Does ChatGPT Watermark Its Text?
No. OpenAI built the technology and decided not to turn it on, and the reason it gave says more about AI detection than the watermark ever could.
No.
Nothing ChatGPT hands you carries a text watermark, on any tier, including the API. Paste its output wherever you like. There is no hidden signal sitting in the words for anybody to go find later.
What makes this worth a whole article is that OpenAI could have shipped one years ago. It built the thing and then left it in a drawer. The reasoning behind that decision turns out to be more useful than the yes-or-no answer, because it is the same argument writers make every time a detector flags work they wrote themselves.
OpenAI had a watermark ready and shelved it
The method is not exotic.
A model picks each word from a ranked list of candidates, and very often the top two or three candidates are equally good. Nudge that pick according to a secret pattern. Repeat across a few hundred words and you get a statistical signature a matching detector can find later, while the prose still reads completely normally to a person.
OpenAI has had a working version of this for a long time. It never shipped, and the reasons were not technical ones.
The first was commercial and fairly blunt. When OpenAI surveyed its users, a large share said they would use ChatGPT less if its output could be traced back to the tool. No amount of policy framing gets around a finding like that.
The second reason deserves far more attention than it got. OpenAI flagged the risk of penalizing people who use the tool as a writing aid, and it named non-native English speakers specifically. Picture a writer working in their second language. They run a finished draft through ChatGPT to fix article usage and preposition choice, and they end up carrying exactly the same mark as somebody who generated the whole piece from a one-line prompt. The mark cannot tell those two people apart. Neither can a detector, which is precisely why false positives in this category have always landed hardest on the writers who could least afford to absorb them.
Then a third problem, quieter than the other two. A watermark that paraphrasing washes out will mostly catch people who were never trying to evade it. Anyone determined to hide runs the output through a second model, or translates it into German and back again, and the signal thins away to nothing. Everyone honest just publishes and gets marked.
What OpenAI marks instead of text
Images, not words.
In May 2026 OpenAI joined the C2PA steering committee and started attaching provenance data to the images its products generate, including Google's SynthID watermark. Pictures are a friendlier problem than prose. You can hide a great deal more signal in several million pixels than in eight hundred words, and an image watermark holds up decently well against screenshots, cropping and recompression.
So the honest summary of where OpenAI stands is short. Pictures get marked. Text does not, and the company has been unusually public about the reasons.
Claude went the other way
On August 11, 2026, Anthropic announced that Claude embeds an invisible watermark in the text it generates. Every Claude model released on or after August 2 ships with it turned on, and the older ones are being retrofitted.
The marking applies worldwide, not only inside the European Union.
Anthropic did this to satisfy the EU AI Act's transparency rules, which became binding on August 2 and require generated content to be machine-readable as generated. The marking happens inside the model, though. A model cannot check your passport before choosing its next word, so every user in every country gets identical treatment.
Coverage is about as wide as it gets. Claude's apps, its API, the coding tools and Claude served through the big cloud platforms all produce marked text. I went through what that mark does and does not prove in more detail, because the distance between those two things is where people are going to get hurt.
Two more pieces fill out the picture. Google has had text watermarking in SynthID for a while, but reading it takes Google's own key, so no public tool can check a passage. And any model running on open weights, on hardware somebody owns outright, will produce unmarked text forever. Regulation does not reach a server sitting in a spare bedroom.
So what does an unmarked document tell you?
Very little. This is the part people keep getting backwards.
Say you have a 900-word article and you want to know whether a person wrote it. Some future tool reports no Claude watermark. Here is what is still entirely possible:
- ChatGPT wrote it, since ChatGPT does not mark anything
- Gemini wrote it, and nothing outside Google can read what Gemini leaves behind in the text
- Somebody ran it on their own hardware
- An older Claude model produced it, one of the many released before August 2026 that never carried a mark
- Claude wrote it, and then enough rewriting or translation happened to break the signal
- A person wrote it
Six possibilities. One of them is the thing you were actually checking for, so a clean result has narrowed almost nothing at all.
The reverse direction is not much better. A mark tells you that a Claude model produced some sequence of words somewhere in the document. Whether the model built the argument, or merely fixed comma splices inside an argument that already existed, it cannot say. Anthropic's own documentation admits this openly, which is more candid than most companies manage about a feature they launched last week.
Researchers have also shown these signals can be forged onto text a model never touched. That attack is not common today. It does mean a watermark hit ought to start a conversation instead of finishing one.
What this means if you write for a living
Stop treating any single check as the answer. Ours included.
A watermark, a detector score and a plagiarism report all measure different things. None of them measures authorship. What answers the authorship question is the record of how a document came to exist, meaning the brief, the outline you abandoned, the source you threw out on Tuesday, the paragraph you cut because it kept doing laps around the point. Boring, specific material that is close to impossible to fake convincingly. Which is what makes it work.
Build it while you write.
Reconstructing all of that three weeks later from browser history is a genuinely bad afternoon, and it shows in the result.
If you use ChatGPT to polish your own drafts, nothing changed for you this month. No mark, no announced plan for one. If you use Claude the same way, your text now carries a signal saying a model touched it, and you should assume somebody will eventually read that signal as something much stronger than it actually is.
The advice lands in the same place either way. Keep the drafts and keep the notes. Get specific about what the tool actually did, because "I used it for an editing pass on the second section" survives a follow-up question and "I barely used it" does not.
The short version of all this
ChatGPT does not watermark text, and OpenAI has explained at some length why it decided against doing so. Claude does, worldwide, on every model from August 2026 onward. Gemini marks text nobody outside Google can check. Open models mark nothing.
That is a patchwork. It is not a system, and anyone telling you a single scan settles whether a human wrote something is selling a much cleaner story than the one that exists.
You can check a draft against a real detector here, see which passages carry the strongest signals, and keep a version history as you revise. A score on its own proves nothing much. Knowing what a reviewer is going to see, before they see it, is worth quite a lot.
