OpenAI's Invisible Ink Fades After a Few Edits
OpenAI is adding a hidden watermark to ChatGPT and Codex text in the EU. Its own numbers show the mark is caught about 92 to 95% of the time on long, untouched text, and only 17% of the time once a quarter of the words are swapped.

Imagine signing every letter you write in invisible ink. Good idea. Now imagine the ink smudges away when someone changes one word in four. That is roughly the picture OpenAI has just given of its own new text watermark.
On 5 October, OpenAI said it will add an invisible statistical watermark called textGrain to eligible ChatGPT and Codex text in the EU over the coming weeks. API customers anywhere in the world can opt in now. The detector that reads the mark is not public. Only approved researchers can use it.
The launch itself isn't the most interesting part. The numbers OpenAI published with it are, because they show where the watermark works and where it stops working.
What a text watermark actually is
You can hold a banknote up to the light and see its watermark. A text watermark works differently. There is no hidden character and no secret tag. It is a statistical pattern in the words the model picks. A single word proves nothing. Across hundreds of words, the pattern builds into something a detector can pick up.
So the signal depends on two things: how much text there is and which exact words were chosen. If you shorten the text or change the words, the pattern gets weaker.
The numbers OpenAI published
OpenAI set its detector to a 1% false-positive target. In other words, it should wrongly flag human-written text about once in a hundred tries. Here is what it reported:
- 200-token passage, unedited: detected about 80% of the time.
- 400-token passage, unedited: about 92 to 95%.
- 400 tokens, 10% of words swapped for synonyms: 66%.
- 400 tokens, 25% of words swapped: 17%.
- Translated or rewritten: OpenAI said on X that this "can completely remove the watermark."
Read down that list and it's like watching a fingerprint get wiped off a glass. On long text nobody has touched, the mark is strong. A light edit cuts detection by about a third. After a moderate edit, the kind a careful writer makes on a second pass, it gets caught fewer than one time in five. Put the text through a translator and the mark can disappear completely.
A watermark that only survives untouched text can tell you who wrote the first draft. It can't tell you who published the final one.
I respect OpenAI for publishing this. Plenty of companies would have led with the 95% and left the 17% out. Putting both numbers out there is the honest move, and it means everyone else can plan around what the watermark can really do.
Why short text is the weak spot
The shortest test was 200 tokens, and even untouched it was caught only about 80% of the time. Now think about how much published text is shorter than that: ad headlines, product blurbs, meta descriptions, social captions, email subject lines. A big share of commercial writing sits right where the statistical signal is weakest.
For a lot of everyday marketing copy, then, the watermark is neither protection nor proof. It can't reliably show that a piece of text was made by AI, and a missing watermark can't show that it wasn't.
The deadline behind the launch
The timing has a reason. The EU AI Act's Article 50 transparency duties have applied since 2 August 2026. Systems already on the market must comply by 2 December 2026, and detection interoperability is due by 2 February 2027. OpenAI isn't the only one doing this. According to PPC Land's August reporting, Anthropic marks Claude text wherever Claude is offered.
Many people will miss this next part: the rules split the job in two.
- The provider (OpenAI, Anthropic) marks the output. That is what textGrain does.
- The deployer, meaning the business that actually publishes the text, may still owe a visible label in some cases. An invisible watermark doesn't do that for you.
Industry guidance is already saying who holds that second duty. As PPC Land reports, IAB Austria's guide says agencies, not their clients, usually carry the labelling obligation. Whatever your role, regulators will want to know whether you labelled what needed a label, not whether a watermark was hidden somewhere along the way.
Why it matters
Think of the watermark as a factory seal on a jar. It's useful. But once the jar is opened, stirred and poured into a new dish, the seal says very little about what ends up on the plate. Responsibility moves to whoever served the dish.
Three takeaways for anyone who publishes with help from AI:
- Don't treat the watermark as your compliance. It is the provider's tool. It is not your label.
- Keep your own record of how AI was used, at the time you create the content. Note which model you used, how much a human edited, and whether a visible label applies. This is easy to write down while you work and nearly impossible to piece together months later.
- If you build on the API, choose the opt-in setting on purpose. The watermark is now a choice, so write down why you turned it on or left it off.
There is a bigger shift here. For years the question about AI text was whether it could be detected. OpenAI's own numbers give the answer: sometimes, under ideal conditions, on long and untouched text. Out in the real world, where words get edited, cut and translated, the proof that holds up is the record you keep yourself.
Invisible ink is clever. It just isn't something you can rely on when a few synonyms make it fade.
One signal a day. No noise.
A 3-minute read when something genuinely shifts in AI, automation, or defense tech. Free, most weekdays.
Free, most weekdays. No spam, unsubscribe anytime.Sources
- PPC Land: OpenAI text watermark detection drops to 17% after 25% of words change - https://ppc.land/openai-text-watermark-detection-drops-to-17-after-25-of-words-change/
Quick answers
What is OpenAI's textGrain watermark?
textGrain is an invisible statistical watermark that OpenAI is adding to eligible ChatGPT and Codex text in the EU over the coming weeks. It is a pattern in word choice, not a visible mark. API customers worldwide can opt in now, and only approved researchers can use the detector.
How reliable is OpenAI's text watermark?
On unedited text, OpenAI reports detection of about 80% for 200-token passages and about 92 to 95% for 400-token passages, at a 1% false-positive target. Swapping 10% of the words for synonyms drops detection to 66%, swapping 25% drops it to 17%, and OpenAI says translation or rewriting can remove the watermark completely.
Does an AI watermark satisfy the EU AI Act labelling rules?
Not always. Under Article 50 the provider marks the output, but the business that publishes the content may still owe a visible label in some cases. A hidden watermark doesn't replace that visible label.
When do the EU AI Act transparency deadlines apply?
Article 50 transparency duties have applied since 2 August 2026. Systems already on the market must comply by 2 December 2026, and detection interoperability is due by 2 February 2027.