MikhbarMIKHBAR
Artificial Intelligence

OpenAI Details Text Watermarking Approach for EU AI Act

OpenAI is rolling out a phased text watermarking approach to meet EU AI Act requirements, introducing its textGrain technology, API opt-in capabilities, and initial detector access for approved researchers.

OpenAI Details Text Watermarking Approach for EU AI Act

Responding to EU AI Act Requirements

OpenAI has shared its approach to text watermarking in response to the EU AI Act, which requires generative AI providers to make generated text identifiable in a machine-readable way. As detailed by [OpenAI News](https://openai.com/index/eu-text-provenance/), text watermarking and detection remain early technologies with significant limitations, and views about their benefits and responsible uses are still developing.

The company's phased approach reflects both the regulatory requirements and the inherent limitations of the technology. OpenAI emphasizes the importance of transparency regarding what a text watermark can and cannot reveal to users.

Safety cases for frontier AI training > Card image
Image related to the report from OpenAI News · Source: OpenAI News

Phased Rollout for APIs and European Users

Starting immediately, API customers globally can choose to opt in to text watermarking for select models, though the feature will remain off by default within the API. Over the coming weeks, OpenAI will also begin adding an invisible watermark to eligible ChatGPT and Codex text output generated within the European Union.

Concurrently, applications are opening for access to the text watermark detector. This access will initially be limited to approved researchers and expert organizations who can help evaluate and improve the technology.

It is important to note that these new measures apply strictly to text provenance. Existing verification tools for audio and images—such as the [openai.com/verify ⁠](https://openai.com/verify) web tool and the [Content Provenance API ⁠ (opens in a new window)](https://developers.openai.com/api/docs/guides/content-provenance)—will continue to remain publicly accessible for organizations evaluating media files.

Introducing the textGrain Technology

The underlying text watermarking technology, known as textGrain, embeds an invisible statistical signal into a model's word choices. The system's detector scans for this signal to determine whether a given passage contains an OpenAI watermark. Further technical insights can be found in the official [technical report ⁠ (opens in a new window)](https://cdn.openai.com/pdf/e9508624-d767-41b6-a26d-e34ca798ada6/textgrain-entropy-calibrated-watermarking-for-language-model-text.pdf), which is slated for updates with additional details in the coming weeks. OpenAI also plans to release the technology as open source to allow external developers to build upon it.

According to internal evaluations, textGrain matched or exceeded the performance of other tested approaches, including SynthID for text. However, strong performance under ideal conditions does not guarantee reliable detection during everyday use.

How we will do better for Australia — Cover
Image related to the report from OpenAI News · Source: OpenAI News

Detection Challenges and Limitations

OpenAI's evaluations highlight that detectors can encounter false positives—reporting a watermark where none exists—or false negatives—missing a watermark that is present. Shorter or more constrained text proves particularly challenging to detect reliably.

At a target false positive rate of 1%, the detector successfully identified watermarks in roughly 80% of 200-token passages, compared to about 95% of 400-token passages for content categories like psychology. Conversely, detection rates dropped substantially for subjects such as mathematics, where word choices offer less flexibility.

Furthermore, text editing can weaken the watermark signal significantly. In evaluations involving 400-token passages, replacing 10% of words with synonyms reduced the detection rate from approximately 92% to 66%, while replacing 25% of words drove the rate down to 17%.

Sam Altman’s remarks at the United Nations Security Council cover image
Image related to the report from OpenAI News · Source: OpenAI News

Interpreting Watermark Results

OpenAI stresses that text watermarks offer only a limited signal regarding the role its systems played in generating a passage. A positive detection result comes with several distinct boundaries on what can be inferred.

A watermark does not measure human contribution, meaning it cannot indicate how much human judgment, editing, or creativity went into a text. It also fails to establish ownership or legal responsibility, does not determine whether text use was lawful or disclosure was required, and does not identify the underlying user, account, or prompt associated with the passage.

Sources

Continue chronologically

Related entity coverage