TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/Articles/OpenAI’s textGrain Turns the EU’s Text-Marking Rule Into a Detector Only Approved Experts Can Run
Articles

OpenAI’s textGrain Turns the EU’s Text-Marking Rule Into a Detector Only Approved Experts Can Run

OpenAI will watermark ChatGPT and Codex text in the EU and offer an API opt-in, but its own charts show 36.5 percent detection for 200-token math and the detector is gated.

October 6, 2026 14 Min Read
30

On October 5, OpenAI said it will add an invisible statistical watermark, called textGrain, to eligible ChatGPT and Codex text in the European Union over the coming weeks. API customers anywhere can opt in from the same day for select models, and the setting stays off by default. The detector that reads the mark is not public: at launch it goes only to approved researchers and expert organizations that apply.

Table Of Content

  • What OpenAI Switched On, and Where
  • How textGrain Works, According to the Technical Report
  • Generation: Keyed Randomness With a Budget
  • Detection: A Keyed Test With a Known Null
  • Why the Key Decides Who Can Run the Detector
  • What the Charts Show
  • Length and Subject Matter
  • A Caveat in the Chart’s Own Note
  • Edits
  • What a 1 Percent False-Positive Target Means at Volume
  • Output Quality
  • What the EU Code of Practice Says About Text
  • The Gate Is Allowed, With Conditions
  • The Interoperability Gap
  • How This Compares With Anthropic’s Rollout
  • What This Means for Teams Building on These Models
  • If You Ship Text to EU Users on OpenAI’s API
  • If You Plan to Use a Detector as Evidence
  • If You Scan for Hidden Characters
  • What to Watch Next

The post’s charts show why. At 200 tokens, the length above which the EU’s Code of Practice requires free-form text to be watermarked, OpenAI’s detector found the mark in 78.5 percent of watermarked psychology answers but only 36.5 percent of mathematics answers, at a false-positive target of 1 percent. The prose says only that detection was “substantially lower” for mathematics; the number sits in the data behind the chart. That gap is the story. The AI Act requires text to be “detectable as artificially generated or manipulated”, the Code lets providers restrict text detectors because they are less reliable, and OpenAI has now published enough to show how much less reliable.

This piece reads the post, the technical report, the final Code of Practice and Anthropic’s own rollout side by side. The text detector is gated, so I could not run it. Every number below comes either from OpenAI’s published charts or from my arithmetic on them, and I say which is which.

What OpenAI Switched On, and Where

The post describes four surfaces with four different defaults.

Surface What OpenAI says Default
ChatGPT and Codex, EU users on all plans “Over the coming weeks, we will introduce text watermarking to eligible ChatGPT and Codex users across all plans in the EU only.” On for eligible EU users once rolled out. OpenAI is “not making text watermarking a global default at launch”.
API, customers worldwide “Starting today, API customers globally will be able to opt in to text watermarking for select models.” Cloud partners are to follow “in the coming weeks”. Off: “Text watermarking will remain off by default in the API.”
Text detector Approved researchers and expert organizations can apply, with access “initially granted on a case-by-case basis”. The API documentation says text verification is “currently available only to approved organizations including AI research and academic institutions”. Not public at launch.
Images and audio C2PA Content Credentials on images and SynthID watermarks on images and audio, checkable at openai.com/verify and through the Content Provenance API. Public.

Three things the post does not say. It does not list the “select models” for the API opt-in. It does not say whether EU ChatGPT users can turn the watermark off. And it gives no date or condition for ending the detector restriction beyond a promise to “expand detector access when we believe results can be interpreted responsibly”.

It also does not mention the two EU dates that frame the rollout. The AI Act’s marking duty began to apply on August 2, 2026, and providers of systems already on the market before that date have until December 2, 2026. That grace period is a paragraph (Article 111(4)) added to the Act by Regulation (EU) 2026/1744, the Digital Omnibus on AI, dated July 8 and published in the Official Journal on July 24. OpenAI says only that it is sharing its approach “in response to the EU AI Act”. A rollout “over the coming weeks” from October 5 leaves room before December 2, though the post does not say the two are linked. Our earlier piece on the Article 50 deadline covers the mechanics of the rule itself.

How textGrain Works, According to the Technical Report

OpenAI published a technical report the same day. It is a mathematics document rather than an evaluation: the abstract says it “provides the mathematical details of the textGrain watermark”, the report has no results tables, and its two figures are diagrams of the method. The post says the report “will be updated with additional details in the coming weeks”.

Generation: Keyed Randomness With a Budget

Like other statistical watermarks, textGrain steers each token choice with pseudorandom values derived from a secret key and the tokens that came before. The report couples the token to that keyed randomness through an optimal-transport problem, and it caps how much of the model’s sampling randomness the watermark may remove. That cap is an entropy budget, a fraction of the next-token entropy averaged over keys. The reason is practical. An older design, Gumbel-max watermarking, has a side effect the report spells out: “at a fixed context and key, it always selects the same token”, so “Repeated generation from the same prompt can therefore produce identical responses”. The report adds: “This matters when an application needs several distinct answers or solutions to the same prompt”.

Two limits are stated just as plainly. The budget bounds an average, and the report says the identity “does not impose the same entropy loss for every fixed key”. The solver is also numerical, so “the requested budget alone is not a guarantee for the numerical output”. The budget OpenAI actually deploys is not given.

The report says textGrain can run with speculative sampling when the draft and target models share a key, with a caution that “distributional equivalence alone does not establish a speedup”. For anyone running an inference stack, the practical point is that the watermark is applied while tokens are sampled, so it is part of the serving path rather than a step applied to finished text.

Detection: A Keyed Test With a Known Null

The report says the detector “requires only the generated text and the secret key and does not need to know the budget used during generation”. At each scored position the detector rebuilds the keyed table from the preceding tokens, reads the cost of the token it actually sees, and converts that to a score. Under the report’s idealized assumptions, each score for unwatermarked text has an average of 1, and the sum over n scored positions follows a Gamma(n, 1) distribution. The detector declares a watermark when the sum passes the 99th percentile (for a 1 percent false-positive rate). To keep repeated phrases from counting twice, the report says to “score only the first occurrence of each distinct context window”.

That null distribution is enough to compute how much evidence a passage must carry. This table is my arithmetic from the report’s null, cross-checked with a four-million-draw simulation (124.74, 234.41 and 448.05 for n = 100, 200 and 400, against 124.72, 234.36 and 447.99 computed directly).

Scored positions (n) 99th percentile of the summed score Average score a passage needs (unwatermarked text averages 1)
50 67.90 1.36
100 124.72 1.25
200 234.36 1.17
400 447.99 1.12

At 200 scored positions a watermarked passage must average about 17 percent above what unwatermarked text produces; at 400, about 12 percent. That is why detection climbs with length. Two cautions apply. The count n is scored positions, which can be fewer than tokens because repeated contexts are skipped. And the average score a deployed watermark actually reaches per token depends on the entropy budget, which is unpublished, so the table shows the bar and not OpenAI’s clearance of it.

Two sentences in the report matter for anyone reading the 1 percent figure. The false-positive rate is exact only “under these assumptions”, and the report adds: “A fixed deployed key and finite precision arithmetic require empirical calibration checks; the idealized null calculation does not by itself guarantee the same error rate for every key or application”. The report does not publish those checks.

Why the Key Decides Who Can Run the Detector

Because detection needs the secret key, whoever runs a textGrain detector either holds the key or has been trusted with it. Publishing the algorithm, which OpenAI says it plans to do (“We also plan to make the technology available in open source”), does not publish the key. My reading is that this pushes a keyed text watermark toward the third of the Code’s three delivery options, a cloud service reached through an API, rather than a public specification or downloadable software, which would require handing the key to third parties.

What the Charts Show

I read the numbers below from the chart data embedded in the page; the rendered charts show the same values. All rates are at a target false-positive rate of 1 percent.

Length and Subject Matter

Length Psychology answers detected Mathematics answers detected
200 tokens 78.5% 36.5%
300 tokens 89.7% 52.0%
400 tokens 94.3% 60.8%

The prose rounds the psychology figures to “about 80%” and “about 95%”. Read as misses, psychology at 200 tokens loses one watermarked answer in five (21.5 percent), and mathematics at 200 tokens loses nearly two in three (63.5 percent). Mathematics at 400 tokens (60.8 percent) is still below psychology at 200 (78.5 percent). OpenAI’s own explanation is that mathematics offers “less flexibility in word choice”, which fits Anthropic’s description of watermarking being “sparser on factual passages”, where fewer word choices can change without hurting accuracy.

How long is 200 tokens? With tiktoken’s o200k_base encoding, the first 200 tokens of OpenAI’s own post covered 173 words, and the first 400 covered 340. The post does not name the tokenizer behind its evaluations, so treat that as a few short paragraphs.

A Caveat in the Chart’s Own Note

The chart description says: “Denominators vary with text-length eligibility. Mathematics uses one response per prompt; Psychology uses ten responses per prompt with responses pooled.” Each point therefore rests on a different set of responses, and the two subjects are not sampled the same way.

Edits

Length Unedited 10% of words replaced 25% of words replaced
200 tokens 66.3% 37.8% 7.0%
300 tokens 84.8% 56.3% 11.6%
400 tokens 92.0% 65.8% 17.2%

The prose gives the 400-token row (about 92 percent unedited, then 66 percent and 17 percent after the two edits); the chart adds the shorter rows, all from the same pool of 600 responses. At the Code’s 200-token floor, about one marked passage in three is missed with no editing at all, more than three in five are missed after 10 percent of words are replaced, and 93 percent are missed after 25 percent.

The Code’s robustness measure lists typical operations that marking and detection solutions should withstand, including “lexical substitution” and, among desynchronization mechanisms, “paraphrasing, translation cycles”. The post tests word replacement only, on English responses, and lists translation as work still to come: “studying how watermarks withstand editing and translation”. In August 2024, OpenAI described an earlier text-watermarking method of its own as “highly accurate and even effective against localized tampering, such as paraphrasing”, but “less robust against globalized tampering”, naming translation systems, rewording with another generative model, and an insert-and-delete-a-character trick. Those are different methods and different tests, so this is not evidence that textGrain is weaker. It is a reminder that “robust” is a curve, not a yes or no.

What a 1 Percent False-Positive Target Means at Volume

The same 2024 post warned that “applying it to large volumes of text would lead to a large number of total false positives”. The arithmetic is simple. At a 1 percent false-positive rate, a check run on one million human-written passages flags 10,000 of them. Whether a hit means anything then depends on how many of the checked passages are OpenAI text at all. This table is my arithmetic, built from OpenAI’s published detection rates and the nominal 1 percent rate. The prevalence levels are assumptions for illustration, not measurements. Each cell shows the share of detector hits that are real.

Passages checked 1% are OpenAI text 5% are OpenAI text 20% are OpenAI text
200-token mathematics (36.5% detected) 26.9% 65.8% 90.1%
200 tokens, edit-chart pool, unedited (66.3% detected) 40.1% 77.7% 94.3%
400-token psychology (94.3% detected) 48.8% 83.2% 95.9%

If one checked passage in a hundred is OpenAI text, a hit on a 200-token mathematics answer is right about 27 percent of the time. The technical report’s caution about “empirical calibration checks” applies here too, because the 1 percent is nominal. OpenAI’s stated reason for the gate is the same concern in one sentence: “Given the risk of missed watermarks and false positives, we are not making it publicly available at launch”.

Output Quality

OpenAI says that across the benchmarks it uses to assess Astra it does “not see meaningful performance differences with and without watermarking”. Its table shows eight scores. Five rose with the watermark and three fell. The largest rise was 3.1 points (Terminal-Bench Science 0.1, 56.90 to 60.00) and the largest fall was 1.1 points (DeepSWE v1.1, 72.80 to 71.68). The post gives no run counts or confidence intervals, so a reader cannot tell whether a one-point swing is signal or run-to-run noise. The claim that textGrain “matched or exceeded the performance of other approaches we tested, including SynthID for text” comes with no comparison table, and the technical report has no evaluation section.

What the EU Code of Practice Says About Text

Article 50(2) of the AI Act asks providers of generative systems to ensure that outputs “are marked in a machine-readable format and detectable as artificially generated or manipulated”, and that their technical solutions are “effective, interoperable, robust and reliable as far as this is technically feasible”. The Code of Practice on Transparency of AI-generated Content is voluntary, but the Commission and the AI Board have confirmed it is an adequate tool for showing compliance. About 190 organizations had signed by the end of July, and the Commission’s note on the signatories lists OpenAI, spelled “Open AI”, among its examples for Section 1, the section for providers. OpenAI’s post says the detector access follows the Code. The table sets the final Code’s text rules beside what the post reports.

Topic What the Code says What OpenAI’s post says
Where text watermarking starts “For free-form text longer than 200 tokens, watermarking still needs to be applied, even though it may have lower reliability compared to that of watermarking very long text”. Both charts start at 200 tokens. There the edit chart’s unedited detection rate is 66.3 percent.
Restricting the text detector Providers “may restrict access to detection mechanisms associated to watermarking techniques for free-form text to the extent that they have a lower level of reliability and robustness”. Approved researchers and expert organizations, case by case, citing “the risk of missed watermarks and false positives”.
How long a restriction can last “Any restriction to the access will be limited in time until more reliable and robust detection mechanisms have emerged”. No date or trigger. OpenAI expects to “revisit each part of this approach as the technology, standards, and evidence evolve”.
Who must get access Free access “without any restriction on the volume of requests” for “competent market surveillance authorities and other regulators, law enforcement authorities, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions, and civil society organisations”. Names “approved researchers and expert organizations”. It does not say whether regulators, media or fact-checkers are covered, or whether access is free of volume limits.
What robustness covers Typical operations include “lexical substitution” and “paraphrasing, translation cycles”, plus attacks such as “copying, removal, regeneration, and modification”. Word replacement at 10 and 25 percent, English only. Translation is future work.
Marking at the model level Model providers “are encouraged to implement watermarking at the model level” to help downstream providers. API opt-in for select models, off by default, with cloud partners to follow.
Signed detection results Results can be downloaded “in a digitally signed format, including at least a hash of the content submitted for detection, a URL or other identifier of the detection solution, and a timestamp”. Not mentioned. The tool is said to report whether it detects an OpenAI watermark, without identifying the user.

The Gate Is Allowed, With Conditions

Because free-form text cannot carry metadata, the Code treats a watermark alone as enough for text: “a single-layer of marking as described in Sub-measure 1.1.2 is considered sufficient”. So for text there is no second layer to fall back on. The Code accepts the trade-off openly: “To compensate for the potential lower reliability of watermarking for free-form text, access to the corresponding detection solution may be restricted to verified expert users”. OpenAI’s gate therefore follows the Code’s design. What the post leaves open are the two parts that bound it: the time limit, and the list of expert users who must be served.

The Interoperability Gap

Article 50(2) also asks for “interoperable” solutions, and the Code is candid that there is little to interoperate with yet: “At the time of publication of this Code, relevant interoperability standards and/or best practices are yet to be developed, except for digitally signed metadata”. For a keyed text watermark that has a concrete meaning. OpenAI’s provenance documentation, the same page that takes text-detector applications, says the tool “doesn’t currently detect content generated by another company’s AI model”, and Anthropic says a check with its key cannot tell whether text came from a different AI, because even a watermarking competitor “would have a different key”. A newsroom or school that wants to check a suspect passage has to apply to each vendor’s detector separately, and each answers only about its own vendor.

How This Compares With Anthropic’s Rollout

Anthropic’s page on its watermark, dated August 14, takes the opposite line on geography: “We’re applying watermarking globally at launch because we don’t yet have a durable way to scope it by region”. OpenAI scopes ChatGPT and Codex to the EU and says that approach “gives us room to learn from real-world use and feedback”. We covered the Anthropic announcement in August, when the detection API was described as coming “soon”. The page now says a detection API is in private preview, “currently available to eligible organizations as required under EU law (such as regulators, law enforcement, media, fact-checkers, independent researchers, educational organizations, and EU civil society groups)” and to “enterprises who are similarly obligated to verify watermarking for their own compliance with the Act”.

Anthropic’s list closely follows the Code’s categories and adds enterprises with verification duties. OpenAI’s launch post names researchers and expert organizations and does not mention enterprises as detector users. The methods also differ: Anthropic says its mark is “a version of the SynthID-Text approach”, while OpenAI built textGrain and says it did at least as well as SynthID for text in its own tests, without showing the comparison.

What This Means for Teams Building on These Models

If You Ship Text to EU Users on OpenAI’s API

OpenAI says the opt-in “lets customers decide how watermarking fits their transparency obligations and the experiences they provide to users”. The Code says that relying on an upstream marking technique is “without prejudice to the Signatories’ own responsibility under the AI Act and the Code to ensure that the outputs of their AI systems are suitably and compliantly marked”. The Commission notes that the legal obligation “applies only to providers of AI systems”. On the Code’s wording, using an upstream provider’s marking tool does not hand your own responsibility to that provider, and whether your product counts as the provider of an AI system is a question for counsel. The switch is off by default, so nothing changes in your integration unless you change it, and you will need to find out which models are supported, because the post does not list them.

If You Plan to Use a Detector as Evidence

OpenAI’s own list of what a text watermark does not tell you is blunt: “The absence of a detected watermark does not prove human authorship”, and a watermark “does not measure human contribution” or identify the user. Add the numbers above: short or mathematical text is missed often, light editing cuts detection sharply, and a hit at low prevalence can be wrong more often than people expect. On these numbers, hiring, grading and moderation workflows should not treat this signal as a verdict.

If You Scan for Hidden Characters

OpenAI describes the signal as living in “the model’s word choices”, so there are no extra characters in the text. The invisible-character scanner from our tutorial on ASCII smuggling and Trojan Source should find nothing in a textGrain passage, and stripping zero-width characters would not be expected to remove the mark.

What to Watch Next

  • The technical report update. OpenAI says it will add details “in the coming weeks” and plans an open-source release. Evaluation tables, the deployed entropy budget and the SynthID comparison are the missing pieces.
  • Detector approval. Who is approved, whether regulators, media and fact-checkers are included, and when the restriction ends.
  • API details. Which models are supported, whether EU ChatGPT users can opt out, and when cloud partners add the setting.
  • Translation and paraphrase results. OpenAI says it is studying them. They are the operations its 2024 post named as the weak points of its earlier method.
  • December 2. The end of the grace period for systems already on the market, and the signatory task forces the Commission said would launch in September 2026.
  • Anthropic’s expansion. Its page says access to the detection API will expand over time.

What I could not check: I could not run textGrain or the gated detector, so I cannot say whether the nominal 1 percent false-positive rate holds on real human text. I read the post and the data inside its charts, the technical report, the final Code of Practice, the text of Article 50(2) and the Digital Omnibus, Anthropic’s page and OpenAI’s 2024 provenance post, and computed the threshold and prevalence tables from those.

Tags:

AI RegulationAI WatermarkingContent ProvenanceEU AI ActOpenAI

Share

Marble statue of the Titan Atlas straining beneath the carved celestial sphere on his shoulders, the figure Atlassian is named after
Previous Post

Atlassian Warns That Eight Data Center Products Share One Critical, Unauthenticated File-Access Flaw

Overhead view of an athletics starting block, with two angled foot plates on a slotted metal rail, lying on a red running track
Next Post

How to Audit Python .pth Startup Hooks and Migrate to Python 3.15 .start Files

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Blue-lit server racks in a modern data center, illustrating the compute infrastructure behind the AI boom.
Articles

The AI Boom Is Spending Real Money Before Proving Real Returns

June 7, 2026
Technician working with a laptop beside server racks, representing enterprise AI retrieval infrastructure
Articles

Google’s Agentic RAG Push Makes Enterprise AI Less of a One-Shot Guess

June 7, 2026
A person with a laptop and smartphone, representing digital attention and AI-assisted work
Articles

AI Chatbots Are Making Attention a Design Problem

June 7, 2026
A customer-support representative wearing a headset against a dark studio background.
Articles

The Meta AI Support Hack Was a Plain Old Authorization Failure

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026