Over the coming weeks, text written by ChatGPT and by Codex, OpenAI's coding tool, will carry an invisible watermark for people in the European Union on every plan. Developers who use OpenAI's API can switch the same watermark on anywhere in the world for select models, but it stays off unless they do. The tool that checks for the mark goes only to approved researchers and expert organizations.
The mark lives in word choices, so editing wipes it out
Wherever the model could pick between several words that fit equally well, a secret key nudges the choice. It works like a writer who follows a private rule each time they could say "big" or "large". Read a few hundred words with that rule in hand and you would see far more rule-following than chance produces. Nothing is added to the text. The signal is the pattern of choices itself, which is why it is invisible and also why it is fragile.
Change a tenth of the words to synonyms and detection falls from about 92% to 66%. Change a quarter and it falls to 17%. A person who properly rewrites an AI draft changes more than that. Length and subject matter matter too: the detector finds the mark in about 80% of passages of 200 tokens, roughly 150 words and the size of a short email, and in about 95% at 400 tokens. It does worse on mathematics, where there is little freedom in word choice.
A detector is better for counting a crowd than for judging a person
OpenAI set the detector to flag human writing by mistake 1% of the time. That sounds small. A hiring team that checked 500 cover letters written by people would see about 5 flagged wrongly, with no way to tell which ones. The same detector misses most edited AI text. That is a weak basis for accusing anyone, and a good one for measuring a crowd: a platform that checks 100,000 comments does not need any single verdict to be right, only the share that carries the mark.
I expect that is how it gets used. Platforms and researchers will use the mark to see how much of a forum, a review site or a search result is raw machine output, and to rank or filter the bulk. Individuals will gain little from it, and the result for one document will stay a rough signal.
A missing mark proves very little
Anthropic is marking Claude's text everywhere, not only in the EU. ChatGPT's text will carry the mark only for EU users at first. So a paragraph pasted from ChatGPT by someone in Toronto has no mark, the same as a paragraph a person in Paris wrote, the same as a paragraph from another company's tool. OpenAI says itself that a missing mark does not show a human wrote the text. For images and audio, anyone can check whether OpenAI made them. For text, it holds the checker back because of the error rates above.
For someone reading a CV or marking an essay, the practical test stays the old one: ask the writer to talk through what they wrote for two minutes. A person who wrote it, or edited it properly, can do that. The watermark cannot tell you.