
On October 5, 2026, OpenAI said it will add an invisible watermark to eligible ChatGPT and Codex text in the European Union over the coming weeks. API customers anywhere can opt in for select models starting that day, with watermarking off by default. The company tied the move directly to the EU AI Act, which requires generative AI providers to make generated text identifiable in a machine-readable way. The same day, it published a technical report on its method, called textGrain, and opened applications for detector access to approved researchers and expert organizations.
The defended position is that text watermarking has become a compliance standard before it has become a reliable measurement. OpenAI’s own numbers show a signal that weakens with short passages, constrained content, and light editing. Operators should treat a watermark result as one piece of evidence that a human must weigh, never as a verdict on authorship. Evidence that would weaken this reading includes independent evaluations showing robust detection after paraphrase, or the Commission naming a technical standard that sets measured detection floors. Neither exists in the sources reviewed today.
What the AI Act and the Code of Practice require
Article 50(2) of the AI Act requires providers of systems that generate synthetic audio, image, video, or text to ensure outputs are “marked in a machine-readable format and detectable as artificially generated or manipulated.” The technical solutions must be effective, interoperable, robust, and reliable as far as technically feasible. The text weighs content limits, implementation cost, and “the generally acknowledged state of the art, as may be reflected in relevant technical standards.” Assistive functions for standard editing that don’t substantially alter the input are exempt.
The European Commission says these transparency obligations apply from August 2, 2026. The AI Office facilitated a Code of Practice on Transparency of AI-generated Content, published in final form on June 10, 2026, with one section for providers on marking and detection and one for deployers on labelling. The Commission and the AI Board confirmed the code is an adequate voluntary tool to demonstrate compliance. Providers who comply another way must show their measures are adequate to market surveillance authorities, case by case.
Adoption is broad. The Commission reported about 190 signatories by the end of July 2026 and lists OpenAI, Anthropic, Google, Meta, Microsoft, and Mistral among Section 1 signatories. Signatories were also invited into two task forces, set to launch in September 2026, to share practices and advance the state of the art. Article 50(7) adds a backstop. If the Commission judges a code inadequate, it may adopt an implementing act with common rules for marking and labelling.
What OpenAI’s own numbers show
textGrain adds a statistical signal to the model’s word choices. The technical report, co-written with researchers from the University of Pennsylvania and Yale, says the detector needs only the generated text and a secret key. OpenAI says the method matched or exceeded the other approaches it tested and plans to release it as open source. It reported no meaningful benchmark differences with watermarking switched on.
The limits are in the company’s own disclosure. At a target false positive rate of 1%, the detector found watermarks in about 80% of 200-token passages and about 95% of 400-token passages for content such as psychology. Detection was substantially lower for mathematics, where word choice is constrained. Replacing 10% of words with synonyms in 400-token passages cut detection from about 92% to 66%. Replacing 25% cut it to 17%.
OpenAI then lists what a watermark can’t tell you. It doesn’t measure human contribution, establish ownership or responsibility, identify the user, or verify accuracy. The absence of a detected watermark doesn’t prove human authorship, because text may be too short, edited, translated, or produced by another company’s tools. That candor is the most useful part of the release. It also explains why detector access starts case by case under the Code of Practice rather than as a public tool.
Why measurement standards now matter more than marks
Article 50 asks for marks that are robust and reliable, yet it leaves “reliable” to the state of the art. Today, a vendor’s own evaluation largely defines that state. A 66% detection rate after light synonym edits is a real result. It is not a threshold anyone should use to discipline a student, reject a job application, or flag a journalist without a human review.
That is where testing standards come in. NIST’s comment period on the initial public draft of NIST AI 200-2, The TEVV-Athlon Framework for Evaluating AI Systems, closes October 6, 2026. The draft describes a four-stage method for building customized assessments in which AI systems are tested through Events and Tools that produce data on measurement concepts NIST calls Blocks. NIST is asking, among other things, which TEVV activities the framework doesn’t yet address. Watermark detection under editing, translation, and short-text conditions is a clear candidate, and a framework like this is how operators move from vendor charts to their own repeatable tests.
What Responsible AI operators should change now
The Factics move pairs each verified fact with a tactic and a measure. The fact is that EU marking duties are live and major providers are shipping text watermarks with disclosed error rates. The tactic is a provenance register that lists every generative tool in use, whether it marks text, image, or audio output, the method used, and who can run detection. The KPI is the share of tools with a documented marking method and a tested detection rate at a stated false positive rate on your own content type, not the vendor’s.
Second, write a detection-use rule before anyone runs a detector. No adverse decision about a person rests on a watermark result alone, and every flagged case goes to a named reviewer who records the decision and the reason. Checkpoint-Based Governance supplies that checkpoint, because the reviewer holds authority to accept, reject, or escalate the signal. The measure is the share of flagged cases with a documented human decision, with a target of every case.
Third, publishers should read the deployer side of Article 50 closely. AI-generated text published to inform the public on matters of public interest must be disclosed. The exception applies where content has undergone human review or editorial control and a person holds editorial responsibility. That exception rewards exactly the workflow a governed newsroom or brand team should already run. Name the editor of record, keep the review log, and disclose anyway when trust is on the line. Factics keeps that brief honest by turning each obligation into something you can count.
The next signals to watch are OpenAI’s promised updates to the textGrain report and its open-source release, early results from the Code of Practice signatory task forces, and the final version of NIST AI 200-2. Each will show whether “detectable” in Article 50 gets a measured meaning, or stays a promise that only the vendor can check.
Sources
- European Commission. (2026). Code of Practice on Transparency of AI-generated Content. Shaping Europe’s Digital Future. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
- European Commission. (2026, July 31). Strong backing for the Code of Practice on Transparency of AI-generated Content [News article]. Shaping Europe’s Digital Future. https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content
- European Union. (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 50: Transparency obligations for providers and deployers of certain AI systems (consolidated text as at July 27, 2026). AI Act Service Desk, European Commission. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
- Li, X., Wen, G., Chen, X., Long, Q., Jain, A., Joly, F., Lam, M., Song, Q., & Su, W. (2026, October 5). textGrain: Entropy-calibrated watermarking for language model text [Technical report]. OpenAI. https://cdn.openai.com/pdf/e9508624-d767-41b6-a26d-e34ca798ada6/textgrain-entropy-calibrated-watermarking-for-language-model-text.pdf
- National Institute of Standards and Technology. (2026, August 7). The TEVV-Athlon framework for evaluating AI systems: Input sought on initial public draft of NIST AI 200-2 through October 6, 2026. U.S. Department of Commerce. https://www.nist.gov/artificial-intelligence/ai-research/tevv-athlon-framework-evaluating-ai-systems
- OpenAI. (2026, October 5). Our approach to EU text provenance rules. https://openai.com/index/eu-text-provenance/
Frequently Asked Questions
What did OpenAI announce about text watermarking on October 5, 2026?
OpenAI said it will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union over the coming weeks, across all plans. API customers globally can opt in for select models starting October 5, with watermarking off by default. It also opened applications for detector access, initially limited to approved researchers and expert organizations.
How does the textGrain watermark work?
textGrain adds an invisible statistical signal to the model’s word choices rather than inserting visible symbols. According to OpenAI’s technical report, the detector needs only the generated text and a secret key to test for the signal. OpenAI says it plans to release the technology as open source.
What does Article 50 of the EU AI Act require for AI-generated text?
Article 50(2) requires providers of generative AI systems to mark outputs, including text, in a machine-readable format so they are detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust, and reliable as far as technically feasible. Article 50(4) requires deployers to disclose AI-generated text published to inform the public on matters of public interest, unless it has undergone human review or editorial control and a person holds editorial responsibility.
What is the Code of Practice on Transparency of AI-generated Content?
It is a voluntary code, facilitated by the EU AI Office and published in final form on June 10, 2026, that helps providers and deployers meet the Article 50 marking and labelling duties applicable from August 2, 2026. The Commission and the AI Board confirmed it is an adequate tool to demonstrate compliance, and about 190 organizations, including OpenAI, had signed by the end of July 2026.
How reliable is text watermark detection?
OpenAI reports that at a 1% target false positive rate its detector found watermarks in about 80% of 200-token and about 95% of 400-token passages for content such as psychology, with lower rates for mathematics. Replacing 10% of words with synonyms dropped detection from about 92% to 66%, and replacing 25% dropped it to 17%. A missing watermark does not prove human authorship.
What should Responsible AI teams do now?
Keep a provenance register of generative tools, their marking methods, and who can run detection. Test detection on your own content at a stated false positive rate, and adopt a rule that no adverse decision about a person rests on a watermark result alone, with a named reviewer documenting every flagged case. NIST’s draft TEVV-Athlon framework, NIST AI 200-2, is one structure for building those repeatable tests.
AI disclosure: This column was researched and drafted with AI assistance by HAIA Agents (RAI by GrokBot) under human governance, using primary sources verified at time of publication. #AIgenerated
Leave a Reply