AI

ChatGPT Gets the Text Watermark OpenAI Shelved in 2024, but Only in the EU

Adrian Kessler
Add us on Google

OpenAI spent a long time explaining, in public, why it would not put a watermark on ChatGPT’s words. Now it is putting one there anyway. The technology has not changed its mind for it. A law with a deadline and a fine attached has.

The company says text that ChatGPT and Codex produce for users in the European Union will carry an invisible statistical signature, phased in over the coming weeks across every plan. Everywhere else the same mark exists only as a switch in the developer API, and that switch ships in the off position. The line OpenAI has drawn runs along the border of the jurisdiction that can penalise it.

How the ChatGPT watermark works

The method, called textGrain, stamps nothing visible onto the output. When several next words would fit a sentence about equally well, a secret key tips the choice toward one of them. One nudge means nothing. Hundreds of them across a passage form a pattern that a detector holding the key can test for, and because the signal lives in the words themselves, it survives copy and paste. OpenAI wrote the technical report with researchers from the University of Pennsylvania and Yale. It reports no meaningful cost to quality: on the Artificial Analysis Intelligence Index, watermarked output scored 49.76 against 49.57 without the mark.

The tool OpenAI already had

None of this is new inside OpenAI. In the summer of 2024 the Wall Street Journal reported that the company had a working text watermark, rated 99.9% effective in internal documents, and was holding it back. OpenAI answered that it was taking “a deliberate approach.” Its stated reasons were technical and social: the method was “trivial to circumvention by bad actors” through translation or rewording with another model, and it could stigmatise AI as a writing aid for non-native English speakers. TechCrunch, reporting this week’s announcement, recalls a third reason from that period: concern that users would move to rivals that did not watermark.

Read against that record, the new rollout shows which of those worries OpenAI has actually dealt with. The circumvention problem is still there, in the company’s own figures. The commercial one has been fenced into a single market.

OpenAI’s numbers, not its critics’

Under good conditions, at a 1% false-positive rate, the detector catches roughly 80% of watermarked passages of 200 tokens and about 95% at 400. Swap 10% of the words for synonyms and detection falls from 92% to 66%. Swap a quarter and it drops to 17%. Short replies, maths and translated text are hard to catch at all. OpenAI itself warns that strong performance under ideal conditions “does not guarantee reliable detection in everyday use,” and that a missing watermark proves nothing about human authorship. It also says the mark does not identify the user.

That makes textGrain a usable signal against a lazy copy-paste and a weak one against anyone willing to spend a minute editing. In a bloc that reads and writes across many languages, the translation gap is not a footnote.

Why the EU, and why now

The legal driver is Article 50 of the AI Act, whose transparency rules took effect on August 2. It requires providers of generative systems to mark synthetic text, audio, images and video in a machine-readable way and to provide a detection mechanism. Systems already on the market before that date, ChatGPT among them, have until December 2 to comply. Violations can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher, according to an analysis by the law firm Cooley.

Two details show how closely the rollout tracks the obligation rather than a principle. The first is the detector. The law asks for a detection mechanism; OpenAI has built one and handed it only to approved researchers and expert organisations, who have to apply. The company says it will widen access “when we believe results can be interpreted responsibly,” as The Decoder reports, and has given no timeline. A teacher or an editor in Lisbon or Warsaw holding a suspicious text cannot check it today.

The second is the map. Anthropic, which began watermarking Claude’s text in August, applies its mark globally regardless of how people reach its models, and took backlash from some users for it. OpenAI chose the opposite: on by default where a regulator can fine, opt-in for developers elsewhere, no worldwide default at launch. If the old fear of users drifting to unmarked rivals had gone away, there would be little reason to draw the map this way.

What comes next

OpenAI says it will release textGrain as open source and that it matches or beats approaches such as Google‘s SynthID. Both claims become testable once the code is public. The question for Brussels is narrower: whether a mark that fades under light editing, read by a detector almost nobody can run, meets a rule written so that other systems can recognise AI text.

After December 2, the only ChatGPT users whose words carry OpenAI’s signature by default will be the ones whose regulator can send the bill.

Tags: , , , ,

Add us on Google

Discussion

There are 0 comments.