OpenAI will watermark ChatGPT and Codex text in the EU, and API customers can opt in
OpenAI published its plan for text watermarking on October 5, 2026, in response to the EU AI Act. Over the coming weeks, eligible ChatGPT and Codex text output in the European Union will carry an invisible watermark called textGrain. In the API, watermarking is available worldwide from the same day for select models, and it stays off unless you turn it on. The detector is not public: OpenAI is limiting it to approved researchers and expert organizations.
The company describes the rollout as phased and regional. Text watermarking is not becoming a global default, and OpenAI says it wants to learn from use in the EU first. The announcement comes with the company's own measurements of how often the detector misses a watermark. Those numbers decide what the watermark can be used for.
What changes, and for whom
For ChatGPT and Codex, the change is automatic and limited to the EU. OpenAI says it will add the watermark to eligible text output for users on all plans there over the coming weeks. It has not given a date.
For the API, nothing changes until you act. You can turn watermarking on for a whole organization under Organization settings, Data controls, Text provenance, or for one project under Project Settings, Text provenance. In both places you pick which models get the watermark, and OpenAI then adds it during generation with no extra work per request. The list of supported models is shown only in those settings. OpenAI says coverage will extend to all legacy models over the coming weeks.
OpenAI also says it is working with cloud partners so that its models reached through their services can produce watermarked output, again in the coming weeks.
How textGrain marks text
The textGrain watermark does not insert anything into the text. According to OpenAI's help center, it adjusts how the model picks at random between possible next tokens, following a pattern set by a secret key. A detector with the same key checks whether a passage follows that pattern more often than chance would allow. OpenAI says the method adds no hidden characters, invisible spaces, or unusual punctuation, and that its effect on generation speed is negligible.
The company built its own method and did not adopt SynthID from Google DeepMind. It says textGrain matched or exceeded the other approaches it tested, including SynthID for text, and that it plans to release the technology as open source. On the benchmarks OpenAI uses for its Astra model, the company reports no meaningful difference between output with the watermark and output without it. On DeepSWE v1.1 it lists 72.80% without the watermark and 71.68% with it. On Terminal-Bench 4.0 it lists 53.90% and 56.06%.
What the detector misses
OpenAI's figures explain why the detector is not public. At a target false positive rate of 1%, the detector found the watermark in about 80% of passages 200 tokens long and in about 95% of passages 400 tokens long, on content such as psychology. For mathematics, where there is less freedom in word choice, OpenAI says detection was substantially lower.
Editing weakens the signal quickly. In OpenAI's test on passages of 400 tokens, replacing 10% of the words with synonyms cut detection from about 92% to 66%. After 25% of the words were replaced, detection was 17%.
The result also depends on the language. OpenAI tested all 24 official EU languages at the same false positive rate. It reports the highest detection rate for Spanish, 69.0%, and the lowest for Romanian, 42.2%. The company says it raised the watermark strength for languages that scored below 60%.
Short answers and code mostly stay unmarked. OpenAI says the EU Code of Practice on the transparency of AI-generated content does not require a watermark in outputs shorter than 200 tokens, about 150 words in English, or in code snippets.
What a detection result does not show
Turning the watermark on does not settle your disclosure duties. OpenAI's help center says watermarks do not replace visible labels or other notices that may be required, and that the company cannot advise customers on their legal obligations. Enabling the watermark does not give you access to the detector either.
OpenAI lists the limits of a detection result itself:
- The watermark does not identify who generated the text. OpenAI says it is not tied to any person, organization, account, prompt, or conversation.
- It does not measure how much of a passage a human wrote or edited.
- It does not establish who owns the text or who is responsible for it.
- It says nothing about whether the text is accurate.
- A passage with no detected watermark is not proven to be written by a human. It may be too short, edited, translated, or produced by another company's model.
„We are not making text watermarking a global default at launch.“
Sources
Related
A preprint finds six commercial LLM routers no better than a random pick between two models
A preprint submitted to arXiv on October 2, 2026, tested six commercial LLM routers in 14 settings. According to the authors, none of them beat a router that picks at random between Gemini 3.7 Flash and Opus 5 at the same cost, and one trailed it by 10.5 percentage points. The authors, who work at Fastino Labs, trace the gap to the way routers are evaluated and to rosters that hold too many models. The paper has not been peer reviewed.
arXiv, Fastino Labsverified

Microsoft's ThinkingBox shows no model passes half of 507 agent tasks 20 times in a row
Microsoft's Copilot Studio team published results from its ThinkingBox benchmark on the Hugging Face blog on October 3, 2026. The benchmark runs 507 business workflows 20 times per model and grades the database state an agent leaves behind, not its final message. Microsoft reports that Claude Opus 5.5 leads single-attempt accuracy at 67.16%, yet it passes only 241 tasks on all 20 attempts. According to the authors, roughly four in five failures come from tool handling rather than reasoning.
Microsoft, Hugging Faceverified

Ai2 releases AstaBrief, an open-weights model that writes cited research reports
Ai2 released the weights and training data for AstaBrief on October 2, 2026. The model takes a research question plus retrieved excerpts from the literature and writes a report with citations. Ai2 measures it at 51.1 seconds per report in its Asta platform, against 178.5 seconds for the Claude-powered mode beside it. The license is Apache 2.0, and Ai2 says its evaluation predates the current frontier models.
Ai2verified
