10 hrs ago
OpenAI Adds Invisible Watermarks to ChatGPT Text in EU
OpenAI plans to add a hidden signal to some text written by ChatGPT and Codex for people in the European Union.
The signal comes from small changes in how the AI chooses words, so readers will not see a label.
A special computer tool can look for the pattern.
At first, only approved researchers and specialist organisations will be allowed to use that tool.
OpenAI says the signal does not show exactly who wrote the text or whether it is true.
It also cannot measure how much a person helped.
Changing some words, translating text, or using a short passage can make the signal harder to detect.
Developers using selected OpenAI models through the API can choose to turn on watermarks around the world.
OpenAI plans to add invisible text watermarks to eligible ChatGPT and Codex outputs for EU users over the coming weeks.
Its textGrain system changes word-selection probabilities to create a statistical pattern that a detector can search for.
The EU AI Act requires AI-generated material to be identifiable by other systems; selected API models worldwide can be watermarked if developers opt in.
Detector access will initially be limited to approved researchers and specialist organisations, with applications assessed case by case.
OpenAI says the signal cannot establish authorship, human contribution, accuracy or responsibility, and modest editing can reduce detection confidence.
- Who
- OpenAI; eligible ChatGPT and Codex users in the EU, and developers who opt in for selected API models.
- What
- OpenAI plans to watermark eligible AI-generated text and provide restricted access to a detector.
- Where
- The planned ChatGPT and Codex rollout is in the European Union; API opt-in is available worldwide for selected models.
- When
- The EU rollout is expected over the coming weeks; expert organisations can apply starting today, according to OpenAI.
- Why
- To respond to EU AI Act transparency requirements for machine-readable identification of AI-generated material.
Reasons for and against watermarking
Concerns and limitations
Transparency and provenance
Reasons for and against watermarking
OpenAI says machine-detectable watermarks can help identify its AI-generated text and respond to EU transparency requirements.
Concerns and limitations
OpenAI says the signal is limited: it cannot identify the user, determine the amount of human contribution, or establish accuracy, ownership, or responsibility.
Access to detection
Reasons for and against watermarking
OpenAI plans to give approved researchers and specialist organisations access to assess and improve the technology.
Concerns and limitations
The detector will not be generally available initially; OpenAI cites reliability and responsible-use considerations, while experiments show that editing can reduce confidence.
Authorship and human input
Reasons for and against watermarking
The watermark can indicate that an OpenAI model generated or processed some part of a passage.
Concerns and limitations
The articles report criticism of watermarking approaches on the grounds that they may treat AI as the author despite substantial human input; OpenAI says its signal cannot measure a person's creative contribution.
Key facts
- Watermark technique
- textGrain changes probabilities used in the model's next-word choices to create a detectable statistical pattern.
- Products
- ChatGPT and Codex
- EU rollout
- Expected for eligible users on all plans over the coming weeks.
- API availability
- Selected models worldwide; developers must enable watermarking themselves.
- Detector access
- Initially limited to approved researchers and specialist organisations, with access granted case by case.
- Reported evasion example
- Replacing about 10 per cent of words with synonyms reduced detection from approximately 92 per cent to 66 per cent in OpenAI's experiments.
- Other limitations
- Short, mathematical, and translated text can be harder to classify; a negative result does not prove that a human wrote the text.










