What’s trending in AI on 5 October 2026: The text you get from ChatGPT is about to carry a fingerprint you cannot see. Today OpenAI unveiled textGrain, an invisible watermark built into the way its models choose words. API customers anywhere in the world can switch it on from today, and in the coming weeks it will be applied by default to ChatGPT and Codex output for users in the European Union, on every plan. The move answers Article 50 of the EU AI Act, whose transparency rules took effect on 2 August and require AI providers to make generated content detectable by machines. Anthropic and Google already mark Claude and Gemini text. On the same day, OpenAI confirmed that ChatGPT will start testing visual ads beside generated images in the US later this month, backed by a long list of ad-measurement partners. This post explains how the watermark works, what it can and cannot prove, who has to do what under the EU rules, what the ads change, and a role-by-role action list for marketing, legal, HR and IT teams.
Key takeaways
- ChatGPT text in the EU will be watermarked by default. The rollout to ChatGPT and Codex for EU users comes in the next few weeks. Elsewhere, API customers can opt in from 5 October; the setting is off by default.
- It works well on long, untouched prose. OpenAI reports roughly 80% detection on 200-token passages and about 95% on 400 tokens, with around a 1% false-positive rate, on its psychology test set.
- Light editing weakens it fast. Replacing a quarter of the words cut detection to about 17%, and translation removes the signal entirely. Code, maths and short text are weak spots.
- A watermark is not a lie detector. It cannot identify the user, reveal the prompt, prove ownership, or prove that unmarked text was written by a human.
- Ads are coming to ChatGPT’s image tool. A US test of labeled visual ads starts later in October, with conversion tracking through partners such as Hightouch, Tealium and LiveRamp. OpenAI says advertisers cannot see private chats.
1. What OpenAI announced
OpenAI’s new system is called textGrain. According to Unite.AI’s report on the announcement, it works in two phases. From 5 October, developers using the OpenAI API anywhere in the world can opt in to watermarking for a set of supported models. The setting is off by default, so each customer decides whether its own transparency obligations call for it. In the coming weeks, OpenAI will then turn watermarking on for ChatGPT and Codex output for users in the EU, across all subscription plans. OpenAI describes the regional approach as a way to learn from real-world use before going further.
Engadget notes that the EU rollout covers code as well as prose, since Codex is included, and that the watermark is invisible to readers. The company was candid about the technology’s limits. In Engadget’s account, OpenAI warned that “strong performance under ideal conditions does not guarantee reliable detection.” That caveat matters, and we come back to it below.
OpenAI is not first. Google has used its SynthID-Text watermark in Gemini, and TechCrunch reported on 11 August that Anthropic would watermark text from its Claude models to comply with the same EU rules, with the mark embedded at the model level. Anthropic said the watermark “will travel with the text when it’s copied and pasted elsewhere,” and that it uses the C2PA provenance standard for files. AlphaSignal reports that Anthropic chose Google’s SynthID-Text approach.
2. How a text watermark actually works
Watermarking an image is easy to picture: you hide a pattern in the pixels. Text has no pixels, so the mark has to go into the words themselves. When a language model writes, it picks each next word from a list of plausible options. textGrain nudges that choice. According to AlphaSignal’s breakdown, it slightly favours a hidden set of words among the reasonable candidates, and it adjusts the strength of that nudge to the context. Where many words would fit, the bias can be stronger; where grammar or meaning leaves little choice, as in code, formulas or set phrases, it backs off so the output is not damaged.
No single word gives anything away. The signal only appears statistically, across many words, when a detector that knows the secret pattern counts how often the favoured choices show up. That is why length matters so much, and why editing is the watermark’s natural enemy. OpenAI says the effect on quality is small: AlphaSignal reports benchmark scores moving between about 1.1 points down and 2.2 points up with the watermark on.
3. How well it works, in numbers
OpenAI published unusually detailed test results, and they deserve a careful read. On psychology-style prose, Unite.AI reports detection of about 80% for 200-token passages (roughly 150 words) and about 95% for 400-token passages. AlphaSignal adds that the false-positive rate, where human or unmarked text is wrongly flagged, was around 1%. Mathematics content scored substantially lower, and code, formal text and short passages are listed as weak spots.
Then comes the editing test. With 400-token passages, replacing 10% of the words dropped detection from about 92% to 66%. Replacing 25% of the words dropped it to about 17%. Translating the text removed the signal entirely. In other words, a person who rewrites a ChatGPT draft in their own voice, or runs it through a translator, will usually wash the watermark out. Engadget reports OpenAI’s claim that textGrain matched or exceeded other approaches such as Google’s SynthID in testing, but every statistical text watermark shares this basic weakness.
4. What a watermark can and cannot prove
Expect confusion here in classrooms, HR departments and courtrooms. OpenAI itself spells out the limits, according to Unite.AI. A positive result means a passage probably came from a watermarked OpenAI model. It does not say how much a human contributed, who owns the text, which user generated it, or whether the content is accurate. Engadget adds that the detector does not identify users or reveal prompts.
The reverse is even more important. A negative result does not prove a human wrote something. The text may be too short, may have been edited or translated, may come from a model or region where watermarking is off, or may come from another company’s model entirely. Any policy that treats “no watermark found” as proof of human authorship will punish nobody who is careful and protect nobody who is honest. We saw the same trap with AI-detection tools in our look at the proof-of-human problem, and courts are already wrestling with similar questions about AI evidence and the deepfake defense.
| Question you might ask | Can a text watermark answer it? | Why |
|---|---|---|
| Did this long passage come from a watermarked OpenAI model? | Often, yes | Around 95% detection on 400 untouched tokens in OpenAI’s tests |
| Was this short message AI-written? | Not reliably | Short text carries too little signal |
| Was this text written by a human? | No | Missing watermark can mean editing, translation, another provider or watermarking switched off |
| Who generated it? | No | The detector does not identify users or reveal prompts |
| Is the content accurate or trustworthy? | No | A watermark says nothing about truth or quality |
| Who owns the copyright? | No | OpenAI says the mark cannot establish ownership or measure human contribution |
For now, there is also a practical barrier: you cannot check text yourself. AlphaSignal reports the detector is available only to approved researchers and expert organizations, granted case by case in line with the EU’s Code of Practice, with a possible open-source release later and no timeline. So any vendor that claims today to “detect ChatGPT watermarks” for you deserves hard questions.
5. The EU rule behind it: Article 50
The trigger for all of this is Article 50 of the EU AI Act, the law’s transparency article. Its obligations started on 2 August 2026. The guide published by artificialintelligenceact.eu splits them in two. Providers, meaning the companies that build generative AI systems, must mark synthetic output in a machine-readable way and make it detectable, and must make sure people know when they are talking to a chatbot. Deployers, meaning businesses that use these tools, must disclose deepfakes and must disclose AI-generated text published to inform the public on matters of public interest, unless a human has reviewed it and someone holds editorial responsibility.
Detail comes from a voluntary Code of Practice on transparency of AI-generated content, which Unite.AI says was published on 10 June, with about 190 signatories by the end of July. Paul, Weiss summarizes its core expectation: providers should use at least two machine-readable techniques, such as signed metadata plus an invisible watermark, though text under 200 tokens needs only one. The Commission has also designed standard EU icons for fully AI-generated and AI-modified content. Systems already on the market before August get a grace period to 2 December 2026, and watermark interoperability is expected by 2 February 2027. Fines for breaching the transparency rules can reach €15 million or 3% of worldwide turnover.
The key point for most businesses: the watermark is the provider’s job, but labelling is often yours. If you publish AI-written articles on public-interest topics without real editorial review, or use AI to create realistic images, audio or video of people, the disclosure duty sits with you, whatever the model does. That is consistent with the direction we flagged in our coverage of Japan’s voice-cloning ruling and the White House AI accord: rules are moving responsibility toward whoever publishes the content.
6. The other ChatGPT change: ads beside your images
On the same day, OpenAI announced a new visual ad format for ChatGPT. In its announcement, the company says ads with product images, usage scenes and inspiration will first be tested during image generation, starting later in October in the US with an initial group of advertisers. Ads will be clearly labelled and kept separate from the images users create. Quartz confirmed the timing. OpenAI says ChatGPT now reaches 1.2 billion people a week.
The bigger shift is behind the scenes. OpenAI now supports a Conversions API, reporting and click attribution through a long list of partners, including customer-data platforms Hightouch, Tealium and LiveRamp and attribution firms such as AppsFlyer, Adjust, Branch and Northbeam. DoubleVerify and Integral Ad Science are running brand-safety pilots. OpenAI states that advertisers cannot access private conversations, and offers “negative phrases” so brands can steer away from certain contexts without seeing chat data. That is a meaningful promise, but the plumbing now looks much like any other ad platform: your purchases on an advertiser’s site can be matched back to a ChatGPT ad click.
For businesses this cuts two ways. Marketers get a new, large channel; OpenAI cites early advertisers such as WeightWatchers reporting a lower cost per acquisition than paid search, though those are company-selected examples. Privacy and security teams get another reason to keep sensitive work off consumer ChatGPT accounts, a theme from our guide to shadow AI. And publishers who worried about AI answers draining traffic, covered in our post on AI starting to pay for the web, now face an AI assistant competing directly for ad budgets.
7. Who does what: a role-by-role action list
Rather than one long checklist, here is what each team should own.
Marketing and content
- Assume marking. If anyone on your team, or an agency, drafts with ChatGPT, Codex, Claude or Gemini from an EU account, treat unedited output as watermarked and detectable by approved parties.
- Write a labelling rule. Decide when you disclose AI involvement, and use the EU’s standard icons for EU audiences where they fit. Do not rely on heavy rewriting to “hide” AI use; that is the wrong goal and an unreliable one.
- Keep proof of human review. The Article 50 exemption for public-interest text depends on real editorial control. A simple log of who reviewed and approved each piece is your evidence. It also supports your generative engine optimization work, since trustworthy, reviewed content is what AI search tends to cite.
Legal and compliance
- Map your role. If you build a product on top of a model API and serve EU users, you may count as a provider with your own marking duty. Opting in to textGrain could be part of meeting it, but get advice on whether it is enough on its own given the two-technique expectation.
- Check the clock. Systems placed on the market before 2 August have until 2 December 2026 for machine-readable marking. Put that date in your compliance calendar now.
- Update contracts. Ask AI vendors and agencies which marking methods they use, whether marks survive their pipelines, and who carries labelling responsibility.
HR, managers and educators
- Ban one-signal decisions. No disciplinary or academic decision should rest on a watermark result or AI detector score alone, in either direction.
- Write the fair-use line. Say clearly where AI help is allowed, for example in job applications, internal reports or coursework, so a detection is not a surprise.
IT and security
- Decide on the API setting. Because textGrain is off by default for API use, choose deliberately per application and record why, especially for customer-facing EU deployments.
- Separate personal and business use. With ads and conversion tracking arriving in consumer ChatGPT, steer staff to business or enterprise plans for company work, and remind them that agents and assistants should run under the rules in our AI agent security guide.
8. What to watch next
Four things will show whether text watermarking becomes a real trust tool or a compliance checkbox. First, the actual EU switch-on date for ChatGPT and Codex, and whether users notice any change in output. Second, detector access: if OpenAI, Google and Anthropic keep detectors limited to vetted researchers, ordinary businesses and schools will not be able to check anything themselves, and if they open them up, expect a market for both checking and stripping marks. Third, the February 2027 interoperability target, which could produce a shared way to check text across providers. Fourth, whether watermarking spreads beyond the EU, now that OpenAI has made the API option global. On ads, watch which ChatGPT plans see them and whether the format spreads from image generation into ordinary answers.
Frequently asked questions
What is OpenAI textGrain?
textGrain is OpenAI’s invisible text watermark. It slightly favours a hidden set of words when the model writes, creating a statistical pattern that a detector can find across a long enough passage. Readers cannot see it.
Is ChatGPT text watermarked now?
For EU users, ChatGPT and Codex output will be watermarked by default in the coming weeks, on all plans. Separately, API customers worldwide can opt in from 5 October 2026.
Can a ChatGPT watermark be removed?
Editing weakens it sharply. In OpenAI’s tests, replacing a quarter of the words in a 400-token passage cut detection to about 17%, and translation removed the signal. Short texts, code and maths are also hard to detect.
Can I check whether text has an OpenAI watermark?
Not yet. The detector is limited to approved researchers and expert organizations, granted case by case under the EU Code of Practice. OpenAI has mentioned a possible open-source release later, without a timeline.
What does Article 50 of the EU AI Act require from businesses?
AI providers must mark generated content in a machine-readable, detectable way. Businesses that use AI must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, unless it had genuine human editorial review. The rules have applied since 2 August 2026.
Will ChatGPT show ads, and can advertisers see my chats?
OpenAI will test labelled visual ads during image generation in the US later in October 2026. It says advertisers cannot access private conversations, though ad clicks can be linked to conversions through measurement partners such as Hightouch, Tealium and LiveRamp.
Sources
- Unite.AI: OpenAI begins phased text watermarking under EU AI Act rules
- Engadget: OpenAI will add a digital watermark to text and code generated in the EU
- AlphaSignal: OpenAI ships textGrain to invisibly watermark AI text for EU compliance
- TechCrunch: Anthropic says it will watermark text generated by its AI models
- artificialintelligenceact.eu: The EU AI Act’s transparency rules, a practical guide to Article 50
- Paul, Weiss: EU finalises transparency rules for AI-generated content
- OpenAI: New ChatGPT ads format and measurement
- Quartz: OpenAI is testing visual ads inside ChatGPT’s image generation tool
