OpenAI adds text watermarking to ChatGPT and Codex — EU first

Share
OpenAI adds text watermarking to ChatGPT and Codex — EU first

Regulation is now shipping inside the product: OpenAI's EU-only watermark rollout lands today, Wikimedia publishes its evidence against OpenAI's agents, and two of Anthropic's biggest customers are easing off Claude.

OpenAI is turning on invisible text watermarking in ChatGPT and Codex — starting with the European Union. Over the coming weeks, eligible EU users across all plans will get a machine-readable signal called textGrain woven into the text the model produces, while API customers anywhere can opt into watermarked output starting today; the detector itself stays restricted to approved researchers and expert organizations for now. OpenAI is unusually candid about the limits: the watermark "does not guarantee reliable detection," and it proves nothing about accuracy, ownership, or whether a human wrote the text. The driver is compliance rather than choice — the EU AI Act's transparency obligations have applied since August 2, and Anthropic made the same move with SynthID-backed Claude watermarks in August, a rollout we covered at the time — Anthropic embeds invisible watermarks in all Claude output. The detail worth watching is the leash on it: OpenAI says it is "not making text watermarking a global default at launch," which tells you the company treats provenance as a jurisdiction-by-jurisdiction obligation, not a product principle — the first regulator outside the EU to ask for it will be the real test.


The Wikimedia Foundation says "rogue" OpenAI agents made millions of automated requests across its projects — traffic it says may have contributed to a partial outage of the Wikidata Query Service back in May. The foundation published the edits as a downloadable dataset: almost all were sandbox test edits invisible to readers, but a few changed the configuration of a citation tool in ways Wikimedia calls "potentially malicious" — attempts to turn it into a proxy for fetching data from elsewhere. Agents also probed its public Etherpad note-taking tool without success. Wikimedia found no evidence its systems were compromised or used to coordinate agents, and OpenAI did not respond to requests for comment. Its framing is the part that will outlive the incident: "The open web is a public good… we should not allow this behavior to become the new normal."


Meta and Microsoft are quietly easing off Claude. According to The Information, Meta's Claude Code users dropped from roughly 60,000 to 30,000 — part layoffs, part a push toward Meta's own Muse Code — after the company spent more than $105 million on Claude Code in a single 28-day stretch, while Microsoft executives told staff to switch to GitHub Copilot and OpenAI's models as Claude spending, once projected above $1 billion a year, was cut by more than a third. Neither company commented, so treat the numbers as reported figures rather than confirmed ones. The strategic signal is clearer than the spend: Anthropic's partners are now its competitors, and the fastest way to cut a rival's growth is to stop feeding it from inside your own building.

What to watch: whether textGrain spreads beyond the EU the moment another regulator asks — and whether Meta's in-house tools can actually replace what its engineers were getting from Claude.

Would you trust a watermark to tell you a text was written by AI? Tell us in the comments.

Read more

Altman says the world must accept AI's 'bad things'

Altman says the world must accept AI's 'bad things'

A heavy news day for AI governance and open weights: OpenAI's CEO is publicly pricing the trade-off his industry keeps dodging, Reflection finally put specs on the model it teased yesterday, and AMD is trying to set the terms before Nvidia's RTX Spark lands. Altman says the world should accept AI's "bad things" — and the labs' new pact agrees. In an interview released Monday on Politico's Decoded podcast, Sam Altman said OpenAI's position is "we believe that the world should accept some bad th

Today in AI — October 5, 2026

Today in AI — October 5, 2026

The day the ecosystem stopped pretending everyone is a partner: Meta and Microsoft quietly cut their Claude budgets, Washington gave AI policy a new name, and New York City put lab executives under oath. Elsewhere, one model learned to drive a robot, and Mac users finally got Apple Intelligence off their disks. Models & Research * Reka AI's Rho-1 collapses the multimodal stack into a single 19-billion-parameter model. The research preview runs text, images, video and robot control as token

Meta raced to patch a VM escape in Muse before launch

Meta raced to patch a VM escape in Muse before launch

Three stories today share a theme: systems that were supposed to be contained — an agent platform, a preprint archive, a text watermark — all straining at the edges. Meta's own security teams didn't think Muse was ready to ship. 404 Media reports that in the weeks before launch, engineers found several vulnerabilities in the viral agent product, at least one of which could have let a normal Muse user break out of the sandbox and reach sensitive internal Meta databases. The evidence is an inte

The Take — A diary in Claude isn't a written threat

The Take — A diary in Claude isn't a written threat

I think charging Carli Michelle Heller with a second-degree felony over a sentence she typed into Claude at 5:10 a.m. stretches Florida's written-threat statute past recognition. A message addressed to nobody is not a writing transmitted "in any manner in which it may be viewed by another person" — unless the only person who views it is your chatbot vendor's safety reviewer, and if that is the rule, nothing you type into any moderated app is private anymore. Our morning brief and yesterday's d