OpenAI's text watermarking is easy to erase: swapping 25% of words drops detection to 17%

Our approach to EU text provenance rules

OpenAI is rolling out textGrain, an invisible watermark for ChatGPT and Codex text in the EU, and opening detector access to approved researchers. The technology performs well on long passages but struggles with short, constrained text like math, and editing can weaken the signal dramatically. OpenAI says watermarking doesn't measure human contribution, establish ownership, or verify accuracy, and it won't be a global default at launch.

In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% of words reduced it to 17%.

More from this day

2026-10-05