OpenAI to Deploy Text Watermarking in EU to Comply With AI Act
In a major product concession to European regulators, OpenAI is introducing invisible watermarks for ChatGPT and Codex outputs in the EU, highlighting the technical challenges of policy compliance.
OpenAI has announced it will begin watermarking text generated by ChatGPT and Codex within the European Union, marking one of the first major product modifications forced by the bloc's landmark AI Act. The move represents a significant shift in how generative AI developers must handle output transparency. Under the new compliance regime, text generated by OpenAI's models will embed invisible identifiers designed to prove machine origin. However, the technology's deployment also exposes the deep technical limitations of current watermarking methods, which the company admits can be easily bypassed or degraded through routine editing.
The compliance push is a direct response to Article 52 of the European Union's AI Act, which mandates that providers of AI systems ensure that outputs are marked in a machine-readable format and detectable as artificially created or manipulated. This requirement aims to curb the spread of automated misinformation and clarify intellectual property boundaries. By targeting both ChatGPT and its developer-focused Codex tool, OpenAI is attempting to establish a baseline of compliance before the European Commission begins active enforcement. The decision highlights how Brussels is successfully setting global product standards, forcing Silicon Valley giants to alter their core codebases.
Technically, text watermarking is far more complex than marking images or video, where metadata or pixel-level alterations can be easily hidden. For text, OpenAI relies on statistical patterns embedded in the token selection process. When generating a response, the model subtly biases its word choice toward a predetermined set of greenlisted tokens. While these adjustments are mathematically detectable by verification tools, they are designed to remain imperceptible to human readers. The challenge lies in balancing this statistical signal with writing quality, as over-biasing token selection can lead to repetitive phrasing or unnatural syntax.
Despite the implementation, OpenAI has openly acknowledged the fragility of the system. In technical documentation, the company noted that even minor manual edits, translation to another language, or paraphrasing by another AI model can significantly degrade or entirely erase the watermark. This limitation raises critical questions about the efficacy of the EU's regulatory mandates. If a user can strip the watermark simply by asking a secondary, unregulated model to rewrite the text, the compliance measure becomes more of a bureaucratic checkbox than a robust defense against synthetic misinformation.
This EU-specific deployment highlights a growing fragmentation in the global AI landscape. While European users will interact with watermarked models, OpenAI has not committed to a similar blanket rollout in the United States, where legislative efforts like California's vetoed SB 1047 have struggled to establish uniform transparency mandates. Other major players, including Google and Anthropic, are watching OpenAI's rollout closely. The industry has historically resisted mandatory watermarking due to performance overhead and the competitive disadvantage of delivering altered text, but the pressure of the European market is now overriding those technical reservations.
Looking forward, the success of OpenAI's watermarking initiative will depend on the availability and accuracy of detection tools. For watermarks to be useful, third-party platforms—such as social media networks, academic institutions, and search engines—must integrate verification APIs capable of reading these invisible signals. If OpenAI keeps its detection tools proprietary or charges high fees for access, the utility of the watermarks will be severely constrained. The coming months will test whether the European Union's prescriptive regulatory framework can actually foster a secure digital ecosystem, or if it will merely generate technical friction for developers.
Sources
- 01 OpenAI will start watermarking ChatGPT’s text in the EU — TechCrunch