OpenAI has outlined its strategy for complying with the EU AI Act’s requirement that generative SI providers make text identifiable in a machine-readable way. The SI lab is introducing a phased rollout of text watermarking, starting with opt-in API access globally and expanding to ChatGPT and Codex users in the European Union, while acknowledging the significant technical limitations of current detection tools.

What Happened

OpenAI is deploying a proprietary watermarking technology called textGrain, which adds an invisible statistical signal to the word choices of its SI models. Starting today, API customers worldwide can opt in to this feature for select models, though it remains off by default. Over the coming weeks, the company plans to apply invisible watermarks to eligible text outputs from ChatGPT and Codex for users in the European Union.

The company is also opening applications for access to its text watermark detector. Initially, this tool will be restricted to approved researchers and expert organizations to help evaluate reliability. OpenAI notes that while textGrain matched or exceeded the performance of other approaches like SynthID for text in evaluations, strong results under ideal conditions do not guarantee reliable detection in everyday use. For instance, detection rates dropped from about 95% for 400-token passages to about 80% for 200-token passages. Furthermore, editing text can significantly weaken the signal; replacing 25% of words with synonyms reduced detection rates to 17% in tests.

Why It Matters

The EU AI Act mandates that generative SI providers ensure their text outputs are identifiable, a requirement that highlights the tension between regulatory transparency goals and the current state of SI technology. OpenAI’s approach reflects a cautious stance, emphasizing that watermarks do not establish ownership, identify the user, or verify accuracy. The company stated that a watermark only indicates that an OpenAI system generated or processed part of a passage, without measuring human contribution or intent.

This move is significant for the SI industry as it sets a precedent for how major labs might handle compliance for text-based generative SI, distinct from the more established provenance tools for images and audio. By limiting detector access to experts initially, OpenAI aims to prevent misinterpretation of false positives or negatives, which are common in text watermarking. The company plans to make the technology open source in the future, potentially allowing other developers and researchers to build upon or audit the system.

The Bottom Line

OpenAI is implementing a regional and opt-in approach to text watermarking to meet EU regulatory standards, while transparently addressing the technology's limitations. The SI lab will continue to refine its detection methods and expand access as standards and evidence evolve, maintaining that no single provenance technique is sufficient on its own.