChatGPT watermark its text?
No. This is the short answer that most pages targeting this search deliberately avoid giving, because there is no product to sell at the end of it.
OpenAI did build a text watermarking system. Reporting on it described high accuracy against its own output. It was never shipped, and the reasons discussed publicly centred on the risk that it would work unevenly across languages, could be defeated by paraphrasing anyway, and would push users toward competitors who did not mark their output.
So when someone tells you they removed the ChatGPT watermark, the accurate description is that they removed something else.
How this differs from Claude and Gemini
Claude has carried a SynthID statistical watermark since 2 August 2026, and Gemini has for longer. Those are real, keyed, invisible marks in the word choices. ChatGPT text has no equivalent.
The invisible characters people actually find
Paste ChatGPT output into a Unicode inspector and you may well find non-ASCII characters that do not render. They are real. They are just not a watermark.
| Character | Codepoint | Where it comes from |
|---|---|---|
| Zero-width space | U+200B | Web UI line-breaking hints, copied along with the text |
| Zero-width joiner / non-joiner | U+200D / U+200C | Emoji sequences and script shaping |
| Narrow no-break space | U+202F | Typographic spacing before punctuation and in numbers |
| Non-breaking space | U+00A0 | HTML rendering, preserved by the clipboard |
| Byte-order mark | U+FEFF | Encoding artefact from file and clipboard handling |
| Em dash, curly quotes | U+2014, U+201C, U+201D | Ordinary typography — visible, and not hidden at all |
Why these are not a watermark
A watermark needs properties these characters do not have:
- A key. A watermark is verifiable by whoever holds the secret. These characters encode nothing and verify nothing.
- Consistency. A watermark is applied deliberately to every output. These appear inconsistently, depending on the interface, the browser and how you copied.
- Robustness. A watermark is designed to survive editing. These vanish the moment text passes through a plain-text field.
- Attribution. A watermark identifies a source. A zero-width space identifies nothing — it is in text from every tool that renders HTML.
Which cuts both ways
Because these characters prove nothing, finding them in someone's document is not evidence they used AI — and removing them from your own is not covering anything up. Anyone treating a zero-width space as proof of authorship is misreading it in both directions.
How to strip invisible characters yourself
This does not need a paid tool, an account or an upload. It is a character-class deletion, and here is the whole thing.
Three ways, pick whichever suits
- Paste through a plain-text field. Paste into a plain text editor — TextEdit in plain mode, Notepad, or any code editor — then copy it back out. This drops most formatting-derived characters without any tooling at all.
- Find and replace with a regex. In any editor supporting regex search, replace the class [\u00A0\u200B-\u200F\u202F\u2060\uFEFF] with a single ordinary space, then collapse any double spaces. That covers the characters in the table above.
- One line of Python. import re; clean = re.sub(r'[\u00A0\u200B-\u200F\u202F\u2060\uFEFF]', ' ', text) — then re.sub(r' +', ' ', clean) to tidy the spacing.
Check your work
Any Unicode inspector will show you what is left. Unlike a statistical watermark, this is a case where you can verify the result completely, in seconds, for free.
What stripping characters does not fix
If your actual concern is an AI detector flagging your text, cleaning invisible characters will not move the score. Detectors do not look at them.
What they measure is how statistically predictable the writing is — perplexity, and how much sentence length and structure vary across a passage. Those are properties of the wording. Deleting an invisible character changes neither.
That is a rewriting problem, not a cleaning problem, and it is worth being clear that the two get conflated constantly by tools that do the cheap one and imply the expensive one.
- AI detector false positives — what detectors actually measure, and why plain writing gets flagged
- Free AI detector — see where your text sits before anyone else scans it
Rewriting ChatGPT output with RewriteAI
If the goal is text that reads less like a model wrote it, that is a rewrite. RewriteAI re-expresses a passage — different word choices, varied sentence structure. It is not a character cleaner, and on this page in particular it is worth saying that the free method above is the right tool for the other job.
Free plan: 500 words per month, 300 words per request, English only, account required.
ChatGPT images are a different question
Text and images diverge here. Images from DALL-E and Sora carry C2PA provenance metadata, and OpenAI adopted SynthID for images in May 2026.
C2PA is metadata attached to the file rather than to the content, so it does not survive a re-save, a format conversion or a screenshot. An image-domain watermark like SynthID is embedded in the pixels and is a genuinely different problem, closer to the text case in spirit: nothing to delete, only to degrade.
- The three kinds of AI watermark — statistical, invisible characters, and file metadata
If you came here about Claude or Gemini
Those are the two that genuinely watermark text, and the answers there are different — nothing to strip, and rewriting is the only lever.
- Claude watermark remover — SynthID since 2 August 2026, with no public detector yet
- Gemini watermark remover — the longest-running deployment, and a published detector
Sources
- How Claude's text watermarking works — Anthropic
- SynthID: Identifying AI-generated content — Google DeepMind
- C2PA content credentials specification — C2PA
- AI watermark removers flood the web. Almost none can prove they work. — BleepingComputer