OpenAI has introduced a text watermarking system called textGrain, aimed at making it possible to identify whether a passage was produced by an OpenAI model without leaving visible marks in the writing itself. According to the source article, global API customers can enable the watermark starting today, while ChatGPT and Codex will add support in the coming weeks.

That would raise the odds that AI-generated homework, resumes, or work reports could be flagged if they are copied and pasted without changes. The article lists four main points from the release: the feature is live for API users; with the false positive rate set at 1%, more than 90% of 400-token psychology responses can be detected; GPT-6 Astra shows little performance loss after watermarking, with five of eight core benchmark scores slightly higher; and the detector is not open to the public, with access limited for now to approved researchers and professional institutions, while textGrain itself will be open-sourced.
The article adds that Google, Anthropic, and OpenAI have now all deployed systems meant to attach a form of provenance to AI-generated text.
How textGrain embeds a watermark without making the text look different
Large language models generate text one token at a time. Before each token is produced, the model assigns probabilities to candidate words and then samples from that distribution. The article uses the example of the phrase “The morning was ___,” where “warm” has a 30% probability, “cold” has 25%, and the remaining options split the rest.
textGrain changes that sampling step in a way that follows a secret key, but it is built around a strict requirement the article calls “unbiasedness.” Averaged across all possible keys, each candidate word must keep exactly the same probability it had before. For anyone who does not know the key, the output still looks like ordinary random text, and the model’s intended meaning is not directly rewritten.
The article says an earlier watermark developed at OpenAI by Scott Aaronson satisfied that unbiasedness condition but had a drawback: with the same prompt and the same key, the model could keep choosing the same token at each step, making repeated answers to the same question nearly identical.

A 1781 earth-moving problem reappears in AI text watermarking
The solution behind textGrain comes from optimal transport. The article traces that line of math back to 1781, when French mathematician Gaspard Monge studied how to move a pile of earth into another hole at the lowest total transport cost. In the 1940s, Soviet mathematician Leonid Kantorovich relaxed the setup so one unit of earth could be split and sent to multiple destinations as long as total quantities matched, turning the problem into linear programming. Kantorovich later shared the 1975 Nobel Prize in Economics with Tjalling Koopmans for work on optimal resource allocation.
The article notes that one of the report’s authors, Yale economist Xiaohong Chen, now holds a chair named after Koopmans. It also points to later milestones: Fields Medal winner Cédric Villani connected optimal transport with geometry, probability, and partial differential equations, and in 2013 Marco Cuturi introduced entropy regularization and the Sinkhorn algorithm, making the computations much faster and helping optimal transport become a standard tool in machine learning.
In textGrain, what gets “moved” is not earth but probability mass over the next token.
The core idea: a fixed “randomness budget”
The article says textGrain works by assigning the watermark a “randomness budget.” The paper proves an identity under which the extra correlation created between token choices and the secret key is exactly equal to the average randomness the model gives up. In other words, every gain in statistical detectability comes at an equal cost in randomness.
That lets OpenAI set a ratio in advance to cap how much of the model’s original randomness the watermark is allowed to consume. The article gives an example of a budget set at 0.2, which would preserve at least 80% of the original randomness on average and leave that portion available for response diversity.

The process is described in three steps.
First, the key and the preceding context randomly divide candidate words into groups, and the probabilities inside each group are added together. In the example shown in the article, six words are split into three groups: “warm, calm” with 0.40, “cold, sunny” with 0.35, and “mild, bright” with 0.25.
Second, OpenAI prepares four different biased plans. The key generates a random score for each group-plan cell, and entropy-constrained optimal transport then shifts probability mass toward higher-scoring cells, using the Sinkhorn algorithm to repeatedly correct rows and columns until the budget is exhausted. Averaged across the four plans, each group still keeps its original probability of 0.40, 0.35, and 0.25.
Third, the key selects one of those plans. In the article’s example, the second column is chosen, lifting the probability of the “cold, sunny” group from 0.35 to 0.69. A token is then sampled within that group using the original 25-to-10 ratio, and the model outputs “cold.”
To anyone without the key, that still looks like an ordinary draw. To someone holding the key, it reveals which group the step was supposed to favor.

Detection needs only the text and the key
At detection time, the article says the question is simple: do the token choices in a passage repeatedly land, by apparent coincidence, on positions favored by the key?
For ordinary human-written text, there is no relationship to the key, so the score at each position is random and the total score falls within a probability distribution that can be calculated exactly. Watermarked text, by contrast, lands on high-scoring cells more often, pushing the total score unusually high.
According to the article, the detector needs only the text and the key. It does not need the model itself, and it does not need to know what budget was used during generation.
OpenAI says model quality is largely unchanged
The article says the watermark does not make the model noticeably worse. Across eight benchmarks for GPT-6 Astra, five scores rose slightly after watermarking, while the largest decline was just 1.12 points. Tests inside ChatGPT also showed almost no change in user downvote rates.
OpenAI also said that with the false positive rate fixed at 1%, more than 90% of 400-token psychology responses can be detected, and it claimed the result matches or exceeds Google’s SynthID.

A research team spanning OpenAI, Penn, and Yale
The source article says the technical report runs 20 pages and includes four university-affiliated scholars among nine authors whose backgrounds span statistics, economics, optimization, and machine learning.
First author Xiang Li completed both his undergraduate and doctoral studies in statistics at Peking University under Zhihua Zhang. The article says his recent work has focused on text watermarking and evaluation for large models, and that he will join the statistics department at Rutgers University as an assistant professor in January next year.
Qi Long of the University of Pennsylvania is described as a biostatistician who came from the Special Class for the Gifted Young at the University of Science and Technology of China and now leads Penn’s Institute for Biomedical Informatics.
At Yale, Xiaohong Chen is a member of the American Academy of Arts and Sciences and shared the 2017 China Economics Prize with Gregory Chow. Gang Wen is a fifth-year PhD student in Yale’s Department of Statistics and Data Science, a Peking University mathematics graduate, and has worked with Weijie Su since 2021 on high-dimensional probability and random matrices.
Among the OpenAI authors, Qingquan Song is part of the foundation models team and is one of the authors of the open-source tool Auto-Keras. Arzav Jain and Florent Joly both worked on ChatGPT search, according to the article.

The corresponding author tying the group together is Weijie Su. The article says he formally joined OpenAI in May this year while remaining a professor of statistics and data science at the Wharton School of the University of Pennsylvania. Su entered Peking University’s School of Mathematical Sciences in 2007, ranked first in his major there, won the all-around gold medal in the first S.-T. Yau College Student Mathematics Contest, and later earned a PhD in statistics at Stanford under Emmanuel Candès.
The article adds that Su’s work spans statistical machine learning, high-dimensional inference, optimization, and privacy protection. It says ICML 2023 used his “rank-preserving mechanism” in an experiment where authors ranked their own submissions to calibrate review scores. In February this year, he received the COPSS Presidents’ Award, and the first point in the citation mentioned the statistical foundations of generative AI, including watermarking research.
Access to the detector is still restricted
The article closes with the practical question many users care about most: whether personal use of AI writing can be detected.
Its answer is that copying AI output verbatim does carry risk. A few hundred consecutive words may be enough for the detector to identify the passage. Still, the people who can use such tools are not, at least for now, ordinary teachers or HR staff. According to the official notice cited in the article, OpenAI’s detector is available only to approved researchers, while Anthropic’s tool is limited to regulators, media organizations, researchers, and educational institutions.
Even with access still restricted, the article argues that the direction is already clear. ChatGPT is used by 1.2 billion people every week, and as more text comes from models, Google, Anthropic, and OpenAI have all chosen to embed provenance directly into the text itself.

The article ends on a narrower point: a watermark can show that a passage came from AI, but it cannot prove that a passage came from a specific person. In that sense, the claim “I wrote this” may also need evidence in the future.
Sources cited in the article
OpenAI: eu-text-provenance
OpenAI technical report: textgrain-entropy-calibrated-watermarking-for-language-model-text.pdf
Original Chinese article credited to the WeChat account Xinzhiyuan, written by ASI Qishilu and edited by Moses

