ChatGPT Text Watermark Explained: Who Gets It, and Can Anyone Detect It?
OpenAI says it will add an invisible watermark to ChatGPT text over the coming weeks, but only in the European Union. It covers every plan there, free included. Outside the EU nothing changes. There is no public detector: on October 5, 2026 access opened to approved researchers only, and the mark never identifies you.
If you have wondered whether anyone can tell ChatGPT wrote your email, OpenAI has now answered it, and the answer depends on where you live. On October 5, 2026 it published its approach to EU text provenance rules, confirming that it will add an invisible watermark to ChatGPT text. The catch is geographic: OpenAI is switching it on in the European Union only, and says in the same post that it is "not making text watermarking a global default at launch."
That is the opposite of the choice Anthropic made. Anthropic turned Claude's text watermark on worldwide in August because it did not have "a durable way to scope it by region." OpenAI has chosen the region and said why: a regional rollout "gives us room to learn from real-world use and feedback."
The second thing to know is that nobody can check your writing yet. The detector exists, but applications opened on October 5, 2026 to "approved researchers and expert organizations" only, case by case, and OpenAI says it is "not making it publicly available at launch."
Key Takeaways
- EU only, and not yet. OpenAI says that "over the coming weeks, we will introduce text watermarking to eligible ChatGPT and Codex users across all plans in the EU only." Outside the EU, nothing about your ChatGPT text changes.
- Every plan, including Free. OpenAI's phrase is "across all plans." There is no watermark-free tier to upgrade to, and no discount for accepting one.
- There is no public detector, and that is deliberate. Applications opened October 5, 2026 for approved researchers and expert organizations. OpenAI's reason: "Given the risk of missed watermarks and false positives, we are not making it publicly available at launch."
- The technology is called textGrain and it works by nudging the model's word choices, not by adding characters. OpenAI says it "matched or exceeded the performance of other approaches we tested, including SynthID for text," and that it plans to release it in open source.
- Editing breaks it fast. On 400-token passages, replacing 10% of words with synonyms dropped detection from about 92% to 66%; replacing 25% dropped it to 17%.
- Short text and maths barely carry it. At a 1% false-positive target, detection was about 80% on 200-token passages and 95% on 400-token passages for psychology content, and "substantially lower" for mathematics.
- It cannot identify you. OpenAI: a watermark "does not associate a person, organization, account, prompt, or conversation with the text."
- No watermark does not mean no AI. OpenAI says the absence of a detected watermark "does not prove human authorship."
- Developers get a global opt-in, off by default. From October 5, 2026, API customers anywhere can turn watermarking on for select models. It stays off unless they choose it.
- Images and audio were already covered, worldwide. Supported images get C2PA Content Credentials and an invisible SynthID watermark; supported audio gets SynthID. Anyone can check a file free at openai.com/verify, which does not check text.
- Quality does not move. OpenAI published watermarked and unwatermarked benchmark pairs for its Astra model that land within roughly a point of each other.
Who Actually Gets the ChatGPT Watermark
Three different groups, on three different timetables. The post sorts them explicitly, and the distinction matters more than the technology does, because only one of the three is an ordinary person typing into ChatGPT.
| Who you are | Is your text watermarked? | OpenAI's wording |
|---|---|---|
| ChatGPT or Codex user in the EU | Soon, on every plan | "Over the coming weeks, we will introduce text watermarking to eligible ChatGPT and Codex users across all plans in the EU only" |
| ChatGPT or Codex user outside the EU | No | "We are not making text watermarking a global default at launch" |
| API customer, anywhere | Only if they switch it on | "Starting today, API customers globally will be able to opt in to text watermarking for select models. Text watermarking will remain off by default in the API" |
| Using an OpenAI model through a cloud partner | Not yet | "We are also working with cloud partners to make watermarking available for OpenAI model outputs accessed through their services in the coming weeks" |
Two qualifiers in that first row are doing quiet work. "Eligible" is not defined anywhere in the post, so which models and which kinds of output are covered is not published. And "over the coming weeks" means that as of October 6, 2026 an EU reader's ChatGPT text is not marked yet. Neither gap has a vendor surface that fills it: OpenAI's own help centre article on provenance signals, the one the post links to for more information, still answered the question "Do you have plans to support text outputs?" in the future tense in its most recent capture before the announcement.
What Changes for You If You Are Not in the EU
Nothing, for now, and that is the honest answer rather than a reassuring one. OpenAI did not say "not yet" about the rest of the world so much as "not by default":
We are not making text watermarking a global default at launch. This regional approach gives us room to learn from real-world use and feedback.
A company that frames a rollout as learning is a company that expects to extend it. The thing to watch is not an announcement but the help centre article above: a "which countries" or "which plans" line appearing there is what turns this from an EU story into a global one.
One group outside the EU is affected straight away. If you use a product built on the OpenAI API, its developer can turn watermarking on from October 5, 2026 wherever they are. You will not be told, because this is a setting on their account, not yours.
What a ChatGPT Watermark Can and Cannot Prove
Much less than most people assume, and OpenAI spends a whole section of the post saying so. This is the most useful part of the announcement for anyone worried about being accused of using AI, so here it is as a table, in OpenAI's own terms:
| Question someone might ask | Can the watermark answer it? |
|---|---|
| Did an OpenAI system generate or process part of this? | Yes, as a signal, on a long enough passage |
| How much of it was the human's own work? | No. It "does not measure human contribution" |
| Who owns this text, or was its use allowed? | No. It "does not establish ownership or responsibility" |
| Who typed the prompt? | No. It "does not identify the user" |
| Is what it says true? | No. It "does not verify accuracy" |
| No watermark found, so a human wrote it? | No. Absence "does not prove human authorship" |
That last row is the one worth repeating to anyone running a classroom or a hiring process. OpenAI lists five ordinary reasons a genuinely AI-written passage comes back clean: it is too short, it was edited, it was translated, it came from an unsupported model, or it predates watermarking. A sixth is that it came from a different company's AI, which OpenAI's detector is not built to find.
How Reliable Is the Detection, in Numbers
Reliable on long, discursive writing and weak on everything else. OpenAI published its own evaluation figures rather than a general assurance, which is unusual and worth reading literally. All of these are at a target false positive rate of 1%:
| Condition | Detection rate |
|---|---|
| 400-token passage, psychology questions | about 95% |
| 200-token passage, psychology questions | about 80% |
| Mathematics questions | "substantially lower" than psychology, no figure given |
| 400 tokens, 10% of words replaced with synonyms | 92% down to 66% |
| 400 tokens, 25% of words replaced | down to 17% |
The pattern is the same one Anthropic described for Claude: a watermark lives in the gaps between equally good word choices, so text with one correct answer has nowhere to hide a signal. A 400-token passage is roughly 300 words, so a short answer, a quick rewrite or a maths solution is effectively untestable. OpenAI's own framing is blunt about the gap between the lab and real life: "strong performance under ideal conditions does not guarantee reliable detection in everyday use."
Those limits are the stated reason the detector is not public. OpenAI says restricting it to researchers and expert organizations is so they "can help us evaluate reliability and responsible uses."
Does It Make ChatGPT Worse, Slower or Dearer?
No, and OpenAI published paired benchmark scores instead of a promise. The comparison is on Astra, which it calls "our latest frontier model," watermarked against unwatermarked:
| Benchmark | Unwatermarked | Watermarked |
|---|---|---|
| Artificial Analysis Intelligence Index | 49.57 points | 49.76 points |
| AutomationBench | 34.09% | 34.86% |
| DeepSWE v1.1 | 72.80% | 71.68% |
| Terminal-Bench 4.0 | 53.90% | 56.06% |
| Terminal-Bench Science 0.1 | 56.90% | 60.00% |
| BrowseComp | 87.92% | 87.35% |
| HealthBench Professional | 64.27% | 64.60% |
| GPQA Diamond | 94.44% | 93.94% |
Scores move in both directions and OpenAI's reading is that it does "not see meaningful performance differences with and without watermarking." Nothing in the post attaches a price or a speed cost to watermarking, and the mechanism gives it no room to: changing which word gets picked does not add words.
ChatGPT Versus Claude: Who Marks What
The two biggest consumer AI companies have now taken visibly different paths on the same EU rule, and the difference decides whether it touches you at all.
| ChatGPT (OpenAI) | Claude (Anthropic) | |
|---|---|---|
| Text watermark in place | Not yet, EU only when it arrives | Yes, on five models |
| Where it applies | European Union only at launch | "Wherever Claude is offered, worldwide" |
| Plans covered | "All plans" in the EU | All plans, including Free, via Sonnet 5.5 |
| Technology | textGrain, OpenAI's own | SynthID-Text, from Google DeepMind |
| Detector for text | Approved researchers and expert organizations, from October 5, 2026 | Private preview since September 1, 2026, named eligibility list |
| Public tool for files | openai.com/verify, images and audio | claude.com/check-files, files |
| Published deadline for older models | None | December 2, 2026 |
The practical reading: if you are outside the EU and you care about this, Claude is currently the one marking your text and ChatGPT is not. If you are inside the EU, both will mark it, and neither will tell anyone who you are. Our full page on Claude's text watermark covers the Anthropic side in detail, including which models carry it.
Images and Audio Were Already Marked, and You Can Check Those Yourself
This is the part that already works, everywhere, for free. OpenAI's provenance help centre article sets out what carries what:
| Content type | Provenance signals | Can you check it? |
|---|---|---|
| Images from ChatGPT, Codex or the API | C2PA Content Credentials and SynthID watermark | Yes, free at openai.com/verify |
| Audio from OpenAI tools | SynthID watermark, inaudible | Yes, same tool |
| Text | textGrain, EU rollout pending | No public tool |
OpenAI also documents a trick most people do not know: you can ask for a visible watermark. Its help centre says you can "request a visible disclosure on images generated with ChatGPT, Codex, and the OpenAI API by prompting the model to include one," and gives the example prompt "Include a visible OpenAI watermark in the image." That is separate from the invisible signals and is useful if you want a picture to announce itself.
Two caveats the same article is careful about. A result from the checker confirms a signal is present, not that the content is "accurate, unedited, legally owned, or presented in the correct context," and it does not say who made it. And a clean result is weak evidence: metadata gets stripped by uploads and conversions, and watermarks degrade under compression, cropping and editing. Google does the same thing on the Gemini side, which our guide to Nano Banana and Gemini image generation covers.
Should You Change Anything?
Do not change what you pay for. Every ChatGPT plan is treated the same, in the EU and out of it. If you are weighing a subscription for other reasons, which AI chatbot is worth paying for covers what actually differs, and the best free AI chatbot covers whether you need to pay at all.
If you use ChatGPT to help with your own writing, there is nothing here to worry about. Editing, proofreading and short answers carry little or no watermark, the detector is not public, and nothing about you is recorded even when it is detected.
If you submit long AI-drafted text where it is not allowed, the EU rollout is the one to watch. A full draft is the case the watermark is built for, and 300 words is enough for it to register. Outside the EU, this specific risk has not arrived.
If you are being accused of using AI, read the limitations section. OpenAI itself says a watermark "does not measure human contribution" and "cannot distinguish" how much of a passage was yours, and that no watermark does not prove a human wrote it. Those are the vendor's own words, and they are more useful to you than any detector score.
If you build on the OpenAI API, this is a decision you now have to make. Watermarking is off by default and opt-in globally from October 5, 2026, so it is yours to switch on, and your users will not know either way unless you tell them.
The bottom line: ChatGPT text watermarking is real, free, invisible, anonymous, and for now European. It will cover every plan in the EU within weeks of October 5, 2026 and no plan anywhere else. Nobody outside a short list of approved researchers can check a passage, OpenAI's own numbers show that a light edit cuts detection by a third, and the company says in writing that a clean result proves nothing about who wrote what.
Sources
- OpenAI, Our approach to EU text provenance rules, October 5, 2026, Safety. Read October 6, 2026.
- OpenAI, textGrain: entropy-calibrated watermarking for language model text, technical report linked from the post, which OpenAI says "will be updated with additional details in the coming weeks."
- OpenAI, Provenance signals (Content Credentials, SynthID) in OpenAI-generated content, help centre. Read October 6, 2026 from the capture taken 2026-10-05 01:56 GMT, about thirteen hours before the announcement; it still described text support as a goal rather than a rollout.
- European Commission, Code of Practice on Transparency of AI-generated content, cited by OpenAI as the basis for case-by-case detector access.
- Anthropic, How Claude marks AI-generated content, for the comparison column. Read September 28, 2026.
Read next
Keep up without the jargonClaude's Text Watermark Explained: Can Anyone Tell You Used Claude?
Anthropic hides an invisible watermark in the text Claude writes, to comply with the EU AI Act. It costs you nothing and carries nothing about you. As of September 28, 2026 five models mark their text, and the newest of them, Sonnet 5.5, is on the free plan. Every listed model tags the files it generates. The rest are due by December 2, 2026.
Nano Banana Explained: Is Gemini's Image Generator Free?
Nano Banana 2 is the image generator inside the Gemini app, and it is free: Google lists image generation on every plan, including no plan at all. What money buys is the Pro redo, 2K downloads and video. You must be 13 to generate images and 18 to edit them.
Which AI Chatbot Should You Pay For in 2026?
For most people, ChatGPT Plus at $20/month is the best-value paid chatbot. Choose Google AI Pro ($19.99) if you live in Google apps, or Claude Pro ($20, $17 on annual) if you mostly write and work with documents. Light users stay free, and college students should take Google's free year first.
The Best Free AI Chatbot in 2026
Google Gemini is the best free AI chatbot for most people in 2026: solid models, image generation, and Deep Research at no cost. But free ChatGPT now runs GPT-5.6 Luna with unlimited text chats, confirmed by OpenAI, so pick it if you chat in long sessions. Free Claude quietly gives you Sonnet 5.5, new on September 28, 2026.
Frequently Asked Questions
Is my ChatGPT text watermarked?
Only if you are in the European Union, and not yet. OpenAI says it will add the watermark to eligible ChatGPT and Codex output in the EU over the coming weeks. It states plainly that it is not making text watermarking a global default at launch.
Does it matter which ChatGPT plan I pay for?
No. OpenAI's wording is that the EU rollout reaches eligible ChatGPT and Codex users 'across all plans'. Free, Go, Plus, Pro and the business tiers are treated the same, so paying more does not buy you unwatermarked text.
Can my teacher or my boss check whether ChatGPT wrote this?
Not with a public tool. OpenAI opened detector applications on October 5, 2026 but limited access to approved researchers and expert organizations, case by case. It says it is not making the detector publicly available at launch, given false positives and missed watermarks.
Can I get around the watermark by editing the text?
Editing weakens it a lot. In OpenAI's own evaluation of 400-token passages, swapping 10% of the words for synonyms cut detection from about 92% to 66%, and swapping 25% cut it to 17%. Short answers and maths are barely detectable to begin with.
Does the watermark identify me?
No. OpenAI states the watermark does not associate a person, organization, account, prompt or conversation with the text, and that the detector reports only whether an OpenAI watermark is present without revealing the user or their conversations.
Does watermarking make ChatGPT's answers worse?
OpenAI published benchmark pairs saying no. On its Astra model, watermarked and unwatermarked scores land within about a point of each other on eight benchmarks, moving up on some and down on others. Nothing about your price or speed changes either.
What about images and audio from ChatGPT?
Those are already marked, worldwide, and you can check them yourself for free. Supported images carry C2PA Content Credentials plus an invisible SynthID watermark; supported audio carries SynthID. The public checker is at openai.com/verify, and it does not check text.