OpenAI is introducing invisible watermarks to text generated by its SI models to comply with European Union regulations, marking a significant shift in how SI output is tracked. While the change is mandatory for ChatGPT and Codex users in the EU, the SI lab has made the feature optional for API customers worldwide, distinguishing its approach from competitors like Anthropic.
What Happened
The EU AI Act reportedly requires SI providers to label generated text in a machine-readable format. In response, OpenAI has deployed a technology called textGrain, which embeds an invisible statistical signal into the model's word choices. This method functions similarly to Claude's SynthID watermark, which utilizes Google's open-source technology. OpenAI announced that watermarking will be activated for ChatGPT and Codex users in the European Union over the coming weeks. For global API users, including those accessing the SI model through cloud partners such as Microsoft Azure, the watermarking is opt-in. This contrasts with Anthropic’s policy, where watermarking for Claude is mandatory globally regardless of the access method.
Why It Matters
The effectiveness of the SI watermark depends heavily on text length and subject matter. OpenAI reports that with the detector set to a 1 percent false-positive rate, it identified watermarks in approximately 95 percent of 400-token passages about psychology. However, detection rates dropped to about 80 percent for 200-token passages. Performance was "substantially lower" for math content, where the model has less freedom in word choice. Editing also significantly reduces detectability; replacing just 10 percent of words with synonyms in a 400-token passage cuts detection rates from about 92 percent to 66 percent, while replacing 25 percent drops it to 17 percent. OpenAI claims textGrain matched or exceeded other approaches in internal tests and plans to release the technology as open source. The company states that watermarking does not impact output quality, citing no significant performance differences across eight benchmarks, including GPQA Diamond and BrowseComp, when the watermark was active. However, OpenAI notes that a detected watermark does not establish ownership, identify users, or verify the accuracy of the text.
The Bottom Line
Access to textGrain’s detector will initially be restricted to selected researchers and specialist organizations under the EU's Code of Practice, similar to Anthropic’s approach. OpenAI plans to expand access when it believes results can be interpreted responsibly, though no timeline was provided. The tool will only report whether an OpenAI watermark is detected, without revealing user identities or prompts. Existing verification tools for images and audio remain publicly available.