OpenAI and Anthropic are putting invisible watermarks in text. Here's what they can and can't catch.
Both companies now embed hidden signals in generated text to meet the EU AI Act. The signal is easy to weaken, and nobody outside a small group can check it yet.

Until this month, you could not tell from the text alone whether a chatbot had written it. That is about to change for two of the biggest AI companies, because the EU AI Act says generated text has to be marked in a form a machine can read. OpenAI and Anthropic both answered, in slightly different ways.
What is actually being added?
Both companies put a statistical signal into the words a model picks. You can’t see it, and it doesn’t change the meaning. OpenAI calls its version textGrain. Anthropic says its text watermark is applied at the model level, so it goes with the text wherever the text is copied.
Anthropic’s support page says the watermark covers every surface where Claude runs, including the API, Claude Code and cloud partners on AWS, Google Cloud and Microsoft Foundry. It also says models released before 2 August 2026 are being added to the scheme, and the page lists the Sonnet 5.5 and Haiku 5.5 models among those that already carry marks.
OpenAI’s plan is narrower. Over the coming weeks, ChatGPT and Codex text will carry the watermark for users in the European Union only. API customers can turn it on, but it is off by default. OpenAI says it isn’t making the watermark a global default at launch.
Why does the EU setup look so different?
The gap is the most interesting part. Anthropic’s marks apply everywhere Claude is offered. OpenAI’s apply to ChatGPT in the EU, and to API traffic only when a developer opts in. Both companies are meeting the same law with different amounts of coverage.
I’d read that as a sign that nobody is sure what “marked” should mean in practice. The law asks for machine-readable marks. It doesn’t say how strong they have to be, or whether a company has to offer a detector.
How well does it survive editing?
Not very well. The Decoder reported the figures from OpenAI’s technical write-up. On 400-token passages, the detector found about 94 percent of watermarks in psychology text but only about 60 percent in math, where the model has fewer word choices to work with. On shorter passages of 200 tokens, the psychology rate fell to about 80 percent.
Editing hurts more. According to the same figures, swapping 10 percent of words for synonyms dropped detection on 400-token passages from about 92 percent to 66 percent. Swapping a quarter of the words brought it down to 17 percent. I could not open OpenAI’s full technical report, so these are the figures as the Decoder reported them.
That means the mark is a stronger signal for text that is copied as is than for text someone has worked over. A student who rewrites a paragraph in their own words would probably slip past it. The people most likely to be caught are the ones who copy and paste without reading.
Who can check the mark?
Almost nobody yet. OpenAI says only selected researchers and specialist organizations can apply for its text detector, and it will grant access case by case. Anthropic’s detection is in private preview for organizations that the EU rules cover, such as regulators, fact-checkers, researchers and some enterprises.
So for a normal reader, the watermark does nothing visible. A journalist or teacher who wants to test a suspicious essay can’t run it through a public tool. OpenAI also says that a missing mark doesn’t prove a human wrote the text, because the passage may be short, edited, translated, or made by another company’s model.
My take
I don’t think these marks will change much for most people in the short run. They are built to satisfy a legal duty, and the design shows it: the detector is restricted, the marks are fragile, and the companies say so themselves. That is honest, but it also means nobody should treat a “no watermark found” result as proof of anything.
What I’d watch is whether OpenAI opens its detector wider, and whether the open-source release of textGrain that OpenAI promised shows its numbers on real editing. If the marks survive light edits in outside testing, this becomes a real provenance tool. If they don’t, the EU rule will have created a label that only works on text nobody bothered to change.
For now, if you need to know whether a text came from a model, a watermark check is not the tool you have. Ask the person, or look at the document history.
Sources
- OpenAI: Our approach to EU text provenance rules, 5 October 2026
- Anthropic support: How Claude marks AI-generated content, updated October 2026
- The Decoder: OpenAI will watermark ChatGPT text in the EU but makes it optional for API users worldwide, 5 October 2026
- Pivot News: OpenAI brings text watermarking to ChatGPT in the EU, 6 October 2026