Design a content record around the watermark signal
OpenAI’s textGrain adds a detectable statistical pattern to selected model output. Publishing systems should treat a positive result as one content signal and retain source, editing and approval history separately.
Trace the interfaces between applications and records before changing a system.
On 5 October, OpenAI described textGrain, a watermark that puts a statistical pattern into selected model outputs. Its application programming interface (API) customers can opt in for selected models. The feature is off by default. OpenAI said eligible ChatGPT and Codex text in the European Union would receive a watermark over the following weeks, while access to its detector would initially be limited to approved researchers and expert organisations.
For a publishing team, the useful decision is not whether to stamp a passage “written by AI”. It is how to use a detector result without losing the record of how a specific asset was produced, edited and approved. Keep the watermark as one signal attached to that record. Do not make it the record itself.
The signal is statistical, not a signature
During generation, textGrain uses a secret key and the preceding text to influence how the model samples its next token. The method groups possible tokens, uses an optimal-transport calculation to create a dependence on keyed randomness, and sets an entropy budget to limit how much sampling randomness is removed on average. At detection, the same tokenizer and watermark configuration are used with the key and observed text to test for that statistical dependence. The detector does not need the original generating model or its entropy budget, but it does need the relevant key and configuration. The technical report describes the construction and the assumptions behind its detection calculation.
The implementation aims to leave ordinary token probabilities unbiased when averaged over keys. That is a property of the method’s construction, not evidence that every watermarked passage reads identically to an unwatermarked one or that every deployed detector has a fixed error rate. The report says finite-precision arithmetic and a deployed key still require empirical calibration. Its idealised false-positive calculation depends on stated independence assumptions.
OpenAI reports detection rates that show why a result needs scope. At a target false-positive rate of one per cent, it detected about 80 per cent of 200-token psychology passages and 95 per cent of 400-token passages. Detection was substantially lower for mathematics, where there is less flexibility in word choice. In a separate test on 400-token passages, replacing ten per cent of words with synonyms reduced detection from about 92 to 66 per cent. Replacing 25 per cent reduced it to 17 per cent. These are provider-reported results on English responses to questions from the ELI5 dataset, not independent measurements of an organisation’s documents or calibration of its deployed detector.
Route a watermark result without overstating it
Swipe or scroll for the full diagram →
What should a detected text watermark change?
Owner: Publishing editor. Threshold: Interpret a result only within the tested provider, model, length, language and editing conditions.
- Expand
- When a signal and a generation record agree, route the item through the approved review and disclosure process.
- Retain narrower scope
- Do not infer who wrote the text, how much a person contributed, or whether it is true or lawful.
- Gather more evidence
- When the signal is absent or the detector is unavailable, retrieve generation and edit records. An absent signal is inconclusive.
Illustrative publishing decision path. It does not certify authorship or compliance.
A positive detector result is checked against its tested scope and the asset’s generation record. It can trigger review but cannot establish author, truth or disclosure status. An absent result remains inconclusive.
- OpenAI text provenance announcement · What a text watermark does not tell you
- EU AI Act, consolidated text · Article 50
Preserve the content history separately
A positive detection supports a narrow claim: the passage contains a signal associated with the provider’s watermark, within the detector’s supported conditions. It does not identify a person, show how much human judgement or editing contributed, establish ownership or lawful use, or check whether the passage is accurate. A negative result does not prove human authorship. OpenAI makes these limits explicit in its announcement.
That distinction matters when a passage moves through a content operation. A hypothetical publishing workflow might generate a product description, send it to an editor, translate it and publish a revised version. The origin record should identify the asset and generation event, provider and model where known, whether watermarking was enabled, the versions that were materially edited or translated, the responsible reviewer and the final published version. Keep only the prompt or source material needed for the record, with access and retention appropriate to its sensitivity. Store a detector result, detector version and test conditions as separate evidence. A later negative result on a translated paragraph should not erase the generation event.
This gives a watermark a useful role. If content is copied without its surrounding metadata, a surviving signal may help a platform or editor decide which record to retrieve or which item needs review. The signal can point to evidence, but it cannot reconstruct an absent history. Conversely, a first-party generation record can document a known event even when a later edit makes its watermark harder to detect.
Keep the EU duties in their proper roles
For systems within scope, Article 50(2) of the current consolidated EU AI Act requires providers of systems generating synthetic text, among other content, to mark outputs in a machine-readable format and make them detectable as artificially generated or manipulated. The technical approach must be effective, interoperable, robust and reliable so far as technically feasible, taking account of content-specific limits, implementation cost and generally accepted technical methods. The paragraph includes exceptions for assistive standard editing, outputs that do not substantially alter deployer-provided input or its semantics, and certain law-enforcement uses. The obligations apply from 2 August 2026. The current transitional provision gives providers of systems placed on the market before that date until 2 December 2026 to take the necessary steps for Article 50(2).
Article 50(4) addresses a different role and use: a deployer publishing AI-generated or manipulated text to inform the public on a matter of public interest must disclose that status. Exceptions include use authorised by law to detect, prevent, investigate or prosecute criminal offences, and content that has undergone human review or editorial control where a person holds editorial responsibility for publication. Whether a particular system, provider, deployer or publication falls within these provisions depends on its role and use. A detector response is not, by itself, a legal conclusion or proof of compliance. The European Commission’s Article 50 guidance and qualified legal advice remain relevant to that assessment.
For a proposed content pipeline, ask the provider what models and routes support watermarking, how the organisation can obtain a result, and what evidence supports the provider’s claims under the intended language, length and editing conditions. Then test representative passages, including short constrained text and translated or edited versions. The publishing owner should decide what to disclose and retain from the content record, not treat a detector score as a verdict about its author.