AIAI News Online

OpenAI's textGrain explained: a watermark hidden in ChatGPT's word choices

OpenAI will watermark ChatGPT and Codex text in the EU with textGrain. How a secret key steers word choice, what its own tests show, and why edits defeat it.

16 min at full depth14 sources

In 60 seconds

  • On 5 October 2026 OpenAI said it will add an invisible statistical watermark, called textGrain, to ChatGPT and Codex text for EU users within weeks, to meet Article 50 of the EU AI Act; API developers worldwide can opt in, off by default, and only approved researchers get the detector.
  • A secret key plus the preceding tokens seed pseudorandom numbers that sort the vocabulary into blocks and bias which block the next word comes from, under an 'entropy budget' that caps how much of the model's randomness the watermark may consume; anyone with the key can later test whether the text follows the key more often than chance.
  • OpenAI's own figures: about 95% of clean 400-token passages are detected at a 1% false-positive target, but swapping a quarter of the words for synonyms cuts detection to 17%, maths is much worse, OpenAI's own chart for the 24 official EU languages tops out at 69%, and nobody outside an approved group can verify any of it.

In November 2022 a researcher at OpenAI described how to hide a secret signal in ChatGPT's choice of words. The company built it, tested it, and kept it on the shelf for fear of losing customers. On 5 October 2026 OpenAI announced that a descendant of that idea, called textGrain, will be switched on for ChatGPT and Codex users in the European Union within weeks, because an EU law now requires it. OpenAI's own figures say the mark is found in about 95% of clean 400-token passages, and in 17% of passages once a quarter of the words have been swapped for synonyms. That gap, between what the mathematics can promise and what a light edit can undo, is the whole story.

For: Everyone

The plain-English version

When ChatGPT writes, it rarely knows the next word for certain. At most points it has several acceptable options, say "big", "large" and "huge", each with a probability, and it rolls a weighted die to choose. Because the roll is random, the same question can produce different answers on different days.

A text watermark swaps that die for something that only looks random. Picture a writer with a pocket calculator. Before each word, the writer types in a secret number and the last few words already written, and the calculator answers with a preference: this option rather than that one. The writer still chooses only among words that fit, so the sentence reads normally and no reader can tell. But anyone who owns the same calculator and knows the secret number can go back through the finished text, recompute the preference at each point, and count how often the writer followed it. A human author agrees with the calculator about as often as chance. The watermarked model agrees far more often. Over a few hundred words, the excess becomes statistical evidence.

That is what textGrain does. OpenAI describes it as "an invisible statistical signal" in the model's word choices. Its help pages stress that nothing is added to the text: no hidden characters, no invisible spaces, nothing that copy-and-paste would strip, because the mark lives in the words themselves.

It is arriving now because of law, not choice. Article 50 of the EU AI Act, in force since 2 August 2026, says providers of systems that generate text "shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated". Systems already on the market have until 2 December 2026, according to a Paul, Weiss memo on the final rules. OpenAI has signed the accompanying Code of Practice, as have Anthropic, Google, Meta and Microsoft, TechCrunch reports.

Three things to hold on to. First, the watermark is regional and partial: EU users of ChatGPT and Codex on all plans will get it on "eligible" output over the coming weeks, developers elsewhere get an off-by-default switch, and OpenAI says it is "not making text watermarking a global default at launch". Not every answer counts as eligible: OpenAI's help pages note that the EU Code of Practice does not require watermarks on outputs shorter than 200 tokens, about 150 English words, or on code snippets. Second, you cannot check for it yourself; the detector is open only to approved researchers and expert organisations who apply. Third, OpenAI itself lists what the mark cannot do: it cannot say who used ChatGPT, how much a person contributed, who owns the text or whether it is true, and a missing watermark does not prove a human wrote something.

The weakness is in the company's own tests. The evidence is spread thinly across every word, so every word you change removes a little of it. Swap one word in ten for a synonym and detection fell from about 92% to 66% in OpenAI's evaluation. Swap one in four and it fell to 17%.

For: Curious

How it actually works

The problem. A language model produces text one token at a time (a token is a word or part of one). At each step it computes a probability for every token in its vocabulary, then samples one. Where the distribution is spread out, as in an essay, there is "entropy", meaning genuine freedom of choice. Where it is sharply peaked, as in the next digit of an arithmetic answer or the next character of code, there is almost none. Any watermark that works by steering choices can only live where there are choices to steer. That single fact explains most of the numbers in this story.

The old ways. Three families of generative watermark preceded textGrain, and its technical report positions itself against each.

  1. Green lists. In 2023 Kirchenbauer and colleagues proposed hashing the previous token with a key to split the vocabulary into a "green" list and a "red" list, then nudging the green tokens' probabilities upward. Detection counts green tokens. It is simple and strong, but it changes what the model says; the report notes that such methods alter the output distribution "even after averaging over their keyed token subsets".

  2. Gumbel-max. Scott Aaronson's 2022 proposal, developed at OpenAI, kept the model's distribution intact on average by replacing the random numbers used in sampling with pseudorandom ones derived from the key and the preceding tokens. The catch, as the textGrain report puts it: at a fixed context and key "it always selects the same token", so asking the same question twice yields the identical answer. Variety disappears.

  3. Tournament sampling. Google DeepMind's SynthID-Text, published in Nature in 2024, draws several candidate tokens and runs them through a keyed knockout tournament across 30 layers, seeded by a hash of the previous four tokens. It is unbiased in its default mode, has run in Gemini since 2024, and is the method Anthropic adopted for Claude in August 2026.

The new idea. textGrain treats the watermark as a budgeting problem: how much of the model's randomness are you willing to spend on the signal? A generation step runs like this.

  1. Keyed randomness. The secret key and a window of preceding tokens seed a pseudorandom generator, exactly as in the earlier schemes.
  2. Blocks and columns. The pseudorandom numbers sort the whole vocabulary into a fixed number of groups, called blocks, and lay out a small cost table between those blocks and a handful of equally likely "columns". Each cell's cost is minus a random Gumbel value, so a large Gumbel draw means a low cost, and a low cost means "the watermark would like this block to go with this column".
  3. A small transport problem. The model's probabilities for the blocks form one side of the table and the uniform columns form the other. The algorithm finds a joint plan that favours low-cost cells but pays a penalty for every bit of dependence it creates between block and column. The penalty is the Kullback-Leibler divergence from independence, and the report proves it equals exactly the average amount of sampling randomness the watermark removes. A budget, written β, caps that at a chosen fraction of the step's entropy.
  4. Sampling. The key picks a column. The plan gives the probability of each block given that column, a block is drawn, and finally a token is drawn inside the block using the model's original relative probabilities.
  5. Detection. Someone holding the key and the text, but not the model, recomputes the blocks, cost table and column at each position, reads off the cost of the block the observed token belongs to, turns it into a score and adds the scores up. Under human text the sum follows a known distribution; an unusually large sum is the watermark.
Budget β What happens Detectability Variety under one key
0 Column and block independent; plain sampling None Full
Small A fraction of each step's randomness is spent on the signal Grows with text length Most retained
Large Block almost fixed by key and context, the same loss of variety Gumbel-max suffers Highest per token Repeated prompts tend to repeat answers

Why it works: averaging over the columns gives back the model's original probabilities exactly, so a reader without the key faces text whose statistics are those of the unwatermarked model. Grouping tokens into blocks shrinks the optimisation from the size of the vocabulary to the number of blocks, which is what makes solving a transport problem on every token affordable. And because the budget is defined in information-theoretic terms, "spend 10% of the entropy" means precisely that, on average over keys. The report also shows the scheme can be combined with speculative decoding, the trick production systems use to generate several tokens per model call, provided the draft and target models share the key. OpenAI's help pages say the effect on speed is negligible.

For: Practitioner

The deep dive

Watermarking as a coupling

The report, by Xiang Li, Garrett Wen, Xiaohong Chen, Qi Long, Arzav Jain, Florent Joly, Mike Lam, Qingquan Song and Weijie Su, with Su as corresponding author, frames every unbiased watermark as a coupling. Let PP be the next-token distribution at some prefix, Ξ∼μ\Xi \sim \mu the keyed pseudorandom variable, and WW the emitted token. A watermark is unbiased if the joint law π\pi of (W,Ξ)(W,\Xi) has marginals PP and μ\mu, so that averaging the conditional sampling distribution Q(⋅∣ξ)Q(\cdot \mid \xi) over keys recovers PP. Plain sampling is the independent coupling P⊗μP \otimes \mu. Gumbel-max sits at the other extreme: WW is a deterministic function of ξ\xi.

The report's central identity is that for any such coupling,

DKL(π ∥ P⊗μ)=Iπ(W;Ξ)=H(P)−EΞ H{Q(⋅∣Ξ)}.D_{\mathrm{KL}}(\pi \,\|\, P \otimes \mu) = I_\pi(W;\Xi) = H(P) - \mathbb{E}_{\Xi}\, H\{Q(\cdot \mid \Xi)\}.

Mutual information between token and key equals the entropy the watermark removes on average. That turns "watermark strength" from a tuning knob into a quantity with units. The scheme is then an entropy-regularised optimal transport problem,

πλ∈arg⁡min⁡π∈Π(P,μ){Eπ c(W,Ξ)+λ DKL(π ∥ P⊗μ)},\pi_\lambda \in \arg\min_{\pi \in \Pi(P,\mu)} \left\{ \mathbb{E}_\pi\, c(W,\Xi) + \lambda\, D_{\mathrm{KL}}(\pi \,\|\, P \otimes \mu) \right\},

with a cost cc that rewards the dependence the detector will later look for.

Block optimal transport

Solving that over a vocabulary of 10510^5 tokens at every step would be too slow, so textGrain works on blocks. A keyed partition g:V→[B]g: \mathcal{V} \to [B] assigns each token in the support A\mathcal{A} to one of BB blocks, giving block probabilities Pbblk=∑w:g(w)=bPwP^{\mathrm{blk}}_b = \sum_{w: g(w)=b} P_w. The keyed randomness is a uniform choice JJ among mm columns. For each block-column pair the key also draws a standard Gumbel variable ZbjZ_{bj} with distribution function FG(z)=exp⁡{−exp⁡(−z)}F_G(z) = \exp\{-\exp(-z)\}, standardised to GbjG_{bj}, and the cost is c(b,j)=−Gbjc(b,j) = -G_{bj}: large Gumbel values are cheap. The budgeted problem is

min⁡π∈Π(Pblk,um)∑b=1B∑j=1mπ(b,j) c(b,j)subject toDKL(π ∥ Pblk⊗um)≤β H(P),\min_{\pi \in \Pi(P^{\mathrm{blk}}, u_m)} \sum_{b=1}^{B} \sum_{j=1}^{m} \pi(b,j)\, c(b,j) \quad \text{subject to} \quad D_{\mathrm{KL}}(\pi \,\|\, P^{\mathrm{blk}} \otimes u_m) \le \beta\, H(P),

and the token is sampled from

Q(w∣j)=m π(g(w),j) PwPg(w)blk.Q(w \mid j) = m\, \pi(g(w), j)\, \frac{P_w}{P^{\mathrm{blk}}_{g(w)}}.

Because tokens inside a block keep their original relative probabilities, m−1∑jQ(w∣j)=Pwm^{-1}\sum_j Q(w \mid j) = P_w exactly, and the coupling "retains at least a fraction 1−β1-\beta of NTP entropy on average across columns". The solver is a Sinkhorn iteration in the log domain with an outer loop that adjusts λ\lambda until the achieved entropy loss matches the target, followed by a marginal-correction step so that the sampled distribution stays unbiased even when the iteration has not fully converged. Each update costs O(Bm)O(Bm) and a whole step O(∣A∣+NitBm)O(|\mathcal{A}| + N_{\mathrm{it}} B m). The report proves the optimal coupling's KL divergence is non-increasing in λ\lambda, which makes the outer loop well posed. It is explicit that a finite iteration limit "can leave that loss above or below the target", so the achieved loss should be reported alongside the request.

Appendix B extends the construction to speculative sampling with a shared key: both draft and target apply the watermark, the target verifies proposals jointly using the block-verification rule of Sun et al., and the output law equals direct watermarked sampling from the target. Whether this speeds anything up "requires empirical measurement".

The detection statistic

Detection needs the tokenizer, the key, the block and column counts and the context-window rule, and nothing else. At scored position tt the detector rebuilds the partition, cost table and selected column, finds the cost ctc_t of the observed token's block, undoes the standardisation to recover ZtZ_t, and computes

Yt=−log⁡{1−FG(Zt)},Sn=∑t=1nYt.Y_t = -\log\{1 - F_G(Z_t)\}, \qquad S_n = \sum_{t=1}^{n} Y_t .

If the text is independent of the key, each ZtZ_t is a standard Gumbel variable, each YtY_t is unit exponential, and Sn∼Gamma(n,1)S_n \sim \mathrm{Gamma}(n,1). The detector declares a watermark when SnS_n exceeds the (1−α)(1-\alpha) quantile, giving a conditional false-positive rate of α\alpha under the stated assumptions. Only the first occurrence of each distinct context window is scored, to avoid reusing the same pseudorandom table. The report is careful about what this does not guarantee: "A fixed deployed key and finite precision arithmetic require empirical calibration checks; the idealized null calculation does not by itself guarantee the same error rate for every key or application." It also notes that because the reconstructed Gumbel values have a different distribution under textGrain than under Gumbel-max, optimality results for Gumbel-max detectors "do not transfer automatically".

What OpenAI measured

The technical report contains no experiments. The numbers below come from OpenAI's blog post, as relayed by TechCrunch, The Decoder and others, and are vendor-reported.

Condition (language not stated) Detection rate at a 1% target false-positive rate
200 tokens, "content such as psychology" about 80%
400 tokens, same content type about 95%
Content such as mathematics "substantially lower", no figure given
400 tokens, 10% of words replaced by synonyms from about 92% to 66%
400 tokens, 25% of words replaced by synonyms 17%
24 official EU languages, 500 English prompts translated into the other 23 (help pages; passage length not stated) highest Spanish 69.0%, lowest Romanian 42.2%

The language chart on OpenAI's help pages matters for an EU-only deployment. OpenAI says the watermark has "an adjustable strength parameter", a knob it turned up for languages whose detection fell below 60%, which is the entropy budget of the technical report put to work. The blog post's 80% and 95% headline figures do not say which language they were measured in.

On quality, OpenAI reports eight benchmarks for its GPT-6 Astra model with the watermark off and on. Two of them, as relayed by Unite.AI: an Artificial Analysis Intelligence Index of 49.57 against 49.76, and GPQA Diamond of 94.44% against 93.94%. OpenAI calls the differences not meaningful, which is what the unbiasedness theorem predicts for average quality. OpenAI also says textGrain "matched or exceeded" the other methods it tested, including SynthID for text, without publishing the comparison.

How it compares

Scheme Unbiased on average over keys Variety at a fixed key Strength control Production use
Green list, Kirchenbauer et al. 2023 No Yes Logit bias Research
Gumbel-max, Aaronson 2022 Yes None None Prototyped at OpenAI, never shipped
Tournament sampling, Dathathri et al. 2024 Yes in non-distortionary mode Partial Number of layers; a distortionary mode Gemini since 2024; Claude since August 2026
Block OT, textGrain 2026 Yes Retains at least 1−β1-\beta of entropy on average Entropy budget β\beta, blocks BB, columns mm ChatGPT and Codex in the EU; API opt-in

The closest relatives are the other coupling-based schemes the report cites: Xie et al. and Long et al. optimise worst-case detection power over a class of next-token distributions, Huang et al. jointly optimise a coupling and an e-value, and Tsur et al. use optimal transport with costs drawn from coding theory or heavy-tailed distributions. The report's claimed distinction is the objective: it uses the coupling's KL divergence from independence to control the average entropy loss, so the watermark's strength is a budget rather than a by-product. SynthID-Text's large-scale evidence remains the benchmark to beat: its Nature paper compared about 20 million live Gemini responses and found thumbs-up rates differing by 0.01% and thumbs-down rates by 0.02%, both statistically insignificant. OpenAI has published no comparable live data yet.

For: Everyone

Why it matters

For everyday users. If you use ChatGPT or Codex in the EU, text you generate over the coming weeks will carry a statistical signature that OpenAI, and the organisations it approves, can test for. OpenAI has not said whether EU users can switch it off, a gap Search Engine Journal flagged. The signature does not identify you, and a positive result means only that an OpenAI model wrote or touched part of the passage. A negative result means nothing: the text may be short, edited, translated or from another company's model.

For developers. The API switch sits in project and organisation settings, applies per model and is off unless you turn it on. Opting in does not grant you the detector. Code is the weakest case because there are few plausible alternatives at each position; OpenAI's help pages say code is harder to watermark for that reason, the EU Code of Practice does not require marks on code snippets, and Anthropic says plainly that where an exact output is required its own watermark is not applied. OpenAI's stated plan to open-source textGrain matters more in the long run: an open implementation, combined with the entropy-budget framing, gives anyone running open-weight models a documented way to add provenance signals with a quantified cost in variety.

For companies. Three labs now run three different unbiased watermarks: Google's tournament sampling, Anthropic's variant of it, and OpenAI's block transport. Article 50's obligation to make watermark detection interoperable applies from 2 February 2027 after a deferral, according to the Paul, Weiss memo. A detector that needs each provider's key and each provider's algorithm is not interoperable in any practical sense, so expect the next year to be about shared detection interfaces rather than new sampling tricks.

For the field. For two years the research question was "distortion-free or not". textGrain replaces it with "how much entropy, and where". That makes the trade-off between detectability and variety a design parameter you can budget, audit and compare across schemes. It also exposes the hard limit: the signal is paid for in entropy, and low-entropy text, which includes maths, code and the formulaic prose a content farm produces, has little to pay with.

For: Critical

What to be skeptical of

Every number is OpenAI's. The headline detection figures are for "content such as psychology", which is high-entropy prose that flatters any watermark, and they do not state a language. OpenAI's own chart for the 24 official EU languages, the languages this deployment is for, ranges from 42.2% for Romanian to 69.0% for Spanish before OpenAI turned up the strength for the weakest languages. Mathematics is "substantially lower" with no figure, and code is not quantified at all. The quality numbers are eight benchmarks on one model.

Edits, paraphrase and translation. A drop to 17% after replacing a quarter of the words is not a corner case; it is a normal editing pass. OpenAI's own 2024 statement said its earlier method was "effective against localized tampering, such as paraphrasing" but "less robust against globalized tampering" such as translation or rewording by another model. Aaronson said in 2022 that "this can all be defeated with enough effort". Zhang and colleagues argued, in a paper published at ICML 2024, that no watermark can survive an attacker with a quality oracle and a perturbation oracle, and demonstrated their attack on three schemes. On the other side, Kirchenbauer's group found that even strong human paraphrasing leaves a detectable trace after about 800 tokens at a very strict false-positive rate, so the practical question is length, not possibility.

The detector is closed. Only approved organisations can test text. Nemecek, Chaudhary and Ayday argue in a September 2026 paper that "unverifiability, rather than watermarking itself, is the substantive governance failure" of the current EU regime. When Anthropic shipped its watermark, developers published removal tools within hours, WIRED reported, and nobody could verify whether they worked because no detector was public. The same will be true of textGrain.

False positives are a target, not a measurement. The 1% figure is the quantile of an idealised null distribution. The report itself says the real error rate for a deployed key needs "empirical calibration checks". At 1%, one human essay in a hundred would be flagged by design, and a detector used at scale by schools or employers would generate many such cases. OpenAI's 2024 worry that watermarks could "stigmatize use of AI as a useful writing tool for non-native English speakers" has not gone away, and the help pages' per-language chart shows the signal is weakest in exactly the languages this rollout serves.

Coverage and incentives. Text from Mistral, DeepSeek, Qwen, open-weight models or any non-watermarking provider is invisible to this detector, and Anthropic's and Google's marks need their own keys. The SynthID paper warned that enforcing watermarks on decentralised open models "is difficult". And the report is written by OpenAI staff and academic co-authors and evaluated by its makers; the "matched or exceeded SynthID" claim has no published comparison behind it.

For: Everyone

What to watch next

  • The EU rollout itself, due "over the coming weeks" from 5 October 2026: which models and outputs count as "eligible" beyond the Code's exemptions for short outputs and code, whether EU users get an off switch, and whether the cloud partners OpenAI mentions follow.
  • 2 December 2026, when the Article 50 marking obligations apply to systems already on the market, and 2 February 2027, when the deferred Article 50 obligation to make watermark detection interoperable applies.
  • The open-source release. Weijie Su said OpenAI will "open-source it so the community can build on top". Watch for code, a published default budget β and, above all, independent detection and robustness measurements from the partners OpenAI's help pages name at Cornell, ETH Zurich and the Kempelen Institute.
  • Anthropic's detection API. It is in private preview for eligible organisations. Once it opens more widely, the removal tools published in August can be tested, and the first cross-vendor comparison of deployed watermarks becomes possible.
  • Hybrid-text research. The report cites the Su group's work on estimating what fraction of a document is watermarked and on locating watermarked segments. That is the technical path toward the question regulators actually ask: not "did AI touch this" but "how much".

Check your understanding

Pick an answer — you'll see why right away.

1. OpenAI's detector can check a passage for the textGrain watermark without running the language model. Why is that possible?

2. What does textGrain's entropy budget, written beta, actually control?

3. A 400-token essay from ChatGPT in the EU is edited so that 25% of the words are replaced by synonyms. According to OpenAI's published test, what happens when the detector checks it?

4. Why does OpenAI say detection is 'substantially lower' for mathematical content than for prose on topics like psychology?

Glossary

Text watermark (statistical)
A hidden pattern embedded in an AI model's choice of words, invisible to readers but detectable by a statistical test using a secret key.
Token
A chunk of text, usually a word or part of a word, that a language model reads and writes one at a time.
Next-token distribution
The set of probabilities a model assigns to every possible next token before it picks one.
Entropy
A measure of how spread out a probability distribution is; high entropy means many plausible next tokens, low entropy means one obvious choice.
Secret key
A number known only to the provider that seeds the pseudorandom choices used to embed and later detect the watermark.
Unbiased (distortion-free) watermark
A watermark that, averaged over all possible keys, leaves the model's output distribution exactly unchanged.
Optimal transport
A mathematical method for finding the cheapest way to match one probability distribution to another given a table of costs.
Coupling
A joint probability distribution over two variables, here the chosen token and the keyed random value, with fixed marginals for each.
False-positive rate
The share of genuinely human-written passages that a detector wrongly flags as watermarked.
Article 50
The EU AI Act's transparency article, requiring providers to mark AI-generated content so that it is machine-readable and detectable, in force since 2 August 2026.

Questions people ask

Does ChatGPT watermark its text?

From October 2026, yes for users in the European Union: OpenAI is rolling out an invisible statistical watermark called textGrain to eligible ChatGPT and Codex output in the EU over the coming weeks. Outside the EU, text is only watermarked if an API customer switches it on for their project or organisation, and it is off by default.

Can I detect or remove the ChatGPT watermark?

You cannot detect it yourself: the detector is available only to approved researchers and expert organisations who apply to OpenAI. As for removal, OpenAI's own tests show that replacing 25% of words with synonyms cut detection from about 92% to 17%, and translation or rewriting with another model weakens it further. OpenAI also says a missing watermark does not prove a human wrote the text.

Does the watermark identify me or my account?

No. OpenAI says the watermark can indicate that an OpenAI system generated or processed part of a text, but cannot tell who used the system, how much a person contributed, who owns the text or whether it is accurate. The detector reports presence or absence and does not reveal users or prompts.

Why is OpenAI only watermarking in the EU?

Article 50 of the EU AI Act requires providers to mark AI-generated text in a machine-readable, detectable way from 2 August 2026, with a grace period to 2 December 2026 for systems already on the market. OpenAI says it is starting with the EU to gather real-world feedback and is 'not making text watermarking a global default at launch'. Anthropic, by contrast, watermarks Claude text worldwide.

Does watermarking make ChatGPT's answers worse?

OpenAI reports no meaningful change across eight benchmarks on its GPT-6 Astra model with the watermark off and on. Two examples: the Artificial Analysis Intelligence Index was 49.57 without the watermark and 49.76 with it, and GPQA Diamond 94.44% against 93.94%. These are OpenAI's own numbers. The method is designed to preserve the model's output distribution on average over keys, though it does reduce how varied repeated answers to the same prompt are, by an amount OpenAI controls with an entropy budget.

How is textGrain different from Claude's or Gemini's watermark?

All three are statistical watermarks embedded in word choice using a secret key. Google's SynthID-Text, a version of which Anthropic uses for Claude, picks tokens through a keyed knockout tournament. textGrain instead groups the vocabulary into keyed blocks and solves a small optimal transport problem with an explicit budget on how much of the model's randomness the watermark may use. Each provider's detector needs its own key, so none can detect the others' marks.

Discussion

  1. Loading comments…

Sources

  1. Our approach to EU text provenance rules — OpenAI · official announcement
  2. textGrain: Entropy-Calibrated Watermarking for Language Model Text — OpenAI, University of Pennsylvania, Yale University · paper
  3. Provenance signals in OpenAI-generated content — OpenAI Help Center · docs
  4. Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems — EU Artificial Intelligence Act (Future of Life Institute) · docs
  5. Code of Practice on transparency of AI-generated content — European Commission · official announcement
  6. EU Finalises Transparency Rules for AI-Generated Content — Paul, Weiss · analysis
  7. OpenAI will start watermarking ChatGPT's text in the EU — TechCrunch · news
  8. OpenAI will watermark ChatGPT text in the EU but makes it optional for API users worldwide — The Decoder · analysis
  9. Scalable watermarking for identifying large language model outputs — Nature (Google DeepMind) · paper
  10. Anthropic's LLM watermarking — Shtetl-Optimized (Scott Aaronson) · analysis
  11. Watermarks Without Verification: AI Text Watermarking After the EU AI Act — arXiv · paper
  12. How Claude's text watermark works — Anthropic · official announcement
  13. Understanding the source of what we see and hear online — OpenAI · official announcement
  14. Coders Say They Already Found Workarounds to Claude's Invisible Watermarks — WIRED · news

How this was made: researched and written by an AI model (Claude) from the primary sources listed above, then checked claim-by-claim against those sources in a separate AI fact-check pass. Spotted an error? Email [email protected] and we correct it publicly. Our process.