In short
- Text from ChatGPT and Codex will carry an invisible watermark in the EU within the coming weeks. Claude has done this worldwide since August. Both point to Article 50 of the EU AI Act.
- Only a detector can find the watermark, and it is not public. The signal weakens quickly with editing, translation or short passages.
- Little changes for your team: there is nothing to switch off or scrub out. Do agree where AI is used and who signs off on a text.
Is AI-generated text getting a watermark? Yes. This month OpenAI starts adding an invisible watermark to ChatGPT and Codex text for users in the EU, and Anthropic has been marking Claude's text worldwide since August. The watermark sits in the model's choice of words. You cannot see it, and it travels with the text when you copy and paste.
The key caveat: only a detector can find the watermark, and for now access is limited to researchers, regulators and similar organisations. A client, hiring panel or competitor cannot simply run your text through it. And even with the detector, a result is not proof.
What is changing in ChatGPT and Claude?
OpenAI set out its approach on 5 October 2026 (OpenAI, Our approach to EU text provenance rules). Anthropic describes its approach in the Claude Help Center (Anthropic, How Claude marks AI-generated content).
| OpenAI | Anthropic | |
|---|---|---|
| Where | ChatGPT and Codex, EU only, all plans | Claude, Claude Code and the API, worldwide |
| Since | Over the coming weeks | Models launched from 2 August 2026 |
| API | Opt-in, off by default | Part of the model |
| Detector | On application, for researchers and expert organisations | For regulators, media, fact-checkers, researchers and others |
Both companies cite the AI Act. Article 50 requires providers of AI systems to mark generated text, images, audio and video in a machine-readable way. Systems already on the market before 2 August 2026 have until 2 December 2026. What else that article asks of you is covered in EU AI Act 2026: a delay for high-risk AI, not for transparency.
How does a text watermark work?
For every word, a language model chooses between several good options. A watermark nudges that choice slightly, following a pattern only the detector knows. A reader notices nothing, and the text reads just as well. OpenAI says it saw no meaningful difference in quality between watermarked and unwatermarked output from its latest model.
OpenAI calls its technique textGrain and plans to release it as open source. Anthropic says the watermark is part of the text, so it carries over when copied and pasted. For images, both companies also use Content Credentials (C2PA): provenance metadata attached to the file.
How reliable is it?
Less reliable than the word suggests. OpenAI published its own figures, measured on English text at a 1% false positive rate (one in a hundred texts without a watermark is wrongly flagged):
| Situation | Watermark detected |
|---|---|
| 400 tokens, unedited | about 95% |
| 200 tokens, unedited | about 80% |
| 400 tokens, 10% of words swapped | 66% (was 92%) |
| 400 tokens, 25% of words swapped | 17% |
A token is a fragment of a word; 200 tokens is roughly 150 English words. For mathematical text, where there is less choice of words, detection was clearly lower. Anthropic gives a similar warning: the signal can disappear with heavy editing, paraphrasing, translation or mixing with other text, and very short passages do not give a reliable signal.
What a watermark does not tell you
OpenAI is unusually explicit about the limits. According to the company, a detected watermark does not tell you:
- how much human work, editing or creativity went into the text;
- who owns it or is responsible for it, or whether its use was allowed;
- who produced it: the watermark carries no user, account or prompt;
- whether the text is accurate.
The reverse also holds: no watermark found does not mean a human wrote it. The text may be too short, edited or translated, or come from a different tool. Anthropic says the same: a detected mark means the content "may have been processed by Claude", nothing more.
Dutch technologist Bert Hubert told public broadcaster NOS that he sees the main value in fraud cases, such as convincing emails from a fake energy company that were written by AI, which an email system could then flag (NOS). That seems the logical use to us: spotting misuse at scale, not judging a marketing team's newsletter.
Do you now have to label AI text yourself?
Usually not. The watermark is an obligation for the provider of the tool, not for you as a user. Your own labelling duty under Article 50 covers deepfakes and AI-generated text that informs the public on matters of public interest without human editorial review. Marketing copy that a colleague has reviewed and approved generally falls outside that.
Building something on the OpenAI API yourself, such as a chatbot or a tool that writes copy for clients? Then the watermark is off by default. Whether you should switch it on depends on whether you count as the provider of an AI system yourself. OpenAI deliberately leaves that choice to the customer. Put the question to whoever handles AI Act matters in your organisation.
What should your team do?
- Do not strip the watermark. A tool that promises to make AI text "undetectable" mostly gives you weaker copy, and an awkward conversation if anyone asks. Editing already weakens the signal on its own.
- Agree where AI helps write and who signs off. One line in your content process is enough: who is ultimately responsible for every text that goes out. That is exactly the human editorial review the AI Act names as the exception.
- Never treat a detection result as proof. If you are ever shown a result about a text from a freelancer, supplier or applicant, treat it as an indication. OpenAI and Anthropic say so themselves.
- Look beyond text. Provenance works differently for images. With the iPhone 18 Pro, Apple tackles the opposite question, proving that a photo is real: Apple Reference Image: how to prove a photo is real.
Want to agree how your team uses AI for writing, including review and responsibility? Book a conversation.
Sources
- OpenAI (5 October 2026). Our approach to EU text provenance rules.
- Anthropic. How Claude marks AI-generated content, Claude Help Center.
- Regulation (EU) 2024/1689 (AI Act), Article 50: transparency obligations.
- NOS (6 October 2026). Ook ChatGPT-teksten krijgen onzichtbaar 'watermerk' (in Dutch).
