2026 rollout
Does ChatGPT watermark text in 2026?
Sometimes. In 2026 OpenAI’s text watermark, textGrain, applies to eligible ChatGPT and Codex text generated in the EU, and to API text only where a customer has turned it on. It is not a mark on every past chat, and it is not a hidden character you can highlight.
The primary sources are OpenAI’s note on EU text provenance and the provenance help article. This page is the coverage map. The mathematics of the mark is how textGrain works. The legal duty it is answering is what the EU AI Act asks for.
The short answer by product
| Path | Text watermark in OpenAI’s 2026 description |
|---|---|
| ChatGPT and Codex text generated in the EU | textGrain on eligible text, rolling out over the weeks after the announcement. Not a rewrite of old chats. |
| ChatGPT outside that EU path | Not described as a global default at launch. |
| OpenAI API, any region | Off unless the project or the organization opts in and selects models. |
| Images from ChatGPT, Codex, or the API | Not textGrain. Content Credentials plus SynthID. |
| Audio | SynthID in the audio. Not a text mark. |
| A paste that contains a zero-width space | A clipboard artifact. Separate from textGrain. See hidden characters. |
If a blog still says “ChatGPT does not watermark text,” it is describing the world before this rollout, or it is talking only about hidden characters. Both readings were common. Neither one is a complete account of 2026.
ChatGPT and Codex in the EU
OpenAI says it is watermarking ChatGPT text in the EU to comply with the EU AI Act and the transparency code of practice it signed with other providers. The public note says eligible ChatGPT and Codex text generated in the EU receives the mark over the coming weeks. “Eligible” is doing real work. Coverage can vary by product, model, export path, and the date the text was created. A screenshot of a conversation from earlier in the year is not pulled back and stamped.
The mark is in the wording. OpenAI’s help text is explicit that copying the text does not introduce hidden material, and that the watermark does not add watermark-only tokens. A reader in Brussels and a reader elsewhere see the same sentences. The difference is whether a detector with the key would recognize the pattern.
Codex is included in the same sentence as ChatGPT for EU text, with the same caveat that code is a weak carrier. OpenAI says short outputs and code are harder, and points at the code of practice, which does not require watermarks under about 200 tokens or on code snippets. A one-line shell fix generated in the EU is not the same object as a long prose answer.
The API, including Azure and other clouds
API customers worldwide can opt in. OpenAI documents two places: organization settings under data controls, labeled text provenance, and a project-level override. The customer chooses which currently listed models are marked. The help text says coverage of legacy models widens over the following weeks. The switch is not a global default at launch, which is the point vendors keep missing when they say “all GPT output is watermarked now.”
Turning the switch on does not include the detector. Detection access stays with the research and academic review. A startup that wants marked output, so its own customers can meet a disclosure rule, still cannot offer those customers a textGrain verdict unless the startup itself is approved for detector access.
Cloud and distribution partners are a separate sentence in the help article. OpenAI says it is working with providers so provenance signals, including watermarks, are embedded in eligible outputs, and that availability may vary by output and by partner. “We use Azure OpenAI” is not, by itself, “this string is marked.” The project still has a setting, and the partner still has a rollout.
Writing products that resell the API inherit whatever that project chose. A freelancer using a blog-drafting app may be generating marked text without seeing the word textGrain. The editor’s checklist for that situation is how to check a blog writer.
Images, audio, and video are a different stack
People who download a picture from ChatGPT and ask “is the watermark on?” are usually asking about a file, not about a paragraph. OpenAI’s table for that file is Content Credentials and SynthID, including API images, with stated exceptions for models it lists as headed for deprecation. Audio generated by ChatGPT or the API carries a SynthID watermark in the audio. Video is called out separately; the help article points at the Sora discontinuation note rather than a text-style mark.
Those signals are what openai.com/verify is built to read. Text is not on that form. Mixing the rows is how a clean essay gets described as “OpenAI said it isn’t AI” after someone uploaded a PDF export that never contained SynthID.
When marked text still will not detect
Coverage and detectability are different. A reply can be in scope and still be a poor specimen:
- Very factual answers, math, and text the model was told to reproduce have little room to vary the next token.
- Short passages do not contain enough scored positions. The code-of-practice floor OpenAI cites is about 200 tokens, near 150 English words.
- Code has fewer plausible next choices than prose.
- Languages differ. OpenAI published a spread across the 24 official EU languages, from Spanish at 69.0 percent to Romanian at 42.2 percent at a 1 percent false-positive rate, before they strengthened the weaker languages.
- Substantial paraphrasing, translation, or rewriting can drop the pattern below the threshold. Light copying is what the scheme is meant to survive.
OpenAI also says that on the benchmarks it reported, watermarking did not move quality outside ordinary run-to-run noise, and that earlier ChatGPT tests did not show a change in thumbs-down rates. A marked answer is not supposed to read as marked. If you can “see” the watermark, you are seeing something else, usually a formatting glitch or a hidden character.
Older chats and unofficial wrappers
Text created before the signal existed is unmarked, even if you paste it today. Text from an unsupported product or model is unmarked. Text that traveled through a browser extension, a note-taking app, or a human editor may be a mixture: some paragraphs from a marked session, some typed, some from a second model with a different mark or none.
Unofficial wrappers and “free GPT” sites are not the API setting. They may be a scraped interface, a different model, or a cache of old answers. Nothing on this page certifies those strings. If you need a yes or no for a file you generated yourself through the official API, the honest method is to know whether the project switch was on at generation time, and to keep the original text if you later obtain detector access.
What you can see without the key
You can see whether a paste picked up invisible Unicode, and whether a file picked up C2PA or AI metadata. That is the ChatGPT watermark detector on this site. It will return a count. It will not return “textGrain: present,” and a zero count does not mean the EU switch was off.
You can also read the negative correctly. No detection, once someone with the key has actually run it, still does not prove a person wrote the draft. The reasons are collected in what a missing watermark means. Until that detector is available to you, the absence of a public result is even weaker: it means you did not run the test.
Check listed carriers on text or a file you own →Other labs are on different schedules. Claude’s public description is a SynthID-Text watermark on covered models globally, plus C2PA on supported files. Gemini has used SynthID-Text in Google’s own account since the 2024 research deployment. The comparison is Claude, Gemini, and ChatGPT. Assuming “if ChatGPT is marked, they all are, the same way” will mis-file a draft.
What changed since the 2023 rumors
For two years, “Does ChatGPT watermark text?” had a folklore answer. A paper from Kirchenbauer and colleagues had shown that a green-list sampler could work. Scott Aaronson had described a related idea. OpenAI had talked about detection and then not shipped a public text detector. Blog posts filled the gap by pointing at zero-width spaces, which are real and which are not a sampling watermark. That folklore is why this site’s older pages had to separate characters from statistics before textGrain had a public name.
The 2026 documents replace the rumor with a product boundary. There is a name, textGrain. There is a technical report. There is a help-center table that says EU ChatGPT text, API opt-in, images and audio on a different stack. There is an explicit denial that hidden characters are the method. There is an explicit denial that the public verify page scores essays. If you are updating an old internal FAQ, replace “OpenAI does not watermark text” with the table at the top of this page, and replace “hidden characters are the watermark” with a link to the character guide.
What did not change is the key. The public still does not get a paste box that returns a textGrain probability. Classifier sites still occupy the search results for “detector.” A style score in 2026 is not more of a watermark than it was in 2023. The comparison with AI detectors is the page to send to someone who thinks the new rollout made GPTZero official.
What an engineering team should record
If you run the API, the watermark is a configuration fact, not a property you can recover from the string later unless you have the detector. Write it down at generation time.
- Whether organization default text provenance was on, and whether the project overrode it.
- Which model ids were selected. The help text says the list of eligible models grows, including legacy models over the following weeks.
- The date. Text from before the switch is unmarked even if you replay the prompt after.
- Whether the output was prose, code, or a short tool call. Do not promise a detectable mark on a 40-token JSON blob.
- Whether a second system, such as a translation pass or a humanizer a PM added, rewrote the tokens after the fact.
Store that beside the completion id your logs already keep. When a customer asks “was this marked?”, the answer is the setting, until the day you have detector access and can score the stored text. Scoring a later edit and blaming the model is the failure mode in what a missing watermark means.
Consumer ChatGPT is harder to log, because the end user may not know which region path they hit. If the text matters, keep the original paste and the account region rather than a screenshot. Screenshots drop Unicode and cannot carry textGrain in any form a detector can read back from the image. They can carry an accidental photograph of the words, which is not the same object.
FAQ
Does every ChatGPT reply in 2026 contain a watermark?
No. EU ChatGPT and Codex text is the path OpenAI describes as being marked. The API is opt-in. Old chats are not retroactively marked.
Are hidden characters the watermark?
No. OpenAI says textGrain does not insert hidden characters. A zero-width space is a separate paste issue.
Can I opt in on the API without getting the detector?
Yes. OpenAI says those are separate. The switch marks output. Detector access is a review for qualifying organizations.
Does the public verify page accept text?
It accepts supported image and audio files. It does not score an essay.