Two measurements

ChatGPT watermark vs an AI writing detector

A ChatGPT watermark is a pattern OpenAI puts into token choices while the model is writing. An AI writing detector looks at the finished paragraph and estimates whether it resembles machine prose. They can disagree on the same page without either one malfunctioning.

OpenAI states the contrast in its provenance help: third-party tools such as the classifiers it names look at patterns after generation, while the EU marking rule asks for a signal embedded in the text. textGrain is that embedded signal. GPTZero, Originality, Copyleaks, and Turnitin’s AI writing report are the after-the-fact kind. The ChatGPT watermark detector on this site is a third thing again: a scan for invisible characters and file metadata, not a style score and not textGrain.

Definitions that stay put

A sampling watermark needs a secret at generation time. The model already has a distribution over the next token. The watermark biases which draw is taken, in a way a later detector can test if it shares the key. For ChatGPT, that construction is textGrain, documented in the technical report and explained in ordinary language in how the watermark works. The detector does not need the prompt. It does need the key. It reports whether the pattern is strong enough, not who clicked send.

An AI writing detector needs no cooperation from the generator. It is trained on examples of human and machine text, then scores a new passage. Turnitin describes a transformer model and, separately, a similarity database. Other vendors describe perplexity and burstiness. The shared feature is that the evidence is statistical resemblance, not a bit OpenAI planted. That is why two detectors can score one essay differently, and why a vendor can update the model without OpenAI shipping a new key.

Hidden characters are neither. They are codepoints. A scanner either finds U+200B or it does not. Cleaning them does not move a classifier and does not move textGrain. Keeping them in the same sentence as “detector” is how product pages become mush.

When each one fires

Situation textGrain, if the path was marked A typical AI writing detector
Long unmarked API output, watermark switch off No signal to find Often a high score
Long EU ChatGPT answer, lightly copied Designed to remain detectable Often a high score, not because it read the key
The same answer, heavily rewritten by a person Can fall below the threshold Depends how far the style moved
Short factual answer or code Weak or out of scope under the code-of-practice floor Unreliable in both directions
Human text in a very even, formal register Should not carry OpenAI’s key Can still score as machine-like
Claude or Gemini text Not OpenAI’s key. Their own marks differ. See the lab comparison May still look like AI writing

Read the table across, not down. “High detector score” never upgrades into “watermark found.” “Watermark found” never upgrades into “every sentence was unedited model output.” OpenAI says a hit is evidence the model likely generated or processed the content, and that it does not measure how much a person contributed.

What editing does to each

Light edits are the case the watermark literature cares about: a few words, a tense change, a paste into a doc. Sampling schemes are built so that kind of change does not erase the pattern, though no vendor promises a hit on every paragraph. A classifier often stays high too, because the sentences are still mostly the model’s.

A paraphrase tool aims at the classifier. Turnitin now folds likely AI-paraphrase into the AI writing report, which is an admission that the attack is common and only partly successful. The same paraphrase is also the attack on textGrain: change enough wording and the keyed pattern thins out. One edit, two effects, neither of which you can watch unless you hold both instruments. The Turnitin article stays on that institutional classifier. The removal article stays on what “remove” can mean without pretending a spinner is a decoder.

Translation is a sharp version of the same split. OpenAI says substantial translation can make textGrain undetectable. A detector trained mostly on English may also lose the trail, or may flag translationese as machine prose. Publishing a translated post and citing either miss as proof of human authorship is not a reading the vendors support.

False comfort from either column

The dangerous sentence is “the detector said human, so there is no watermark,” or the reverse. A quiet classifier is a statement about that model’s threshold. It is silent on whether the EU ChatGPT path was used, whether an API project opted in, and whether a second model with its own mark wrote the outline. Those coverage facts are in does ChatGPT watermark text in 2026.

The other dangerous sentence is “no watermark, so a person wrote it.” OpenAI lists the ordinary misses: too short, too factual, code, unsupported path, predates the rollout, rewritten. That list is expanded in what a missing watermark means. Classifiers have their own ordinary misses, including text that was machine-written and then line-edited, and text in a language the model barely saw.

Free tools amplify the confusion because the pages are labeled with the search query rather than the method. A box that returns “87% AI” has not decoded textGrain. A box that returns “no hidden characters” has not run a classifier. The map of which free surface is which is free AI watermark checkers compared.

Which one to run

Run a character and metadata check when you have a draft or a file and you need to know about carriers you can actually list. That is this site’s tool. Run a classifier only if you wanted a resemblance score and you will label it as one. Run a keyed watermark detector only if you are the vendor or an organization they approved. For OpenAI images and audio, the public path is openai.com/verify, which is not a text box.

If you are an editor deciding whether to publish, put the measurements next to a disclosure instead of stacking them into a verdict. The intake order is in how to check a blog writer. If you are an instructor with Turnitin, read the percentage as Turnitin’s percentage. If your institution later gets text-detector access, file that PDF beside the writing report. Do not average them.

Check listed carriers, not a style score →

What a policy should say

A one-line policy, “AI detectors are banned” or “everything must pass the detector,” collapses the table above. A policy that survives a mixed draft names the instrument.

Write the instrument into the appeal process too. A student or a writer who is told “the watermark failed” cannot answer a classifier, and a writer who is told “GPTZero said 90” cannot answer textGrain. The accusation has to name the report, the date, and the span. Otherwise the appeal is about a rumor.

What perplexity is actually measuring

Classifier marketing often says perplexity. In the language-model sense, perplexity is how surprised a particular model is by the next token. Text that sits in the middle of a model’s habits scores as unsurprising. Human text with odd proper nouns, a sharp change of register, or a lot of quotations scores as more surprising. Early public detectors leaned on that gap: machine text looked too even.

A watermark does not measure surprise. It measures whether the chosen tokens line up with a key more often than chance. A passage can be unsurprising and unmarked, because the API switch was off and the model still writes smooth prose. A passage can be marked and only moderately surprising, because textGrain is designed to spend a limited amount of the model’s freedom. OpenAI’s claim that quality metrics stayed inside ordinary noise is a claim that the surprise budget is small. A perplexity detector is not tuned to that small, keyed shift. It is tuned to a coarser difference between human and machine habits, which is why paraphrases that add burstiness became a product category.

Burstiness, the other word on those pages, is how much the surprise varies from sentence to sentence. It is still a property of the finished text. It still does not require OpenAI’s key. When a vendor updates the model, yesterday’s burstiness threshold is not a law of nature. A watermark threshold moves only when the key holder moves it.

Four drafts side by side

Keep the drafts imaginary and the readings strict. No percentages, because this page does not have either vendor’s model in the room.

Draft A is 1,200 words from EU ChatGPT, pasted with light fixes to names. Expect a style detector to take an interest. Expect textGrain, if anyone with the key ran it, to be in the regime the scheme was built for. Expect a character scan to find nothing, which is normal. None of those three sentences contradicts the others.

Draft B is the same piece after a humanizer. The style detector may move, including toward a paraphrase flag if the institutional model has one. textGrain may weaken because the words moved. The character scan is still a character scan. Calling Draft B “watermark removed” names only the middle instrument, and only if you measured it.

Draft C is a human editor writing in a flat house style, no model. textGrain should be absent. A classifier can still hesitate, especially on short pages and on text that was edited to sound like the last ten posts on the site. The remedy is the assignment history, not a second detector.

Draft D is Claude, long, from a covered model, as Anthropic describes coverage. An OpenAI textGrain test should miss. A classifier may hit. A C2PA check hits only if a file was exported with a credential. The miss on textGrain is not a human result. It is the wrong key, which is the point of the lab comparison. File each draft’s note with the instrument name attached. A shared spreadsheet that only has a column called “watermark” will merge Draft A’s character miss with Draft D’s textGrain miss, and the next reader will treat them as one fact.

When a report has to leave the building, put the instrument in the first sentence. A client who reads “watermark check: pass” will hear a provenance result. A client who reads “classifier score from vendor X on the first 500 words” will hear a resemblance result. Those readers are the reason the labels exist. Keep the raw export next to the sentence so the next person can rerun the same slice.

FAQ

Is an AI detector the same as a watermark detector?

No. The watermark test looks for an embedded signal with a key. The AI detector scores finished prose. OpenAI describes them as different.

Can both be true on one paragraph?

Yes. Marked text often also looks like AI writing. Unmarked model text often looks like AI writing too. Human text can look like AI writing without a watermark.

Does this site’s checker take a side?

It lists invisible Unicode and file metadata. It does not print an AI percentage and it does not read textGrain.

Will cleaning hidden characters change a detector score?

No. The score follows the words. The characters are not the words.

← All AI watermark guides