# OpenAI adds invisible textGrain watermarks to ChatGPT and Codex text in the EU

> OpenAI will watermark ChatGPT and Codex text in the EU. The signal weakens sharply once text is edited, and it does not identify the user, which limits what it proves.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-07
Canonical: https://hisnlabs.com/en/news/openai-invisible-watermarks-chatgpt-codex-eu-textgrain

OpenAI is adding invisible watermarks to text produced by ChatGPT and Codex in the European Union over the coming weeks, BleepingComputer reported on 6 October 2026. The technique, called textGrain, changes word choices slightly to leave a statistical pattern that a detector can later test for [[1]](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-adding-invisible-watermarks-to-chatgpt-and-codex-text-in-the-eu/).

## Background

A text watermark is a hidden statistical signal embedded while a language model writes. It is not visible to a reader and is unrelated to the metadata of a file. According to the report, OpenAI has not named the EU law that requires the change, and it has not given a hard deadline [[1]](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-adding-invisible-watermarks-to-chatgpt-and-codex-text-in-the-eu/).

## What the report describes

API developers worldwide can switch watermarking on immediately; it is off by default. In the EU, ChatGPT and Codex output will be watermarked in the coming weeks. OpenAI is accepting applications for the detector, with initial access limited to approved researchers and expert organisations [[1]](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-adding-invisible-watermarks-to-chatgpt-and-codex-text-in-the-eu/).

OpenAI’s own testing, as reported, shows that edits weaken the signal. Replacing 10 per cent of words with synonyms reduced detection from about 92 per cent to 66 per cent, and replacing 25 per cent of words reduced it to 17 per cent. Detection also varies with subject and length: about 80 per cent for 200-token psychology answers against 95 per cent at 400 tokens, and lower for mathematics [[1]](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-adding-invisible-watermarks-to-chatgpt-and-codex-text-in-the-eu/).

OpenAI states that the absence of a watermark does not prove human authorship, that the mark disappears when text is edited, translated or shortened, and that a detected watermark reveals nothing about the user, the account, the prompt or the degree of human editing. Its quality testing, as reported, found no meaningful effect on GPT-6 Astra performance [[1]](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-adding-invisible-watermarks-to-chatgpt-and-codex-text-in-the-eu/).

> AI features are moving onto the Mac, and some keep their model local. FireAI, developed by HisnLabs, offers an optional on-device model that runs only on the Mac. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/fireai/en/download)

## Implications for Mac users

For readers and students, a missing watermark is not evidence that a text was written by a person, and a present one is not evidence of misuse; the stated figures show the signal fails after moderate editing. For users, OpenAI’s statement is that the mark carries no information about the account or prompt. The report concerns OpenAI’s hosted products and does not say whether other vendors or locally run models will add comparable marks.

## Recommendations

1. Do not treat a detector result, or its absence, as proof of authorship.
2. Read the terms of any AI service to see what is attached to generated text.
3. Developers who use the OpenAI API should check whether the opt-in setting suits their application, since it is off by default.

## Relevance to FireAI

FireAI does not generate, watermark or detect AI text. Its optional on-device AI model is downloaded once and then runs only on the Mac; it writes plain-language summaries of facts FireAI has already gathered, and the summaries can be wrong. FireAI sends no telemetry, and its per-app rules let a user decide which apps, including AI apps, may connect to the internet.

> FireAI lets a Mac user decide which AI apps may reach the internet and shows where they connect. It does not read or label AI text. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/fireai/en/download)

## Limitations

This account rests on one BleepingComputer report of OpenAI’s announcement. The legal basis, the start date for the EU and the detector’s eligibility criteria are not stated. The detection figures come from OpenAI’s own testing as relayed by the outlet [[1]](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-adding-invisible-watermarks-to-chatgpt-and-codex-text-in-the-eu/).

To control which apps connect from a Mac, [download FireAI](https://hisnlabs.com/fireai/en/download) and try it free for 17 days. FireAI is made by HisnLabs.

## Sources

- [BleepingComputer, 6 October 2026: OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU](https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-adding-invisible-watermarks-to-chatgpt-and-codex-text-in-the-eu/)
