does chatgpt watermark its text? what openai announced on october 5, 2026
as of october 2026, the answer to "does chatgpt watermark its text" depends on where you are. in the eu, soon: openai said on october 5, 2026 that it will add an invisible chatgpt watermark to eligible chatgpt and codex text output there over the coming weeks. everywhere else, chatgpt text is not watermarked by default. api customers can opt in for select models.
the detector is not public. for now, access is limited to approved researchers and expert organizations.
does chatgpt watermark its text right now?
outside the eu, no, and inside the eu it arrives over the coming weeks. openai's post says the eu watermark covers eligible chatgpt and codex users across all plans, and that it is not making text watermarking a global default at launch.
openai's post does not define which users are eligible, and it gives no cutover date. our reading: if you are in the eu, assume your chatgpt drafts will carry the mark within weeks, not that they all carry it today.
the trigger is the eu ai act. the european commission says the act's article 50 transparency obligations apply from august 2, 2026. it adds that signing its code of practice is voluntary, while the article 50 requirements are legal obligations.
what did openai announce on october 5, 2026?
openai announced three separate changes, and each one reaches different people.
- chatgpt and codex in the eu: an invisible watermark on eligible text output, arriving over the coming weeks.
- openai api watermarking, worldwide: opt in watermarking for select models from october 5, 2026. it stays off by default. openai says it is also working with cloud partners to bring watermarking to its models on their services in the coming weeks.
- the ai text detector: applications opened the same day. access starts with approved researchers and expert organizations, granted case by case.
the developer docs put the detector limit plainly: text verification is currently only for approved organizations, including ai research and academic institutions. the public openai.com/verify tool and the content provenance api check images and audio, not text.
how does textgrain work, and can editing remove it?
textgrain, openai's watermark, hides a statistical signal in which words the model picks, and openai's own tests show editing can weaken it substantially. nothing visible is added. a detector holding the key looks for the pattern, and the technical report says detection needs only the text and the secret key.
openai published two sets of detection results. the length test ran at a target false positive rate of 1%; the editing test is a separate evaluation of 400 token passages.
| openai's own evaluation | share of watermarked passages detected |
|---|---|
| length test: 200 token passages, content such as psychology | about 80% |
| length test: 400 token passages, content such as psychology | about 95% |
| editing test: no words replaced | about 92% |
| editing test: 10% of words replaced with synonyms | 66% |
| editing test: 25% of words replaced with synonyms | 17% |
openai adds that detection was substantially lower for content such as mathematics, where there is less freedom in word choice. it also says textgrain matched or beat the other methods it tested, including synthid for text. our take: these are vendor figures until outside researchers get detector access and test them.
does watermarking make chatgpt worse?
openai says it does not, and in our reading its benchmark table supports that. across the benchmarks it uses to assess gpt-6 astra, it reports no meaningful difference with the watermark on. both columns in openai's table are labelled astra, max. these are openai's watermark test runs, not the scores in its september 3 astra launch post, which our coding comparison uses. compare the two columns with each other, not with other tables.
five of the eight pairs it published, unwatermarked first:
- gpqa diamond: 94.44% vs 93.94%
- deepswe v1.1: 72.80% vs 71.68%
- terminal-bench 4.0: 53.90% vs 56.06%
- browsecomp: 87.92% vs 87.35%
- healthbench professional: 64.27% vs 64.60%
the other three pairs, the artificial analysis intelligence index, automationbench and terminal-bench science 0.1, scored higher with the watermark on. so some scores went up and some went down. in our view that is noise, not a quality hit. anthropic makes a similar claim, saying its method has no practical impact on the quality or content of claude's output.
how is the chatgpt watermark different from the claude watermark?
in our view, geography is the biggest difference between the two. anthropic said on august 14, 2026 that future claude models would generate watermarked text, and it applies the claude watermark globally at launch because it does not yet have a durable way to scope it by region. openai chose the opposite: eu only for chatgpt, off by default on the api.
| question | chatgpt and codex | openai api | claude |
|---|---|---|---|
| where is text marked? | eu only | wherever a customer opts in | worldwide |
| who gets it? | eligible users on all plans, over the coming weeks | customers who opt in, select models | supported models |
| who can detect it? | approved researchers and expert organizations | the same text detector | eligible organizations, private preview |
| method | textgrain | textgrain | a version of google deepmind's synthid text |
claude's help center says marks on supported models apply across the api, the claude apps and claude code, and that claude models launched on or after august 2, 2026 support marking at launch. support for older models is still being added. anthropic says it signed the eu code of practice in july 2026, alongside around 190 total signatories.
google's synthid page says synthid can mark images, audio, text or video and is embedded across google's generative ai consumer products. the check it offers inside gemini is for images, video and audio. for the wider model picture, see our claude vs chatgpt vs gemini comparison.
what can a chatgpt watermark prove?
in our view a chatgpt watermark proves much less than people fear. openai lists five things a detection result cannot tell you:
- it does not measure how much human judgment or editing went in.
- it does not establish ownership, lawful use or responsibility.
- it does not identify you. openai says plainly that "a watermark does not identify the user."
- it does not verify that the text is accurate.
- a missing watermark does not prove a human wrote it. the text may be too short, edited or translated, from an unsupported model or another company's tools, or older than the watermark.
anthropic makes a similar point: its key can only estimate how likely it is that claude was involved. our take: that matters most for anyone who fears a detector score at school or work. we covered the wider privacy picture in where your ai conversations go.
should you change how you use chatgpt because of the watermark?
our verdict: most people should change nothing, and nobody should build a workflow around stripping marks. pick by your situation:
- you write with chatgpt outside the eu: nothing changes by default today. openai says it expects to revisit each part of this approach, so recheck before you assume it stays that way.
- you are an eu user: expect the mark on eligible chatgpt and codex text over the coming weeks. if you already disclose ai help where it matters, the mark changes little for you.
- you ship an eu product on the openai api: you have to decide whether to turn watermarking on, because it is off by default. talk to counsel about article 50 first, since the commission calls those duties legal obligations.
- you are a teacher or editor: unless your organization is approved, you cannot run openai's text detector, and its own editing test shows synonym swaps cut detection substantially. we would never treat a detector score as the only evidence.
- you use codex for coding: eligible codex text output in the eu is in scope. anthropic says that for claude, exact code generally carries less watermarking than some other kinds of text. openai's post gives no code specific figure.
for the legal side of recording your own work in europe, see gdpr and screen recording.
your own record of how a document came together
a watermark can say a model touched a passage, but it cannot show the drafts, sources and edits that made it your work. in our view, your own history of that work is the better record.
remynd is a mac app that keeps that history. it captures the focused window, runs ocr locally with apple vision, and keeps the searchable index on your mac. you can exclude apps and sites, and recordings are kept for 30 days by default. history access is read only.
the agent window runs your own claude code or codex cli against it, and settings accept a custom endpoint compatible with the openai responses api. models and vendors keep changing, and we think your working context should not be locked to one of them.
download remynd for mac and keep the trail behind your writing on your own mac.