- The Watermark Lives in Token Selection
- Technical Specifications
- Short Text Is Harder to Detect
- Detection Is Not Proof
- Rewriting Weakens the Signal
- OpenAI vs Claude
- Why This Is Different From AI Detectors
- What Changes for Developers
- What the Watermark Does Not Reveal
- The EU AI Act Is the Main Driver
- Bottom Line
The system is called textGrain. It does not use zero-width characters or hidden metadata. Instead, it changes token-selection probabilities during generation so that longer outputs carry a detectable statistical pattern.
The Watermark Lives in Token Selection
An LLM normally assigns probabilities to possible next tokens. textGrain slightly modifies those probabilities using a secret watermarking rule.
The output still looks normal, but repeated token choices create a statistical signal that can later be detected.
General logits-bias watermarking architecture. The diagram shows the principle, not OpenAI's proprietary implementation.
Simplified generation flow:
Prompt → model → token probabilities → watermarking layer → output
Detection:
Text → tokens → statistical analysis → watermark signal
Technical Specifications
| Parameter | OpenAI textGrain |
| Watermark type | Statistical |
| Visible to users | No |
| Hidden Unicode characters | No |
| Signal location | Token-selection pattern |
| ChatGPT | EU rollout |
| Codex | EU rollout |
| API | Global opt-in |
| API default | Off |
| User identity encoded | No |
| Prompt identity encoded | No |
| Detection on short text | Weak |
| Robust to rewriting | Limited |
Short Text Is Harder to Detect
Statistical watermarking needs enough token choices to produce a reliable signal.
That makes detection weaker for:
- short replies;
- headlines;
- captions;
- code snippets.
The EU rules do not require watermarking for outputs under roughly 200 tokens or for code snippets.
Detection Is Not Proof
OpenAI reports different detection rates across EU languages.
At a 1% false-positive rate, its published results include:
- Spanish: 69.0%
- Romanian: 42.2% before strength adjustment
OpenAI can increase watermark strength for languages where detection is weaker. A detected signal therefore means the text is statistically consistent with OpenAI watermarking. It does not prove authorship. Likewise, no detected watermark does not prove that a human wrote the text.
Rewriting Weakens the Signal
Detection can degrade after:
- paraphrasing;
- translation;
- aggressive shortening;
- mixing AI text with human text;
- passing the output through another model.
The watermark is therefore a provenance signal, not a permanent identifier.
OpenAI vs Claude
Anthropic introduced a similar invisible text watermark for Claude earlier in 2026.
| Feature | OpenAI | Claude |
| Invisible watermark | Yes | Yes |
| Hidden characters | No | No |
| Statistical token signal | Yes | Yes |
| User identity encoded | No | No |
| Heavy rewriting weakens detection | Yes | Yes |
| EU regulation is a driver | Yes | Yes |
| Detection access | Restricted initially | Restricted initially |
| Deployment | EU consumer rollout, global API opt-in | Broader rollout |
The core mechanism is similar: the model embeds a detectable pattern during generation rather than relying only on post-generation AI classifiers.
Why This Is Different From AI Detectors
Traditional AI detectors analyze finished text and estimate whether it resembles machine-generated content.
Text → classifier → probability of AI authorship
Watermarking inserts a provider-controlled signal during generation.
Model → embedded signal → text → watermark detector
This gives the detector access to information that generic AI classifiers do not have.
What Changes for Developers
For API users, watermarking happens during inference.
Application → OpenAI API → model + textGrain → response
Three points matter:
Post-processing can damage the watermark
Translation, rewriting, or regeneration may reduce detection reliability.
API watermarking is optional
It is not enabled by default for API customers.
Detection access is limited
OpenAI is initially giving detector access to approved researchers and expert organizations rather than exposing a public yes/no checker.
What the Watermark Does Not Reveal
According to OpenAI, textGrain does not encode:
- user identity;
- account information;
- prompts;
- conversation IDs;
- authorship.
It only provides a signal that the text may have been generated or processed by an OpenAI system.
The EU AI Act Is the Main Driver
The rollout is tied to EU transparency requirements for AI-generated content. Text is harder than images or audio because metadata disappears when content is copied and pasted. Statistical watermarking avoids that problem because the signal is carried by the wording itself.
Bottom Line
OpenAI's text watermark is a statistical pattern embedded in token selection. It is invisible, survives ordinary copy-and-paste, and can be detected in sufficiently long text.
It does not identify the user, does not guarantee perfect detection, and can be weakened by rewriting or translation.
The broader shift is clear: OpenAI and Anthropic are moving from generic AI-text detection toward provider-controlled content provenance.