For editors

How to check if a blog writer used watermarked AI text

You can check three things on a draft a freelancer sent you: invisible characters in the paste, provenance metadata on the file, and whether the wording still matches a vendor watermark you are actually allowed to read. You cannot, from a free webpage, pull OpenAI’s textGrain verdict out of a Google Doc.

Editors search this because the business problem is concrete. A post goes up under your brand. A client, a newsroom, or a regulator later asks whether a model wrote it and whether it was marked. The useful habit is to separate those questions before you accuse a writer or, just as badly, before you publish a file that still carries a manifest you did not mean to ship.

What “watermarked AI text” usually means

Writers and the tools they use now leave four different traces. Mixing them up is how a content team bans the wrong thing.

A writer can use a model and hit none of the first three, because they typed from notes, because the model’s watermark was off, or because they rewrote. A writer can also hit the first one and still have done the reporting themselves, with a model only cleaning a paragraph. The check tells you which trace is present. It does not assign the byline.

What to collect before you check

Ask for the artifact you will actually ship, not a screenshot of a chat. A screenshot has no Unicode from the clipboard and no C2PA box. A paste into Slack may already have dropped or added characters. The cleanest intake is:

  1. The draft as a Doc, Markdown file, or DOCX, whatever your CMS eats.
  2. Any image files as the original exports, not a re-saved JPEG from a slide.
  3. A one-line note of which tools touched the draft, if your agreement requires it.
  4. The sources for claims that are not the writer’s own reporting.

Keep that bundle. If you only store the CMS HTML, you have already thrown away the file-level credential and you may have thrown away the character-level one too. HTML export can introduce its own entities and non-breaking spaces, which is a second reason to scan the version you paste into the editor, not only the writer’s attachment.

Pass 1: invisible characters

Paste the draft into the text tab of the ChatGPT watermark detector and run Check. The report counts zero-width spaces, joiners, a leading BOM, bidi controls, and related format characters, with offsets. This is the pass that explains a headline that will not match in search, a slug that looks duplicated, or a code snippet in a tutorial that fails when a reader copies it.

Treat a hit as hygiene. Clean it if you own the draft and you want the visible words left exactly as they are. Then re-check. A zero count means those codepoints are gone. It does not mean a person wrote the post, and it does not remove textGrain, because textGrain is not a character. The removal article separates those operations so a production editor does not tick the wrong box.

A miss on this pass is the common result. Chat interfaces do not put a hidden character in every paragraph. Do not end the review because the character count is zero.

Pass 2: the file, not the paste

Images are where brands get surprised. A writer generates a header in ChatGPT or Firefly, downloads a PNG, and the file carries Content Credentials plus, for OpenAI images, a SynthID signal in the pixels. Your CMS may strip the manifest on resize and keep the pixels, or it may display a “made with AI” treatment if it reads C2PA. Check the original upload with the images tab before you resize it.

Document exports deserve the same pass. DOCX and PDF metadata can name a generator even when the sentences were later rewritten by hand. Markdown front matter sometimes still says generator or ai_generated because a script put it there. None of that is the text watermark. All of it is visible to a buyer who bothers to look, and some of it is visible to a platform.

If the commercial question is “will this asset announce itself as model output on a site that reads credentials?”, you want the original file, a check, and a decision. Stripping a manifest you are required to keep is a disclosure problem, not a production shortcut. Stripping a stale tag on a photograph you took yourself is a different decision. The C2PA guide covers that split.

Pass 3: the statistical watermark

This is the pass most “AI watermark checker” landing pages pretend to sell, and it is the one a private editor usually cannot run. OpenAI’s textGrain detector is not on the public verify page. That page takes images and audio. Text-detector access is an application process for qualifying organizations. Turning watermarking on in your own API project, if you even have one, does not hand you detection.

What you can know without the key is whether a watermark was even likely to have been applied. Work through the 2026 coverage rules with the writer’s own account of the tool:

If you do get access to a vendor detector later, read a hit narrowly. OpenAI says a detection means an OpenAI model likely generated or processed the content. It does not name the user, the prompt, or the share of the article a person wrote. A miss does not mean the draft is human. Both limits are the subject of what a missing watermark means.

Where style scores fit

A GPTZero-style score is tempting because it returns a number the same day. It answers “does this resemble the model’s training neighborhood?”, which is not “does this carry a watermark?” The difference is laid out in ChatGPT watermark versus an AI detector. For a commercial edit, the score is a prompt to ask a question, not a reason to void an invoice on its own.

False leads are ordinary in this genre. A writer who learned the web’s cadence, a translated post, a post assembled from your own style guide, and a post that a model only outlined can all land in odd places on a classifier. So can a post that was fully generated and then line-edited by a careful person. Pair the score with the intake note and with the sources. If the sources do not exist, you have an editorial problem that no watermark would have fixed.

Institutional classifiers such as Turnitin are the wrong tool for a publisher unless you already license them and your agreement allows the upload. They still do not read textGrain. That limit is specific enough to have its own page: can Turnitin detect ChatGPT watermarks.

What a contract can require

A detector clause that says “the work must pass an AI checker” is not enforceable in any precise way, because the checkers do not agree and the watermark key is not yours. Clauses that survive contact with production are plainer:

The character and metadata clauses are checkable today with the tool on this site. The disclosure clause is checkable by reading. The watermark clause is checkable only if you later obtain the relevant vendor detector, and even then only as evidence of processing, not as a byline.

What to do before you hit publish

Run this sequence on the version that will go live, not on the pitch sample.

  1. Read the piece. If the reporting is thin, stop. A clean scan will not add sources.
  2. Scan the text for invisible characters. Clean them if they are present and the words should stay.
  3. Scan images and document files for C2PA and AI metadata. Decide, under your disclosure rule, whether the credential stays.
  4. If your house uses a style detector, record the score next to the disclosure note. Do not let the score overwrite the note.
  5. Keep the pre-clean original for a short window so you can show what the file contained.

Publishers who want a map of the free tools in that sequence, and of the tools that only look like they belong in it, can use the comparison of free AI watermark checkers. The mechanism behind the wording mark, if a client asks how it can be invisible and still real, is how the OpenAI text watermark works.

Check text or a file you are allowed to publish →

A note you can file with the draft

Detection arguments fall apart when the only record is a Slack reaction. File a short note with the asset. It takes longer to describe than to write:

That note is what a client can read six months later. “We checked the watermark” is not. If the note says the character count was zero and no manifest was present, it does not say textGrain was absent. Leave that sentence out unless an approved detector actually ran. The reasons a missing mark misleads are in what a missing watermark means.

Images are a separate contract

Writers treat a header image as part of the post. Provenance treats it as a different object. A paragraph can be unmarked API text beside a PNG that carries both Content Credentials and a pixel watermark. Your CMS thumbnail pipeline may strip the manifest and keep the pixels, which is how a badge vanishes while the picture stays identifiable to a vendor tool. Ask for the export before your pipeline touches it, and run the images tab on that export.

Alt text and captions are text, so they follow the text rules. A caption generated in a marked ChatGPT session is a short specimen. OpenAI’s own floor, about 200 tokens before the code of practice expects a mark, means a caption often will not carry a reliable text watermark even when the body essay would. Do not clear the essay because the caption scanned quiet, and do not accuse the caption because a classifier disliked a twelve-word line.

Stock sites and illustration tools add more manifests. Firefly, Designer, and ChatGPT images are not one credential. The signed claim, when it is still in the file, is what Content Credentials Verify displays. Read the claim. “AI” is not the only thing a manifest can say. Cameras sign files too. The distinction is in the C2PA guide.

FAQ

Can I detect a ChatGPT watermark inside a Google Doc?

Not textGrain. You can scan the paste for hidden characters and you can export a file to look for document metadata. The statistical watermark needs OpenAI’s detector.

Does a clean scan mean the writer did not use a model?

No. It means the carriers you checked were absent. Most model drafts have no hidden characters.

What should the writer send?

The draft you will publish, original image exports, and a disclosure if your agreement requires one.

Is a style score enough to reject a draft?

On its own, no. Use it as a question beside sources and the disclosure. A watermark hit, if you ever get one, is evidence of processing, not a full account of who wrote each sentence.

Related: Claude, Gemini, and ChatGPT marks compared and the article index.

← All AI watermark guides