Skip to content

OpenAI Will Put an Invisible Watermark on ChatGPT Text, but Only in the EU: Swapping One Word in Ten Cuts Detection From Around 92 to 66 Percent

1 min read
Share
OpenAI Will Put an Invisible Watermark on ChatGPT Text, but Only in the EU: Swapping One Word in Ten Cuts Detection From Around 92 to 66 Percent

Since 2 August, the transparency rules of the EU Artificial Intelligence Act have applied in the European Union: machine-generated content must be labelled in a way other systems can recognise. Two months later, OpenAI announced that in the coming weeks it will start putting an invisible watermark on text written by ChatGPT and Codex - for users in the EU, on all plans. The company makes no secret of the reason: compliance with the law.

The watermark isn't a symbol or a signature at the bottom of the page. The model subtly shapes its choice of words and leaves a pattern the reader can't see but a detector can catch. Because it lives in the words themselves, the watermark travels with the text even when it is copied and pasted elsewhere. The method is called textGrain, and OpenAI wrote the technical report together with researchers from the University of Pennsylvania and Yale: a secret key orders the next-word predictions, and hundreds of these small nudges together let a detector recognise machine text from nothing but the text and the key. The company says the watermark does not identify the user and that it saw no significant change in model performance with it switched on.

Outside Europe the picture is different. Developers using OpenAI's API anywhere in the world can turn the watermark on for certain models starting today, but it is off by default. Global default watermarking - there is none. That has a history: according to The Wall Street Journal, OpenAI had a text watermark ready as early as 2024 but didn't release it, partly for fear that users would switch to competitors who don't watermark. Europe is often mocked for regulating instead of building. Here it was precisely regulation from Brussels that pulled out of the drawer what the market had kept locked away.

So can the watermark be scrubbed? The company's own tests say yes. When 10 percent of the words are replaced with synonyms, detection drops from around 92 to 66 percent. Short passages, maths answers and translated text are harder to recognise. A student who asks for an essay in English and translates it into their own language, in other words, already has half the job done.

That's why OpenAI won't hand the detector to everyone for now. "These limitations contribute to our decision to give initial access to the detector only to approved researchers and expert organisations, who can help us assess reliability and responsible use," the company said. It also warns that the absence of a watermark "does not prove human authorship": the text may be too short, too heavily edited, or written by someone else's AI. "Watermarks can show that an OpenAI system generated or processed part of a passage, but not how much human judgement, editing or creativity went into it."

OpenAI isn't the first. Two months ago Anthropic announced watermarking for text from Claude, worldwide. Some users protested, arguing that they had supplied "the instructions, the context, the decisions" and Claude was merely "the tool". Anthropic, Google, Meta, Microsoft and OpenAI are among the companies that have committed to following the European code of practice for AI-generated content.

Macedonia is not an EU member, so according to the announcement the watermark won't reach ChatGPT users here. The question is whether that is an advantage or a loophole - and who will be first to use it: the professors checking term papers, or the people writing them?