ChatGPT Watermark: What OpenAI's textGrain Means for Text
OpenAI announced a ChatGPT watermark for text on 5 October 2026: textGrain, which adds an invisible statistical signal to the model's word choices. It is due to reach eligible ChatGPT and Codex users in the EU over the coming weeks, and as of 7 October 2026 OpenAI has not published a start date. API customers worldwide can already opt in on select models, with the watermark off by default, and OpenAI is not making its detector public at launch: access goes first to approved researchers and expert organizations.
The word "watermark" suggests a stamp you could find on the page. textGrain has no character, tag, or metadata to find: it is a pattern spread across which words the model picked when several would have worked, and reading it takes OpenAI's secret key. ChatGPT images are marked differently, with Content Credentials and SynthID, and the ChatGPT image detector reads those.
We read OpenAI's announcement and the technical report published with it, and sorted what they confirm from what they leave open. This post covers both, along with how the mark compares with Anthropic's and Google's. Slop or Not reads different evidence, and we will say where that helps and where it does not. Its AI text detection model reads the English writing itself, and it caught 99.5% of AI text at a 5% false-positive rate on RAID, a public benchmark we do not run, with 11 adversarial attacks in the test set.
Does ChatGPT Watermark Text Now, and How Can You Check?
For API text, possibly already: since 5 October 2026, API customers around the world can opt in on select models, so text from an app built on one of those models may carry textGrain. For ChatGPT and Codex, OpenAI said "over the coming weeks" and, as of 7 October 2026, has not published a start date. Its help center already describes EU ChatGPT text as watermarked, in the present tense, without giving a date either. Either way, you cannot check for it yourself, because OpenAI is not making its detector public at launch.
What can you check today? Two other layers, neither of which needs OpenAI's key. The first is mechanical. Chat interfaces bake typographic characters into copied text: curly quotes, em dashes, and the narrow no-break space (U+202F), which looks exactly like a normal space. The ChatGPT watermark detector flags those alongside its AI verdict, which comes from Slop or Not's AI text detection model reading the English writing itself. The free online detector runs that text check on its own. Neither reads textGrain, and a clean result from either is not a clean result from OpenAI's detector.
Online, Slop or Not deletes the text after processing. In the iPhone and Mac apps, both checks run on-device and the text never leaves your hardware.
Here is what OpenAI has confirmed and what it has left open, as of 7 October 2026:
| Confirmed | Not Yet Known |
|---|---|
| OpenAI announced textGrain on 5 October 2026 | A start date for ChatGPT and Codex |
| ChatGPT and Codex: due to reach eligible users across all plans in the EU over the coming weeks | How EU eligibility is decided, and whether ChatGPT or Codex users can opt out |
| Codex: the EU rollout covers eligible Codex text output | Whether Codex code, not just Codex prose, is marked |
| API: opt-in for select models, worldwide, off by default | Which models: OpenAI lists them in each customer's settings, not publicly, and says coverage extends to all legacy models in the coming weeks |
| Cloud partners: OpenAI says it is working with them, in the coming weeks | Which cloud services, and on what date |
| Detector: applications opened on 5 October 2026; not public at launch, with access initially limited to approved researchers and expert organizations | Whether a public detector will ever exist |
| OpenAI plans to release the technology as open source | When the open-source release will ship |
How Does the OpenAI Text Watermark Work?
textGrain changes how the model picks among words that would all work. OpenAI says it "adds an invisible statistical signal to the model's word choices." According to the technical report, generation uses pseudorandom values derived from a secret key and the preceding text, and the detector needs only the generated text and that key.
A language model writes one token at a time, a word or part of a word, by sampling from a list of likely next tokens. Ordinarily a random number settles each pick. textGrain couples that pick to values computed from the key and the words already written, so across a long passage the choices depend on the key in a way a detector can test. Someone holding the key can rebuild those values and measure the dependence. Without the key, the text reads like any other text, which is why reading the mark takes OpenAI's cooperation.
The report also describes a strength setting, a budget for how much sampling randomness is given up in exchange for signal, and says the detector does not need to know which budget was used. OpenAI plans to release the technology as open source and says the report will gain more detail in the coming weeks.
Does the watermark make answers worse? OpenAI says it saw no meaningful difference on the benchmarks it uses for Astra, its latest frontier model. On the Artificial Analysis Intelligence Index, Astra scored 49.57 points without the watermark and 49.76 with it; on GPQA Diamond, 94.44% without and 93.94% with. Those are OpenAI's numbers, not ours, and we have not reproduced them.
How reliably the mark is found depends on how much room the model had. At a target false-positive rate of 1%, OpenAI's detector identified watermarks in about 80% of 200-token passages and about 95% of 400-token passages, for content such as psychology. For content such as mathematics, where there is less flexibility in word choice, detection rates were substantially lower. Short answers and rigid ones give the key fewer choices to work with.
Can textGrain Be Removed?
Two different things get called a ChatGPT watermark, and they behave differently. Hidden characters can be removed or normalized by any character cleaner. textGrain lives in the word choices: no character cleaner, ours included, touches it; according to OpenAI, changing the words weakens detection. This section explains what each change does to the evidence. It is not a guide to hiding anything.
The character layer is real, and cleaning it is ordinary housekeeping, because invisible characters break software that never expected them. Slop or Not's hidden character detector lists every one it finds by Unicode name and returns a copy with invisible characters removed, Cyrillic and Greek lookalike letters swapped back to their Latin twins, smart punctuation made plain, and non-breaking spaces, U+202F included, swapped for ordinary spaces rather than deleted. The ChatGPT watermark remover runs the same cleanup on a pasted ChatGPT answer and, for English text, adds the verdict from the AI text detection model and highlights the writing tells. Our test of what AI watermark removers actually remove found the same split across the removers we tested: they clear hidden characters and file metadata, and they leave the mark that sits inside the words.
The word layer is different, and OpenAI has published its own evidence of how fragile it is. In an evaluation of 400-token watermarked English responses to questions from the ELI5 dataset, replacing 10% of the words with synonyms reduced detection from about 92% to 66%, and replacing 25% reduced it to 17%. OpenAI states no false-positive rate for that evaluation, and it is a separate test from the length results in the previous section. OpenAI presents these limits as part of its reason for giving initial detector access only to approved researchers and expert organizations. OpenAI says it is still studying how watermarks withstand editing and translation, so these figures describe one test set, not a threshold for any single passage.
So a cleaned copy says nothing about textGrain either way, and neither does a Slop or Not verdict. Our checks cannot tell whether the mark survived an edit. Only OpenAI's detector, with its key, can test that.
What About False Positives and Mixed Authorship?
A watermark detector can be wrong in two directions, and OpenAI says so: it can report a watermark where none is present, or miss one that is there. Neither result settles who wrote a passage. A hit can indicate that an OpenAI system generated or processed part of the text, but not how much human judgment, editing, or creativity went into it.
The 1% in OpenAI's length results is a target false-positive rate, the error level the detector was set to in that evaluation. It is not a promise about any single passage. OpenAI names the risk of missed watermarks and false positives as the reason it is not making the detector public at launch. The same caution belongs on any detector whose result could reach a disciplinary file, ours included, which is why Slop or Not returns a probability and leaves the call to a person.
Mixed authorship is the hard case. Suppose someone drafts a report, asks ChatGPT to rewrite two paragraphs, and then edits the result. A hit could support "ChatGPT touched this," and nothing more. OpenAI is explicit that a watermark does not measure human contribution, and that it does not establish who owns the text, whether its use was lawful, or who is responsible for it.
A missing result clears nobody either. By OpenAI's account, text generated with its tools may be too short, edited, or translated for detection to work reliably, or it may come from an unsupported model, predate watermarking, or have been generated by another company's tools. In OpenAI's words, "The absence of a detected watermark does not prove human authorship."
Is Codex Code Watermarked?
OpenAI has not said. It says the watermark will reach eligible Codex text output in the EU, but it has not said whether that covers the code Codex writes or only the prose around it, such as explanations and comments.
We would expect less signal in code even if it is covered. textGrain works on choices, and OpenAI's own results show detection falling substantially for content such as mathematics, where there is less flexibility in word choice. Code is often just as rigid: a function signature or a closing bracket leaves the model little to choose. Anthropic says of its own watermark that code, which in many cases has to be exact, generally carries less watermarking than some other forms of text. OpenAI's help center makes the same general point about its own watermark: code is harder to watermark because there are fewer plausible choices for what comes next than in ordinary prose. It does not say whether Codex code is marked, so any claim that it is or is not is a guess until OpenAI says.
Can Teachers See the ChatGPT Watermark?
Not as of 7 October 2026. OpenAI is not making its text watermark detector public at launch. Applications opened on 5 October 2026, and OpenAI says access will initially be granted case by case to approved researchers and expert organizations. A classroom teacher has no way to run it, and OpenAI has described no public service that runs it on anyone's behalf.
What a teacher can use is evidence that does not depend on OpenAI's key, read with the same caution. Slop or Not's AI essay detector runs its AI text detection model on English writing and estimates whether it reads as AI-generated. The answer is a probability, not proof, and a watermark hit would not be proof either.
The same check works in the other direction, too. A student who wants to see how a draft reads before handing it in can run it the same way. In the iPhone and Mac apps the check runs on-device, so the essay never leaves the device; the online checker processes text on Numen's private Mac server and deletes it after processing.
Does the Watermark Apply Outside the EU?
It depends on the product. For ChatGPT and Codex, the watermark is due to reach eligible users in the EU, and OpenAI is not making text watermarking a global default at launch. On the API, customers around the world can opt in on select models, and the watermark stays off by default. Cloud partners come next: OpenAI is working with them to offer watermarking for OpenAI model outputs accessed through their services in the coming weeks.
OpenAI ties the approach to the EU AI Act, which requires generative AI providers to make generated text identifiable in a machine-readable way. That explains the EU start for ChatGPT and Codex. It does not limit where marked text can turn up.
So the useful question is how the text was made, not where you are. Text from a third-party app built on an opted-in API model can carry textGrain anywhere, and from the outside you usually cannot tell whether the app's operator switched it on. OpenAI has not said how EU eligibility is decided, whether ChatGPT or Codex users can opt out, or publicly listed which API models are covered. It describes the regional start as room to learn from real-world use and feedback, and says it expects to revisit each part of the approach.
Does the Watermark Identify You?
No, according to OpenAI: "A watermark does not identify the user. It does not associate a person, organization, account, prompt, or conversation with the text." OpenAI says its detector will report whether it finds an OpenAI watermark, without identifying the user or revealing their prompts or conversations.
That promise is narrower than it may first sound. The mark can still indicate that an OpenAI system generated or processed part of a passage, and anyone with detector access can read that much from text you hand them. What it cannot do, by OpenAI's account, is lead back to your account or your chat. It also does not verify accuracy: a watermark says nothing about whether a passage is true.
Anthropic makes the same promise about Claude's mark, which it says carries no identifying information and cannot be traced to a specific person, organization, or chat.
Who Watermarks AI Text?
OpenAI and Anthropic have both announced statistical text watermarks in 2026, and Google said in May 2024 that it was watermarking Gemini text with SynthID-Text. All three work on word choice rather than hidden characters, and Slop or Not reads none of them. They differ in where they apply and in how much each company has published.
OpenAI. textGrain is due to reach eligible ChatGPT and Codex users in the EU over the coming weeks and is opt-in on the API worldwide. OpenAI says textGrain matched or exceeded the other approaches it tested, including SynthID for text, and adds that strong performance under ideal conditions does not guarantee reliable detection in everyday use.
Anthropic. Anthropic says Claude's text watermark is a version of the SynthID-Text approach Google DeepMind published in 2024, and that it is applying watermarking globally at launch rather than by region. It also says future Claude models will generate watermarked text and that it is working to add watermarking for earlier models over the coming months. Anthropic's public material does not say whether a given Claude response is marked today. Our Claude watermark explainer covers what that mark can and cannot prove.
Google. Google said in May 2024 that it was expanding SynthID to watermark AI-generated text in the Gemini app and web experience. That is a dated statement, and we have not checked how it applies to Gemini today. Google's developer documentation says SynthID Text has since been open sourced, the same step OpenAI now says it plans for textGrain.
Images are a different story, and a more checkable one. OpenAI says it embeds SynthID watermarks in supported images and audio, and Google marks its own AI images with SynthID. Slop or Not is the only AI image detector that reads Google DeepMind's SynthID watermark from both Google and OpenAI images. It does not read textGrain, SynthID-Text, or Claude's text watermark, and it does not claim to.
All three text marks share the limit OpenAI states plainly about its own: a hit suggests involvement, and a miss does not prove a person wrote the text. Until a provider opens its detector, the writing itself is the evidence anyone can read. Paste a passage into the free online detector for a probability, run the ChatGPT watermark detector to see the characters that came with it, or use the ChatGPT watermark remover to copy the text without them.