Lotu Radar About

OpenAI brings text watermarking to its API — and unlike Anthropic, it’s off by default

The New Stack Cloud & Infrastructure Score 7/10
OpenAI brings text watermarking to its API — and unlike Anthropic, it’s off by default

Summary

OpenAI has announced that developers can now opt in to watermarking text generated through its API, as the company extends The post OpenAI brings text watermarking to its API — and unlike Anthropic, it’s off by default appeared first on The New Stack .

Original Text

OpenAI has announced that developers can now opt in to watermarking text generated through its API, as the company extends its existing content provenance efforts to one of the more difficult forms of AI output to reliably identify.

In a blog post published on Monday, the company details a new system dubbed textGrain, which embeds a “statistical signal” into generated text by subtly influencing the words a model chooses — for example, favoring one suitable word over another when either would make sense in a sentence. Over a long enough passage, those choices form a pattern that OpenAI’s detector can identify.

API customers worldwide can enable watermarking on supported models from today, and in the coming weeks, OpenAI says it will begin automatically watermarking eligible text produced by ChatGPT and Codex in the European Union (EU). This is in response to new transparency requirements under the EU AI Act.

“Starting today, API customers globally will be able to opt in to text watermarking for select models. Text watermarking will remain off by default in the API,” the company writes. “This lets customers decide how watermarking fits their transparency obligations and the experiences they provide to users.”

“Text watermarking will remain off by default in the API. This lets customers decide how watermarking fits their transparency obligations and the experiences they provide to users.”

Differing approaches from OpenAI and Anthropic

It’s worth noting that OpenAI’s approach differs from that Anthropic outlined when it announced text watermarking for Claude in August. Anthropic said it would apply watermarking globally to supported Claude models, explaining that it didn’t yet have a reliable way to limit the technology by region. That watermark also extends to developers using Claude through its API, as well as other products such as Claude and Claude Code.

Anthropic doesn’t describe an equivalent opt-out for API developers, giving developers less control over whether their model output carries the watermark.

“Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from,” the company confirms in its documentation.

For OpenAI API customers that do want watermarking, it can be activated at either the project or organization level, with customers able to choose which supported models should use it. The company says no changes to individual API requests are required once it’s enabled.

OpenAI’s provenance track record

OpenAI already uses several provenance technologies for other types of generated content. Back in 2024, it began adding Content Credentials to generated images, using an open standard developed by the Coalition for Content Provenance and Authenticity (C2PA) to record information about a file’s origin and history.

It later added Google’s SynthID watermarks to supported images in May 2026 and audio in July, and now offers a Content Provenance API for checking supported images and audio for those signals.

OpenAI could feasibly have used an existing text watermarking technology such as SynthID, while Meta has developed its own TextSeal method too. On its FAQ page, OpenAI says it developed textGrain to give it “more control….over the balance between watermark detectability and the variety of responses generated from the same prompt.” Indeed, it says textGrain matched or exceeded SynthID’s detection performance in its testing, and plans to open-source the technology so “others can build on it and help improve text watermarking.”

“Code is also harder to watermark”: Where the signal fades

The technique comes with some limitations, however. Because textGrain creates its signal through the choices a model makes between suitable words, detection becomes more difficult when there are fewer choices available.

OpenAI says its detector catches around 80% of watermarked 200-token passages, and 95% of 400-token passages in domains such as psychology, at a target false-positive rate of 1%. And detection is lower for more constrained material such as mathematics.

Impact of text length and type on detection rate (credit: OpenAI)

Editing the output can also substantially weaken the signal. In OpenAI’s tests, replacing 10% of the words in a 400-token passage with synonyms reduced its detection rate from around 92% to 66%. Replacing 25% brought it down to just 17%.

Impact of edits on detection rate (credit: OpenAI)

Notably, OpenAI cautions that shorter passages may simply contain too little material for its detector to reliably identify a watermark.

“Code is also harder to watermark because there are fewer plausible choices for what comes next than in ordinary prose,” the company adds.

“Code is also harder to watermark because there are fewer plausible choices for what comes next than in ordinary prose.”

This makes the forthcoming Codex rollout worth watching. OpenAI plans to automatically watermark eligible Codex text output in the EU, while acknowledging that source code itself is particularly difficult to watermark. The company hasn’t yet explained exactly what it means by “eligible” Codex output, or whether the watermark will apply to generated code itself.

As The New Stack has previously reported, Anthropic has encountered similar limitations with Claude. Code gives its watermarking system fewer opportunities to embed a signal without potentially altering how the program behaves, although natural-language text within code, such as comments, is easier to watermark.

And then there’s also the question of whether introducing those token preferences affects the quality of generated code. OpenAI tested its Astra model with and without watermarking against several coding and agent benchmarks, including DeepSWE, AutomationBench and Terminal-Bench, and says it found no meaningful difference in performance. That suggests textGrain can be enabled without significantly hurting coding ability, although it doesn’t tell us how reliably the resulting code can subsequently be identified as watermarked.

Access to the detector is a separate matter altogether. API customers that opt into textGrain don’t automatically gain the ability to detect its watermark, with OpenAI saying that it’s initially limiting detector access to approved research and academic organizations studying areas including text provenance and detection reliability. Such access could, for example, allow researchers to examine how reliably the watermark survives editing and other transformations, or investigate the circumstances in which the detector produces false positives or misses watermarked text.

The New Stack asked OpenAI for more detail on what constitutes eligible Codex output and whether it has code-specific detection rates. We will update here if, or when, we hear back.

The post OpenAI brings text watermarking to its API — and unlike Anthropic, it’s off by default appeared first on The New Stack.

CloudInfrastructure

Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.