In this briefing
- 01Text watermarking becomes a configurable model-output capability
- 02Detection rates vary with text length, content constraints and editing
- 03Regulation separates generation-side marking from publication-side disclosure
- 04A provenance chain needs both system signals and business processes
- →What to watch next
- ↗Sources and verification
- OpenAI allows API customers worldwide to opt into text watermarking for supported models, while it remains off by default; eligible ChatGPT and Codex text output in the EU is due to receive invisible watermarks over the coming weeks, and the detector will initially be available only to approved researchers and specialist organisations.
- OpenAI's own tests indicate that watermarks become harder to detect as text gets shorter, wording becomes more constrained or editing increases; Anthropic also states the coverage and retention boundaries across models, platforms, short text, translation and format conversion.
- EU Article 50 separates providers' machine-readable marking duty from deployers' disclosure duties for deepfakes and certain public-interest text; the Code of Practice is a voluntary instrument, but the regulation's transparency duties are not voluntary.
Text watermarking becomes a configurable model-output capability
On 5 October, OpenAI announced its approach to text provenance. API customers worldwide can opt into text watermarking for supported models, while the API default remains off; customer guidance says the setting can apply to a specified project or across an entire organisation. Over the coming weeks, eligible ChatGPT and Codex text output in the EU will receive invisible watermarks. OpenAI has not made the detector public at the same time, initially accepting applications only from approved researchers and specialist organisations because of risks including false negatives and false positives.
Anthropic's public guidance presents another coverage model: supported Claude models add text watermarks across Claude Platform (API), Claude, Claude Code, Claude Cowork, Claude Tag and some cloud-partner environments, while supported generated files can also carry C2PA content credentials. Coverage is not identical across every model, platform and file type. Its model table also notes that deployment for some Amazon Bedrock output is expected to finish only by 12 October. The two providers' regions, default settings, model scope and detector-access arrangements therefore cannot be treated as substitutes for one another.
For enterprise adoption, content marking needs to form part of the model and channel inventory: the marking state of the same workflow may differ between a direct API connection, employee products, cloud partners and file output, and defaults may differ too. Procurement or integration acceptance cannot merely record that a supplier 'supports watermarking'; it also needs to map the capability to the model version, project or organisation setting, output type, deployment region and detector access before determining whether the actual chain produces a verifiable signal.
Detection rates vary with text length, content constraints and editing
OpenAI describes textGrain as an invisible statistical signal embedded in word choice, with a detector then judging whether the text contains that signal. The technical report uses entropy-budgeted optimal transport to apply keyed randomness to token groups; the watermark is therefore not a fixed label attached to a file, but is linked to the generation-sampling process. OpenAI also stresses the boundary of its findings. Results under ideal conditions cannot guarantee reliable detection in everyday use.
In the provider's evaluation at a target false-positive rate of 1%, about 80% of 200-token psychology passages were detected, rising to about 95% for 400-token passages; performance was substantially lower for mathematical content because fewer wording choices were available. When 10% of synonyms in 400-token English passages were replaced, detection fell from about 92% to 66%, and it fell to 17% when 25% were replaced. Anthropic likewise states that short text, rewriting, translation, mixing with other text, format conversion or screenshots may weaken or remove the mark. These figures come from OpenAI's own testing and cannot yet be treated as a general benchmark across models, languages or independent environments.
For enterprise adoption, watermark detection is closer to an evidence signal with error conditions than a binary judgement of authenticity. Testing needs to preserve language, length, task type, editing and translation paths, while recording both false positives and false negatives; neither a single threshold nor one non-detection can directly prove that content was created by a person, was not processed by a model or meets disclosure requirements.
Regulation separates generation-side marking from publication-side disclosure
The European Commission says the transparency duties in AI Act Article 50 apply from 2 August 2026. On the provider side, the focus is on making generated or manipulated audio, image, video and text detectable and marked in a machine-readable format, with technical solutions considering effectiveness, interoperability, robustness, cost and the state of the art so far as technically feasible. On the deployer side, the focus is on deepfakes and AI-generated or manipulated text published to inform the public about matters of public interest.
For public-interest text, the boundaries listed by the Commission include content that has undergone human review and for which a natural or legal person holds editorial responsibility. The Code of Practice organises providers and deployers into separate strands to help demonstrate compliance. Joining the Code is voluntary, but the legal duties in Article 50 are not. Providing a watermark through a model service therefore does not automatically prove that an enterprise using the model has completed its publication-side disclosure, human review or editorial responsibility.
For enterprise adoption, records of a model provider's technical marking and records of a content deployer's publication governance need to be retained separately. The former addresses whether output carries a machine-readable signal; the latter also addresses the publication scenario, public-interest status, human review and editorial responsibility. The two forms of evidence may support one another, but one watermark check cannot replace either. The precise scope still depends on the regulation, Commission guidance and the facts of the use case, rather than a supplier page's general description.
A provenance chain needs both system signals and business processes
Both providers describe marking as a limited signal. OpenAI explicitly states that a watermark cannot measure human contribution, determine ownership, responsibility or user identity, or verify whether text is accurate; a failure to detect a watermark likewise cannot prove that text was written by a person. Anthropic states that detecting a mark only indicates content may previously have been processed by Claude. The original words or ideas may have come from other sources, and the content may have been modified again after processing.
An enterprise content-provenance evidence chain therefore cannot be reduced to a one-off scan of the final text. A more complete record would connect input sources, the model and version, the marking setting, generation time, subsequent editing or translation, human review and the final publication target; a watermark or C2PA supplements one technical segment, while workflow records describe the business processing that the content underwent. Today's material shows marking capabilities entering product configuration, but does not show that watermarks can independently reconstruct a complete chain of authorship or determine whether content is true.
For enterprise adoption, provenance signals, factual verification and responsibility approval are three separate controls. A watermark may help identify traces of processing by a particular type of model, but it cannot replace citation checks, fact review, permission records or publication responsibility. Only by retaining machine signals alongside a traceable business process may an organisation explain during procurement, audit or dispute handling why a passage appeared, who reviewed it and which transformations it underwent.
What to watch next
- Whether textGrain and other text watermarks will receive published independent false-positive and false-negative testing across languages, text lengths, translation and multiple rounds of human editing.
- Whether different models, API services, employee products and cloud partners can provide a stable, queryable matrix of marking coverage, configuration audit records and detector-access conditions.
- How Commission guidance and subsequent enforcement of Article 50 will define human review, editorial responsibility and deployer duties for enterprise-built generative AI services.
Sources and verification
Golden Data has edited this briefing from the public materials listed above. The original sources govern facts and figures. The enterprise relevance sections are Golden Data editorial analysis and do not constitute an endorsement of any third-party product.
← Back to AI Daily Briefing