TL;DR: The textGrain Codex watermark is real, but a detector hit on it proves far less than most people will assume. On 5 October 2026 OpenAI said it will hide a statistical mark, called textGrain, inside eligible ChatGPT and Codex text in the European Union over the coming weeks. The API (the programmer’s door to the same models) can opt in worldwide, and that switch is off unless someone turns it on. The mark is not a hidden character. It is a bias in which word-piece the model picks when several word-pieces would have been fine. OpenAI’s own tests say a 400-token psychology passage is often caught, a quarter of the words swapped for synonyms mostly kills the signal, and code is harder because the next piece is often forced. The detector is not public. A hit does not name the person. A miss does not prove a human wrote the code.

What actually shipped on 5 October?

A provider’s mark on some text, not a badge you can see, and not a scanner you can run.
OpenAI’s post that day, “Our approach to EU text provenance rules,” says three product facts. Starting that day, API customers anywhere can opt in to text watermarking for select models, and it stays off by default. Over the coming weeks, eligible ChatGPT and Codex text in the EU, on all plans, gets an invisible watermark. OpenAI is not making that a global default at launch. “Eligible” is their word. The New Stack notes they have not said which Codex outputs count, or whether the mark is even meant for the code itself.
A watermark here means a mark that says “this came from a machine,” not a logo in the corner. Provenance means where something came from. Text provenance means a way to ask that question about a paragraph. OpenAI already had public tools for images and audio. Text is the new, weaker one.
The detector (the program that looks for the mark) is not in the product. OpenAI is taking applications from approved researchers and expert organizations. It reports whether an OpenAI watermark is present. It does not name the user, the prompt (the message you typed), or the conversation. Opting in on the API does not hand you that detector.
What is a watermark, before any of the AI words?
On paper, a watermark is pressed into the sheet while the sheet is made. You do not stamp it on afterwards.
Hold an old page up to the light and a pale picture sits in the fibers. The ink on top of the page is a separate thing. The picture below shows that idea: the mark lives in the paper itself, not in the ink on top.

A screen has no fibers. If you add a character, a reader can see it, and a copy can delete it. So a text watermark has to be made of the words themselves. OpenAI’s Help Center says textGrain does not add hidden characters, invisible spaces, or odd punctuation. Copy and paste does not insert a secret payload. If the wording survives, the pattern survives. If you rewrite the wording, you are tearing the paper.

What is a token, and why does the next one have odds?
A model does not commit to a sentence and then type it. It picks the next small chunk, then the next, then the next.
That chunk is a token (often a whole word, often a piece of a word, like “ing”). The vocabulary is every token the model is allowed to pick. At each step it assigns a likelihood (a chance, from almost none to almost certain) to each of them. The list of those chances is the next-token distribution. Sampling means actually picking one, using randomness, instead of always taking the top.
Sometimes the chances are spread out. “The cat sat on the ___” can honestly continue with mat, floor, or rug. That spread is slack: room to choose without breaking the sentence. Sometimes one token has almost all the chance. After return user. the token id may be the only one that still means the same program. Entropy is the number that measures that spread. High entropy means many decent next tokens. Entropy near zero means the next token is forced.
textGrain spends a budget of that entropy. The technical report’s title is “Entropy-Calibrated Watermarking.” Calibrated means they set the budget on purpose, instead of nudging as hard as they can.

The bars above are a teaching picture, not OpenAI’s measured odds for those words. The shape is the point. Prose has slack. A precise line of code, or a math answer, often does not. OpenAI’s Help Center says the same thing in its own words: code is harder to watermark because there are fewer plausible choices for what comes next than in ordinary prose. The same page says short passages usually do not hold enough text for reliable detection.
How does the secret key change the pick?
A secret key is a password the detector also has. It is not written into your file.
The Help Center gives the steps without the paper’s math, and those steps are the ones to remember:
- At each step the model assigns a likelihood to every possible next token.
- The watermark builds several adjusted lists. Each list favors different choices, using the key.
- The lists are balanced so that, averaged together, they match the model’s original likelihoods.
- The key selects one list. The model then makes a fresh random choice from that list.
- Later, a detector with the same key and the same settings asks whether the passage followed that secret pattern more often than chance.
One picked word proves nothing. Chance picks words too. The mark is the pile of picks.

The 20-page report, by researchers at the University of Pennsylvania, Yale, and OpenAI, says how they keep that nudge from wandering off. They frame the nudge as optimal transport (the math of moving a pile of chances onto a new list at the lowest cost) with a limit on KL divergence. KL divergence, here, means how far the new chances drift from the old ones. They set that drift equal to a fraction of the next-token entropy, so the “strength” knob is a real information budget, not a vibe. To make the math cheaper they do it on blocks of the vocabulary (groups of tokens), and inside a block the original relative chances stay put.
Two sentences from their abstract matter more than the solver. The detector needs only the generated text and the secret key. It does not need to know the budget used while writing, and it does not need the model. And the report says the guarantees assume things that real systems only approximate: a consistent tokenizer (the program that cuts text into tokens), the same block settings, and key values that behave like fresh randomness.
This is not the older classroom version of a text watermark, where someone paints half the vocabulary green and prefers green tokens (a green list). textGrain does not describe itself that way. If a blog tells you to “look for the green words,” that blog is describing a different method.
What do OpenAI’s own tests actually say?
Long, loose English is the easy case. Short text, math, code, and a light rewrite are the hard cases. They printed the hard cases.
A false positive is the detector saying “watermark” when there is none. A false negative is a miss. OpenAI set a target false-positive rate of 1 percent, about 1 in 100 unmarked texts flagged, and then measured how often a real watermark was found.
For psychology-style passages: about 80 percent of 200-token passages, and about 95 percent of 400-token passages. Their Help Center says 200 tokens is about 150 English words. Detection was substantially lower for mathematics, where the wording has less room. The chart on their post uses the ELI5 dataset (short “explain like I’m five” answers) for that length comparison.
Editing: on 400-token passages, replacing 10 percent of words with synonyms dropped detection from about 92 percent to about 66 percent. Replacing 25 percent dropped it to about 17 percent. OpenAI’s line, not mine: strong performance under ideal conditions does not guarantee reliable detection in everyday use.

Do not mix that chart with a second test. The Help Center also reports a check across the 24 official EU languages, at the same 1 percent false-positive target: Spanish at 69.0 percent detection, Romanian at 42.2 percent, the high and the low they name. Those are not the 80 and 95. A mark that is decent in one language can be mediocre in another. They also say the strength knob can be turned per domain or language. They do not say which setting your Codex seat will get.
They say textGrain matched or exceeded other methods they tried, including SynthID for text (Google’s text watermark, also what Anthropic has used). “Matched in our lab” is not “caught in your pull request.”
On quality, OpenAI published a comparison for the Astra model at maximum effort, with and without the watermark, and said they saw no meaningful difference. The tasks include coding and agent benchmarks such as Terminal-Bench 4.0, DeepSWE, and AutomationBench. A one-point swing in either direction is not “watermarking makes Codex smarter,” and Astra-at-max is not automatically the model behind your Codex seat. Read their table before you quote a cell.
So what does the textGrain Codex watermark mean for a Codex diff?
Most of a function is the low-slack case. The comment above it is the high-slack case.
A token like return, ., or id is often the only legal next piece. Swap it for a synonym and the program breaks or the tests fail. There is no honest “rug” instead of “mat.” The Help Center’s code sentence is the whole mechanism, applied to source code (the human-readable instructions that become a program).
OpenAI also says the EU Code of Practice on transparency of AI-generated content does not require watermarks in outputs shorter than 200 tokens, or in code snippets (a short fragment of a program, not a whole essay). That is OpenAI’s summary of the code; the legal wording is in the code itself.
Put those two facts next to the product fact. Codex text in the EU is scheduled to be watermarked. A typical function is short, and it is code. Both are the situations OpenAI says are hard, and one of them is a situation they say the code of practice does not even require. Comments, docstrings (the note in the code that explains it), commit messages, and PR descriptions (the note on a change request) are where the slack is. The New Stack is right to call “eligible” an open question. I will not invent the answer.
Nothing here says you should stuff comments in to “hold” a watermark, or strip them to wash one off. The first makes the code worse. The second is just editing, which OpenAI already says weakens the signal. It is a limitation, not a trick I am recommending.
What a hit does not prove, and what a miss does not prove
OpenAI printed this list so that a detector score would not get promoted into a verdict.
From their 5 October post: a watermark does not measure how much a human contributed. It does not decide ownership, whether a disclosure was required, or who is responsible. It does not identify the user. It does not say the passage is true. And the absence of a detected watermark does not prove a human wrote it. The text may be too short, edited, or translated. It may come from a model they are not marking, from before this rollout, from the API with the switch off, or from another company’s tool.

If a vendor, a teacher, or a compliance form treats “no watermark” as “human-authored,” they are contradicting the company that built the mark.
Which law is this even for?
There are two duties. One is a machine-readable mark. The other, only in some public uses, is a label a person can see. Codex commits are usually the first conversation, not the second.
The EU AI Act is the European Union’s law for AI systems. An article is a numbered section of that law. Article 50 is the transparency section. A provider is the company that puts the system on the market. OpenAI is the provider. A deployer is whoever uses the system in a way that reaches other people. That might be you, if you publish its words.
The European Commission’s FAQ on Article 50 says providers of systems that generate synthetic audio, image, video, or text must mark those outputs in a machine-readable format so they can be detected as artificially generated or manipulated. That is Article 50(2). It applies from 2 August 2026. Systems already on the market before that date get until 2 December 2026 for this marking duty. The FAQ calls that a limited grace period, and only for that duty.
A separate duty, Article 50(4), is about text published to inform the public on a matter of public interest. That one wants a disclosure people can notice. It is not “every function an agent wrote.” A human who reviews the text and takes editorial responsibility can change that public-interest duty. I am not your lawyer, and OpenAI’s Help Center says they cannot tell a customer what that customer’s legal duty is. The split below is the map, not advice on your filing.

The Code of Practice, published 10 June 2026, is voluntary. It is a checklist for meeting Article 50, not a second statute. OpenAI says it signed. Signing the code is not the same thing as the Act already being satisfied, and a watermark this fragile does not, by itself, look like the Act’s words “effective, reliable, robust.” OpenAI’s own post is unusually frank about that gap. That frankness is the useful part.
What should you do this week?
Match the surface you actually use. Do not run a detective experiment you cannot run.
If you use ChatGPT or Codex outside the EU, OpenAI says this is not the global default. Nothing in your files changed on 5 October because of this post. Do not tell a client that unmarked code is therefore human.
If you use them inside the EU, expect the coming weeks to start marking eligible text, on every plan. A long design doc or a PR write-up is the realistic carrier. A 30-line function may carry little or nothing, and OpenAI says a code snippet is not in the “must watermark” line of the code of practice. Do not promise a customer that their EU Codex output is marked. “Eligible” is still undefined in public. If your Codex work arrives through an OpenAI dots cloud computer task, the same open question applies.
If you ship a product on the OpenAI API, the switch is yours, it is off, and it is for select models. Turning it on is a product decision about your users’ output. It does not give you a scanner for those users’ essays. The detector stays with approved research groups. The Decoder reports that cloud partners, including Microsoft Azure, are to follow in the coming weeks.
If someone waves a detector score at you, ask three things before you believe a story. What false-positive target was it set to? How long was the passage, and was it prose or code? Was the text edited, translated, or only partly from OpenAI? A 1 percent false-positive target means a clean page can still light up.
The report says it will be updated, and that OpenAI plans to open-source the method.